Data Protection No. 24 of 2019 [Subsidiary] (d) the number of data subjects or other persons affected by the notifiable data breach; (e) the personal data or classes of personal data affected by the notifiable data breach; (f) the potential harm to the affected data subjects as a result of the notifiable data breach; (g) information on any action by the data controller or data processor, whether taken before or to be taken after the data controller or data processor notifies the Data Commissioner of the occurrence of the notifiable data breach to— (i) eliminate or mitigate any potential harm to any affected data subject or other person as a result of the notifiable data breach; or (ii) address or remedy any failure or shortcoming that the data controller or data processor believes to have caused, or enabled or facilitated the occurrence of, the notifiable data breach; (h) the affected individuals or the public that the notifiable data breach has occurred and how an affected data subject may eliminate or mitigate any potential harm as a result of the notifiable data breach; or (i) contact information of an authorized representative of the data controller or data processor. (2) Where the data controller intends not to communicate a notifiable data breach to a data subject affected by such breach, under the conditions set out in section 43(1) (b) of the Act, the notification to the Data Commissioner under sub-regulation (1) shall additionally specify the grounds for not notifying the affected data subject. PART VII – TRANSFER OF PERSONAL DATA OUTSIDE KENYA 39. Interpretation of the Part VII In this Part, unless the context otherwise requires — (a) “data in transit” means personal data transferred through Kenya in the course of onward transportation to a country or territory outside Kenya, without the personal data being accessed or used by, or disclosed to, any entity while in Kenya, except for the purpose of such transportation; (b) “recipient” means an entity that receives in a country or territory outside Kenya the personal data transferred to the recipient by or on behalf of the transferring entity, but does not include an entity that receives the personal data solely as a network service provider or carrier; (c) “transferring entity” means an entity that transfers personal data from Kenya to a country or a territory outside Kenya but does not include an entity dealing with data in transit; and (d) “relevant international organisation” means an international organisation that carries out functions for any of the law enforcement purposes. 40. General principles for transfers of personal data out of the country A data controller or data processor who is a transferring entity shall before transferring personal data out of Kenya ascertain that the transfer is based on— (a) appropriate data protection safeguards; (b) an adequacy decision made by the Data Commissioner; (c) transfer as a necessity; or (d) consent of the data subject. 41. Transfers on the basis of appropriate safeguards (1) A transfer of personal data to a another country or a relevant international organisation is based on the existence of appropriate safeguards where— 33

Select target paragraph3