No. 24 of 2019 Data Protection [Subsidiary] (a) a legal instrument containing appropriate safeguards for the protection of personal data binding the intended recipient that is essentially equivalent to the protection under the Act and these Regulations; or (b) the data controller, having assessed all the circumstances surrounding transfers of that type of personal data to another country or relevant international organisation, concludes that appropriate safeguards exist to protect the data. (2) Where a transfer of data takes place in reliance on sub-regulation (1)— (a) the transfer shall be documented; (b) the documentation shall be provided to the Commissioner on request; and (c) the documentation shall include— (i) the date and time of the transfer; (ii) the name of the recipient; (iii) the justification for the transfer; and (iv) a description of the personal data transferred. 42. Deeming of appropriate safeguards For the purpose of confirming the existence of appropriate data protection safeguards anticipated under section 49 (1) of the Act and these Regulations, any country or a territory is taken to have such safeguards if that country or territory has— (a) ratified the African Union Convention on Cyber Security and Personal Data Protection; (b) a reciprocal data protection agreement with Kenya; or (c) a contractual binding corporate rules among a concerned group of undertakings or enterprises. 43. Binding corporate rules (1) The contractual binding corporate rules contemplated under regulation 41 shall be valid if they— (a) are legally binding and apply to and are enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees; (b) expressly confer enforceable rights on data subjects with regard to the processing of their personal data; and (c) fulfil the requirements laid down in sub-regulation (2). (2) The binding corporate rules referred to in sub-regulation (1) shall specify— (a) the structure and contact details of the group of undertakings, or group of enterprises engaged in a joint economic activity and of each of its members; (b) the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected and the identification of another country or countries in question; (c) their legally binding nature, both internally and externally; (d) the application of the general data protection principles; (e) the rights of data subjects in regard to processing and the means to exercise those rights; (f) the complaint procedures; and (g) the mechanisms within the group of undertakings, or group of enterprises engaged in a joint economic activity for ensuring the verification of compliance with the binding corporate rules. 34

Select target paragraph3