No. 24 of 2019
Data Protection
[Subsidiary]
(a)
a legal instrument containing appropriate safeguards for the protection of
personal data binding the intended recipient that is essentially equivalent to
the protection under the Act and these Regulations; or
(b)
the data controller, having assessed all the circumstances surrounding
transfers of that type of personal data to another country or relevant
international organisation, concludes that appropriate safeguards exist to
protect the data.
(2) Where a transfer of data takes place in reliance on sub-regulation (1)—
(a)
the transfer shall be documented;
(b)
the documentation shall be provided to the Commissioner on request; and
(c)
the documentation shall include—
(i)
the date and time of the transfer;
(ii)
the name of the recipient;
(iii)
the justification for the transfer; and
(iv)
a description of the personal data transferred.
42. Deeming of appropriate safeguards
For the purpose of confirming the existence of appropriate data protection safeguards
anticipated under section 49 (1) of the Act
and these Regulations, any country or a territory is taken to have such safeguards if that
country or territory has—
(a)
ratified the African Union Convention on Cyber Security and Personal Data
Protection;
(b)
a reciprocal data protection agreement with Kenya; or
(c)
a contractual binding corporate rules among a concerned group of
undertakings or enterprises.
43. Binding corporate rules
(1) The contractual binding corporate rules contemplated under regulation 41 shall be
valid if they—
(a)
are legally binding and apply to and are enforced by every member concerned
of the group of undertakings, or group of enterprises engaged in a joint
economic activity, including their employees;
(b)
expressly confer enforceable rights on data subjects with regard to the
processing of their personal data; and
(c)
fulfil the requirements laid down in sub-regulation (2).
(2) The binding corporate rules referred to in sub-regulation (1) shall specify—
(a)
the structure and contact details of the group of undertakings, or group of
enterprises engaged in a joint economic activity and of each of its members;
(b)
the data transfers or set of transfers, including the categories of personal data,
the type of processing and its purposes, the type of data subjects affected
and the identification of another country or countries in question;
(c)
their legally binding nature, both internally and externally;
(d)
the application of the general data protection principles;
(e)
the rights of data subjects in regard to processing and the means to exercise
those rights;
(f)
the complaint procedures; and
(g)
the mechanisms within the group of undertakings, or group of enterprises
engaged in a joint economic activity for ensuring the verification of compliance
with the binding corporate rules.
34