(4)
Notwithstanding the provision of sub-Article (3) and (4) of this Article, the transfer of
personal data to a third party jurisdiction that does not ensure appropriate level of
protection is prohibited.
29.
(1)
Conditions for Cross Border Transfer
A data controller or data processor may transfer personal data to a third party
jurisdiction where:
(a) he has given proof to the Commission on the existence of appropriate level of
protection in that third party jurisdiction, and the Commission has made the
determination according to sub-Article (3) of Article 28 of this Proclamation;
(b) the data subject has given explicit consent to the proposed transfer, after having
been informed of the possible risks of the transfer such as the absence of
appropriate level of protection;
(c) the transfer is necessary; or
(d) the transfer is made from a register which, according to law, is intended to provide
information to the public.
For the purpose of sub-Article (1) lit. (c) of this Article, the transfer is necessary where:
(a) the performance of a contract between the data subject and the data controller or
data processor or implementation of pre-contractual measures taken at the data
subject’s request;
(b) for the conclusion or performance of a contract concluded in the interest of the
data subject between the data controller and another person;
(c) for important reasons of public interest;
(d) for the establishment, exercise or defence of a legal claim; or
(e) in order to protect the vital interests of the data subject or of other persons, where
the data subject is physically or legally incapable of giving consent.
(2)
30.
(1)
(2)
31.
(1)
(2)
(3)
Safeguards Prior to Cross Border Transfer
The Commission may request a person who transfers data to a third party jurisdiction
to demonstrate the effectiveness of the security safeguards and the existence of
compelling legitimate interests.
The Commission may, in order to protect the rights and fundamental freedoms of data
subjects, prohibit, suspend or subject the transfer to such conditions as may be
determined.
The Principle of Data Sovereignty
Every data controller or data processor shall ensure the storage, on a server or data
center located in Ethiopia, of personal data collected or obtained locally.
The Commission shall prescribe, based on grounds of strategic interests of the state,
categories of personal data as critical personal data that shall only be processed in a
server or data center located in Ethiopia.
Cross-border transfer of sensitive personal data shall require the prior approval of the
Commission.
15