(4) Notwithstanding the provision of sub-Article (3) and (4) of this Article, the transfer of personal data to a third party jurisdiction that does not ensure appropriate level of protection is prohibited. 29. (1) Conditions for Cross Border Transfer A data controller or data processor may transfer personal data to a third party jurisdiction where: (a) he has given proof to the Commission on the existence of appropriate level of protection in that third party jurisdiction, and the Commission has made the determination according to sub-Article (3) of Article 28 of this Proclamation; (b) the data subject has given explicit consent to the proposed transfer, after having been informed of the possible risks of the transfer such as the absence of appropriate level of protection; (c) the transfer is necessary; or (d) the transfer is made from a register which, according to law, is intended to provide information to the public. For the purpose of sub-Article (1) lit. (c) of this Article, the transfer is necessary where: (a) the performance of a contract between the data subject and the data controller or data processor or implementation of pre-contractual measures taken at the data subject’s request; (b) for the conclusion or performance of a contract concluded in the interest of the data subject between the data controller and another person; (c) for important reasons of public interest; (d) for the establishment, exercise or defence of a legal claim; or (e) in order to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent. (2) 30. (1) (2) 31. (1) (2) (3) Safeguards Prior to Cross Border Transfer The Commission may request a person who transfers data to a third party jurisdiction to demonstrate the effectiveness of the security safeguards and the existence of compelling legitimate interests. The Commission may, in order to protect the rights and fundamental freedoms of data subjects, prohibit, suspend or subject the transfer to such conditions as may be determined. The Principle of Data Sovereignty Every data controller or data processor shall ensure the storage, on a server or data center located in Ethiopia, of personal data collected or obtained locally. The Commission shall prescribe, based on grounds of strategic interests of the state, categories of personal data as critical personal data that shall only be processed in a server or data center located in Ethiopia. Cross-border transfer of sensitive personal data shall require the prior approval of the Commission. 15

Select target paragraph3