Businesses using offshore AI could face tougher data protection obligations under Kenya's draft rules
Kenyan companies using offshore artificial intelligence platforms could soon face stricter obligations before sending personal data outside the country under new draft guidance from the Office of the Data Protection Commissioner (ODPC). The proposal would require organisations to demonstrate that personal information transferred to overseas AI providers remains protected throughout its lifecycle, placing legal accountability on the Kenyan entity even when processing takes place in another jurisdiction.
The draft guidance comes as businesses across banking, insurance, healthcare, telecommunications and other sectors rely more heavily on cloud-based AI tools for customer analytics, fraud detection, document processing and automation. While many of those services are delivered from data centres outside Kenya, the regulator argues that the movement of personal data across borders must be accompanied by enforceable privacy safeguards rather than informal arrangements between organisations and technology vendors.
Under the proposal, organisations would be required to assess whether the destination country offers adequate data protection before transferring information for AI processing. Where those protections cannot be demonstrated, businesses would have to rely on contractual mechanisms such as binding corporate rules or contractual clauses that ensure Kenyan privacy standards continue to apply after the data leaves the country.
The draft also requires organisations to enter into written data processing agreements with offshore AI vendors, setting out how personal data will be collected, stored, processed and protected. Those agreements would become more than procurement paperwork; they would form part of an organisation’s legal compliance obligations under Kenya’s data protection framework. Companies would also need a lawful basis for every cross-border transfer of personal data linked to AI systems, making it harder to rely on broad or undefined arrangements when adopting new AI services.
One of the proposal’s most consequential provisions is that responsibility does not end once information is handed to an overseas processor. The ODPC makes it clear that organisations deploying AI systems remain accountable for compliance with Kenya’s data protection law throughout the system’s lifecycle. In practical terms, a Kenyan bank, insurer or hospital could still be held responsible if customer information processed through an offshore AI platform is mishandled abroad because the decision to transfer that data originated with the local organisation.
That approach mirrors a wider direction emerging across Kenya’s AI regulatory agenda. Recent draft policy proposals have sought to extend oversight to foreign AI systems whose services reach Kenyan users, even when the companies behind those models operate outside the country. The ODPC guidance complements that framework by focusing on the movement and protection of personal data rather than the AI models themselves, creating another layer of governance around how organisations adopt cross-border AI services.
Together, the proposals suggest Kenya is building a broader governance framework for artificial intelligence rather than treating privacy, AI deployment and cross-border data transfers as separate issues. Earlier policy proposals outlined risk-based oversight for AI providers and high-risk applications, while the latest guidance focuses on ensuring that organisations cannot outsource responsibility for protecting personal information simply because processing occurs in another country.
The practical impact is likely to be felt most strongly in sectors that routinely process sensitive personal information. Financial institutions already use AI to support fraud detection, credit assessment and customer service, healthcare providers rely on machine learning for diagnostic support, while employers, retailers and digital platforms continue expanding their use of AI-driven recruitment, recommendation and personalisation tools. Each of those applications may require organisations to revisit vendor contracts, review cross-border data flows and strengthen governance processes before the guidance is finalised.
The proposal also reflects a broader international trend as regulators seek greater oversight of AI systems that depend on global cloud infrastructure and cross-border data processing. Rather than restricting the use of foreign AI services, Kenya appears to be moving towards requiring stronger contractual safeguards, documented accountability and clearer governance over how personal data is handled once it crosses national borders.
If adopted in its current form, the guidance would represent one of the clearest indications yet that organisations deploying AI will be expected to treat data governance as a core part of AI adoption rather than a compliance exercise completed after implementation. For businesses that have rapidly integrated global AI platforms into everyday operations, the proposal could require a closer examination of where personal data travels, who processes it and whether existing agreements provide sufficient legal protection under Kenyan law.
For many organisations, the immediate challenge may not be adopting new technology but understanding where their existing AI tools process data. A customer service chatbot, document summarisation platform or fraud detection system may appear to operate locally while relying on infrastructure spread across several countries. That complexity has made data governance one of the most scrutinised aspects of AI deployment worldwide, particularly where personal information can move between multiple jurisdictions before a response is generated.
The draft guidance encourages organisations to take a more structured approach before sharing personal data with AI providers. That includes identifying what categories of information are being transferred, determining whether the destination country provides adequate legal protection, and documenting the safeguards used where equivalent protections cannot be established. Businesses that already maintain data protection impact assessments may need to expand those reviews to account for AI-specific processing and international data transfers.
Vendor management is also likely to receive greater attention. Many organisations procure AI capabilities through software vendors rather than dealing directly with model developers, creating multiple layers of subcontractors responsible for storing or processing information. The proposed requirement for written data processing agreements means organisations will need greater visibility into those arrangements instead of assuming privacy obligations are covered by standard commercial terms.
The proposal could prove particularly significant for financial institutions, where AI supports fraud monitoring, anti-money laundering controls, customer service and credit assessment. Healthcare providers using AI-assisted diagnostics or patient management platforms may face similar obligations because medical information attracts a higher standard of protection under Kenya’s data protection framework. Telecommunications companies, employers, retailers and digital platforms would also need to examine how customer and employee information moves through AI-powered systems, especially where overseas cloud infrastructure is involved.
Small and medium-sized businesses may encounter a different set of challenges. Many rely on readily available cloud AI services because they offer enterprise-grade capabilities without the cost of building in-house infrastructure. While the draft guidance does not prohibit those services, it does raise expectations around due diligence and governance. Smaller organisations that have limited legal or compliance resources may need additional support to understand contractual requirements and assess whether vendors provide sufficient safeguards for cross-border data transfers.
The proposals also reflect a broader international conversation about accountability in artificial intelligence. Regulators across several jurisdictions have recognised that AI services rarely operate within a single country’s borders, making traditional approaches to data governance less effective. Kenya’s draft guidance adopts a principle that has gained wider acceptance internationally: organisations cannot transfer responsibility for personal data simply because processing is outsourced to another company or takes place overseas. Instead, accountability follows the organisation that decides how and why personal information is used.
That approach complements the country’s emerging AI policy framework, which proposes oversight of foreign AI systems whose products or services have an impact in Kenya. While the draft AI policy focuses on the governance of AI technologies and providers, the ODPC guidance concentrates on the personal data that powers those systems. Together, the two proposals indicate that policymakers are building parallel safeguards that address both the technology itself and the information flowing through it.
Although the guidance remains in draft form, organisations that rely on AI would be well served by reviewing their existing practices before any final requirements take effect. Mapping where personal data is processed, identifying offshore vendors, reviewing contractual protections and strengthening internal governance processes are measures that could reduce future compliance risks regardless of whether the final guidance is amended during consultation.
The draft does not seek to limit access to global AI innovation or discourage organisations from adopting new technologies. Instead, it reflects a growing expectation that the use of AI should be accompanied by clear governance, documented accountability and enforceable protections for personal data. As AI becomes embedded in everyday business operations, questions about where information travels and who remains responsible for it are becoming just as important as the capabilities of the technology itself.
If the guidance is adopted, Kenyan organisations may find that deploying AI is no longer viewed solely as a technology decision. It will also require careful consideration of legal obligations, vendor relationships and data governance, placing privacy alongside security, cost and performance as a central factor in evaluating AI systems. Together with the government’s wider AI policy proposals, the draft guidance points towards a more comprehensive framework in which organisations are expected to demonstrate not only that AI delivers value, but also that it handles personal data in a manner consistent with Kenyan law.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke


