Skip to content

Policy pillar deep dive · dataset policy-2026-Q3-r16

Localisation & sovereignty

Where data must physically live, and what authorisation moves it across borders.

Coverage
100% verified
Claims
3 claims
Sources
6 sources
Countries covered
3/4 markets
Structured gaps
0 gaps

Coverage across the four markets

Uganda UG

no researched claims

Rwanda RW

100%

1 verified · 0 partial · 0 other

Tanzania TZ

100%

1 verified · 0 partial · 0 other

Kenya KE

100%

1 verified · 0 partial · 0 other

Open the same tiles in the coverage matrix to compare this pillar against every other pillar.

Claims & evidence trails

Rwanda RW

1 claim
  • VerifiedRW-DP-C4

    Personal data must be stored in Rwanda; storage outside Rwanda is only permitted if the controller/processor holds a valid registration certificate authorising storage outside Rwanda, issued by the supervisory authority (Art. 50).

    Verbatim captured; the DPO's official services menu ('Authorization to Store Outside Rwanda') corroborates operationally. MATERIAL DIFFERENCE vs Uganda: no equivalent default-localisation provision captured in Uganda's Act. Direct colocation-demand driver for in-country Rwandan facilities.

    View evidence trail · 2 sources ▾
    1. Republic of Rwanda (Official Gazette n° Special of 15/10/2021), hosted by RISA — Law No 058/2021 of 13/10/2021 relating to the protection of personal data and privacy (official gazette text, bilingual PDF, 82pp, via RISA)T1 · capturedArticle 48: ... share or transfer personal data to a third party outside Rwanda if: 1° he or she has obtained authorisation from the supervisory authority after providing proof of appropriate safeguards ... 2° the data subject has given his or her consent; 3° the transfer is necessary ... Article 50: The data controller or the data processor stores personal data in Rwanda. However, the storage of personal data outside Rwanda is only permitted if ... holds a valid registration certificate authorising him or her to store personal data outside Rwanda, which is issued by the supervisory authority.
    2. Data Protection and Privacy Office (Rwanda) — Data Protection & Privacy Office (DPO) - official services siteT1 · capturedServices: Apply as a Data Controller ... Apply as a Data Processor ... Authorization to Transfer Outside Rwanda ... Authorization to Store Outside Rwanda ... What to do after registering with NCSA

Tanzania TZ

1 claim
  • VerifiedTZ-DP-C6

    The default rule for non-adequate destinations is restrictive (s.32): 'transfer of personal data to countries outside the United Republic is not authorised' except in enumerated cases (consent, necessity and others); operationally the PDPC 'Issues permits to entities intending to transfer personal data outside the country', assesses destination-country adequacy, requires safeguards prior to transfer, sets conditions and monitors/audits adherence.

    MATERIAL DIFFERENCE, both T1: Tanzania operates a pre-approval PERMIT regime (like Rwanda's Art. 48/50 authorisation model), vs Uganda's records-based regime with no advance approval (UG-DP-C5). Direct colocation-demand driver for in-country facilities.

    View evidence trail · 2 sources ▾
    1. Personal Data Protection Commission (Tanzania) — Personal Data Protection Act, 2022 (Act No 11 of 2022, GN No 395B) - official PDF, 42ppT1 · captured14.-(1) A person shall not collect or process personal data without being registered as a data controller or a data processor under this Act. ... 31.-(1) The Commission may, subject to the provisions of this Act, prohibit the transfer of personal data to a place outside the country. ... 32: transfer of personal data to countries outside the United Republic is not authorised (exceptions enumerated).
    2. Personal Data Protection Commission (Tanzania) — PDPC - Cross-Border Data Transfer Permit (official service page)T1 · capturedAccording to the Personal Data Protection Act, Chapter 44, the Personal Data Protection Commission (PDPC) is mandated to regulate and oversee the transfer of Personal Data outside the country... In discharging this mandate, the Commission: Issues permits to entities intending to transfer personal data outside the country; Assesses the level of Personal Data protection in the destination country...; Ensures that appropriate legal, technical, and organizational safeguards are in place prior to any Personal Data transfer; Establishes conditions and compliance requirements...; Monitors and audits adherence to the set conditions.

Kenya KE

1 claim
  • VerifiedKE-LOC-C1

    Kenya's regime imposes no general data-localisation mandate: in-country storage is not a blanket precondition, and cross-border movement is governed by the DPA's transfer conditions - materially lighter than Rwanda's registration-certificate-based storage rule.

    Negative/material-difference claim, deliberately held at partially-verified: absence is asserted only until the DPA text is captured in full. Upgrade path: DPA 2019 full-text capture; cross-check against the ODPC guidance pages. | r10 upgrade: DPA statute text (T1, 2026-09-22) evidences conditions-not-prohibition; comparative limb rests on captured T1 instruments of both countries - flagged for editor eye.

    View evidence trail · 2 sources ▾
    1. DLA Piper — DLA Piper Data Protection Laws of the World - Kenya chapter (country profiles landing)T3 · snippetData Protection Laws of the World ... Kenya Kosovo Kuwait ... (country index captured; Kenya chapter content not rendered in text extraction).
    2. new.kenyalaw.org — kenyalaw-dpa-aknT1 · captured

policy-2026-Q3-r16 · 3 claims in this pillar · 6 sources · editorial gate: EDITORIAL REVIEW COMPLETE (Uganda, Rwanda, Tanzania, Kenya - all four country pipelines approved for publication)