# Cross-border data transfers for global carriers and MVNOs
A subscriber from Nairobi lands at Frankfurt airport, turns on roaming, and makes a call. Within seconds, a CDR (call detail record: metadata showing who called whom, when, for how long, and from which cell tower) generated by Safaricom's network gets shared with Deutsche Telekom for billing reconciliation. That single record just crossed a legal fault line most telecom staff never think about: a cross-border personal data transfer, and it may have triggered obligations under Kenya's Data Protection Act and the EU's GDPR (General Data Protection Regulation) simultaneously.
This lesson teaches you to tell the difference between transfer mechanisms that do real legal work and paperwork that exists mostly for show.
A CDR looks technical, but regulators treat it as personal data because it can identify a subscriber and reveal location, contacts, and behavior patterns. Under GDPR (Article 4), personal data includes anything linkable to an identified or identifiable person, IMSI numbers and MSISDNs (the subscriber's phone number identifier) included.
This matters because the moment that CDR leaves Kenya and lands on a German operator's billing system, it is a "transfer of personal data to a third country" under GDPR Chapter V, and Kenya's own Dataown DataData collected directly from your own customers and prospects through your own channels: your most reliable and privacy-compliant source. Protection Act (2019), enforced by the Office of the Data Protection Commissioner (ODPC), imposes its own cross-border transfer conditions.
1. Adequacy decisions. The European Commission can declare a country's data protection regime "adequate," meaning data can flow there without extra safeguards, as if it were still inside the EU/EEA. As of early 2026, adequacy covers a short list including Japan, South Korea, UK, and Canada (commercial organizations); Kenya is not on that list. Check the current roster on the European Commission's adequacy decisions page.
No adequacy decision for Kenya means the Safaricom-to-Deutsche Telekom flow needs a different mechanism.
2. Standard Contractual Clauses (SCCs). These are pre-approved contract templates issued by the European Commission that both parties sign, legally binding the non-EU recipient to GDPR-equivalent protections. For our roaming example, Safaricom and Deutsche Telekom would embed SCCs into their roaming agreement (often via the GSMA's standard IOT, Inter-Operator Tariff, agreements that already reference data protection annexes).
SCCs are the actual workhorse of telecom data transfers. GSMA (the mobile operator trade body) roaming frameworks like AA.14 and BA.27 build data protection language into commercial roaming contracts by default.
3. Localization carve-outs. Some jurisdictions require certain data categories to stay on domestic soil, full stop, no transfer mechanism cures it. Examples: Russia's data localization law requires personal data of Russian citizens to be first recorded on servers in Russia. India's telecom and financial sector rules impose sector-specific storage requirements. Nigeria's Data Protection Act (2023) and NDPC (Nigeria Data Protection Commission) guidance restrict certain government and critical data from leaving the country without approval.
Carve-outs override SCCs. If a carve-out applies, no contract clause makes the transfer legal.
Here is the applied skill: spotting when a "compliance" step is real versus decorative.
Theater example 1: SCCs signed but never operationalized. A carrier signs SCCs with a roaming partner but never runs the required Transfer Impact Assessment (TIA), a documented check of whether the destination country's laws (e.g., surveillance access) undermine the contractual promises. Post the *Schrems II* ruling (Court of Justice of the EU, 2020), SCCs alone are legally insufficient; you must assess and document that the destination actually offers effective protection. Signed paper without a TIA is a checkbox, not a control.
Theater example 2: Adequacy assumed, not verified. Teams sometimes assume "the UK is fine, it's basically still in Europe." The UK's post-Brexit adequacy status is real but was time-limited and subject to renewal review; treating it as permanent without monitoring is a governance gap.
Theater example 3: Anonymization claims that aren't. Some MVNOs (Mobile Virtual Network Operators, companies that resell network capacity from an MNO, Mobile Network Operator, without owning infrastructure) claim CDR data shared for analytics is "anonymized" and therefore outside GDPR entirely. If the dataset retains cell-tower-level granularity and timestamps, re-identification is often trivial (a known finding from mobility data research, e.g., studies referenced by MIT's work on unicity of human mobility traces). Calling it anonymized when it's merely pseudonymized is a real compliance risk, not a solved one.
A real, non-theater case: in 2021 the Kenyan ODPC and telecom regulator scrutiny around SIM registration data pushed Safaricom to tighten how subscriber data was shared with third parties, showing local enforcement does have teeth even without EU-style fines.
When you inherit a roaming or interconnect data flowdata flowAn automated sequence of steps that moves data from source to destination: ingestion, transformation, validation, and loading, so it arrives clean and ready to use.View full definition →, run these checks before assuming a mechanism is valid:
Transfer Audit Checklist (data flow: Origin MNO -> Destination Partner)
1. Data mapping
- What fields are in the CDR/record? (IMSI, location, call content?)
- Is it personal data under both origin and destination law?
2. Mechanism check
- Is there an adequacy decision covering destination? (Y/N, cite source)
- If no: are SCCs signed AND is there a documented Transfer Impact Assessment?
- Does any localization law apply to this data category? (carve-out check)
3. Operational verification
- Encryption in transit? (yes/no, protocol)
- Retention period matches contract terms?
- Sub-processors (e.g., billing clearinghouses like BICS or Syniverse) covered
by the same SCCs, or is there a gap?
4. Governance sign-off
- DPO (Data Protection Officer) reviewed and dated?
- Renewal/monitoring trigger set (e.g., adequacy status review date)?Note step 3's mention of clearinghouses: roaming data often does not go carrier-to-carrier directly. Intermediaries like Syniverse or BICS handle CDR exchange and settlement, meaning your transfer chain has more hops, and more potential gaps, than the two-party contract suggests.
Knowledge check
1. Why do regulators classify a CDR (call detail record) as personal data rather than mere network metadata?
2. A Kenyan MNO's roaming CDR is shared with a German operator for billing reconciliation. Which statement best captures the legal complexity of this scenario?
3. What is the practical legal effect of the European Commission granting a country an 'adequacy decision'?
4. Select ALL correct answers about why a roaming CDR shared between a Kenyan and a German carrier constitutes a 'cross-border personal data transfer' with real legal consequences.
Select all the correct answers.
5. Select ALL correct answers describing the distinction the lesson draws between transfer mechanisms that 'do real legal work' versus 'paperwork that exists mostly for show'.
Select all the correct answers.
Mature telecom groups treat cross-border transfer compliance as an ongoing operational process, not a one-time legal sign-off:
🎬 [VIDEO: "GDPR International Data Transfers Explained" - youtube.com/results?search_query=GDPR+international+data+transfers+explained - a walkthrough of adequacy, SCCs, and Schrems II from a data protection training channel]