Most cryptographic-based access control schemes implemented in IoT-based and mobile cloud computing generally provide secure and lightweight privacy-preserving data sharing and access for data users. Ciphertext policy attribute-based encryption (CP-ABE) is one of the suitable techniques used to support fine-grained and secure data sharing in data outsourcing environment. However, its cryptographic construct is based on pairing and exponentiation which are expensive operations that are not practical to be run in the resource-constraint devices. In this paper, we propose a secure and efficient mobile-cloud based access control based on the fully outsourced CP-ABE decryption. Essentially, we introduce a transformation key technique to allow a mobile user to compute the secret key upon the decryption. Our proposed scheme outperforms the existing works in the way that there is no secret key retained at the mobile device and no cost of CPABE decryption at the mobile client side. Finally, we conducted performance evaluation to substantiate that our proposed scheme is efficient in practice.