Privacy education, consultancy & implementation, in 50+ jurisdictions.enquiry@vedhacon.com
Guidance and examples adapt to your selection.↑↓ to browse, ↵ to apply
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
African Union · 55 states · National regimes

Continental ambition, national enforcement.

Around forty-four African states now have data protection laws and roughly thirty-eight have operational authorities. The African Union’s Malabo Convention finally entered into force in 2023 but remains thinly ratified, so compliance is built country by country, with South Africa, Nigeria and Kenya setting the enforcement pace.

Overview

A continent of national regimes, converging slowly

Data protection legislation has spread rapidly across Africa over the last decade, driven by mobile money, digital identity programmes, digital lending and the need to trade with the European Union. Roughly forty-four of the fifty-five African Union member states have adopted comprehensive laws, and around thirty-eight have an operational supervisory authority. The gap between those two numbers matters: a law without a funded regulator produces obligations without guidance.

GDPR as the template

Most African laws borrow the European structure of lawful bases, data subject rights, accountability and transfer restrictions, often via the Malabo Convention or the ECOWAS and SADC model frameworks. A GDPR programme maps across reasonably well at the conceptual level.

Registration as the differentiator

Where African regimes depart from the GDPR is administrative: registration or licensing of controllers and processors, registration of information or data protection officers, and prior authorisation for defined processing. These are the duties most often missed by foreign entrants.

Uneven enforcement

Enforcement concentrates in a handful of jurisdictions. South Africa, Kenya, Nigeria, Ghana, Morocco and Egypt generate most of the visible activity. Elsewhere a law may be in force with little published practice, which is a reason to build to a defensible standard rather than to observed enforcement.

Localisation pressure

Several states impose residency or copy-retention requirements for health, financial, government or critical-infrastructure data, often in sectoral instruments rather than the data protection law itself. Check the sector rule before choosing a hosting region.

African Union

The Malabo Convention, and why it under-delivers

The African Union Convention on Cyber Security and Personal Data Protection was adopted in Malabo in June 2014. It needed fifteen ratifications to enter into force and did not reach that threshold until 2023, entering into force in June of that year, nine years after adoption.

What it requires

Parties must establish a legal framework for personal data protection, create an independent supervisory authority, and give effect to principles of consent and legitimate basis, lawfulness and fairness, purpose limitation, accuracy, transparency, confidentiality and security, alongside cyber security and cybercrime commitments.

Why its effect is limited

Ratification stands at roughly sixteen member states. Nigeria and South Africa, the continent’s largest economies and its most active enforcers, have not ratified. A convention that does not bind the jurisdictions generating most of the practice cannot function as the operative standard.

What it does achieve

It supplies a normative reference that national legislatures and courts cite, and it underpins the AU Data Policy Framework, which sets out a continental vision for data governance and cross-border flows. Its influence is on drafting rather than on compliance.

Where to watch instead

The AfCFTA Digital Trade Protocol ties data governance to market access and therefore carries commercial incentive. Regional economic communities also matter: the ECOWAS Supplementary Act, the SADC Model Law and the EAC framework have shaped national drafting more directly than the Convention has.

At a glance

Principal regimes across the continent

Selected African data protection regimes
JurisdictionPrincipal instrumentRegulatorDistinguishing feature
South AfricaProtection of Personal Information Act 2013 (POPIA)Information RegulatorFull commencement July 2021. Information officer registration, prior authorisation for defined processing, and the continent’s highest-profile enforcement.
NigeriaNigeria Data Protection Act 2023Nigeria Data Protection CommissionReplaced the 2019 Regulation with primary legislation. The controller of major importance designation drives registration and DPO duties.
KenyaData Protection Act 2019Office of the Data Protection CommissionerMandatory registration of controllers and processors above thresholds, and a high volume of published penalty decisions.
GhanaData Protection Act 2012 (Act 843)Data Protection CommissionRegistration and biennial renewal for data controllers, with an established licensing culture.
EgyptLaw No. 151 of 2020Personal Data Protection CentreLicensing and permit-based model with criminal penalties. Executive regulations have been slow to follow.
MoroccoLaw No. 09-08CNDPOne of the earliest African regimes, operating a declaration and authorisation model and the only African jurisdiction historically treated as adequate by the European Union in limited respects.
RwandaLaw No. 058/2021National Cyber Security AuthorityRegistration of controllers and processors, with localisation requirements unless authorised otherwise.
UgandaData Protection and Privacy Act 2019Personal Data Protection OfficeRegistration duty with published register, and an active complaints practice.
Zambia, Tanzania, Côte d’Ivoire, SenegalNational acts of 2021 to 2023National authoritiesNewer regimes following the registration-plus-safeguards pattern, with guidance still developing.

South Africa

POPIA and the Information Regulator

Scope and roles

POPIA regulates responsible parties, the equivalent of controllers, and operators, the equivalent of processors, and applies where the responsible party is domiciled in South Africa or, if not, where it makes use of automated or non-automated means in the Republic.

Eight conditions

Lawful processing rests on accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. These map closely to the GDPR principles.

Information officers

Every public and private body has an information officer by operation of law, usually the head of the body, who must be registered with the Regulator before performing duties, and who may designate deputy information officers. Registration failures are a common first finding.

Prior authorisation

Required before processing unique identifiers for purposes other than collection, processing criminal or unlawful behaviour on behalf of third parties, processing for credit reporting, and transferring special personal data or children’s data to countries without adequate protection.

Breach notification

Notify the Regulator and affected data subjects as soon as reasonably possible after discovery, with specified content requirements and a public communication route where individual contact is not reasonably practicable.

Enforcement

The Regulator issues enforcement notices and may impose administrative fines up to ZAR 10 million, with criminal penalties for non-compliance with enforcement notices. The ZAR 5 million fine issued against the Department of Justice and Constitutional Development signalled willingness to act against state bodies.

Nigeria

The NDPA 2023 and the Commission

From regulation to statute

The Nigeria Data Protection Act 2023 replaced the 2019 NDPR framework with primary legislation and established the Nigeria Data Protection Commission as a statutory regulator with investigative and enforcement powers.

Controller of major importance

Controllers and processors above a threshold set by the Commission, or processing data of particular value or significance to the economy, society or security, are designated as being of major importance. Designation triggers registration with the Commission and appointment of a data protection officer.

Compliance audits

The framework retains an audit and filing culture inherited from the NDPR, with licensed compliance organisations conducting audits and annual returns. Budget for the filing cycle rather than treating it as optional.

Penalties

The Commission may impose remedial fees and penalties, calculated by reference to annual gross revenue for controllers of major importance, with lower caps for others. Enforcement has focused on registration, unlawful disclosure and digital lending practices.

Kenya

The Data Protection Act 2019 and the ODPC

Registration

Controllers and processors must register with the Office of the Data Protection Commissioner unless they fall below the prescribed turnover and headcount thresholds, with certain sectors required to register regardless of size.

Enforcement volume

The ODPC publishes determinations at a rate unmatched elsewhere on the continent, frequently involving digital lenders, landlords, employers and recruitment practices. Penalties reach the lower of five million Kenyan shillings or one percent of annual turnover.

Impact assessments

A data protection impact assessment is required where processing is likely to result in high risk to rights and freedoms, and the ODPC has issued guidance on when it expects to see one.

Transfers

Permitted on proof of appropriate safeguards, consent or defined necessity grounds, with the Act contemplating that certain processing of sensitive data requires a serving copy to be stored on a server in Kenya.

Patterns

What to expect wherever you operate

Register before you process

Registration, licensing or notification is the most common first obligation and the most common first failure. Check whether the duty attaches to the controller, the officer, or both.

Consent-heavy drafting

Many African statutes foreground consent more strongly than the GDPR does, and some require written consent for sensitive data. Do not assume a legitimate-interest analysis will be accepted where the statute names consent.

Local officers and representatives

DPO or information officer appointment is frequently mandatory and sometimes must be resident. Record the appointment, the registration and the contact route published to data subjects.

Language and accessibility

Notices may need to be available in official or widely used national languages, and accessibility expectations for low-bandwidth and mobile-first users are practical, not theoretical, across much of the continent.

Mobile money and digital lending

These sectors attract disproportionate regulatory attention across Kenya, Nigeria, Ghana and Uganda. If you operate in them, expect scrutiny of consent, contact-list access and debt-collection practices.

Sectoral localisation

Health, financial, telecom and government data often carry residency or copy requirements in sector legislation that sits outside the data protection act. Confirm before selecting a hosting region.

Implementation

Where to start

1

Build a country matrix

For each country of operation record the statute, regulator, registration duty, officer appointment duty, transfer mechanism, breach clock and penalty exposure. This is the artefact that makes the rest tractable.

2

Complete registrations first

Information officer registration in South Africa, Commission registration in Nigeria, ODPC registration in Kenya and Data Protection Commission registration in Ghana all have renewal cycles. Calendar them with owners.

3

Appoint and publish officers

Name the information officer or DPO, register the appointment where required, and publish a working contact route. An unpublished officer is treated as no officer.

4

Set transfer mechanisms per destination

Record the safeguard relied on for each destination and each source country, and identify where prior authorisation or localisation applies.

5

Localise notices and consent

Translate where required, simplify for mobile-first delivery, and ensure sensitive-data consent is captured in the form the statute specifies.

Questions

Frequently asked questions

Is there a single African data protection law?

No. The African Union Convention on Cyber Security and Personal Data Protection, known as the Malabo Convention, was adopted in 2014 and finally entered into force in June 2023 after reaching the fifteen ratifications it required. But ratification remains limited, at roughly sixteen of the fifty-five member states, and two of the continent’s largest economies, Nigeria and South Africa, have not ratified it. The practical consequence is that the Convention sets a normative direction rather than an operative rulebook, and compliance work is national.

Which African regulators are actually enforcing?

South Africa’s Information Regulator is the most visible, having issued enforcement notices against public bodies and a fine of ZAR 5 million against the Department of Justice and Constitutional Development. Kenya’s Office of the Data Protection Commissioner enforces at high volume with a steady stream of penalty notices, often in digital lending, property and employment contexts. Nigeria’s Data Protection Commission has moved quickly on registration and remediation since the NDPA came into force. Treat these three as the enforcement centres of gravity.

What is a controller of major importance under the Nigerian NDPA?

It is a designation under the Nigeria Data Protection Act 2023 for controllers or processors that are domiciled, resident or operating in Nigeria and process the personal data of a number of data subjects above a threshold set by the Nigeria Data Protection Commission, or that process data of particular value or significance to the economy, society or security. Being designated triggers registration with the Commission and the appointment of a data protection officer, so it is the first classification question for any organisation with a Nigerian presence.

Does POPIA require a local representative or registration?

POPIA does not impose a general registration duty on all responsible parties, but it does require registration of information officers with the Information Regulator, and that step is frequently missed. Every public and private body has an information officer by operation of law, usually the head of the organisation, who may delegate to deputy information officers, and the registration must be completed through the Regulator’s portal. Prior authorisation from the Regulator is separately required for defined categories of processing.

How do cross-border transfers work across the continent?

Most national laws follow an adequacy-plus-safeguards model with consent as a derogation, but a significant minority add a prior-authorisation or notification step to the regulator, and a few impose localisation for specific data categories such as health, financial or government data. Kenya requires proof of appropriate safeguards and, for certain sensitive processing, that a copy is held in Kenya. Nigeria and South Africa follow safeguard-based models. Assume a per-country analysis rather than a continental answer.

Is the AfCFTA Digital Trade Protocol going to harmonise this?

It is the most credible route. The African Continental Free Trade Area’s Digital Trade Protocol addresses cross-border data flows, personal data protection and digital trade facilitation, and it carries the commercial incentive that the Malabo Convention lacked. It is more likely to drive practical convergence on transfer mechanisms than the Convention has, but implementation is at an early stage and organisations should plan on national compliance for the foreseeable future.

Verify

Primary sources

General information, not legal advice. African regimes are being adopted and amended rapidly, regulator guidance is uneven, and several statutes await implementing regulations. Verify the current national instrument and any sectoral overlay before relying on this page. Researched 21 September 2026.

Expanding across Africa?

We build country matrices, complete registrations and officer appointments, and design transfer and notice frameworks that work across multiple African regimes at once.

Talk to Vedhacon