Questions
Frequently asked questions
Is there a single African data protection law?
No. The African Union Convention on Cyber Security and Personal Data Protection, known as the Malabo Convention, was adopted in 2014 and finally entered into force in June 2023 after reaching the fifteen ratifications it required. But ratification remains limited, at roughly sixteen of the fifty-five member states, and two of the continent’s largest economies, Nigeria and South Africa, have not ratified it. The practical consequence is that the Convention sets a normative direction rather than an operative rulebook, and compliance work is national.
Which African regulators are actually enforcing?
South Africa’s Information Regulator is the most visible, having issued enforcement notices against public bodies and a fine of ZAR 5 million against the Department of Justice and Constitutional Development. Kenya’s Office of the Data Protection Commissioner enforces at high volume with a steady stream of penalty notices, often in digital lending, property and employment contexts. Nigeria’s Data Protection Commission has moved quickly on registration and remediation since the NDPA came into force. Treat these three as the enforcement centres of gravity.
What is a controller of major importance under the Nigerian NDPA?
It is a designation under the Nigeria Data Protection Act 2023 for controllers or processors that are domiciled, resident or operating in Nigeria and process the personal data of a number of data subjects above a threshold set by the Nigeria Data Protection Commission, or that process data of particular value or significance to the economy, society or security. Being designated triggers registration with the Commission and the appointment of a data protection officer, so it is the first classification question for any organisation with a Nigerian presence.
Does POPIA require a local representative or registration?
POPIA does not impose a general registration duty on all responsible parties, but it does require registration of information officers with the Information Regulator, and that step is frequently missed. Every public and private body has an information officer by operation of law, usually the head of the organisation, who may delegate to deputy information officers, and the registration must be completed through the Regulator’s portal. Prior authorisation from the Regulator is separately required for defined categories of processing.
How do cross-border transfers work across the continent?
Most national laws follow an adequacy-plus-safeguards model with consent as a derogation, but a significant minority add a prior-authorisation or notification step to the regulator, and a few impose localisation for specific data categories such as health, financial or government data. Kenya requires proof of appropriate safeguards and, for certain sensitive processing, that a copy is held in Kenya. Nigeria and South Africa follow safeguard-based models. Assume a per-country analysis rather than a continental answer.
Is the AfCFTA Digital Trade Protocol going to harmonise this?
It is the most credible route. The African Continental Free Trade Area’s Digital Trade Protocol addresses cross-border data flows, personal data protection and digital trade facilitation, and it carries the commercial incentive that the Malabo Convention lacked. It is more likely to drive practical convergence on transfer mechanisms than the Convention has, but implementation is at an early stage and organisations should plan on national compliance for the foreseeable future.