The last two years have seen a massive uptake in data protection laws and regulations in Africa with South Africa, Kenya, Zambia, Zimbabwe, Botswana, and Swaziland all passing laws and/or regulations. Compliance is mandatory in these countries, however in Botswana you have until October 2023 to fully comply as that is when the grace period ends. The data protection law in Namibia is due to come into effect in July 2023.
In addition to the above, Angola, Egypt, Ghana, Mauritius, Uganda and La Reunion (as a French territory, the European Economic Area General Data Protection Regulation (GDPR) applies) all have established data protection laws.
While Nigeria has regulations on data protection, it does not have a principal legislation. A bill was introduced in 2022 which would see a fully-fledged data protection law being implemented. Most other African countries have laws that touch on protection of personal information but no formal laws yet.
The introduction of robust data protection laws as well as the enforcement of such laws is imperative. Not only for the protection of fundamental rights to privacy but it is also paramount for African countries to operate in the global economy. There exists the concept of adequacy decisions in many data protection laws which enables authorities in those countries to grant adequacy decisions to countries which are deemed to have sufficient laws and enforcement in place. Adequacy decisions in general allow for easier cross-border transfer of personal information and lower costs to organisations trying to do business globally. Lower costs in the sense that they can have local data centres and do not need to incur legal costs in negotiating data transfer agreements for example. Interestingly the United States is not deemed adequate by the European Economic Area and despite attempts to set up frameworks such as the EU US Privacy shield, these attempts have fallen short. What we see is therefore many US headquartered companies with data centres and operations in countries in Europe where European data can be stored.
While most data protection laws in Africa have similar concepts to the GDPR, there are some key areas of difference, both to the GDPR and amongst the different African countries, these generally include:
- Cross-border transfers – differences are usually around instances when a transfer is allowed.
- Sensitive or special personal information – differences occur in what constitutes sensitive or special personal information and the basis on which such information can be processed. Also, in some countries consent of the data subject or possibly of the regulator is required prior to transferring special or sensitive personal information cross-border.
- Registration requirements – differences arise in the application procedure, what information needs to be submitted, whether it is the organisation or whether a data protection officer needs to be registered or both.
- Penalties and enforcement – different penalties apply for contraventions as well as on what bases penalties can be levied. Regulators also have different enforcement rights and the process differ too.
While there are some differences, there are several similarities between data protection laws globally. It is therefore possible to implement a compliance programme across multiple African jurisdictions, with policies and procedures and training taking the different legal nuances into consideration. Not only is it possible but it is also advisable to have a unified approach to your data protection compliance across all jurisdictions you operate.
Louella Tindale has significant experience in designing and executing compliance programmes across multiple jurisdictions. Get in touch for assistance.


Leave a reply