Data Protection

Data protection law across Africa: a comparative overview

By Ademola Adekunbi·Published 27 June 2026
AlgeriaAngolaBeninBotswanaBurundiCabo VerdeCameroonCentral African RepublicComorosCongo (DRC)Congo (Republic)Côte d'IvoireDjiboutiEgyptEquatorial GuineaEritreaEswatiniEthiopiaGabonGambiaGuineaGuinea-BissauKenyaLesothoLiberiaLibyaMadagascarMalawiMauritaniaMauritiusMoroccoMozambiqueNamibiaNigerNigeriaRwandaSenegalSierra LeoneSouth AfricaSouth SudanSudanTanzaniaTunisiaUgandaZambiaZimbabwe

The oldest comprehensive data protection statute tracked in this Library was enacted in January 2001, in Cabo Verde cv-dp-2001. The most recent, The Gambia's Personal Data Protection and Privacy Act gm-pdpp-2025, was assented to in November 2025, weeks before this guide was written. Between those two dates sits one of the fastest and least even bursts of legislative activity in the world. Of the 54 jurisdictions tracked here, 43 now have a comprehensive data protection law in force. Twenty-three of those 43, more than half, were enacted in 2019 or later. The continent did not adopt data protection law gradually; it adopted most of it in the past six years.

That compression is why a continental view is more useful than a country-by-country reading for anyone working across borders. The headline numbers suggest convergence: most of Africa now has a law, most of the laws look broadly similar on the page, and the newest of them borrow openly from the European General Data Protection Regulation. But the similarity is partly an artefact of timing. Laws drafted within a few years of one another, often from shared models, end up resembling one another in text while diverging sharply in everything that determines whether they matter in practice, when they took effect, whether a regulator was ever stood up to administer them, and whether that regulator has issued a single decision. A map coloured simply by "has a law" or "has no law" would put Lesotho, whose 2011 statute has never had an appointed commissioner, in the same category as Kenya, whose regulator has issued a steady stream of penalties since 2022. The more revealing distinctions run underneath the statute book. This guide sets out where the continent actually stands, the recurring models its laws follow, and the widening gap between enacting a law and enforcing one.

The current landscape

Across the 54 jurisdictions on file, 43 have a comprehensive data protection law in force. A further four have a draft bill on file but no enacted statute: Liberia lr-dp-draft, Mozambique mz-pdpb-2025, Namibia na-dpb-2025 and Sierra Leone sl-dp-draft. The remaining seven have neither a comprehensive law nor an advanced public bill on file, the Central African Republic, Burundi, Eritrea, Sudan, Libya, South Sudan and Guinea-Bissau. Put differently, roughly four in five of the jurisdictions covered here have crossed the threshold of having a law on the books; the open questions are increasingly about what happens after that threshold, not before it.

The depth of that coverage is uneven, and the Library's internal Coverage Score, a 0 - 100 completeness metric, is a useful proxy for it. The distribution is bimodal rather than smooth. Five jurisdictions sit at zero, reflecting the total absence of a law, a regulator or an advanced bill. Six more fall in the 1 - 20 band: Libya and South Sudan, where only incidental cybercrime provisions touch personal data, and the four bill-stage countries. Five jurisdictions occupy a middle band between 21 and 59, typically an in-force law paired with a thinly documented or unconstituted supervisory authority, Lesotho, the Democratic Republic of Congo, Equatorial Guinea, Comoros and Djibouti among them. The bulk of the continent, 24 jurisdictions, sits in the 60 - 79 band, denoting a functioning legal framework with some combination of documentation gaps or nascent enforcement. Fourteen jurisdictions score 80 or above, the group where a comprehensive law, an operational regulator and (in most cases) a documented enforcement record all coincide. A handful of these frameworks have begun to mature beyond a single statute into layered regimes, Kenya pairs its Act with General Regulations ke-dpgr-2021, and South Africa za-popia-2013, Uganda ug-dppa-2019, Zambia zm-dpa-2021 and Zimbabwe zw-cdpa-2021 have each added implementing instruments, a depth that the bare "has a law" count cannot capture.

Regionally, the differences are real but narrower than the stereotypes suggest. Southern Africa records the highest average Coverage Score (60.5), marginally ahead of West Africa (59.1), with Central Africa (54.4), North Africa (52.5) and East Africa (52.1) clustered close behind. No region is uniformly strong or weak. West Africa contains both some of the most mature frameworks, Nigeria ng-ndpa-2023, Benin bj-dp-2009, Côte d'Ivoire ci-dp-2013 and Niger ne-dp-2022 all score 80, and three of the continent's bill-stage or no-law cases (Liberia, Sierra Leone and Guinea-Bissau). North Africa pairs two of the highest-scoring regimes, Egypt eg-pdpl-2020 and Algeria dz-dp-2018, against Libya and Sudan at the floor. East Africa spans Kenya ke-dpa-2019 and Uganda ug-dppa-2019 at the top and Eritrea, Burundi and South Sudan at the bottom. The pattern that holds across every region is not geographic but temporal: the jurisdictions with the most complete coverage are disproportionately those that legislated, and built institutions, earliest or most deliberately, not those in any particular part of the continent.

Models and approaches

Three recurring patterns run through the instruments on file. They are not tidy boxes, several laws sit in more than one, but each is supported by enough examples to be a genuine structural feature rather than a coincidence.

The first is the choice between a standalone data protection statute and data protection provisions embedded in a broader cybersecurity, electronic-transactions or digital code. The embedded model is well represented: Zimbabwe's Cyber and Data Protection Act zw-cdpa-2021, Guinea's Cybersecurity and Personal Data Protection Act gn-csdp-2016, the Democratic Republic of Congo's Digital Code cd-dc-2023, Djibouti's Digital Code dj-digital-code-2025 and Benin's Digital Code bj-digital-code-2018 all fold personal data rules into a larger digital-regulation instrument. The significance of this design is more than drafting housekeeping: where privacy sits inside a security or transactions statute, it is often administered by a body whose primary mandate is something else, and it can be subordinated to a broader security agenda. Two jurisdictions show a clear trajectory away from the embedded model. Malawi originally regulated data protection through Part IV of its 2016 Electronic Transactions and Cyber Security Act mw-etcsa-2016, then replaced it with a standalone Data Protection Act in 2024 mw-dpa-2024; Cameroon similarly moved from its 2010 cyber law cm-cyber-2010 to a dedicated Personal Data Protection Act in 2024 cm-pdpa-2024. The drift is towards purpose-built statutes administered by purpose-built authorities.

The second pattern is generational. The earlier wave of laws, Tunisia's 2004 Organic Law tn-dp-2004, Senegal 2008 sn-dp-2008, Benin 2009 bj-dp-2009, Morocco 2009 ma-dp-2009, Gabon 2011 ga-dp-2011, Côte d'Ivoire 2013 ci-dp-2013 and Madagascar 2014 mg-dp-2014, overwhelmingly follow a declaration-and-authorisation model, in which controllers register processing operations with, and seek permissions from, a supervisory commission. This architecture descends from the French data protection tradition and the Council of Europe's Convention 108; five African states (Cabo Verde, Mauritius, Morocco, Senegal and Tunisia) have formally acceded to that convention. The later wave, broadly from Kenya 2019 ke-dpa-2019 onward, shifts towards the GDPR's accountability model: lawful bases rather than blanket authorisation, mandatory breach notification, data protection officers, impact assessments and turnover-linked fines. Nigeria ng-ndpa-2023, Rwanda rw-dpl-2021, Egypt eg-pdpl-2020, Zimbabwe zw-cdpa-2021 (with an unusually demanding 24-hour breach-notification window), Botswana bw-dpa-2024 (fines up to 4% of global turnover) and Eswatini sz-dpa-2022 all reflect this generation. The two waves are not sealed off from each other: several older regimes are now retrofitting the accountability toolkit by amendment rather than replacement. Algeria's 2025 amending law dz-law-25-11-2025 added data protection officers, records of processing, impact assessments and a five-day breach-notification duty to its 2018 statute, and Niger has amended its 2022 law within a year of passage ne-law-2023-31.

The third pattern concerns supervisory architecture, and it cuts across the other two. A substantial group of jurisdictions vest data protection oversight not in a dedicated authority but in an existing sectoral regulator, usually for telecommunications or communications. Zimbabwe's authority is its telecoms regulator POTRAZ; Côte d'Ivoire's is ARTCI; Eswatini's is the communications commission ESCCOM; Malawi's is MACRA; Ethiopia's is the Ethiopian Communications Authority et-pdpp-2024; and in Guinea the posts-and-telecoms regulator ARPT acts as de facto supervisor because the dedicated authority the 2016 law contemplated was never operationalised. This contrasts with the dedicated-commission model of Kenya's Office of the Data Protection Commissioner, Nigeria's Data Protection Commission, South Africa's Information Regulator and the francophone protection authorities. The distinction matters because a regulator built for spectrum licensing carries different incentives, expertise and independence from one built for privacy, a structural point that bleeds directly into the question of enforcement.

Institutional capacity — the enforcement gap

The single most important fact about data protection in Africa is not how many laws exist but how few of them are actively enforced. The Library's data makes the gap concrete, and it falls into three tiers.

At one extreme are jurisdictions where the law is in force but the regulator does not functionally exist. Lesotho is the starkest case: its Data Protection Act has been on the books since 2011 ls-dpa-2011, yet the Data Protection Commission it establishes has never been appointed, leaving the statute without an operational supervisor for well over a decade. Cameroon's 2024 Act cm-pdpa-2024 provides for a dedicated authority whose composition still awaits a Presidential decree, so the cybersecurity agency ANTIC remains the only relevant body. The Democratic Republic of Congo's Digital Code cd-dc-2023 envisages a supervisor that has not been established by decree; Djibouti's authority is designated but not yet constituted dj-digital-code-2025; and Guinea's dedicated authority gn-csdp-2016 was never stood up. In each, a compliant controller would struggle to identify whom to notify of a breach.

A second tier has, or recently had, a multi-year supervisory vacuum between a law taking effect and a regulator being inaugurated. The Republic of Congo's law has been in force since 2020, but its data protection commission was only inaugurated in January 2026 cg-dp-2019. Madagascar's 2014 law mg-dp-2014 waited roughly a decade: its commission became operational only in August 2025. Angola's authority began work in 2019, eight years after the 2011 statute ao-dp-2011. These gaps matter because rights that cannot be vindicated for years after enactment exist on paper alone.

A third, smaller tier is where active enforcement actually looks like enforcement, and the Library's Cases records show what that means. Kenya's Office of the Data Protection Commissioner moved from registration to penalties with its first determination against Oppo Kenya in 2022, imposing the then-maximum fine under the 2019 Act ke-dpa-2019 for commercial use of an image without consent, and followed with penalties against Roma School and the digital lender Mulla Pride in 2023 for, respectively, processing children's data and weaponising borrowers' contacts. In 2025 the High Court of Kenya applied the same Act to mass biometric processing, quashing Worldcoin's iris-scanning operation and ordering deletion of the data collected, a ruling of continental significance on consent and impact assessments. Nigeria shows a comparable depth: the Data Protection Commission fined Fidelity Bank some ₦555.8 million in 2024 under the 2023 Act ng-ndpa-2023 over consent failures affecting more than a million app users, while the Court of Appeal had already anchored data protection in the constitutional right to privacy in 2021 ng-ndpr-2019 and a tribunal upheld a USD 220 million penalty against Meta and WhatsApp in 2025. South Africa's Information Regulator issued its first administrative fine under POPIA in 2023 za-popia-2013, penalising a government department for security failures that enabled a ransomware breach. Newer entrants are joining this tier: Tanzania's commission issued its first determination in 2025 tz-pdpa-2022, and Uganda's office found Google subject to the extraterritorial reach of its 2019 Act ug-dppa-2019 in the same year. The lesson the Coverage Scores encode is that the jurisdictions scoring 80 and above, Kenya, Nigeria, South Africa, Egypt, Zambia zm-dpa-2021, Zimbabwe and Uganda among them, are largely those where a resourced regulator has begun to leave a public record of decisions, while the broad middle band reflects laws whose enforcement remains unconfirmed or only just beginning. Even within the active tier, independence varies: Zambia's commission and Egypt's centre both sit within or under a ministry rather than as fully autonomous bodies, a structural feature worth watching as their caseloads grow and as their decisions begin to bind well-resourced controllers.

Where the gaps remain

Eleven jurisdictions still lack a comprehensive data protection law in force, and they do not form a single group. The first cluster is shaped less by legislative choice than by circumstance: the Central African Republic, Burundi, Eritrea, Sudan, South Sudan and Libya. Several are in or emerging from conflict, and the records reflect it. Sudan has no law and no advanced bill, with institutional development constrained by the conflict environment; Eritrea has no law, no bill and no adjacent framework that might carry incidental provisions; South Sudan's 2021 Cybercrimes Order imposes data-retention obligations without corresponding privacy safeguards, and its reported bill remains unenacted; Libya's 2022 cybercrime and electronic-transactions laws offer only incidental, non-protective coverage. To group these together is not to suggest they are interchangeable, still less that legislation is imminent or impossible in any of them, only that the binding constraint is institutional capacity rather than legislative intent.

The second cluster is at the drafting stage and is best read as a matter of legislative timing. Namibia's Data Protection Bill na-dpb-2025 and Mozambique's Personal Data Protection Bill mz-pdpb-2025 are both advancing, with the substantive design, including the shape of the future regulator, still subject to parliamentary amendment. Liberia's draft bill lr-dp-draft and Sierra Leone's combined data-protection and access-to-information bill sl-dp-draft are similarly in progress, the latter not yet public in final form. Guinea-Bissau reportedly has a draft, though no confirmed text is on file. These are jurisdictions where a law is plausibly a question of when rather than whether, but the Library records them as bills, not statutes, and this guide treats them accordingly. Predicting assent dates for legislation moving through any parliament is hazardous, and nothing in the data warrants treating enactment as a foregone conclusion in any individual case.

What would change the picture

The next few years of African data protection will be defined less by new statutes than by whether existing ones acquire institutional muscle. Three developments already visible in the data point the way.

The first is the conversion of recently constituted regulators into ones with a track record. Several authorities reached operational status only in the last eighteen months, the Republic of Congo's commission in January 2026 cg-dp-2019, Madagascar's in August 2025 mg-dp-2014, Egypt's centre as its framework became fully operational in late 2025 eg-pdpl-er-2025, and Zambia's, which commenced formal enforcement in March 2025 zm-dpa-2021. Whether these follow Kenya and Nigeria into a steady cadence of decisions is the central question for the period ahead. The second is modernisation of the earlier-generation laws by amendment, exemplified by Algeria's 2025 reform dz-law-25-11-2025 and the modernisation bills pending in jurisdictions such as Tunisia, whose 2004 statute tn-dp-2004 predates the entire accountability model. The third is cross-border cooperation: the Library already records a cooperation memorandum between Mauritania's and Algeria's authorities, and the African Union's Malabo Convention now provides a continental baseline that an increasing share of these regimes can be measured against. The pending bills in Namibia, Mozambique, Liberia and Sierra Leone will, if enacted, narrow the no-law group further. But the more consequential shift will be quieter, the gap between a law in force and a regulator that enforces it closing, jurisdiction by jurisdiction, until the continental map reflects not just where data protection has been legislated, but where it actually operates.

This guide was produced by Ademola Adekunbi and reviewed by the ATLPF research team. It reflects the state of the law as at 27 June 2026. Notify us of an error or update (opens in new tab).

Related guides

Topic guide

How Africa actually regulates digital finance: a comparative guide to fintech law

NigeriaKenyaGhanaTanzaniaUgandaRwandaZimbabweZambiaSouth AfricaMoroccoEgyptAlgeriaMauritiusEthiopiaNamibiaMalawiMadagascarBotswanaLiberiaSudanMozambiqueSouth SudanComorosDjiboutiGambiaGuineaMauritaniaBeninCôte d'IvoireGuinea-BissauNigerSenegalCameroonCongo (Republic)Equatorial GuineaGabonCentral African Republic

Ademola Adekunbi · June 2026

If you set out to find "the fintech law" of an African country, you will usually fail, not because the activity is unregulated, but because there is rarely a single statute to find. Across the ATLPF L

Read →
Topic guide

Switched off: surveillance powers, internet shutdowns, and the law behind them in Africa

South AfricaRwandaZimbabweUgandaNigeriaNamibiaBotswanaEgyptTunisiaTanzaniaKenyaCameroonEthiopiaBeninSierra LeoneSenegalSudanZambiaCabo VerdeComorosGabon

Ademola Adekunbi · June 2026

The most important thing the Digital Rights sweep surfaced is not that African states restrict communications, it is how they do it. Across the jurisdictions surveyed, the legal authority used to inte

Read →
Topic guide

One law, many jobs: how African cybercrime statutes carry data protection, fintech, and digital rights obligations

MalawiCameroonBeninCongo (DRC)NigeriaEgyptDjiboutiSouth AfricaSudanZimbabweGuineaKenyaTanzaniaUgandaGhanaRwandaAngola

Ademola Adekunbi · June 2026

A meaningful number of African countries do not have a separate data protection act, a separate cybercrime act, a separate fintechfraud regime, and a separate digitalrights statute sitting side by sid

Read →
Topic guide

How African data protection authorities are actually enforcing the law

NigeriaKenyaSouth AfricaGhanaRwandaEgypt

Ademola Adekunbi · June 2026

A data protection law is only as real as its enforcement. Across Africa the past decade has produced a wave of new statutes, comprehensive frameworks modelled, to varying degrees, on the GDPR, but the

Read →