How African data protection authorities are actually enforcing the law
A data protection law is only as real as its enforcement. Across Africa the past decade has produced a wave of new statutes, comprehensive frameworks modelled, to varying degrees, on the GDPR, but the meaningful test of any of them is not the elegance of their drafting. It is whether a regulator or a court has ever actually used them against a real respondent. On that measure, the picture the Library can currently document is both uneven and revealing.
Of the 43 African jurisdictions whose data protection law the Library records as currently in force, only five have a documented enforcement action or judgment on file: Kenya, Nigeria, South Africa, Tanzania and Uganda. Every other jurisdiction with a law on the books, including several where the statute has been in force for well over a decade, has, so far as the Library has been able to establish, no recorded enforcement decision at all. That ratio is the single most important fact about data protection in Africa today. The continent has largely finished legislating. It has barely begun enforcing, or at least barely begun enforcing in ways that produce a public, citable record.
This guide draws exclusively on the enforcement decisions and judgments documented in the Library's Cases database, twelve matters across those five jurisdictions. It does not ask what the laws say. It asks what the regulators and courts have actually done with them: who is acting, against what kind of conduct, and to what effect. Where a decision rests on secondary reporting rather than a published primary text, that limitation is flagged in the discussion, because a guide making comparative claims across cases must hold itself to a higher evidentiary standard than any single database entry.
Who is actually enforcing
The five jurisdictions with a documented enforcement record divide into two groups: dedicated data protection authorities exercising administrative powers, and ordinary courts applying the statutes on review or appeal. In several of the five, both appear in the record.
Kenya has the deepest documented record, and its Office of the Data Protection Commissioner (ODPC) is the most active single regulator in the dataset. The ODPC regulates the processing of personal data and enforces compliance with the Data Protection Act 2019, and the cases on file show it doing exactly that: a sequence of penalty notices against a range of respondent types, a consumer-electronics company, a private school, a digital-credit provider, beginning with the first penalty notice ever issued under the Act in December 2022. Kenya is also the only jurisdiction in the dataset where a superior court has applied the Act to a major technology operator, in the Worldcoin litigation discussed below. The combination gives Kenya both administrative breadth and judicial depth.
Nigeria presents a different shape. Its dedicated authority, the Nigeria Data Protection Commission (NDPC), regulates and enforces standards under the Nigeria Data Protection Act 2023 and is recorded imposing a substantial fine on a major bank. But Nigeria's documented record is notable for its institutional variety: the largest documented penalty in the country came not from the NDPC at all but from the Competition and Consumer Protection Tribunal upholding a decision of the Federal Competition and Consumer Protection Commission (FCCPC), and the foundational ruling on the constitutional status of data protection came from the Court of Appeal. Nigeria's enforcement, as documented, runs across a data protection regulator, a competition-and-consumer-protection regulator, a specialist tribunal and the senior appellate court.
South Africa's Information Regulator monitors and enforces compliance with the Protection of Personal Information Act 4 of 2013 (POPIA) and the Promotion of Access to Information Act. The single documented South African matter is its first administrative fine under POPIA, a significant marker, since it is the point at which the Regulator's enforcement powers became operative in practice rather than on paper.
Tanzania's Personal Data Protection Commission (PDPC), an independent body established in May 2023 under the Personal Data Protection Act 2022, accounts for three of the twelve documented matters, though all three rest on secondary sources rather than published primary texts. Two are first-instance determinations by the Commission; the third is a constitutional challenge to the 2022 Act heard by the High Court. Tanzania thus shows both a new regulator moving quickly into adjudication and a judiciary willing to test the statute itself.
Uganda's Personal Data Protection Office (PDPO), established within the National Information Technology Authority and operational since August 2021, appears once, in a determination against a global platform for processing Ugandans' data without registering as a data controller. As with Tanzania, the regulator is recent and the documented activity is early.
The through-line is that documented enforcement clusters where a dedicated authority has been operationalised and resourced, and that courts enter the picture mainly when a constitutional question or a high-profile technology operator is involved.
What is actually being enforced against
Grouped by the conduct penalised, the documented cases fall into five recognisable patterns. Some are supported by several matters; others rest on a single decision, and are identified as such.
Unauthorised commercial use of personal data, including children's images. This is the most frequently documented category and the clearest. In Kenya, the ODPC's first-ever penalty notice, against Oppo Kenya in December 2022, concerned the use of a complainant's photograph on a corporate Instagram account for commercial purposes without consent, contrary to section 37 of the Data Protection Act 2019. In September 2023 the ODPC fined Roma School in Nairobi for publishing photographs of minor pupils on social media for marketing purposes without parental consent, the first Kenyan determination on children's data. The same fact pattern recurs in Tanzania, where the PDPC's inaugural determination, in the matter recorded as Nyangoma Mwesingwa v Cecilia Maliganya (2025), concerned the commercialisation of a newborn child's image on Instagram without parental consent. The Tanzanian determination is drawn from secondary legal analysis; the Commission has not published the full text. A second Tanzanian PDPC determination, recorded as Abdul Said Naumanga v Mi Casa Company Limited (Complaint No. 08 of 2024), addressed unauthorised publication of an individual's personal data in the media and ordered compensation; it too rests on secondary reporting, and its decision date could not be confirmed from the record. Across these matters, regulators consistently treat an identifiable person's image as personal data whose commercial use requires consent, with a heightened requirement of verifiable parental consent where the data subject is a child.
Biometric data collection without valid consent. The single most significant decision in the dataset is the Kenyan High Court's judgment in Republic v Tools for Humanity Corporation & others; Katiba Institute & others [2025] KEHC 5629 (KLR), the Worldcoin litigation. The court held that the collection and processing of Kenyans' iris and facial biometric data through the "Orb" device contravened the Data Protection Act 2019 on two independent grounds: consent procured by the inducement of cryptocurrency tokens was not valid consent, and the operators had failed to conduct an adequate Data Protection Impact Assessment as required by section 31. The remedies were correspondingly strong, certiorari quashing the processing, a mandamus compelling permanent deletion of all biometric data within seven days under the Data Commissioner's supervision, and a prohibition on further biometric processing absent a lawful assessment. The decision matters well beyond Kenya: it establishes, at superior-court level, that financial inducement vitiates consent and that an impact assessment is a mandatory legal precondition, not a procedural afterthought, for high-risk biometric processing. It is, as a published primary judgment, also among the best-evidenced matters in the dataset.
Platform-level data practices at scale. Two documented matters concern global platforms. In Nigeria, the Competition and Consumer Protection Tribunal in Meta Platforms Inc & WhatsApp LLC v FCCPC (2025) dismissed the companies' appeal and upheld the FCCPC's finding that their data-privacy practices were discriminatory and exploitative toward Nigerian consumers, including sharing data without consent and denying Nigerian users control over their data. In Uganda, the PDPO in Ssekamwa Frank & 3 Others v Google LLC (2025) found Google in breach of the Data Protection and Privacy Act 2019 for processing Ugandans' personal data without registering as a data controller, holding that the Act applies extraterritorially under section 1 to any entity handling Ugandan citizens' data and ordering Google to register and evidence compliance with cross-border-transfer requirements. The shared proposition is that offshore platforms cannot escape local obligations by operating from abroad where there is a commercial nexus with local data subjects.
Financial-sector data misuse. Two matters concern the financial sector. In Kenya, the ODPC fined Mulla Pride Limited, a digital-credit provider, in September 2023 for unlawfully obtaining the contact details of borrowers' third-party referees from borrowers' phones and using them for threatening debt-collection, the leading documented Kenyan determination on abusive practices by digital lenders, a sector that generated the bulk of early complaints to the ODPC. In Nigeria, the NDPC's decision against Fidelity Bank Plc (2024) found that the bank processed the personal data of over one million users of its banking application without valid consent and engaged non-compliant third-party processors. The Fidelity Bank matter must be read with caution: the NDPC has not published a full written decision, the entry is drawn from the Commission's public statements and reputable secondary reporting, and the bank publicly disputed the findings.
Government-sector security failures. One documented matter, in South Africa, addresses security obligations rather than collection or consent. The Information Regulator's R5 million administrative fine against the Department of Justice and Constitutional Development (2023) followed the Department's failure to comply with an enforcement notice and its breach of the security-safeguard obligations in sections 19 and 22 of POPIA, specifically, a failure to renew antivirus, intrusion-detection and SIEM licences that contributed to a 2021 ransomware breach. As the only documented matter of its kind in the dataset, it stands for the proposition, on a single example, that inadequate technical security is a sanctionable breach in its own right and that public bodies are not exempt.
A sixth, cross-cutting theme is the constitutional status of data protection, evidenced by two matters: the Nigerian Court of Appeal's ruling in Digital Rights Lawyers Initiative & Ors v NIMC (2021), holding that the constitutional right to privacy encompasses data protection, and the Tanzanian High Court's order in Tito Magoti v Attorney General (2024) requiring amendment of vague provisions of the 2022 Act. The Magoti holding is drawn from contemporaneous reporting rather than a located primary judgment.
The size and shape of penalties
The documented monetary outcomes span several orders of magnitude, and the most useful thing this guide can do is present them as recorded rather than force them into a single comparable figure. Converting between currencies without a sourced and dated exchange rate would risk misleading more than it informs, so the amounts below are given in the currency in which each decision recorded them.
At the lower end sit the Kenyan ODPC penalties, imposed in Kenyan shillings against individual respondents: KES 5,000,000 against Oppo Kenya (the maximum then available under the Act), KES 4,550,000 against Roma School, and KES 2,975,000 against Mulla Pride. South Africa's Information Regulator imposed an administrative fine of R5,000,000 on the Department of Justice. Tanzania's PDPC, in the Naumanga matter, ordered compensation of TZS 20,000,000 to the data subject, a remedy directed to the complainant rather than a penalty to the state, and one drawn from secondary reporting. Nigeria's NDPC penalty against Fidelity Bank, recorded at approximately ₦555.8 million, is the largest sum imposed by a dedicated data protection authority in the dataset, though, as noted, it rests on the Commission's public statements rather than a published decision and was disputed by the bank.
Standing entirely apart is the Nigerian Meta/WhatsApp matter, where the Competition and Consumer Protection Tribunal upheld a penalty of USD 220 million (plus USD 35,000 in investigation costs). This figure is a different order of magnitude from everything else documented and should be read as the outlier it is, not blended into any notion of a typical or average penalty. It is also doctrinally distinct: it issued under competition and consumer-protection law following a joint FCCPC - NDPC investigation, not as a fine under a data protection statute, which is why the matter is not tied to a data protection instrument in the underlying record. The shape of the data, then, is not a smooth distribution but a long tail: a cluster of regulator penalties in the low millions of local-currency units, one substantially larger data-protection-authority fine still contested, and a single competition-law penalty in the hundreds of millions of dollars.
What's missing from this picture
Three cautions apply to everything above. The first and most important is that this is the enforcement activity ATLPF has been able to document, not, necessarily, all the enforcement activity that exists. The Cases database records twelve matters; the true universe of African data protection enforcement is certainly larger, and the gap between the two cannot presently be measured.
The second is the striking absence of documented activity in jurisdictions that have had laws in force for years. Ghana's Data Protection Act has been in force since 2012 and its Data Protection Commission has maintained a register for over a decade, yet the Library records no enforcement decision from Ghana. Rwanda's 2021 data protection law is supervised by the National Cyber Security Authority through its Data Protection and Privacy Office, and Egypt's Personal Data Protection Law No. 151 of 2020, now supplemented by 2025 executive regulations, is overseen by a dedicated Personal Data Protection Centre; neither jurisdiction has a documented case on file. These are not marginal frameworks. They are established regimes with named regulators, and their absence from the enforcement record is conspicuous.
The third caution is that the Library cannot currently distinguish between the possible explanations for that absence. A jurisdiction with no documented case may genuinely be doing little enforcement; it may be enforcing actively but not publishing its decisions in a form that can be found and verified; or the relevant decisions may exist and simply not yet have been located and recorded in the Library. These are very different states of the world, and nothing in the present dataset adjudicates between them. The four documented matters that rest on secondary sourcing rather than published primary texts, the Nigerian Fidelity Bank decision and all three Tanzanian matters, are a useful reminder of how much turns on publication practice: in each, an enforcement event is reported to have occurred, but the primary record is not publicly available, which is precisely the condition that, multiplied across a jurisdiction, would render real enforcement invisible to a project like this one.
What this record will tell us next
For now, the honest reading is that documented data protection enforcement in Africa is concentrated, recent and thin, five jurisdictions, twelve matters, a handful of published primary decisions. That is not a verdict on the continent's data protection ecosystem; it is a snapshot of what can currently be evidenced.
What would change the picture is more documented enforcement, and an increase would itself be a meaningful signal. As more regulators move from registration to adjudication, as more publish their decisions in citable form, and as more courts test these statutes against constitutional standards, the body of evidence will shift from a few landmark rulings toward something closer to a settled enforcement practice, the point at which a data protection regime stops being a statute and becomes a system. The Worldcoin judgment shows what a fully evidenced, superior-court application of one of these laws looks like; the gaps elsewhere show how far most jurisdictions are from generating a comparable record.
This is, accordingly, a living dataset. ATLPF will update this guide as further enforcement decisions are identified and verified, adding jurisdictions as their first documented matters surface, upgrading secondary-sourced entries as primary texts become available, and revising the patterns above as the evidence base grows. Readers should treat the absence of a jurisdiction or a pattern here as an invitation to look closer, not as proof that nothing is happening.
This guide was produced by Ademola Adekunbi and reviewed by the ATLPF research team. It reflects the state of the law as at 27 June 2026. Notify us of an error or update (opens in new tab).
Related guides
How Africa actually regulates digital finance: a comparative guide to fintech law
Ademola Adekunbi · June 2026
Switched off: surveillance powers, internet shutdowns, and the law behind them in Africa
Ademola Adekunbi · June 2026
One law, many jobs: how African cybercrime statutes carry data protection, fintech, and digital rights obligations
Ademola Adekunbi · June 2026
Data protection law across Africa: a comparative overview
Ademola Adekunbi · June 2026