One law, many jobs: how African cybercrime statutes carry data protection, fintech, and digital rights obligations
A meaningful number of African countries do not have a separate data protection act, a separate cybercrime act, a separate fintech-fraud regime, and a separate digital-rights statute sitting side by side. They have one law, usually styled as a cybercrime, cybersecurity, or "digital code" statute, that was drafted broadly enough to do two, three, or four of those jobs at once. A practitioner who assumes a tidy one-topic-one-law architecture will, in these jurisdictions, look in the wrong place.
This is not a theoretical observation. When the Library queried its own Instruments database for every record tagged with Cybercrime alongside at least one other topic, 35 instruments came back. The clearest illustrations are statutes the research team catalogued, then had to return to and re-tag as later topic sweeps revealed obligations the first read had missed. Malawi's Electronic Transactions and Cyber Security Act mw-etcsa-2016 is tagged across four topics. Cameroon's 2010 cybersecurity and cybercriminality law cm-cyber-2010 carries three. Benin's Digital Code bj-digital-code-2018 and the Democratic Republic of the Congo's Digital Code cd-dc-2023 each carry four. Nigeria's Cybercrimes Act ng-cyber-2015 and Egypt's Anti-Cyber and Information Technology Crimes Law eg-cyber-2018 both pull in fintech-fraud and data-protection material under a cybercrime banner.
This guide walks through what "combined" actually looks like, why it happens, and, most usefully, the concrete search risk it creates for anyone researching these markets.
What "combined" actually looks like
Start with Malawi, because the Library's own records show the overlap being discovered in stages rather than seen whole. The Electronic Transactions and Cyber Security Act, 2016 mw-etcsa-2016 was first catalogued during the Data Protection sweep, on the strength of its Part IV data-protection provisions. The Changelog then records a 26 June 2026 entry "Updated for the Cybercrime sweep": the team confirmed via MalawiLII and the regulator that only Part IV had been displaced by the standalone Data Protection Act, 2024, while Part X, unauthorised access, interception, hacking, the introduction of viruses, child pornography, cyber-harassment, cyber-stalking and offensive communication, remained fully operative. The statute's status was flipped from Superseded back to In Force, and its title broadened beyond the original data-protection scoping. A third entry, dated 27 June 2026, then "Updated for the Digital Rights sweep (Malawi checked first per brief)" and added the Digital Rights topic, having identified section 24 (online public communication subject to restriction), section 83 (search warrants over information systems) and section 84(2) (ministerial discretion to permit interception). One statute, three sweeps, four topics, Data Protection, Cybercrime, Telecoms and Digital Rights, each earned on the strength of provisions that genuinely sit in the text.
Cameroon's Law No. 2010/012 on cybersecurity and cybercriminality cm-cyber-2010 tells a similar staged story. Its offence catalogue lives in sections 60 to 89: unauthorised access, data manipulation, identity theft, online fraud, child sexual abuse material, and hate speech communicated electronically, with penalties reaching twenty years. The Changelog shows the Cybercrime tag and these offence provisions were present "from the original sweep," so the cybercrime review on 26 June 2026 created no duplicate and required no substantive change. The Digital Rights tag came later, on 27 June 2026, when the team recognised that the law's surveillance dimension, a mandatory ten-year retention of connection and traffic data, disclosable to authorities on request, plus criminalised interception and electronic content offences, squarely engages digital rights. Notably, the same review investigated Cameroon's 2017 - 2018 Anglophone-region internet shutdowns and found they rested on administrative ministerial directives under the telecommunications laws and emergency powers, not a dedicated statutory shutdown power; rather than fabricate a non-existent instrument, the team flagged the absence. Its data-protection provisions, meanwhile, are explicitly incidental rather than a standalone regime, and are being superseded by Cameroon's dedicated 2024 data protection law, but the 2010 statute remains the live home of the cybercrime and surveillance rules.
The francophone "digital code" model compresses even more into a single instrument. Benin's Code du numérique bj-digital-code-2018 consolidates electronic communications, the digital economy, e-transactions, data protection (Book V) and cybercrime (Book VI) in one law. Here too the Changelog shows progression: a 26 June 2026 cybercrime enrichment noting Cybercrime "already present in Topics from the prior Data Protection sweep," followed the same day by a Digital Rights sweep that added the pink tag once the team focused on the Code's online-expression offences, notably Article 550 on disseminating "false information" and electronic harassment, which press-freedom organisations have documented being used against journalists. The DRC's Digital Code cd-dc-2023 follows the identical arc: initial draft, a cybercrime sweep confirming the offence content (attacks on system confidentiality and integrity, phishing, electronic harassment, the Article 360 false-information offence, corporate criminal liability) was "already present," then a Digital Rights tag added on 27 June 2026. In both, a researcher reading only the data-protection title would walk straight past the surveillance and content-offence machinery.
A narrower but instructive variant is Angola's network-and-systems protection law ao-cyber-2017, which earns only two tags, Cybercrime and Telecoms, but makes the same basic point: the offence content and the communications-infrastructure obligations live together in one instrument, and neither is where a reader expecting a stand-alone statute would first look.
The honest point these Changelogs illustrate is methodological: ATLPF did not see the full topic footprint of these statutes on first read. It surfaced topic by topic, sweep by sweep, which is exactly how cross-cutting legislation reveals itself in practice. The progression is not a sign of sloppy first-pass work; it is the unavoidable consequence of cataloguing statutes whose reach exceeds their titles. A reviewer working a Data Protection sweep is reading for data-protection provisions, and will reliably find and tag them, but the cybercrime offences and surveillance powers in the same text only get their due when a reviewer comes back through with cybercrime or digital-rights eyes. Each pass is accurate to its own remit; the full picture is the sum of the passes.
Why this happens
It is worth being careful here, because the temptation is to over-explain. The Library's records establish that these combined instruments exist; they do not prove why any given legislature chose a single bill over several. What can be said is that a particular institutional logic is plausible and worth naming.
Drafting and passing primary legislation is expensive in time, parliamentary attention and specialist expertise. A jurisdiction building out its digital-law framework more or less from scratch faces a choice: pass one comprehensive bill covering computer-related offences, electronic transactions, data handling and cybersecurity together, or sequence three or four separate specialist statutes through the legislative pipeline over many years. The first route gets a working framework onto the statute book in a single legislative act. The "digital code" instruments, Benin bj-digital-code-2018, the DRC cd-dc-2023, and Djibouti's Code du numérique dj-digital-code-2025, are the most visible expression of this consolidating instinct: the title itself signals an intent to cover the whole digital field in one text.
There is also a drafting-template effect. Many of these statutes are visibly aligned to the same two reference models, the Council of Europe's Budapest Convention and the African Union's Malabo Convention, which themselves bundle substantive offences, procedural powers and cross-border cooperation. A national bill that imports that structure inherits its breadth, picking up data-preservation, interception and service-provider obligations as a matter of course, even when the bill is nominally "about" cybercrime. Add the common pattern of designating the existing communications regulator as the implementing authority, MACRA in Malawi mw-etcsa-2016, ANTIC in Cameroon cm-cyber-2010, and a single statute ends up carrying telecoms, data and enforcement functions together.
None of this is a proven causal claim, and it would be wrong to present it as one. Some combined instruments may reflect deliberate codification policy; others may reflect capacity constraints; others simply the convenience of a borrowed template. The pattern is real and recurrent; the precise driver in any one country is a question the records here do not settle.
The practitioner risk this creates
This is where the pattern stops being a curiosity and becomes a working hazard. If you are researching one of these jurisdictions and you search only for the obviously-titled instrument, you will miss live, enforceable obligations sitting in a differently-titled act.
Consider the fintech-fraud dimension. A compliance lead mapping electronic-payment-fraud exposure in Nigeria might reasonably search for a payments or financial-crime statute. But the detailed card, ATM, phishing and financial-institution-system offences sit inside the Cybercrimes Act ng-cyber-2015, tagged for Fintech precisely because that is where the electronic-fraud provisions live. Egypt is the same: the fraudulent-use-of-bank-card and electronic-payment offences are in the Anti-Cyber and Information Technology Crimes Law eg-cyber-2018, not a dedicated fintech text. Conversely, the cyber dimension can hide inside a financial-regulatory instrument: South Africa's payment-system cyber-resilience requirements come not from the Cybercrimes Act but from a Reserve Bank directive za-npscyberdirective-2024, and Sudan's mobile-payment fraud controls sit in a central-bank directive sd-fintech-newpayment-controls-2026. Search on the wrong side of the fintech/cybercrime line and the obligation is invisible.
The same trap operates for data protection and for digital rights. In Zimbabwe, the data-protection regime and the cybercrime offences share a single statute, the Cyber and Data Protection Act zw-cdpa-2021. In Guinea gn-csdp-2016, cybersecurity and personal data protection are combined in one 2016 law. A researcher looking for "the data protection act" in these countries and not finding a free-standing one might wrongly conclude the jurisdiction has no data-protection regime, when in fact it is embedded in the cyber statute. The digital-rights exposure is the most easily missed of all, because it is rarely signposted in a title: the surveillance, interception, data-retention and content-offence provisions that NGOs track as free-expression risks are typically buried in cybercrime or digital-code instruments, Cameroon's ten-year retention rule cm-cyber-2010, Malawi's interception discretion mw-etcsa-2016, the Article 360 / Article 550 false-information offences in the DRC cd-dc-2023 and Benin bj-digital-code-2018. The same Cybercrime-plus-Digital-Rights pairing recurs across a long tail of jurisdictions, Kenya ke-cyber-2018, Tanzania tz-cyber-2015, Uganda ug-cyber-2011, Ghana gh-cyber-2020, Rwanda rw-cyber-2018, South Africa za-cyber-2020 and many francophone and lusophone states besides.
So the practical rule follows directly. If you cannot find a country's dedicated statute on a digital-law topic, do not assume the topic is unregulated, open the cybercrime or "digital code" act and read it through. Specifically: for data-protection rules, look for a "personal data" part or title inside the cyber statute (as in Zimbabwe and Guinea). For fintech-fraud, look for the computer-related fraud and forgery offences and any provision naming card, ATM, electronic-payment or financial-institution systems (as in Nigeria and Egypt). For digital-rights and surveillance exposure, look for data-retention periods, interception or lawful-access powers, website-blocking provisions, and "false information" or online-harassment content offences. A statute that names a sector regulator as its implementing authority is a strong signal that telecoms or sector-specific obligations are bundled in as well. In these markets, the title of an act is an unreliable guide to its contents, and the responsible research move is to read past it.
Why the Library is built this way
This pattern is the reason the Instruments database tags each entry with every topic it genuinely earns, rather than forcing one instrument into one topic. A single-topic taxonomy would have filed Malawi's Act mw-etcsa-2016 under Data Protection and stopped, and a user searching the Cybercrime or Digital Rights topic would never have found it, even though the statute is a live source of law in all three areas. Multi-tagging is what allows the same instrument to surface correctly from four different starting points.
The Changelogs reinforce the point. Records like Malawi mw-etcsa-2016, Cameroon cm-cyber-2010, Benin bj-digital-code-2018 and the DRC cd-dc-2023 show topics being added over successive sweeps, each addition tied to a specific provision the reviewer identified and a source they checked. That is an honest account of how legal research in this field actually has to work: cross-cutting statutes do not announce their full reach, and a catalogue that pretended otherwise would mislead its users. By recording the progressive discovery rather than smoothing it into a single confident classification, the Library captures something true about the material, and gives the practitioner the one thing the statute's title will not: a reliable map of everything the law actually does.
This guide was produced by Ademola Adekunbi and reviewed by the ATLPF research team. It reflects the state of the law as at 27 June 2026. Notify us of an error or update (opens in new tab).
Related guides
How Africa actually regulates digital finance: a comparative guide to fintech law
Ademola Adekunbi · June 2026
Switched off: surveillance powers, internet shutdowns, and the law behind them in Africa
Ademola Adekunbi · June 2026
Data protection law across Africa: a comparative overview
Ademola Adekunbi · June 2026
How African data protection authorities are actually enforcing the law
Ademola Adekunbi · June 2026