The unfinished map: legislative trajectories in African data protection law
African data protection law is most often described as a snapshot, a count of which countries "have a law." That framing flatters the settled jurisdictions and misreads the rest. The more useful question is directional: not who has a law, but which way each jurisdiction is actually moving.
As documented in the ATLPF Instruments and Jurisdictions databases on this guide's publication date, the continent's fifty-four tracked jurisdictions fall into three groups. Forty-three have an in-force comprehensive data protection law. Four have a bill at a documented draft stage but nothing yet enacted: Liberia, Mozambique, Namibia and Sierra Leone. Seven have no comprehensive instrument at all, Burundi, the Central African Republic, Eritrea, Guinea-Bissau and Sudan with nothing on the books, and Libya and South Sudan with only incidental coverage buried in cyber or electronic-transactions statutes.
None of these categories is static. Within the period the Library itself has been tracking, the in-force column has grown, The Gambia's Act gm-pdpp-2025, Cameroon's cm-pdpa-2024 and Djibouti's Digital Code dj-digital-code-2025 all carry 2024 - 2025 enactment dates, and at least one record had to be corrected the other way: Namibia, assumed enacted in 2024 in the Library's own earlier research, was confirmed on review to be still at bill stage na-dpb-2025. The map, in other words, is being redrawn while we read it.
The completed transitions — what supersession looks like
A supersession is the cleanest evidence of trajectory: a jurisdiction not merely acquiring a law but replacing one regime with another. The Instruments database currently records two genuine examples, and they are different in kind.
Nigeria is the anchor case and the most fully documented. Its first substantive instrument was the Nigeria Data Protection Regulation 2019 ng-ndpr-2019, issued by the National Information Technology Development Agency (NITDA) under its NITDA Act powers. The NDPR was subsidiary legislation, not an Act of Parliament, a regulator's instrument rather than a statute. Its most distinctive feature was institutional: controllers above set thresholds had to engage a licensed Data Protection Compliance Organisation (DPCO) to run annual audits and file compliance reports with NITDA, building a private-sector compliance industry around the regulator. It granted data subjects rights of access, rectification and objection, restricted cross-border transfers to destinations with adequate protection, and imposed breach notification, but it rested on the delegated authority of an agency, with the vulnerability that implies.
The Nigeria Data Protection Act 2023 ng-ndpa-2023 changed the foundation, not just the detail. Three substantive shifts stand out from the two records. First, status: the framework moved from subsidiary regulation to primary legislation passed by the National Assembly, curing the long-standing doubt about whether a regulation could properly carry a national data-protection regime. Second, the supervisor: the Act established the Nigeria Data Protection Commission (NDPC) as a statutory authority succeeding NITDA's Data Protection Bureau, with its own legal personality and enforcement standing rather than delegated agency power. Third, continuity: rather than a clean break, the Act carried over key NDPR machinery, the DPCO-led audit model survived the transition, so the change was a consolidation onto firmer ground rather than a wholesale redesign. For practitioners the day-to-day regime felt familiar; what changed was its legal durability and the standing of its regulator.
The second example is narrower but real. In Malawi, data protection originally sat inside Part IV of the Electronic Transactions and Cyber Security Act 2016 mw-etcsa-2016, data-handling rules embedded in a broader cyber-statute rather than a dedicated regime. That content was superseded by the standalone Data Protection Act 2024 mw-dpa-2024, in force from 3 June 2024, which gave Malawi its first dedicated, comprehensive law. The pattern here is the recurring African move from incidental coverage inside a cyber-statute to a purpose-built data-protection Act, though, notably, supervision in Malawi still sits with the communications regulator (MACRA) rather than a dedicated authority, so the transition modernised the law without fully separating the institution.
Two supersessions are not a continent-wide trend, and this guide does not present them as one. They are the only clear cases currently on file. What they show is the two routes by which an existing regime gets replaced: upgrading a regulator's instrument to a statute, as in Nigeria, and extracting data protection from a host cyber-law into a dedicated Act, as in Malawi.
Bills in motion — the draft-stage jurisdictions
Four jurisdictions currently hold an Instrument at Status "Draft." All four were re-confirmed against live sources for this guide; none had been enacted as of the publication date. They cluster in West Africa (Liberia, Sierra Leone) and Southern Africa (Mozambique, Namibia), and each is described below from its existing Instrument record and a current-status check.
Liberia. The draft "Act for the Collection, Processing, Transmission, Storage, Protection, and Use of Personal Information" lr-dp-draft was developed by the Ministry of Posts and Telecommunications with EU and Internews support under the Liberia Media Empowerment Project. After two stakeholder validation rounds, the most recent in Monrovia in December 2024, President Boakai submitted it to the Legislature in 2025, and the House of Representatives began committee review. Its substantive provisions, data-subject rights, lawful bases, sensitive-data categories, cross-border restrictions, are modelled on the ECOWAS Supplementary Act of 2010. No supervisory authority has been established, and the record carries a reviewer flag that no official public text has yet been located. Status confirmed June 2026: still under parliamentary review, not enacted.
Sierra Leone. The Data Protection and Right to Access Information Bill 2025 sl-dp-draft, developed by the Ministry of Information and Civic Education, is notable for its architecture: it combines data protection and access-to-information in a single statute under one unified regulator, repealing and replacing the existing Right to Access Information Commission Act, the same model The Gambia adopted in 2025 gm-pdpp-2025. Cabinet approved the underlying national data-protection policy in April 2026 and authorised finalisation with the Attorney-General's office; the bill also contemplates regulating intelligence and security-agency use of personal data within a national-security carve-out balanced against privacy. Status confirmed June 2026: national validation concluded (November 2025), the bill moving toward Parliament via Cabinet, not yet enacted.
Mozambique. The Personal Data Protection Bill mz-pdpb-2025, led by the National Institute of Information and Communication Technologies (INTIC), advanced quickly through 2025: a public consultation opened in September 2025, a Council of Europe alignment session followed in October, and revised provisions circulated in November. The proposed framework is principle-based, lawfulness, purpose limitation, minimisation, accuracy, storage limitation, accountability, with the full modern rights catalogue including portability and objection to automated decision-making, and would establish a supervisory authority under INTIC oversight. Status confirmed June 2026: in technical harmonisation and ministerial review, not yet enacted; no dedicated authority yet exists.
Namibia. The Data Protection Bill na-dpb-2025 is the cautionary entry. Developed since a 2022 public call for comment by the Ministry of Information and Communication Technology, it was tabled in the National Assembly in September/October 2025. It draws on both the GDPR and the AU Malabo Convention, and would create an independent Information Commissioner with audit and sanction powers, mandate data-protection impact assessments for higher-risk processing, and restrict cross-border transfers. Crucially, the Library's own earlier research had assumed Namibia's law was "recent (2024)"; current verification confirmed that assumption was wrong, the bill remains under parliamentary consideration. Status confirmed June 2026: tabled, not enacted.
A related but distinct signal sits outside the four draft Instruments. Two mature in-force jurisdictions are mid-revision rather than mid-first-enactment: Tunisia's 2004 Organic Law has a modernisation bill pending but unenacted, and Angola's 2011 law has a 2025 draft revision pending. Neither is captured as a draft Instrument, they appear only in the Jurisdictions Notable Gaps fields, but they are the same kind of movement, one tier up: not "will there be a law" but "will the existing law be brought up to the GDPR generation." By contrast, Algeria and Niger have already completed that amend-in-place move, enacting amendments dz-law-25-11-2025, ne-law-2023-31 to their base laws dz-dp-2018, ne-dp-2022 rather than waiting for a wholesale replacement.
The jurisdictions with no instrument at all
Seven jurisdictions have no comprehensive data-protection instrument on file. They are not uniform, and grouping them by region and by whether any forward signal exists is the honest way to read them.
West Africa. Guinea-Bissau (Coverage Score 0) is the region's sole gap. Its Notable Gaps record reports a draft law but notes it is unenacted with no confirmed text on file, a forward signal exists, but only a faint one, and no Instrument record was created precisely because no reliable text could be confirmed. The contrast with the rest of West Africa, which is almost wholly covered, is stark.
East Africa. Three jurisdictions sit here. Burundi and Eritrea (both score 0) show no visible activity at all: the records describe a complete absence of law, supervisory authority and any identifiable draft or adjacent cyber-statute. South Sudan (score 10) differs in degree, its 2021 Cybercrimes Order imposes data-retention obligations without corresponding privacy safeguards, and a data-protection bill is reported but unenacted with no confirmed text. East Africa therefore contains both the "nothing observable" cases and one "incidental coverage plus a reported bill" case.
North Africa. Two jurisdictions. Sudan (score 0) has no law and no identified draft, with the record explicitly noting that the conflict environment limits institutional development. Libya (score 5) has 2022 cybercrime and electronic-transactions laws that provide only incidental, non-protective coverage, no data-subject rights, no oversight mechanism, and no comprehensive bill identified.
Central Africa. The Central African Republic (score 0) completes the group: no comprehensive law, no supervisory authority, no advanced draft, and, unusually, no broader cyber-law infrastructure that might otherwise carry incidental provisions.
Read together, the seven divide into two honest sub-groups. In two cases, Guinea-Bissau and South Sudan, there is a reported but unconfirmed bill, a forward signal too thin to record as an Instrument. In the other five, Burundi, the Central African Republic, Eritrea, Libya and Sudan, there is no visible comprehensive legislative activity at all, though Libya and South Sudan do carry incidental data-handling provisions in adjacent statutes. Several of these records note a constraining backdrop, active or recent conflict in Sudan, South Sudan, Libya and the CAR, without drawing causal conclusions from it. The geographic concentration is itself the most reliable observation: the gaps cluster in Central and Eastern Africa and in conflict-affected states, while West Africa stands almost fully covered with Guinea-Bissau the lone exception. What this guide will not do is predict when, or whether, any of these jurisdictions will legislate. The data supports a description of the present, not a forecast.
What drives the pace of change
The dataset supports correlation, not causation, and a few patterns are worth naming on that basis.
The clearest is regional clustering. Francophone West and Central Africa legislated early and densely: Senegal in 2008 sn-dp-2008, Benin in 2009 bj-dp-2009, and a steady run through Côte d'Ivoire in 2013 ci-dp-2013, with much of the region carrying laws of the same vintage and the same architecture, the CNIL-style "declaration-and-authorisation" model that recurs across the francophone Notable Gaps entries. This is less coincidence than shared legal heritage and shared regional templates.
Two of those templates are explicitly referenced in the instrument records themselves, which is what licenses naming them. The ECOWAS Supplementary Act of 2010 is cited as the model for the Liberian bill's substantive provisions lr-dp-draft; the AU Malabo Convention is cited as a source for Namibia's bill na-dpb-2025; and Council of Europe involvement shaped the Mozambican draft mz-pdpb-2025. Where regional or international frameworks appear, they appear as influences on text and structure, not as enforced mandates, several countries legislated long before, or independently of, ratifying them.
A second, looser pattern is generational. Earlier laws, the francophone 2000s wave, Morocco, South Africa, follow the permission-based declaration model and predate the GDPR accountability toolkit; later enactments and current bills, including Nigeria's 2023 Act ng-ndpa-2023 and the Mozambican and Namibian drafts, reach for breach-notification deadlines, mandatory DPOs, impact assessments and portability rights. A third pattern follows from the first two: the most recent activity is increasingly amendment rather than first enactment, Algeria and Niger amending in place, Tunisia and Angola with revisions pending, a sign that for much of the continent the frontier is shifting from "first law" to "second-generation law." These are patterns worth tracking, not laws of motion; the dataset names them but cannot prove their causes.
Closing
This guide is, by design, the most perishable of the three. Legislative status is the single most volatile field in the Library: a draft becomes an Act with one parliamentary vote, and a gap closes with one presidential assent. Everything above reflects the documented state as of the publication date, cross-checked against live sources, not a standing description.
Going forward, ATLPF will track the four live drafts most closely, since each could move to in-force at any sitting: Liberia lr-dp-draft, Sierra Leone sl-dp-draft, Mozambique mz-pdpb-2025 and Namibia na-dpb-2025. We will watch the two reported-but-unconfirmed bills in Guinea-Bissau and South Sudan for a confirmable text that would justify an Instrument record. We will follow the amend-in-place jurisdictions, Tunisia and Angola, where revision is pending. And we will keep correcting our own record where it drifts, as the Namibia entry shows we must.
What we will not do is predict dates. The value of this guide is not in forecasting the map's final shape but in showing, accurately, where the lines are still being drawn, and in committing to redraw them as the Instruments database is updated. Readers should treat this as a dated snapshot of motion, and check the underlying records for the current position.
This guide was produced by Ademola Adekunbi and reviewed by the ATLPF research team. It reflects the state of the law as at 27 June 2026. Notify us of an error or update (opens in new tab).
Related guides
How Africa actually regulates digital finance: a comparative guide to fintech law
Ademola Adekunbi · June 2026
Switched off: surveillance powers, internet shutdowns, and the law behind them in Africa
Ademola Adekunbi · June 2026
One law, many jobs: how African cybercrime statutes carry data protection, fintech, and digital rights obligations
Ademola Adekunbi · June 2026
Data protection law across Africa: a comparative overview
Ademola Adekunbi · June 2026