Senegal
West Africa
Senegal was one of West Africa's data protection pioneers. Its primary instrument, Law No. 2008-12 of 25 January 2008 on the protection of personal data, predates the ECOWAS Supplementary Act and drew on Convention 108 and the French data protection tradition. The law governs automated processing and non-automated processing in structured filing systems, covering controllers established in Senegal and those outside the country that use equipment located in Senegalese territory; purely personal or domestic processing is excluded. Core data-quality principles, purpose limitation, adequacy, accuracy, and storage limitation, anchor the regime, and controllers must implement appropriate technical and organisational security measures. A defining feature is the mandatory prior declaration and authorisation regime. All processing must be declared to the Commission de Protection des Données Personnelles (CDP) before it begins; the CDP issues a receipt within one month authorising the processing without relieving the controller of its legal responsibilities. Processing involving sensitive data, biometrics, or data relating to criminal offences or national security requires prior authorisation rather than simple declaration. Data subjects hold rights of access, rectification, erasure, and opposition (including to direct marketing without giving reasons), and automated decisions producing significant legal effects attract specific safeguards. Cross-border transfers are prohibited unless the recipient country ensures adequate protection or derogations and safeguards apply. The CDP, created by the 2008 law, is an established and active independent supervisory authority that receives declarations and authorisations, conducts on-site investigations, issues warnings and injunctions, and refers matters for criminal prosecution; penalties include fines and imprisonment, with aggravated sanctions for unauthorised sensitive-data processing. Having legislated in 2008, earlier than most ECOWAS states, and maintained a continuously operating regulator, Senegal is one of the more established regimes in West Africa, even though its declaration-based architecture reflects the pre-GDPR generation of laws.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 1 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 0 | 0 | ○ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 1 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Loi N° 2021-33 du 23 juillet 2021 modifiant le Code pénal et Loi N° 2021-34 modifiant le Code de procédure pénale (Senegal 2021 anti-terrorism amendments, 'offences relating to information and communication technologies' and 'serious disturbance of public order' as terrorist acts)
Enacted 25 Jun 2021
Loi n° 2008-11 du 25 janvier 2008 relative à la cybercriminalité (Law on Cybercrime) (Senegal)
Enacted 25 Jan 2008
Stratégie nationale et feuille de route du Sénégal sur l'Intelligence Artificielle à l'horizon 2028 (Senegal National Artificial Intelligence Strategy and Road Map to 2028)
Enacted 1 Jan 2023
Loi N° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel (Senegal Personal Data Protection Act 2008)
Enacted 25 Jan 2008
The 2008 declaration-and-authorisation model predates the GDPR accountability approach: there is no fixed statutory breach-notification deadline, no general DPO mandate, and no portability right on file. No modernising amendment or implementing regulation is recorded.