SN

Senegal

West Africa

4Instruments
0Cases
2Regulators
65%Coverage
Overview

Senegal was one of West Africa's data protection pioneers. Its primary instrument, Law No. 2008-12 of 25 January 2008 on the protection of personal data, predates the ECOWAS Supplementary Act and drew on Convention 108 and the French data protection tradition. The law governs automated processing and non-automated processing in structured filing systems, covering controllers established in Senegal and those outside the country that use equipment located in Senegalese territory; purely personal or domestic processing is excluded. Core data-quality principles, purpose limitation, adequacy, accuracy, and storage limitation, anchor the regime, and controllers must implement appropriate technical and organisational security measures. A defining feature is the mandatory prior declaration and authorisation regime. All processing must be declared to the Commission de Protection des Données Personnelles (CDP) before it begins; the CDP issues a receipt within one month authorising the processing without relieving the controller of its legal responsibilities. Processing involving sensitive data, biometrics, or data relating to criminal offences or national security requires prior authorisation rather than simple declaration. Data subjects hold rights of access, rectification, erasure, and opposition (including to direct marketing without giving reasons), and automated decisions producing significant legal effects attract specific safeguards. Cross-border transfers are prohibited unless the recipient country ensures adequate protection or derogations and safeguards apply. The CDP, created by the 2008 law, is an established and active independent supervisory authority that receives declarations and authorisations, conducts on-site investigations, issues warnings and injunctions, and refers matters for criminal prosecution; penalties include fines and imprisonment, with aggravated sanctions for unauthorised sensitive-data processing. Having legislated in 2008, earlier than most ECOWAS states, and maintained a continuously operating regulator, Senegal is one of the more established regimes in West Africa, even though its declaration-based architecture reflects the pre-GDPR generation of laws.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection10
AI Governance10
Fintech00
Cybercrime10
Digital Rights10
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
sn-digitalrights-penalcode-2021·Act

Loi N° 2021-33 du 23 juillet 2021 modifiant le Code pénal et Loi N° 2021-34 modifiant le Code de procédure pénale (Senegal 2021 anti-terrorism amendments, 'offences relating to information and communication technologies' and 'serious disturbance of public order' as terrorist acts)

SenegalDigital RightsIn Force
Verified

Enacted 25 Jun 2021

sn-cyber-2008·Act

Loi n° 2008-11 du 25 janvier 2008 relative à la cybercriminalité (Law on Cybercrime) (Senegal)

SenegalCybercrimeIn Force
Verified

Enacted 25 Jan 2008

sn-ai-2023·Guidance

Stratégie nationale et feuille de route du Sénégal sur l'Intelligence Artificielle à l'horizon 2028 (Senegal National Artificial Intelligence Strategy and Road Map to 2028)

SenegalAI GovernanceProposed
Verified

Enacted 1 Jan 2023

sn-dp-2008·Act

Loi N° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel (Senegal Personal Data Protection Act 2008)

SenegalData ProtectionIn Force
Verified

Enacted 25 Jan 2008

Notable gaps

The 2008 declaration-and-authorisation model predates the GDPR accountability approach: there is no fixed statutory breach-notification deadline, no general DPO mandate, and no portability right on file. No modernising amendment or implementing regulation is recorded.