Bimonthly Update on Privacy in Africa (May & June)

TH ADMIN
No items found.

Introduction 

Africa's data protection and AI governance landscape continued to evolve rapidly over the past two months, with countries shifting from policy development to implementation while accelerating efforts to strengthen digital governance. Across the continent, Data Protection Authorities (DPAs) issued new guidance, advanced legislative reforms and intensified enforcement. Regional cooperation also gained momentum through new partnerships and initiatives aimed at promoting regulatory harmonisation and supporting Africa's digital sovereignty. AI governance also gathered pace as countries unveiled new strategies, policies and regulatory frameworks to guide the responsible adoption of AI.

Trend Spotlight: From AI Strategy to AI Institutions (contribution by Digital Policy Alert) 

In the past 2 months, the region witnessed a shift from adopting AI strategy documents to creating institutions and implementing arrangements. Rwanda approved the establishment of a National Artificial Intelligence Agency to support the execution of its AI agenda through a dedicated institutional framework. Egypt announced a National Strategy for Data Centres and Cloud Computing with an explicit AI-authority-governance dimension, tying infrastructure planning with oversight considerations. India and South Africa announced a bilateral cooperation arrangement on artificial intelligence and digital infrastructure. Taken together, these developments suggest African AI governance is entering an implementation phase of the national AI strategies set out over the past year. 

Data Protection

  • At its Annual General Meeting in Abidjan, the Network of African Data Protection Authorities (NADPA) adopted the Abidjan Declaration and a 2026–2030 roadmap to strengthen Africa's digital sovereignty through coordinated data governance. Discussions focused on AI, data governance, cross-border data flows and regional harmonisation. During the meeting, Cape Verde was elected to chair the body, with Côte d'Ivoire and Zimbabwe emerging as vice-chairs. Malawi, Guinea, Togo and Madagascar were admitted as new members. Zimbabwe was also voted to host the next AGM.
  • In May, several DPAs convened in Nigeria on a Data Protection Cross-Regional Study Tour. During the tour, the National Commissioner of Nigeria’s DPA emphasised that the exchange focuses on cross-border data transfer, particularly within the African Continental Free Trade Area framework.
  • Rwanda's DPA published Guidance on Personal Data Protection in the Health Sector and the Guidance on Personal Data Protection and Media.  The guidance notes aim to provide practical guidance to controllers and processors on complying with the obligations under the Personal Data Protection and Privacy Act.
  • Kenya and Guinea are advancing their national data governance frameworks. Kenya has opened consultations on its Draft National Data Governance Policy, proposing a new governance architecture led by a National Data Governance and Emerging Technologies Council and extending regulation to non-personal data through a proposed Data Governance Law. Meanwhile, Guinea has begun developing a National Data Governance Strategy to govern the processing, protection and value of data generated within the country.
  • Senegal's DPA has begun work on its 2026–2028 Strategic Development Plan, positioning privacy regulation to support the country's accelerating digital transformation, including AI, biometrics, digital identity and connected technologies under the New Deal Technologique.
  • Efforts are underway in Nigeria to review the Nigeria Data Protection Act. Nigeria's Senate has initiated a review of the Nigeria Data Protection Act to address emerging technological risks. The DPA is also considering amendments to better regulate AI, robotics and big data.
  • Mali's DPA convened a five-day extraordinary session to review outstanding data processing declarations and authorisation requests, and to examine undeclared processing activities and potential enforcement measures.
  • Colombia has proposed recognising Kenya and South Africa as providing an adequate level of data protection for international transfers. Meanwhile, discussions between Kenya and the EU on Kenya’s adequacy decision have entered their final stages.
  • South Sudan's National Communication Authority held a validation workshop for the country's draft Data Protection Bill, marking another step towards its adoption.
  • Algeria's DPA has confirmed that employers using fingerprint systems for attendance monitoring must notify the authority, inform employees, limit biometric processing strictly to attendance management, and implement strict safeguards for such biometric data.
  • Following the end of the voluntary registration period, Tanzania's DPA has warned that organisations processing personal data must now register as controllers or processors or risk fines and other enforcement action. 
  • The Mauritian Cabinet has approved the promulgation of the Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 to formalise the roles and responsibilities of Data Protection Officers (DPOs) within the country. 
  • Niger's Government has approved a decree dissolving the High Authority for the Protection of Personal Data, transferring its functions to the Ministry of Justice and the Ministry of the Interior, Public Security and Territorial Administration.
  • The Democratic Republic of Congo, working with the UN Economic Commission for Africa, convened a stakeholder workshop and capacity-building programme to support the development of its National Data Governance Strategy. The country also clarified authorisation requirements under the Digital Code, stating that processing involving sensitive personal data, cross-border transfers, children's data, video surveillance and large-scale profiling requires prior authorisation.
  • Senegal's DPA has released its quarterly report, highlighting key activities, including the processing of 286 declarations, 31 authorisation requests and the issuance of 27 authorisations.

Enforcement Action

  • Angola's DPA has imposed a fine of 505,000 USD on a technology company and a fine of 112,000 USD on a digital centre for failing to comply with key data protection obligations.
  • Kenya's DPA fined a healthcare provider 500,000 KES for using a former employee's personal data for commercial purposes without consent. A Kenyan High Court awarded KES 9.9 million in damages against Safaricom after finding that it had violated the constitutional privacy rights of 11 subscribers. Separately, the High Court suspended the operations of an AI-assisted teleradiology platform over alleged non-compliance with healthcare, digital health and data protection laws. 
  • South Africa's DPA has issued an enforcement notice against Central Johannesburg TVET College for unlawfully disclosing employees' personal data.
  • Uganda's DPA has dismissed a complaint against the National Identification and Registration Authority (NIRA), confirming that statutory data access rights cannot be used to obtain another person's personal data.

AI Governance

  • Governments across Africa continue to develop national AI frameworks. Algeria is developing a National AI Strategy; Burkina Faso approved the 2026–2030 AI roadmap prioritising AI applications across key sectors; Mozambique has published a draft strategy; Kenya is developing a National AI and Emerging Technologies Policy; and Sierra Leone is working with the World Bank on its first National AI Strategy. At the regional level, the East African Community has validated its 2026–2031 AI Strategy.
  • At the Africa Forward Summit in Nairobi, participating countries adopted the Africa Forward 2026 Summit Declaration, committing to a rights-based approach to AI governance aligned with the AU Continental AI Strategy, the AU Data Policy Framework and the AfCFTA Digital Trade Protocol. The declaration also promotes ethical AI, digital trade, interoperability and greater technological autonomy for Africa.
  • New AI regulators are emerging across the continent. Mozambique, Rwanda and Tanzania are establishing dedicated AI authorities to oversee the governance and regulation of AI.
  • Libya has unveiled its National AI Strategy 2026–2030 alongside a National Charter for AI Ethics, setting out principles of transparency, accountability, human oversight and digital sovereignty while positioning AI as a tool to support human decision-making.
  • Kenya's Judiciary has published a draft AI Policy outlining how AI may be responsibly deployed across judicial functions, including case management, document review, transcription and AI-powered chatbots. The policy also proposes establishing an AI Governance Committee to oversee implementation.
  • Mauritius has approved the promulgation of the Higher Education (Use of AI) Regulations 2026, which establish a formal governance framework for the use of AI in the country’s higher education sector. The regulations empower the Higher Education Commission to issue binding standards while prohibiting AI applications that facilitate bias, plagiarism, academic misconduct or breaches of privacy, intellectual property and cybersecurity laws.
  • Nigeria's Federal Ministry of Communications, Innovation and Digital Economy convened a National AI Trust Workshop in London, part of its continued international engagement on AI governance. 
  • South Africa has appointed an independent expert panel to redraft its National AI Policy after the previous draft was withdrawn following the discovery of AI-generated fictitious references.
  • With support from the International Telecommunication Union (ITU), Mozambique will establish an AI regulatory sandbox to support innovation alongside the development of its National AI Strategy and National Data Governance Policy.
  • Uganda's Ministry of ICT and National Guidance, together with UNESCO, has validated findings from its AI Readiness Assessment, paving the way for the country's forthcoming National AI and Emerging Technologies Strategy.

Partnerships

  • Nigeria’s DPA is forging strategic partnerships at the national and continental levels to advance its data protection agenda.  At the NADPA-RAPDP AGM, Nigeria signed Memorandums of Understanding (MoUs) with  Morocco and Gambia’s DPA. On a national level, the DPA signed MoUs with the Nigeria Governors’ Forum and the  Bureau of Public Procurement. The DPA hosted a working visit by a delegation from the UK Foreign, Commonwealth and Development Office (UKFCDO) to discuss potential areas of collaboration.
  • Senegal's DPA and the Observatory of the Quality of Financial Services (OQSF) have signed a partnership agreement to promote stronger personal data protection and consumer-focused financial services in response to the sector's growing digitalisation.

Conclusion

In the coming months, we anticipate continued momentum with enforcement as implementation frameworks mature. We also predict that several draft laws, policies, and strategies will near formal adoption.

Stay Informed
Stay ahead of tech trends. Get our twice-monthly updates on tech policy, data laws, and business rules across Africa sent straight to you.
Get the Insights
Your Name
FULL NAME
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.