HomePolicy & RegulationData Protection Laws in Africa: Nigeria, Kenya and South Africa Compared

Data Protection Laws in Africa: Nigeria, Kenya and South Africa Compared

If your business collects names, phone numbers, ID numbers or any other personal information in Africa, data protection law almost certainly applies to you. This guide compares three of the continent’s most important regimes: Nigeria, Kenya and South Africa. It is a general overview, not legal advice.

At a glance

Nigeria Kenya South Africa
Main law Nigeria Data Protection Act 2023 (NDPA) Data Protection Act 2019 Protection of Personal Information Act 2013 (POPIA)
Regulator Nigeria Data Protection Commission (NDPC) Office of the Data Protection Commissioner (ODPC) Information Regulator
Fully in force 2023 2019, with regulations from 2021 1 July 2021
Registration Required for data controllers and processors of major importance Registration of data controllers and processors above set thresholds Information officers must be registered with the Regulator
Breach notification to regulator Within 72 hours of becoming aware, where a breach is likely to risk individuals’ rights Within 72 hours of becoming aware As soon as reasonably possible

Thresholds, fees and guidance are set by each regulator and change over time. Check the latest regulations and guidance notes.

Common principles

All three laws share core principles:

  • Lawful basis: process personal data only with consent or another legal ground, such as a contract, legal obligation or legitimate interest
  • Purpose limitation: use data only for the stated purpose
  • Data minimisation: collect only what you need
  • Accuracy and retention limits: keep data correct and do not keep it longer than necessary
  • Security: protect data with appropriate technical and organisational measures
  • Accountability: be able to show how you comply

Individuals’ rights

People generally have the right to be informed about processing, to access their data, to correct or delete it, and to object to certain processing such as direct marketing. Stronger protections apply to sensitive data such as health, biometric, religious or financial information, and to children’s data.

Cross-border data transfers

All three laws restrict sending personal data to other countries unless certain conditions are met, such as adequate protection in the receiving country, appropriate safeguards in contracts, or the individual’s consent. This matters when you use foreign cloud services, CRMs or AI tools; see How to Use AI Assistants Safely at Work.

Penalties

Regulators can issue enforcement notices and fines, and individuals may seek compensation. Fines can be significant, calculated as fixed maximums or a percentage of annual turnover depending on the law. Regulators in all three countries have taken enforcement action against organisations in recent years.

A practical compliance checklist

  1. Map what personal data you collect, where it is stored and who can access it
  2. Identify your lawful basis for each type of processing
  3. Publish a clear privacy notice
  4. Register with the regulator where required
  5. Appoint a data protection officer or information officer if required
  6. Put contracts in place with vendors that process data for you
  7. Secure data with access controls, encryption and 2FA; see our cybersecurity guide
  8. Prepare a breach response plan; see ransomware response
  9. Check rules before transferring data abroad
  10. Train staff and review compliance regularly

Other African data protection laws

Many other countries, including Ghana, Rwanda, Uganda, Egypt, Morocco, Senegal, Mauritius and others, have data protection laws with similar principles. If you operate in several countries, you may need to comply with each one. Continental efforts such as the Malabo Convention aim to harmonise rules; see The Malabo Convention Explained.

Back to our guide to tech policy in Africa.

TechBrief Africa Desk
TechBrief Africa Deskhttps://techbrief.africa/about/
The TechBrief Africa Desk is the editorial team behind TechBrief Africa. We research and write practical, plain-English coverage of artificial intelligence, startups, fintech, cybersecurity, connectivity and digital skills across Africa. Every article is checked against primary sources such as regulators, official company filings and published research, and is updated when facts change. Read our editorial policy at techbrief.africa/editorial-policy/.
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments