If your business collects names, phone numbers, ID numbers or any other personal information in Africa, data protection law almost certainly applies to you. This guide compares three of the continent’s most important regimes: Nigeria, Kenya and South Africa. It is a general overview, not legal advice.
At a glance
| Nigeria | Kenya | South Africa | |
|---|---|---|---|
| Main law | Nigeria Data Protection Act 2023 (NDPA) | Data Protection Act 2019 | Protection of Personal Information Act 2013 (POPIA) |
| Regulator | Nigeria Data Protection Commission (NDPC) | Office of the Data Protection Commissioner (ODPC) | Information Regulator |
| Fully in force | 2023 | 2019, with regulations from 2021 | 1 July 2021 |
| Registration | Required for data controllers and processors of major importance | Registration of data controllers and processors above set thresholds | Information officers must be registered with the Regulator |
| Breach notification to regulator | Within 72 hours of becoming aware, where a breach is likely to risk individuals’ rights | Within 72 hours of becoming aware | As soon as reasonably possible |
Thresholds, fees and guidance are set by each regulator and change over time. Check the latest regulations and guidance notes.
Common principles
All three laws share core principles:
- Lawful basis: process personal data only with consent or another legal ground, such as a contract, legal obligation or legitimate interest
- Purpose limitation: use data only for the stated purpose
- Data minimisation: collect only what you need
- Accuracy and retention limits: keep data correct and do not keep it longer than necessary
- Security: protect data with appropriate technical and organisational measures
- Accountability: be able to show how you comply
Individuals’ rights
People generally have the right to be informed about processing, to access their data, to correct or delete it, and to object to certain processing such as direct marketing. Stronger protections apply to sensitive data such as health, biometric, religious or financial information, and to children’s data.
Cross-border data transfers
All three laws restrict sending personal data to other countries unless certain conditions are met, such as adequate protection in the receiving country, appropriate safeguards in contracts, or the individual’s consent. This matters when you use foreign cloud services, CRMs or AI tools; see How to Use AI Assistants Safely at Work.
Penalties
Regulators can issue enforcement notices and fines, and individuals may seek compensation. Fines can be significant, calculated as fixed maximums or a percentage of annual turnover depending on the law. Regulators in all three countries have taken enforcement action against organisations in recent years.
A practical compliance checklist
- Map what personal data you collect, where it is stored and who can access it
- Identify your lawful basis for each type of processing
- Publish a clear privacy notice
- Register with the regulator where required
- Appoint a data protection officer or information officer if required
- Put contracts in place with vendors that process data for you
- Secure data with access controls, encryption and 2FA; see our cybersecurity guide
- Prepare a breach response plan; see ransomware response
- Check rules before transferring data abroad
- Train staff and review compliance regularly
Other African data protection laws
Many other countries, including Ghana, Rwanda, Uganda, Egypt, Morocco, Senegal, Mauritius and others, have data protection laws with similar principles. If you operate in several countries, you may need to comply with each one. Continental efforts such as the Malabo Convention aim to harmonise rules; see The Malabo Convention Explained.
Back to our guide to tech policy in Africa.

