11
4.2 AFRICAN POLICY AND LEGISLATIVE CONTEXT
In line with international precedents, most efforts in data regulation on the continent have
focused on data protection, with the chief aim being to observe and safeguard internet users’
privacy rights. While the use and processing of data is a cross-cutting concern, which impacts
an array of traditionally siloed areas of policy, there are no examples of umbrella laws that
regulate every aspect of data. Instead, data has been regulated across five branches of the
law: data protection law, competition law, cyber security law, electronic communications and
transactions law and intellectual property law, which potentially conflict in some instances
and leave gaps in others.3
It is estimated that 32 of Africa’s 55 countries have enacted or embraced some form of regulation with the chief aim of protecting personal data. Regionally, legislative tools such as
the 2008 East African Community Framework for Cyberlaws, the 2010 Supplementary Act on
Personal Data Protection of the Economic Community of West African States (ECOWAS), and
the 2013 Southern African Development Community model law harmonising policies for the
ICT Market in sub-Saharan Africa have been developed. Continentally, the African Union developed the first pan-African framework with the African Union Convention on Cyber Security
and Personal Data Protection (Malabo Convention) in 2014, which has not come into effect but
is currently being ratified.
Regional competition laws and protocols on competition in the established Regional
Economic Communities (RECs) apply to businesses that process data, although they mostly
do not explicitly refer to data. They include the 2004 COMESA Competition Regulations and
Competition Rules, The EAC Competition Act (2006) and The EAC Common Market Protocol
and the Protocol on the Establishment of an EAC Customs Union, The ECOWAS Supplementary
Act on the “Adoption of Community Competition Rules and the modalities of their application
within ECOWAS”, The SADC Protocol on Trade (2006), and the SADC Declaration on Regional
Cooperation in Competition and Consumer Policies (2009). They address anti-competitive
practices, including abuse of dominance and also market structure through regulation of
mergers and acquisitions. However, details and approaches differ, which presents challenges
for businesses operating in multiple regions.
OTHER MAJOR INITIATIVES ON THE CONTINENT LOOKING AT DATA POLICY
Policy and Regulation Initiative for Digital Africa (PRIDA) 4: Within the framework of the implementation of this project, The African Union Commission established an Expert Working Group that contributed to the identification of the key harmonisation indicators and the
development of a Monitoring and Evaluation (M&E) Model and Tool on Data Protection &
Localisation which is ready to use by the AU Member States and Regional Organisation to
assess the extent of harmonisation and alignment of national laws and regulations
Smart Africa is supporting the creation of a harmonised framework for data protection
legislations in Africa through the Smart Africa Data Protection Working Group that aims
at producing a mapping of legal frameworks, implementation guidelines for Smart Africa
Member States, as well as recommendations on enhancing harmonisation and collaboration mechanisms between Data Protection Authorities (DPAs).
3
4
The continental dimensions of these challenges are addressed through continental digital collaboration.
PRIDA is a joint initiative of the African Union (AU), the European Union (EU) and the International Telecommunication Union
(ITU) that aims at enabling the African continent to reap the benefits of digitalisation, by addressing various dimensions of
broadband demand and supply in Africa and by building the capacities of African stakeholders in the Internet Governance
space.
Select target paragraph3
Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents