11 4.2 AFRICAN POLICY AND LEGISLATIVE CONTEXT In line with international precedents, most efforts in data regulation on the continent have focused on data protection, with the chief aim being to observe and safeguard internet users’ privacy rights. While the use and processing of data is a cross-cutting concern, which impacts an array of traditionally siloed areas of policy, there are no examples of umbrella laws that regulate every aspect of data. Instead, data has been regulated across five branches of the law: data protection law, competition law, cyber security law, electronic communications and transactions law and intellectual property law, which potentially conflict in some instances and leave gaps in others.3 It is estimated that 32 of Africa’s 55 countries have enacted or embraced some form of regulation with the chief aim of protecting personal data. Regionally, legislative tools such as the 2008 East African Community Framework for Cyberlaws, the 2010 Supplementary Act on Personal Data Protection of the Economic Community of West African States (ECOWAS), and the 2013 Southern African Development Community model law harmonising policies for the ICT Market in sub-Saharan Africa have been developed. Continentally, the African Union developed the first pan-African framework with the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) in 2014, which has not come into effect but is currently being ratified. Regional competition laws and protocols on competition in the established Regional Economic Communities (RECs) apply to businesses that process data, although they mostly do not explicitly refer to data. They include the 2004 COMESA Competition Regulations and Competition Rules, The EAC Competition Act (2006) and The EAC Common Market Protocol and the Protocol on the Establishment of an EAC Customs Union, The ECOWAS Supplementary Act on the “Adoption of Community Competition Rules and the modalities of their application within ECOWAS”, The SADC Protocol on Trade (2006), and the SADC Declaration on Regional Cooperation in Competition and Consumer Policies (2009). They address anti-competitive practices, including abuse of dominance and also market structure through regulation of mergers and acquisitions. However, details and approaches differ, which presents challenges for businesses operating in multiple regions. OTHER MAJOR INITIATIVES ON THE CONTINENT LOOKING AT DATA POLICY Policy and Regulation Initiative for Digital Africa (PRIDA) 4: Within the framework of the implementation of this project, The African Union Commission established an Expert Working Group that contributed to the identification of the key harmonisation indicators and the development of a Monitoring and Evaluation (M&E) Model and Tool on Data Protection & Localisation which is ready to use by the AU Member States and Regional Organisation to assess the extent of harmonisation and alignment of national laws and regulations Smart Africa is supporting the creation of a harmonised framework for data protection legislations in Africa through the Smart Africa Data Protection Working Group that aims at producing a mapping of legal frameworks, implementation guidelines for Smart Africa Member States, as well as recommendations on enhancing harmonisation and collaboration mechanisms between Data Protection Authorities (DPAs). 3 4 The continental dimensions of these challenges are addressed through continental digital collaboration. PRIDA is a joint initiative of the African Union (AU), the European Union (EU) and the International Telecommunication Union (ITU) that aims at enabling the African continent to reap the benefits of digitalisation, by addressing various dimensions of broadband demand and supply in Africa and by building the capacities of African stakeholders in the Internet Governance space.

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents