vii
While there are multiple competing definitions of data, common to all is the recognition that
there are many different types of data. There are also numerous ways that data can be categorised that affect the appropriate policy and regulation of that category in order to mitigate any
potential risk associated with the processing, transfer or storage of it. A primary distinction is
between personal data and non-personal data, with data protection referring to ensuring the
privacy of data subjects. Data categorisation guidelines should be one of the first actions of
the data information regulator, a key institution for the development of an integrated national
data system, which should be established in partnership with all relevant stakeholders. Essential to the development of an enabling environment for the data economy is ensuring the
necessary foundational digital infrastructure and the human resources necessary to develop
data as a strategic asset. Due consideration needs to be given to developing robust Digital ID
systems for the delivery of public and private value to citizens and consumers.
As the framework also emphasises, this can only be properly achieved through instilling a
culture of trust in the data ecosystem. This is done through the establishment of safe and secure data systems based on effective cybersecurity and data protection rules and practices,
and ethical codes of conduct for those who set data policy, implement it and those who use
data – whether in public, private or other sectors. This is not sufficient, however. Trust in data
governance, and a national data system is established through legitimacy. This includes systems and standards that guarantee public and private sector compliance, government itself
adhering to personal data protection rules, and government sharing public data.
The framework instils the importance of collaborative and evidence-based policy processes
for the domestication of the policy proposed. The governance and institutional arrangements
should assign clear roles to the government as policy maker and independent, agile and capacitated regulators to implement policy and effectively regulate the data economy to ensure
that fair competition produces positive consumer welfare outcomes. The creation of data and
information regulators to promote and safeguard the rights of citizens and their participation
and fair representation in the data economy and society will need to be a priority for those
countries that have not yet established these. Coordination with other regulators to achieve
this will be essential. The legal ecosystem must be harmonised and rebalanced.
Access to data is a prerequisite for value creation, entrepreneurialism and innovation. When
data are of poor quality or not interoperable, they limit the capacity of firms and the public
sector to engage in the sharing and analytics that can provide economic and social value
to data. These processing frameworks should align with the following principles: consent
and legitimacy; limitations on collection; purpose specification; use limitation; data quality;
security safeguards; openness (which includes incident reporting, an important correlation
to cybersecurity and cybercrime imperatives); accountability; and data specificity. Security
models also need to be transversal, with specific emphasis on cloud storage and processing
of sensitive/proprietary data, API management, and support of equitable data economies.
Attention needs to be paid to access to quality, interoperable and reliable data – primarily
from the state but also from the private and other sectors – with a reinvigoration of the principles of open governance across the continent. Capacity-building should be a key national
and regional priority, and resources will need to be allocated in this regard in the areas of data
protection, cybersecurity and institutional data governance in relevant agencies. Skills and an
understanding of the data ecosystem will also need to be built in state institutions, amongst
other sectors and communities.