Most data protection training available to lawyers and compliance professionals was designed for the GDPR. It treats African frameworks as derivative, uses European case studies, and leaves practitioners underprepared for the regulatory environment they actually work in.
This course starts from African law and works outward.
Every module is grounded in African statutes, regulations, regulatory guidance, and published enforcement decisions drawn from the African Enforcement Tracker. The tracker is also the course companion, with practical exercises that take participants into real enforcement decisions and regulatory reasoning.
Where global frameworks intersect with African operations, those intersections are addressed in context rather than treated as the starting point.
Designed for in-house counsel, startup founders, data protection officers, compliance officers, consultants, and organisations operating across African jurisdictions.
The modules, the tracker-linked case studies and the editions, shown on screen. The video is in production and embeds here when ready.
The course is available in 15 editions. Choose the edition that reflects the jurisdiction where you practise, advise clients, or operate.
The Pan-African Edition is designed for practitioners and organisations operating across multiple African jurisdictions. It focuses on regional compliance, comparative legal frameworks, cross-border data transfers, multi-jurisdiction operations, and the points where national laws diverge across Africa.
Each country edition is written specifically for that jurisdiction's legal framework. It is not a generic African course with local examples. The legal content, regulator guidance, registration obligations, enforcement practice, and practical compliance exercises are tailored to that country's law.
SELECT A HIGHLIGHTED COUNTRY
Every edition covers the complete lifecycle of data protection compliance within its jurisdiction through 18 practitioner modules. Select a module to see what it covers.
The constitutional and statutory basis for privacy protection across African jurisdictions, the core definitions that determine whether a law applies at all (personal data, processing, controller, processor, data subject), and the processing principles that every later obligation is built on: lawfulness, fairness, purpose limitation, minimisation, accuracy, storage limitation, integrity and accountability.
When a data protection statute actually binds an organisation. Material scope, the establishment, targeting and equipment tests that extend a law beyond its borders, the obligation on foreign controllers to appoint a local representative, and the exemptions commonly drawn for household, journalistic, judicial and national security processing.
Selecting and documenting a lawful basis. The conditions that make consent valid and the consequences of withdrawal; contract, legal obligation, vital interests, public interest and legitimate interests; the balancing exercise where legitimate interests is relied on; and the points at which African statutes depart from the familiar European set.
Handling requests defensibly: access, rectification, erasure, restriction, objection, portability and rights in relation to automated decision-making and profiling. Identity verification, statutory response deadlines, the narrow grounds for refusal, and the internal workflow that produces an auditable answer.
Processing that carries heightened conditions: health, genetic and biometric data, race and ethnic origin, political opinion, religious or philosophical belief, trade union membership and sex life, with children's data and, in some jurisdictions, gender treated as sensitive. The narrower grounds, the regulator authorisation routes, and the safeguards expected in practice.
Allocating legal responsibility correctly, including joint controllership and the practical test for who determines purpose and means. The mandatory content of a processing agreement, processor due diligence, sub-processor authorisation, cross-border processing by vendors, and how liability falls between the parties when something goes wrong.
Embedding compliance in systems and products rather than documenting it afterwards. Data minimisation and purpose limitation at the design stage, default settings, retention by design, pseudonymisation and anonymisation, and how to evidence that design decisions were taken and why.
The legal grounds for moving personal data out of a jurisdiction: adequacy determinations, contractual safeguards, binding corporate rules, regulator authorisation, consent and the narrow derogations. Data localisation and copy-retention requirements, onward transfers, and mapping flows in a stack that spans several countries.
Determining whether an incident is a notifiable breach, assessing risk to data subjects, and meeting notification deadlines that range from 24 hours to 72 hours depending on the jurisdiction. Who must be told, when affected individuals must be informed directly, containment and remediation, and the records a regulator will ask to see.
When designation is mandatory and when it is merely permitted, qualification and independence requirements, the statutory tasks of the office, reporting lines and conflicts of interest, group appointments across entities, and the personal exposure carried by officers and directors under several African statutes.
Building and maintaining the processing register that controllers and processors are required to keep: its prescribed content, how it is derived from a data inventory, how it interacts with registration and notification duties, and why it becomes the evidence base for every other obligation in an inspection.
Identifying processing that requires an assessment, working through a defensible methodology, consulting the regulator where the residual risk remains high, selecting mitigations, and recording the decision to proceed. Includes the assessment triggers African regulators have applied in practice.
How African data protection authorities are constituted and what they can compel. Registration and notification regimes, information notices, investigative and audit powers, inspection procedure, and the path a complaint takes from lodgement to a binding determination.
Administrative fines and how they are calculated, enforcement and compliance notices, compensation awards to data subjects, criminal offences and officer liability, and appeal routes. Grounded in published determinations, so participants can see what regulators are penalising and at what level.
Where access to information legislation meets data protection: the duties of public bodies and, in some jurisdictions, private ones; the personal-information exemption and how it is applied; proactive disclosure; and reconciling a transparency request with a competing privacy obligation.
Comparative practice for counsel advising in more than one market: divergent definitions, notification deadlines and registration duties, conflicting transfer rules, regional instruments and their real effect, and how to design one programme that satisfies several regimes without defaulting to the strictest.
Turning obligations into an operating programme: governance and accountability structure, policies and privacy notices, staff training, vendor management, retention schedules, monitoring and internal audit, and assembling the documentation set that demonstrates accountability to a regulator.
A single organisation worked end to end. Map its processing, identify the applicable obligations, draft the core documents, respond to a data subject request and a reportable breach on the statutory clock, and prepare the file for a regulatory inquiry.
The legal framework taught inside each module changes depending on the edition you select.
Each country edition is built directly from that country's legal framework and regulatory practice. For every jurisdiction, the course includes:
This means the Kenya Edition teaches Kenyan compliance practice, the Nigeria Edition teaches Nigerian compliance practice, the South Africa Edition teaches POPIA, and so on across every available jurisdiction.
This course is built from primary legal sources, not summaries of someone else's guidance. The curriculum draws directly from:
Enforcement is integrated throughout the course, so participants learn not only what legislation says, but how regulators have interpreted and applied it in practice.
Select an edition above, or from the map in § 02.
The founding cohort is working through the course now. Leave your details and we will tell you first when enrolment for the next cohort opens.