LAW LAB AFRICA
LAW LAB AFRICA
Book a Consultation Subscribe to Newsletter
COURSE · AFRICA DATA PROTECTION COMPLIANCE

Africa Data Protection Compliance: A Practitioner's Guide.

Practitioner-grade data protection training built for Africa's regulatory environment. 18 modules. 15 editions. Built from African law and African enforcement practice.

From the team behind the African Enforcement Tracker, this course is built around African statutes, regulations, regulatory guidance, access to information laws, and verified enforcement decisions across the continent. Whether you work in one jurisdiction or across several African markets, choose the edition that matches the legal framework you need to understand.

§ 01About the Course

Built for Africa's regulatory reality.

Most data protection training available to lawyers and compliance professionals was designed for the GDPR. It treats African frameworks as derivative, uses European case studies, and leaves practitioners underprepared for the regulatory environment they actually work in.

This course starts from African law and works outward.

Every module is grounded in African statutes, regulations, regulatory guidance, and published enforcement decisions drawn from the African Enforcement Tracker. The tracker is also the course companion, with practical exercises that take participants into real enforcement decisions and regulatory reasoning.

Where global frameworks intersect with African operations, those intersections are addressed in context rather than treated as the starting point.

Designed for in-house counsel, startup founders, data protection officers, compliance officers, consultants, and organisations operating across African jurisdictions.

COURSE WALKTHROUGH · 75 SECONDS · IN PRODUCTION
See it before you enrol

A 75-second walkthrough of the course.

The modules, the tracker-linked case studies and the editions, shown on screen. The video is in production and embeds here when ready.

§ 02Choose an Edition

A Pan-African edition and country-specific editions.

The course is available in 15 editions. Choose the edition that reflects the jurisdiction where you practise, advise clients, or operate.

The Pan-African Edition is designed for practitioners and organisations operating across multiple African jurisdictions. It focuses on regional compliance, comparative legal frameworks, cross-border data transfers, multi-jurisdiction operations, and the points where national laws diverge across Africa.

Each country edition is written specifically for that jurisdiction's legal framework. It is not a generic African course with local examples. The legal content, regulator guidance, registration obligations, enforcement practice, and practical compliance exercises are tailored to that country's law.

West Africa

§ 03What Every Edition Covers

Practitioner training from foundations to implementation.

Every edition covers the complete lifecycle of data protection compliance within its jurisdiction through 18 practitioner modules. Select a module to see what it covers.

01Foundations of Data Protection Law+

The constitutional and statutory basis for privacy protection across African jurisdictions, the core definitions that determine whether a law applies at all (personal data, processing, controller, processor, data subject), and the processing principles that every later obligation is built on: lawfulness, fairness, purpose limitation, minimisation, accuracy, storage limitation, integrity and accountability.

02Scope and Territorial Application+

When a data protection statute actually binds an organisation. Material scope, the establishment, targeting and equipment tests that extend a law beyond its borders, the obligation on foreign controllers to appoint a local representative, and the exemptions commonly drawn for household, journalistic, judicial and national security processing.

03Lawful Bases for Processing+

Selecting and documenting a lawful basis. The conditions that make consent valid and the consequences of withdrawal; contract, legal obligation, vital interests, public interest and legitimate interests; the balancing exercise where legitimate interests is relied on; and the points at which African statutes depart from the familiar European set.

04Data Subject Rights+

Handling requests defensibly: access, rectification, erasure, restriction, objection, portability and rights in relation to automated decision-making and profiling. Identity verification, statutory response deadlines, the narrow grounds for refusal, and the internal workflow that produces an auditable answer.

05Special Categories of Personal Data+

Processing that carries heightened conditions: health, genetic and biometric data, race and ethnic origin, political opinion, religious or philosophical belief, trade union membership and sex life, with children's data and, in some jurisdictions, gender treated as sensitive. The narrower grounds, the regulator authorisation routes, and the safeguards expected in practice.

06Controllers and Processors+

Allocating legal responsibility correctly, including joint controllership and the practical test for who determines purpose and means. The mandatory content of a processing agreement, processor due diligence, sub-processor authorisation, cross-border processing by vendors, and how liability falls between the parties when something goes wrong.

07Privacy by Design and Default+

Embedding compliance in systems and products rather than documenting it afterwards. Data minimisation and purpose limitation at the design stage, default settings, retention by design, pseudonymisation and anonymisation, and how to evidence that design decisions were taken and why.

08Cross-Border Data Transfers+

The legal grounds for moving personal data out of a jurisdiction: adequacy determinations, contractual safeguards, binding corporate rules, regulator authorisation, consent and the narrow derogations. Data localisation and copy-retention requirements, onward transfers, and mapping flows in a stack that spans several countries.

09Personal Data Breaches+

Determining whether an incident is a notifiable breach, assessing risk to data subjects, and meeting notification deadlines that range from 24 hours to 72 hours depending on the jurisdiction. Who must be told, when affected individuals must be informed directly, containment and remediation, and the records a regulator will ask to see.

10Data Protection Officers+

When designation is mandatory and when it is merely permitted, qualification and independence requirements, the statutory tasks of the office, reporting lines and conflicts of interest, group appointments across entities, and the personal exposure carried by officers and directors under several African statutes.

11Records of Processing Activities+

Building and maintaining the processing register that controllers and processors are required to keep: its prescribed content, how it is derived from a data inventory, how it interacts with registration and notification duties, and why it becomes the evidence base for every other obligation in an inspection.

12Data Protection Impact Assessments+

Identifying processing that requires an assessment, working through a defensible methodology, consulting the regulator where the residual risk remains high, selecting mitigations, and recording the decision to proceed. Includes the assessment triggers African regulators have applied in practice.

13Regulators and Regulatory Powers+

How African data protection authorities are constituted and what they can compel. Registration and notification regimes, information notices, investigative and audit powers, inspection procedure, and the path a complaint takes from lodgement to a binding determination.

14Enforcement, Investigations and Penalties+

Administrative fines and how they are calculated, enforcement and compliance notices, compensation awards to data subjects, criminal offences and officer liability, and appeal routes. Grounded in published determinations, so participants can see what regulators are penalising and at what level.

15Access to Information and Data Governance+

Where access to information legislation meets data protection: the duties of public bodies and, in some jurisdictions, private ones; the personal-information exemption and how it is applied; proactive disclosure; and reconciling a transparency request with a competing privacy obligation.

16Operating Across Multiple Jurisdictions+

Comparative practice for counsel advising in more than one market: divergent definitions, notification deadlines and registration duties, conflicting transfer rules, regional instruments and their real effect, and how to design one programme that satisfies several regimes without defaulting to the strictest.

17Building a Compliance Programme+

Turning obligations into an operating programme: governance and accountability structure, policies and privacy notices, staff training, vendor management, retention schedules, monitoring and internal audit, and assembling the documentation set that demonstrates accountability to a regulator.

18Capstone Compliance Exercise+

A single organisation worked end to end. Map its processing, identify the applicable obligations, draft the core documents, respond to a data subject request and a reportable breach on the statutory clock, and prepare the file for a regulatory inquiry.

The legal framework taught inside each module changes depending on the edition you select.

§ 04What Makes Each Edition Different

Every jurisdiction is taught from its own law.

Each country edition is built directly from that country's legal framework and regulatory practice. For every jurisdiction, the course includes:

  • The country's data protection legislation.
  • The country's access to information legislation.
  • Regulations and subsidiary legislation.
  • Guidance, directives, and notices issued by the regulator.
  • Registration obligations for controllers and processors where applicable.
  • Country-specific enforcement decisions and penalties.
  • Practical compliance procedures, templates, and implementation guidance.

This means the Kenya Edition teaches Kenyan compliance practice, the Nigeria Edition teaches Nigerian compliance practice, the South Africa Edition teaches POPIA, and so on across every available jurisdiction.

§ 05Built from Primary Sources

Written from African legislation. Taught through African enforcement.

This course is built from primary legal sources, not summaries of someone else's guidance. The curriculum draws directly from:

  • 44 data protection statutes and regulations reviewed from official gazettes.
  • 591 verified published enforcement decisions across African jurisdictions.
  • Regulatory guidance published by African data protection authorities.
  • Access to information legislation across participating jurisdictions.

Enforcement is integrated throughout the course, so participants learn not only what legislation says, but how regulators have interpreted and applied it in practice.

§ 06Course Format

Designed for working professionals.

Format
Self-paced online course.
Duration
Approximately 12 hours.
Module length
Approximately 45 minutes per module.
Learning materials
Video lessons, legislation references, enforcement exercises, templates, and compliance resources.
Access
Lifetime access to the purchased edition.
§ 07Who This Course Is For

Professionals responsible for privacy and data governance across African markets.

  • Lawyers and advocates.
  • In-house legal teams.
  • Data protection officers.
  • Compliance officers.
  • Startup founders and product teams.
  • Financial institutions.
  • NGOs and development organisations.
  • Consultants advising organisations operating across Africa.
§ 08Explore the Editions

Available now

Select an edition above, or from the map in § 02.

Join the next cohort.

The founding cohort is working through the course now. Leave your details and we will tell you first when enrolment for the next cohort opens.

Name *
Email *
Organisation