Cybersecurity law in Africa is fragmented and moving fast. We map your specific obligations: breach notification timelines, incident response requirements, sector rules, and critical information infrastructure classifications.
Kenya's Computer Misuse and Cybercrimes Act, Nigeria's Cybercrime (Prohibition, Prevention) Act, and South Africa's Cybercrimes Act 2021 each create distinct obligations for organisations operating in those jurisdictions. Breach notification timelines vary. Sector regulators add further layers.
For pan-African organisations, the challenge is identifying which obligations apply to which operations, and building compliance structures that function across multiple frameworks without requiring separate teams in each jurisdiction.
Computer Misuse and Cybercrimes Act. Breach notification obligations. CII designations by Communications Authority. Cross-references with DPA for data breach notification.
Cybercrime (Prohibition, Prevention, etc.) Act 2015. Financial sector-specific provisions. CII protections. Substantial penalties for failure to report incidents.
Comprehensive cybercrime legislation. Electronic communications service provider obligations. 72-hour breach notification requirement to authorities.
The most important time to address cybersecurity legal obligations is before an incident occurs. Organisations that wait until a breach to discover their notification timelines, regulatory contacts, and documentation requirements invariably make the legal situation worse.
We advise on the legal components of incident response planning, ensuring that when a breach occurs, your team knows exactly what the law requires and has the procedures in place to comply.
We will identify what the law requires from your specific operations and help you build the compliance structures to meet it.