From gap assessments to DPIAs, cross-border transfer analysis to breach response planning -- across every major African framework and the global instruments that touch your operations.
Nigeria, Kenya, South Africa, Rwanda, Ghana, Uganda, Ethiopia, Mauritius, and Senegal all have comprehensive data protection frameworks in force. The continent's regulators are not passive: Nigeria's NDPC, Kenya's ODPC, and South Africa's Information Regulator have each issued consequential enforcement decisions in recent years.
For organisations with operations across multiple African jurisdictions, cross-border transfer obligations, divergent breach notification timelines, and inconsistent lawful basis frameworks create compounding compliance complexity. We manage that complexity.
Where your operations also engage the GDPR, CCPA, India's DPDP Act, Brazil's LGPD, or China's PIPL, we advise across those frameworks simultaneously.
Each engagement is scoped to your specific jurisdiction footprint, sector, and compliance maturity. We work from the statute directly, not from GDPR templates adapted to African frameworks.
Many organisations operating in Africa are simultaneously subject to the GDPR, CCPA, India's DPDP Act, Brazil's LGPD, or China's PIPL. We advise across all of them, and specifically on the friction points created by operating under multiple frameworks simultaneously.
595 enforcement actions and penalties across four African jurisdictions. Updated continuously.
Open the Enforcement Tracker ↗We will map your data processing activities against the frameworks that apply to your operations and identify your highest-priority obligations.