LAW LAB AFRICA
LAW LAB AFRICA
Book a Consultation Subscribe to Newsletter
01 · DATA PROTECTION COMPLIANCE

Data Protection Compliance Across Africa and the Globe.

From gap assessments to DPIAs, cross-border transfer analysis to breach response planning -- across every major African framework and the global instruments that touch your operations.

§ 01The Regulatory Landscape

Active frameworks. Active regulators.

Nigeria, Kenya, South Africa, Rwanda, Ghana, Uganda, Ethiopia, Mauritius, and Senegal all have comprehensive data protection frameworks in force. The continent's regulators are not passive: Nigeria's NDPC, Kenya's ODPC, and South Africa's Information Regulator have each issued consequential enforcement decisions in recent years.

For organisations with operations across multiple African jurisdictions, cross-border transfer obligations, divergent breach notification timelines, and inconsistent lawful basis frameworks create compounding compliance complexity. We manage that complexity.

Where your operations also engage the GDPR, CCPA, India's DPDP Act, Brazil's LGPD, or China's PIPL, we advise across those frameworks simultaneously.

Core African Frameworks
JXJurisdictionFrameworkStatus
NGNigeriaNDPA 2023 / GAID 2025IN FORCE
KEKenyaData Protection Act 2019IN FORCE
ZASouth AfricaPOPIA 2020IN FORCE
RWRwandaDPPPA 2021IN FORCE
GHGhanaDPA 2012IN FORCE
UGUgandaDPPA 2019IN FORCE
ETEthiopiaPDPP 2024IN FORCE
MUMauritiusDPA 2017IN FORCE
SNSenegalCDP FrameworkIN FORCE
§ 02Our Services

What we deliver.

Each engagement is scoped to your specific jurisdiction footprint, sector, and compliance maturity. We work from the statute directly, not from GDPR templates adapted to African frameworks.

  • Data protection gap assessment against applicable framework(s)
  • Data Protection Impact Assessment (DPIA) -- design, conduct, and documentation
  • Data mapping and Records of Processing Activities (ROPA)
  • Cross-border transfer analysis and appropriate safeguards
  • Breach response planning: notification timelines, templates, regulatory liaison
  • Ongoing regulatory monitoring retainer
  • Privacy policy and internal documentation drafting
  • Data subject rights request procedures and workflow design
§ 03Global Coverage

Beyond Africa.

Many organisations operating in Africa are simultaneously subject to the GDPR, CCPA, India's DPDP Act, Brazil's LGPD, or China's PIPL. We advise across all of them, and specifically on the friction points created by operating under multiple frameworks simultaneously.

EU GDPR UK GDPR US CCPA/CPRA Brazil LGPD India DPDP China PIPL Egypt PDPL + more
Track enforcement in real time

595 enforcement actions and penalties across four African jurisdictions. Updated continuously.

Open the Enforcement Tracker

Start with a gap assessment.

We will map your data processing activities against the frameworks that apply to your operations and identify your highest-priority obligations.

Book a Consultation Send a Message