Skip to content

MENU

  • Who We Are
  • What We Do
  • Resources
    • Client Guide
    • Insights
  • Get in Touch
    • Log In
Menu
  • Who We Are
  • What We Do
  • Resources
    • Client Guide
    • Insights
  • Get in Touch
    • Log In

DATA PRIVACY AND THE AfCFTA (Part 2)

  • AfCFTA
  • December 3, 2021
BACK TO INSIGHTS

We are still looking into data privacy issues that arises in respect of trade in goods and services under the AfCFTA.

With the emergence of digital technology and the increased usage of Internet-based platforms, the inclusion of E-commerce in the African Continental Free Trade Agreement (AfCFTA) becomes pertinent as technology is rapidly changing the way individuals, businesses and the world operate.

Digital trade involves transfer of data across borders of the member States. Hence, insufficient data protection measures can create negative market effects by reducing stakeholders and consumer confidence in the trading engagements particularly with the adoption of Pan-African payment settlement system (PAPSS), which has a lot to do with cross-border exchange of data through the payment processes.

AfCFTA_Malabo Convention Banner design

The African Union Convention on Cybersecurity and Personal Data Protection (Malabo Convention) 2014 serves as a great measure put in place to ensure protection of personal data and cybersecurity in Africa. The Convention seeks to establish a credible framework for cybersecurity in Africa through the organization of electronic transactions, protection of personal data, and promotion of cybersecurity, and combating cybercrime through each state establishing a legal framework to be aimed at strengthening fundamental rights and public freedoms, protection of physical data, and punishing any violation of privacy without prejudice to the free flow of personal data through the national protection authorities.

However, despite the data protection strategy and enforcement procedure embedded in the convention, so far only 8 states of the 55 member states have ratified the convention and as such most African states today have no data protection regulation.

So far, Data privacy is a fundamental right that is yet to be completely established across many countries in Africa. It is on record that in 2019, Kenya, Nigeria, Togo, and Uganda enacted data protection policies. They were followed by Egypt, which in April 2020 became the most recent AU member to create a data protection framework with its Personal Data Protection Law. Next came South Africa, whose Protection of Personal Information Act came into force in June 2020. Other countries are amending existing data protection policies or working to establish structures to enforce existing laws and regulations.

AFCFTA_Factors Impeding

Many African countries have been reluctant in having legislation for data protection or refused to ratify the existing law for reasons which could include:

  1. Priority of interest: Many African countries are still battling with political instability (internal political issues) and other gross infrastructural deficit, catching up with the continental data protection requirement is the least of their problems.
  2. Poor Awareness: Issues concerning data protection still look esoteric to some African countries and they find it too difficult to acclimatize to the essence of data protection.
  3. The absence of a common enforceable data protection law or regulation applicable across the continent.
  4. Uneven Patchwork of Regulations: Regulatory barriers can also hamper the development of digital trade in several African markets.

However, despite these impediments, some countries are forging forward in their data protection law and regulation. For instance, Mauritius was the first African country to adopt the Budapest Convention on Cybercrime 2014 and the second non- European country to ratify Europe’s Convention for the protection of individuals with regard to automatic Processing of Personal Data. Mauritius has also enacted its Data protection Act 2017 which came into force in January 2018. Also, Kenya was ranked the first in Africa by the International Telecommunication Union (ITU) under legal and cooperation pillars of cybersecurity. The main regulation for data protection affairs in Kenya is the Data Protection Act. Rwanda according to Global Competitiveness Index (GCI) 2018 was reported to be the country that performs best in organizational capacity, Nigeria comes In 5th place in the GCI 2018 ranking.

On enforcement, taking a leaf from the Malabo Convention, there are some strategies that are embedded in the convention to ensure its compliance, which are.

  • Each state is expected to commit to establishing a legal framework aimed at strengthening fundamental rights and public freedoms, protection of physical data, and punishing any violation of privacy without prejudice to the free flow of personal data.
  • Processing of certain kinds of personal data both general and sensitive, may only be undertaken upon an authorization principle from the national protection authority.

State parties are also expected to adopt legislative and or regulatory measures as they deem necessary to confer specific responsibility on institutions and their officials in relation to their responses to cybersecurity incidents, coordination, and cooperation.

AFCFTA_News Updates
  • Why AfCFTA has failed to secure requisite traction amid opportunities.
    READ MORE
  • Nigeria’s success in AfCFTA hinged on public, private partnership. 
    READ MORE
  • Economic Commission for Africa Director seeks ways to boost AfCFTA’s implementation as MSMEs consultation opens. READ MORE

PODCASTS

Quick Links

  • Who We Are
  • What We Do
  • Resources
    • Client Guide
    • Insights
  • Get in Touch
    • Log In
  • Who We Are
  • What We Do
  • Resources
    • Client Guide
    • Insights
  • Get in Touch
    • Log In

CONNECT WITH US

  • contact@firstfiduciary.ng
  • +2349067686317
  • 3A Kayode Otitoju Street, Off Admiralty Road, Lekki Phase 1 Lagos, Nigeria.

Request a Call-back

© 2025 1st Fiduciary Limited. All Rights Reserved.

Developed by Exploits Mediatech.

Privacy Consent
At First Fiduciary Limited, we believe you should know what data we collect and how we use it.

Click here to view our Privacy Policy

By your understanding of our privacy policy, you confirm that 1st Fiduciary Limited will use the information you share within the terms stated.

I AGREE I DISAGREE
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT