Key points
- Twelve years after its adoption, the Malabo Convention binds 20 of the African Union’s 55 member states, and none of Nigeria, South Africa, Egypt, Ethiopia or Kenya.
- Between 41 and 45 African states now have data protection laws, depending on the tracker, but some restrict transfers even to other African countries.
- The AfCFTA Digital Trade Protocol and its annex on data transfers offer the strongest route to free and protected data flows within Africa, but they are not yet in force.
- The AU should make the annex the continent’s common adequacy standard and modernise the Malabo Convention around it.
The African Union has built an ambitious body of continental rules for the digital economy. It has a treaty on data protection and cybersecurity, a data policy framework, a continental strategy on artificial intelligence, and a protocol on digital trade under the African Continental Free Trade Area (AfCFTA). Taken together they describe a continent where data moves freely between countries that protect it.
The reality is different. Most African states now have data protection laws, but those laws have grown largely outside the continental framework, and some of them restrict data flows to other African countries. This commentary asks why, and what would change it.
The Malabo Convention: in force, but marginal
The African Union Convention on Cyber Security and Personal Data Protection, known as the Malabo Convention, was adopted on 27 June 2014 and entered into force on 8 June 2023, after the fifteenth ratification was deposited.1 By February 2026 it had 20 parties among the Union’s 55 member states. Nigeria and South Africa have signed but not ratified, and Egypt, Ethiopia and Kenya have done neither. Ghana ratified in 2019.2 Kenya’s Cabinet approved accession in September 2025, leaving the decision to Parliament.3
The Convention requires each party to establish an independent national data protection authority, and restricts transfers to states outside the Union that lack adequate protection.4 But it says nothing about transfers between African states, and it creates no continental body to ensure that its rules are applied consistently.5 Civil society analysts have noted that it contains no duty to notify data breaches and no requirement for impact assessments.6 Others have called it “an outdated text” whose shortcomings should be corrected rather than simply ratified.7
Meanwhile national law has moved on without it. Depending on the tracker, between 41 and 45 African states now have data protection laws, and at least 38 have operating authorities.8 The European Centre for Development Policy Management has noted that recent laws in the DRC, Kenya, Rwanda, Uganda and Tanzania are said to reflect pressure from Europe more than the Malabo Convention.9
Frameworks that guide, but do not bind
The AU Data Policy Framework, endorsed by the Executive Council in February 2022, aims at “harmonised digital data governance systems to enable the free and secure flow of data across the continent while safeguarding human rights”. It asks member states to agree “common and consistent criteria for assessing adequacy” so that data can move between them.10 Thirty-six member states have asked the AU Commission for help aligning their national policies with it, and in December 2025 the Commission held a workshop to validate draft frameworks, including one on cross-border data flows.11 Much of this work is funded by European partners, through a Data Governance in Africa Initiative that began in 2023 with €60 million.12
The Continental Artificial Intelligence Strategy, adopted by the Executive Council in Accra in July 2024, follows the same pattern. It runs from 2025 to 2030, with national strategies and governance frameworks as the focus of its first phase and a review in 2027, and it calls for a regional instrument on cross-border data transfers for AI “in line with the Malabo Convention and AU Data Policy Framework”.13 By September 2025, twelve African countries had national AI strategies and three had national AI policies.14
These are valuable frameworks. But they are guidance, not law, and their pace depends on member states’ willingness and donors’ funding.
Africa does not lack continental rules on data. It lacks continental rules that national regulators are bound to apply.
Fragmentation at every level
The result is fragmentation, repeated at each level of governance. Some national laws restrict transfers to other African countries as well as to the rest of the world.15 The SADC Model Law applies its restrictions even to transfers within the Southern African Development Community, to members that have not adopted it. The East African Community’s framework has no provisions on data transfers at all, although the Community validated a regional framework on cross-border data flows in June 2026.16 ECOWAS has a binding Supplementary Act on data protection, but it has not been updated since 2010 and has struggled to enforce it.17
For a business that serves customers in several African markets, or a researcher working across borders, the effect is that moving data from Accra to Nairobi can be as hard as moving it from Accra to anywhere else in the world. Our commentary on Egypt’s transfer licensing regime, published alongside this piece, shows how heavy that burden can be.
The Digital Trade Protocol: the best route, not yet open
The instrument with the most promise is the AfCFTA Protocol on Digital Trade, adopted at the AU summit in February 2024.18 It requires each party to maintain a legal framework for protecting personal data, requires parties to allow cross-border transfers of data, including personal data, subject to an annex on data transfers and to public policy and security exceptions, and bars parties from requiring computing facilities to be located in their territory as a condition of digital trade.19 Parties must align their national laws with the protocol within five years of its entry into force.20
The annex on cross-border data transfers, adopted with seven others in February 2025, supplies the missing intra-African rule. States must not restrict transfers to other parties that maintain a data protection framework, may restrict transfers to parties that do not, and must harmonise their data protection laws with a view to a continental legal framework.21 That is, in effect, the common adequacy standard the Data Policy Framework called for, and it comes with a binding duty to align.
But in April 2026 the protocol was not yet in force, and in July 2026 the AfCFTA Secretariat was still calling on states to accelerate its ratification and domestication.22
Recommendations
- Bring the Digital Trade Protocol into force. Member states should ratify the protocol and its annexes, and the AfCFTA Secretariat should publish a status list so that progress can be tracked.
- Make the transfer annex the continent’s adequacy standard. Data protection authorities should treat a state’s compliance with the annex as sufficient for transfers, recognising each other through the Network of African Data Protection Authorities rather than assessing each country separately.
- Modernise the Malabo Convention around it. The AU should update the Convention to include breach notification, impact assessments and a rule for transfers between African states consistent with the annex, and establish a mechanism to monitor its application.
- Bring the largest data economies in. Nigeria, South Africa, Egypt, Ethiopia and Kenya should ratify the Malabo Convention or commit to the protocol’s transfer rules, since continental rules that exclude the largest markets cannot deliver a single digital market.
- Build AI governance on data protection that works. The transfer instrument proposed by the AI Strategy should use the protocol’s framework rather than create another, and national AI strategies should rest on data protection laws with operating, independent authorities.
- Fund authorities from national budgets. Donor support has helped start domestication, but independent data protection authorities need predictable funding from their own governments to enforce continental commitments.
Notes
-
African Union, status list of the Convention on Cyber Security and Personal Data Protection, 2 February 2026; Yohannes Eneyew Ayalew, “The African Union’s Malabo Convention enters into force”, EJIL:Talk!, 15 June 2023. ↩
-
African Union, status list, 2 February 2026. ↩
-
Tatua Digital Resilience Centre, “High-level parliamentary dialogue on the Malabo Convention”, 7 September 2026. ↩
-
African Union Convention on Cyber Security and Personal Data Protection, articles 11 and 14(6). ↩
-
Mercy King’ori, RECs: Towards a Continental Approach to Data Protection in Africa, Future of Privacy Forum, February 2024. ↩
-
ALT Advisory, The Malabo Roadmap, September 2022. ↩
-
Africa Data Protection, “The entry into force of the African Union Convention on cybersecurity and data protection: what is its relevance nine years on?”, 31 January 2024. ↩
-
UNCTAD, Global Cyberlaw Tracker, updated 9 September 2026; Data Protection Africa, January 2026; Digital Policy Alert, “Data protection in Africa: 2025 roundup”, 11 January 2026; Citi Newsroom, report on the Yellow Card study, 22 April 2026. ↩
-
Musoni, Karkare and Teevan, Cross-border data flows in Africa: continental ambitions and political realities, ECDPM Discussion Paper 379, October 2024. ↩
-
African Union, Data Policy Framework, endorsed by Decision EX.CL/Dec.1144(XL), February 2022. ↩
-
D4D Hub, “A unified path towards harmonised data policies in Africa”, 16 June 2025; African Union, press release on the validation workshop, 2 December 2025. ↩
-
Estonian Centre for International Development, Data Governance in Africa. ↩
-
African Union, Continental Artificial Intelligence Strategy, July 2024. ↩
-
Carnegie Endowment for International Peace, “Understanding Africa’s AI governance landscape”, 11 September 2025. ↩
-
Mercy King’ori, “Cross-border data flows in Africa: examining policy approaches and pathways to regulatory interoperability”, Future of Privacy Forum, 6 June 2025. ↩
-
Future of Privacy Forum, February 2024; Top Africa News, “EAC moves to harmonise cross-border data flows”, 6 July 2026. ↩
-
Future of Privacy Forum, February 2024. ↩
-
Covington, “Adoption of the AfCFTA Protocol on Digital Trade”, 28 February 2024. ↩
-
Protocol to the Agreement Establishing the African Continental Free Trade Area on Digital Trade, articles 20 to 22. ↩
-
Protocol on Digital Trade, article 48(4). ↩
-
AfCFTA Secretariat, “African Union adopts eight annexes to the AfCFTA Protocol on Digital Trade”, 2025; compiled annexes, Annex on Cross-Border Data Transfers, articles 15(3), 16(4) and 25. ↩
-
Gerhard Erasmus, “Must the Phase II AfCFTA protocols be ratified to be implemented?”, tralac, 16 April 2026; AfCFTA Secretariat, calls to action from the AfCFTA Digital Trade Forum, July 2026. ↩