Research and analysis
Papers, briefs and commentary on the laws that govern technology across Africa. Filter by type, topic or region.
-
Laws before regulators: data protection in Central Africa and Cameroon’s missing authority
Central African states have adopted data protection laws faster than they have built the authorities to enforce them. Cameroon’s strict 2024 law shows the cost: duties that cannot yet be met, and rights that cannot yet be enforced.
-
Rules on paper, flows in practice: can Africa’s continental frameworks shape national data law?
Africa has a data protection treaty, a data policy framework, an AI strategy and a digital trade protocol, yet national laws have grown largely outside them. The Digital Trade Protocol is the best chance to close the gap.
-
Egypt’s data protection deadline: a regulator inside the executive and a triple lock on data transfers
Egypt’s data protection rules bind organisations from about 1 November 2026. Its regulator sits inside the executive, security bodies stand outside the law, and data leaves the country only through licences.
-
A new Data Commissioner for Kenya: what the next six years should fix
As Kenya appoints its second Data Commissioner, the Office handles thousands of complaints, but its fines are capped low, its decisions are fragile in court, and the state rarely comes before it.
-
ACTPOL commentary on the National Information Technology Authority Bill, 2026
A review of every part of the revised Bill of September 2026, with ten priority amendments and suggested wording to keep the Authority’s reach within its purpose and its powers within the Constitution.
-
Nigeria’s data protection law at three: many regulators, few remedies
Three years after the Nigeria Data Protection Act, enforcement is shaped by overlapping regulators, a funding model tied to fees and fines, and little action against the state. The review now under way can fix all three.
-
Reports without remedies: what South Africa’s POPIA enforcement teaches about regulating the state
Five years into POPIA enforcement, South Africa’s Information Regulator receives thousands of breach reports a year. Its hardest cases involve the state, and its fines arrive late, if at all.
-
ACTPOL submits comments on the draft Cybersecurity (Amendment) Bill
Our written submission to Parliament’s Communications Committee on warrant requirements, data retention, and the role of the Cyber Security Authority.
-
Adequacy and the African data flow: revisiting Ghana’s posture under the GDPR
An assessment of Ghana’s Data Protection Act in light of European adequacy decisions and the practical effect on cross-border data transfers.
-
Sandbox to statute: how regulatory sandboxes are reshaping fintech law in West Africa
A comparative review of fintech regulatory sandboxes in Ghana, Nigeria, and Senegal, and the legal lessons graduating into primary legislation.
-
Lawful intercept, unlawful drift: oversight gaps in state surveillance powers
A constitutional analysis of communications interception powers in Ghana, with recommendations on judicial authorisation and proportionality tests.
No publications match these filters.