Most African countries now have data protection laws, and enforcement has begun in earnest: regulators are issuing fines, serving formal notices and opening investigations. But that record sits scattered across dozens of regulator websites, gazettes and PDFs in several languages, and it rarely reaches the people who have to comply. The Digest fixes that. Enforcement decisions, new laws and regulations, guidance and deadlines from across Africa and the globe, in one brief you can read in five minutes.
Enforcement decisions, new laws and regulatory movement across African jurisdictions, in one brief. Free, and built to be forwarded to the colleague who needs it.
Your address goes to our email service provider and is used to send you the Digest, nothing else. Unsubscribe in one click, in every issue. Privacy policy. This site itself sets no cookies.
Seven sections, every issue. Sent every two weeks, free, readable on a phone in a corridor between meetings.
One major development worth your full attention: a judgment, a new law, or a landmark decision.
A sweep across jurisdictions: new guidance, consultation outcomes, and regulatory announcements from the week.
Practical steps drawn from a live case or guidance document, framed for the people who have to implement them, e.g. data protection officers.
Fines, notices, and determinations from across Africa.
One international development, e.g. from the EU, UK or US, and its impact on African regulators and practitioners.
Upcoming compliance and regulatory dates you can act on.
Fellowships, conferences, calls for papers and other openings worth your time.
Rwanda's Law No.
The NDPC executed two memoranda of understanding on 8 May 2026, one with the Bureau of Public Procurement and one with the Nigeria Governors' Forum. The Bureau of Public Procurement agreement threads data protection compliance into federal procurement, making every vendor and contractor in the government supply chain auditable on NDPA grounds as part of contract compliance.
The UK Information Commissioner's Office published guidance on 6 May 2026 to help public authorities handle Freedom of Information requests involving or generated by AI systems, addressing the rising volume of AI-generated requests and how existing FOI principles apply to them. The ICO's frameworks routinely surface in Kenyan, Nigerian and South African regulatory guidance within a few quarters of publication.
The NDPC hosted a two-day peer exchange in Abuja on 4 and 5 May 2026, bringing data protection regulators from nine African countries and multilateral institutions together to discuss cross-border enforcement coordination. Continental coordination among regulators has been discussed for years, but this meeting was distinguished by the enforcement position of the host: Nigeria convened the exchange while the Temu investigation, the CAC probe and the April advisory were all active, which made the session a working exchange of live case strategies rather than a general discussion. For organisations operating across multiple African jurisdictions, this points toward synchronised regulatory scrutiny, where an enforcement approach tested by one authority is more likely to be applied by its neighbours.
The Central Bank of Kenya advertised senior and managerial roles for virtual asset licensing and compliance functions in late April 2026, with applications closing 18 May, before the VASP Regulations had been finalised. The hiring confirms the division of labour under Kenya's dual-regulator model: the CBK covers payment-side VASPs, stablecoin issuers and custodial services, while the CMA supervises exchanges, brokers and tokenisation platforms.
The National Treasury published the Draft Capital Flow Management Regulations 2026 for public comment in April 2026, replacing the Exchange Control Regulations of 1961 and bringing crypto assets formally within South Africa's capital flow framework for the first time.