As African countries assert greater control over their data, tensions are emerging with the U.S. preference for the free flow of data across borders. But these approaches need not be mutually exclusive. This article examines how African data sovereignty can coexist with U.S. privacy and digital trade priorities. It proposes a hybrid framework that protects sensitive data while enabling responsible cross-border data flows.
Introduction: The Global Data Sovereignty Dilemma
Historically, “Sovereignty” meant a ruler's supreme authority in a monarchical setting before evolving into the concept of state supremacy, a principle now firmly enshrined in international law. Essentially, sovereignty is the state’s “sovereign” right to act freely without external influence and to command all powers within its territory (internal sovereignty).
The concept of data or digital sovereignty is relatively new and can be obscure because it is interpreted differently across political and economic discourses. However, we can categorically state that it emphasises state autonomy with respect to its digital infrastructures and technological advancement, economic autonomy aiming at a nation’s digital transformation of its economic sectors, and finally, with a more recent view, user autonomy as to the autonomy of citizens in their roles as employees, consumers, etc. and users of digital technologies and services.
This concept can be traced to approaches taken by both authoritarian and democratic societies, as governments have increasingly sought to assert control over digital resources, citing national security as justification. In the United States, there is no centralised or comprehensive federal data privacy law governing data collection, usage and security, as compared to its European counterparts with the General Data Protection Regulation (GDPR), and in an attempt to combat this, many states have enacted or are currently in the process of enacting their own comprehensive privacy laws, with California’s Consumer Privacy Act (CCPA) being the most notable example.
In addition to the CCPA, specific sector regulations such as the Health Insurance Portability and Accountability Act (HIPAA) and guidelines set by the Federal Trade Commission (FTC) also apply. These laws support the US policy of free data flow across borders, boosting innovation and economic growth.
In contrast, sentiment in Africa differs: many countries view data as a national asset to be governed locally, without foreign surveillance or exploitation, as shown in Nigeria, Kenya, and others, which embrace data sovereignty by implementing and codifying national data regulations. This has led to stringent data localisation policies, with increasing claims to assert control within their borders, prioritising data protection and economic development. In the context of global trade and the U.S.-Africa relationship, this paper argues for a collaborative partnership that integrates African-style data sovereignty with the U.S.’s focus on free-flowing data to create a hybrid model. By aligning data privacy standards and removing regulatory barriers to digital trade, both regions could create a more stable and predictable environment for technology companies, startups, and investors.
US Privacy laws
The California Consumer Privacy Act (CCPA), which took effect on January 1, 2020, represents a significant advance in protecting privacy rights in the United States, particularly for California residents. It enables individuals to control their personal data. The CCPA requires businesses to disclose what types of data they collect, who they share it with, and why they collect it. Individuals can also request the deletion of their personal information and opt out of data sales to third parties. In addition, the Federal Trade Commission (FTC) complements the CCPA by emphasising transparent practices to prevent unfair competition and deceptive practices affecting commerce. The FTC plays a key enforcement role, ensuring businesses adhere to privacy commitments.
The US philosophy on privacy can be traced to privacy rights rooted in constitutional principles, such as the protection of freedom of speech and religion, which imply a degree of personal autonomy; explicit protection against unreasonable searches and seizures; and marital relations, which can be interpreted to safeguard personal privacy.
With the advent of technology and its complexities, the U.S. Congress enacted certain legislative measures in industry-specific sectors due to growing national and consumer security concerns. This led to early federal legislation such as the Fair Credit Reporting Act (FCRA), the Privacy Act, and Title V of the Gramm-Leach-Bliley Act (GLBA), which provided some informational privacy protection. The FCRA protects consumer information held by credit reporting agencies, while GLBA requires financial institutions to disclose their privacy policies and practices to consumers, thereby protecting consumers’ financial information. The Privacy Act governs the use, collection and dissemination of personally identifiable information (PII) maintained in systems of records by federal agencies.
Similarly, in the area of sensitive health information, the Health Insurance Portability and Accountability Act (HIPAA) introduced significant privacy and security standards for the confidentiality and protection of medical records. Another notable federal legislation is the Children’s Online Privacy Protection Act (COPPA), which aims to protect vulnerable children in the digital space.
Finally, the enactment of the California Consumer Privacy Act (CCPA) marked a significant shift in US data privacy legislation by giving Californian residents strong privacy rights over their personal information. Subsequently, California enacted the California Privacy Rights Act to strengthen enforcement, including by establishing an agency, thereby expanding the CCPA. This has further inspired other states to enact their own privacy laws, such as Colorado, Connecticut, and Texas, with others following suit.
The US operates on a patchwork of state-level regulations and sector-specific federal laws such as the Privacy Act and GLBA, which have led to inconsistent protections and consumer confusion. The U.S. approach leans toward a free-flow-of-data philosophy, encouraging innovation and cross-border economic growth. However, a shift is discernible in the treatment of data implicating national security, where the U.S. has departed from its traditionally fragmented approach.
President Biden's Executive Order 14117, "Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern," restricts the transfer of bulk sensitive personal data, including biometric, genomic, health, financial, and geolocation data, to "countries of concern" such as China, Russia, Iran, North Korea, Cuba, and Venezuela. Notably, this order has survived the change in administration: the Department of Justice's implementing rule took effect on April 8, 2025, and the Trump administration has continued to implement it rather than rescind it, treating its violations as a national security matter and signalling rare cross-administration consensus.
This suggests that, while the U.S. remains resistant to comprehensive consumer-facing privacy legislation, it is increasingly willing to regulate data flows where foreign access implicates national security, effectively treating sensitive personal data as a strategic asset rather than merely a consumer protection matter. Advocacy for federal legislation has also grown amid uncertainty over conflicting laws. Many believe a unified national data privacy framework will ensure consumers' transparency and provide regulatory certainty.
African Data Sovereignty Laws: National Control of Data
The discourse on data sovereignty in Africa has gained traction in global conversations about nations' rights to control the flow of data generated within their borders. The African continent presents a markedly heterogeneous data privacy landscape, shaped by fifty-four distinct jurisdictions with varying colonial legal legacies, levels of legislative maturity, and constitutional traditions. Unlike the European Union, which benefits from a harmonising supranational instrument in the GDPR, Africa's approach to privacy protection has developed largely on a country-by-country basis, resulting in significant divergence in how and whether the right to privacy is constitutionally entrenched. This divergence can broadly be classified into two categories.
The first category consists of countries with express provisions protecting privacy in their constitutions, such as Nigeria, Kenya, and South Africa. The second category includes countries which lack express provisions on the constitutional right to privacy. For example, the Angolan constitution is silent on privacy with respect to its provision on the protection of personal integrity, name and reputation.
Notwithstanding this constitutional divergence, statutory data privacy laws across the continent have converged significantly around a shared regulatory template: the EU's General Data Protection Regulation (GDPR). Nigeria, Kenya, and South Africa, despite falling into one category as indicated above, have each enacted comprehensive data protection statutes that mirror core GDPR concepts such as lawful bases for processing, data subject rights, and cross-border transfer restrictions, and are discussed below.
Key African Laws
Nigeria
One significant early piece of legislation affecting data sovereignty in Nigeria was the Nigerian Data Protection Regulation (NDPR) and the Nigeria Data Protection Regulation 2019: Implementation Framework (Implementation Framework). However, due to certain challenges posed by the existing law with respect to strict data localisation rules and the absence of a data protection authority, this further necessitated the need for the legislature to enact a comprehensive data protection law, the Nigeria Data Protection Act.
The Act provides data principles that align with many international data protection frameworks and also includes novel provisions. The Act introduces a novel category of “data controllers and processors of major importance.” A data controller and processor of major importance is defined as a “data controller or data processor that is domiciled, resident in, or operating in Nigeria and processes or intends to process personal data of more than such a number of data subjects who are within Nigeria.” The Act continues, explaining that “the Commission may prescribe such other class of data controller or data processor that is processing personal data of particular value or significance to the economy, society, or security of Nigeria as the Commission may designate.”
On cross-border data transfers, the Act recognises broad grounds for transfer, as well as parliamentary authorisations, to protect data sovereignty. The Act allows for personal data to be transferred outside Nigeria under two primary conditions. First, it may occur when the data importer complies with specific safeguards that ensure an adequate level of protection for personal data, which can be established through various mechanisms including laws, Binding Corporate Rules (BCRs), contractual clauses, Codes of Conduct, or certification mechanisms. If these criteria are not met, transfers may still be permissible in exceptional circumstances analogous to the exceptions provided under Article 49 of the GDPR.
Data controllers must maintain a comprehensive record of the legal bases for transferring personal data internationally and document the adequacy of the protection measures in place. This requirement reflects a significant evolution from previous models, as it allows individual data controllers to assess adequacy on their terms. The Act empowers the Nigeria Data Protection Commission (the Commission) to formulate guidelines for assessing adequacy based on the criteria specified in the Act. One critical factor in these assessments is the extent of public authorities' access to personal data, a consideration that complicates the regulatory landscape amidst international discussions about governmental data access. Furthermore, the Commission can acknowledge adequacy determinations made by foreign entities if they align with the standards set out in the NDPR, nurturing a cooperative international regulatory environment.
Aligning with the Nigeria National Data Strategy of 2022, the Act emphasises data sovereignty as an enabling pillar, asserting that data should be managed under local laws and regulations. Any mechanisms for international data transfers, including rules or certifications regarding data subject protection, must receive endorsement from Nigeria's National Assembly, reinforcing the regulatory authority over such frameworks. This commitment to data sovereignty has since been reinforced by two further regulatory developments.
In August 2026, Nigeria's Federal Ministry of Communications, Innovation and Digital Economy released the National Digital Cloud Policy, which supersedes the 2019 National Cloud Computing Policy and introduces a tiered data-classification framework: data classified at the highest sensitivity level, covering national security, defence, and critical infrastructure information, must be hosted exclusively on cloud infrastructure physically located in Nigeria, while less sensitive commercial and government workloads may continue to use hybrid or global cloud infrastructure.
Similarly, in the financial sector, a Central Bank of Nigeria circular of 15 June 2026 requires all payment system participants, including licensed banks, mobile money operators, payment service providers, and switching companies, to store payment transaction data on servers located within Nigeria by 1 January 2027.
Overall, this reemphasises Nigeria's data localisation principle, which aims to secure personal data and maintain control over its processing and transfer, reinforcing the commitment to protecting individual privacy in the digital landscape.
Kenya
The Kenya Data Protection Act (KDPA) of 2019 marks a pivotal development in data sovereignty, reflecting Kenya's commitment to controlling personal data generated within its borders. This regulation is based on the constitutional principle of data privacy in the Constitution of Kenya. As the country increasingly recognises data as a vital asset, the Act underscores a proactive approach to managing and protecting it in line with national interests. It expressly prohibits processing certain types of data outside Kenya. This is prescribed under Section 50, which outlines that:
The Cabinet Secretary may prescribe, based on grounds of strategic interests of the state or protection of revenue, certain nature of processing that shall only be effected through a server or a data centre located in Kenya.
To supplement this provision, the government released the Data Protection General Regulations, which provide clear directions on what data is restricted to processing in Kenya. These regulations give effect to Section 50 of the Act by specifying the precise categories of processing that must be localised. A data controller or processor handling personal data for purposes of the "strategic interests of the state" must either (a) process such data through a server and data centre located in Kenya, or (b) store at least one serving copy of the data in a Kenyan data centre.
The Regulations identify six categories of processing to which this requirement applies: the administration of civil registration and legal identity management systems; the conduct of elections; the oversight of public finance administration systems operated by state organs; the operation of any system designated as a "protected computer system" under the Computer Misuse and Cybercrimes Act; the provision of early childhood and basic education; and the provision of primary or secondary healthcare to data subjects within the country.
In effect, the localisation mandate is not a blanket requirement applicable to all personal data, but a targeted intervention confined to data implicating core state functions: civil identity, elections, public finance, critical infrastructure, education, and health, thereby reflecting a national-security and public-interest rationale rather than a general data-protection one.
In addition, the Act restricts cross-border data transfers. The Act prohibits cross-border data transfers unless the transfer is to a country with an adequate level of protection, as in Kenya, or approvals have been obtained after the data controller or data processor has provided sufficient proof that measures are in place to protect the personal data. Data processors and controllers must notify the commissioner when transferring data out of Kenya.
It is worthy of note that Kenya and the US are currently negotiating a new bilateral trade framework, following the collapse of earlier Free Trade Agreement and Strategic Trade and Investment Partnership (STIP) discussions under previous administrations. These talks run alongside efforts to secure a longer-term extension of the African Growth and Opportunity Act (AGOA), which has already been extended through December 2026.
The US has consistently opposed data localisation requirements across successive rounds of trade talks, framing such measures as restrictive to US organisations operating in the country and as negatively affecting digital trade. Given Kenya’s firm commitment to data localisation under Regulation 26 of the Data Protection (General) Regulations, discussed above, this tension is likely to remain a live issue in the negotiations. Both nations would benefit from collaborating on a framework that facilitates digital trade while preserving Kenya’s core data sovereignty interests through negotiated carve-outs or mutual recognition mechanisms, rather than requiring Kenya to abandon localisation altogether.
Malabo Convention
The African Union Convention on Cybersecurity and Personal Data Protection, also known as the Malabo Convention, is the continent's binding treaty on privacy and cybersecurity. It was enacted to ensure data privacy and protection across the continent. The aim of the convention is:
...to set up minimum standards and procedures to reach a common approach on the security issues in Africa and address the need for harmonised legislation necessary to enhance cooperation in the area of cybersecurity in Member States of the African Union.
It is important to note that the Malabo Convention was significantly inspired by the European data protection standards, namely the Council of Europe Convention 108 and the European Union Data Directive 95/46/EC (now superseded by the GDPR). This influence reflects what has been termed the "Brussels Effect": the diffusion of EU regulatory standards through unilateral market and normative influence, a pattern that has shaped not only the Malabo Convention but African digital policymaking more broadly. Notably, both Convention 108 and Directive 95/46/EC were themselves substantially shaped by the OECD's 1980 Guidelines on the Protection of Privacy and Transborder Flows of Personal Data, meaning the OECD's influence on Malabo is best understood as indirect, transmitted through these two European instruments rather than as a direct input.
The Malabo Convention regulates three sets of issues: electronic transactions (chapter I); personal data protection (chapter II); and cybersecurity/cybercrimes (part III). The Malabo Convention requires each African Union member state to establish a legal framework that enhances fundamental rights and public freedoms, with a particular focus on safeguarding personal data. It also emphasises penalising privacy violations while upholding the principle of the free flow of data. Additionally, the framework must balance safeguarding individual freedoms and fundamental rights during personal data processing while acknowledging state authority, the interests of local communities, and the objectives for which businesses are established.
The Malabo Convention outlines six key principles for personal data processing, closely mirroring EU data protection standards. It requires valid consent for data use, except in specific cases. Data must be processed lawfully, fairly, and transparently. It must be relevant, accurate, and stored only as long as necessary for the original purpose. Data subjects must be informed about how their data is used, and strict security measures must protect it from unauthorised access. The Convention also includes additional protections for sensitive data.
The Malabo Convention affords enhanced protection to sensitive categories of personal data and obliges every AU Member State to establish a national authority responsible for personal data protection. With respect to cross-border data transfer, Article 14(6) of the Convention obligates data controllers to refrain from transferring personal data to a non-Member state of the AU unless that state ensures an adequate level of protection of the privacy, freedoms, and fundamental rights of the data subjects concerned. Notably, this obligation is not absolute: it does not apply where the national data protection authority has given consent before the transfer, giving Member States regulatory flexibility to authorise transfers on a case-by-case basis even where the destination country’s protections fall short of the adequacy threshold.
Critically, the Convention does not itself define what constitutes “adequate” protection, leaving this determination to the discretion of national data protection authorities and domestic implementing legislation. This is significant because “adequacy” under the Malabo framework is not a harmonised, continent-wide standard, unlike, for instance, the EU’s adequacy mechanism under the GDPR, where the European Commission issues centralised adequacy decisions binding on all Member States.
Instead, each African state’s data protection authority assesses adequacy independently, risking inconsistent outcomes; a country deemed “adequate” by one Member State’s regulator may not be so regarded by another. Nigeria’s approach illustrates this discretion in practice; its Data Protection Regulation maintains a “white list” of countries deemed to have adequate protection, including the Malabo Convention signatories, EU and EEA states, the United States, Japan, among others.
This decentralised, state-by-state approach to adequacy determination is one of the Malabo Convention’s most significant structural weaknesses and an area where regional harmonisation remains incomplete. To address implementation gaps of this kind, arising from factors such as cultural differences and divergent privacy expectations across the continent, the AU, in collaboration with the Internet Society, developed the Privacy and Personal Data Protection Guidelines for Africa, a blueprint intended to guide state actors in developing national privacy and data protection policy.
The provisions of the major African nations’ data protection regimes reemphasise the prioritisation of governance and control of data within their respective borders. Many African countries have adopted, or are adopting, similar frameworks to govern the use, collection, and processing of data within national borders, contributing to the philosophical approach of data sovereignty. This stems from security concerns and economic development, as this approach aligns with the African Union’s (AU) Agenda 2063, which calls for the development of digital infrastructure and freedom from external exploitation.
A Hybrid Model of Data Sovereignty: Balancing Local Control and Cross-Border Flow?
Despite differences in perception and approach between the United States and African nations on data governance, both appear on course for effective digital collaboration. This is evidenced by the launch of the Digital Transformation with Africa (DTA) initiative, which advances US-Africa digital collaboration and is one of the signature initiatives resulting from the US Strategy Toward Sub-Saharan Africa. A useful comparative reference point is the EU-U.S. Data Privacy Framework (DPF), administered by the U.S. Department of Commerce, which establishes a legal mechanism for transatlantic transfers of personal data for commercial purposes.
The DPF is the successor to two earlier, invalidated instruments: the "Safe Harbour" framework and the EU-U.S. Privacy Shield, both struck down by the Court of Justice of the European Union because they failed to adequately protect EU citizens' data from U.S. government surveillance. This history is instructive: it demonstrates that even well-resourced, mature cross-border data frameworks between close trading partners remain vulnerable to collapse where the balance between commercial flexibility and rights protection is miscalibrated, a caution Africa and the U.S. would do well to heed in designing their own framework.
This context suggests that a cross-border, tailored agreement between the U.S. and African nations could adopt a hybrid model of data sovereignty, one that respects the data protection regimes and localisation priorities of individual African states while still promoting economic growth through the responsible free flow of data. Such a hybrid model would depart from both extremes of the current spectrum: it is neither a wholesale adoption of unrestricted cross-border data flow (as favoured by U.S. trade negotiators) nor a rigid, blanket localisation regime (as reflected in instruments such as Kenya's Regulation 26, discussed above). Instead, it would be defined by three core features:
- Tiered data classification: Distinguishing between data implicating core state functions (e.g. civil identity, elections, public finance, critical infrastructure, health, as under Kenya's model), which remain subject to localisation, and general commercial data, which may flow more freely subject to baseline protections.
- Mutual recognition mechanisms: Allowing African data protection authorities and U.S. regulators to recognise each other's compliance standards (similar in structure, though not necessarily in substance, to the DPF's self-certification model), reducing the compliance burden on companies operating across both jurisdictions without requiring African states to cede regulatory authority over sensitive data categories.
- Independent redress and oversight: Learning from the DPF's own vulnerabilities, any hybrid instrument should build in robust, independent avenues for data subjects to seek redress, rather than relying solely on executive-branch commitments that may be reversed by a change in U.S. administration.
Such an approach would allow African nations to retain meaningful control over their citizens' most sensitive personal information, while enabling U.S. companies to operate within these jurisdictions on predictable, mutually agreed terms, offering a more durable middle path than either a purely sovereignty-driven or a purely trade-driven model would achieve on its own. Realising this model, however, will require deliberate, sustained diplomatic engagement: African and U.S. negotiators should prioritise embedding these principles into the current bilateral trade talks discussed above, rather than treating data governance as a peripheral issue to be resolved after core trade terms are settled.
Conclusion: A Path Forward
The digital trade market in Africa has grown significantly, though it remains smaller than markets in Europe, Asia, and North America. Recent McKinsey research projected the global digital marketplace to be worth $3 trillion, with $797 billion of this value located within Africa and Europe across the sectors we've categorised. From a U.S. trade perspective, many African data protection laws are likely to significantly affect U.S. firms despite their growing presence on the continent. On the other side of the divide, many African countries widely perceive that U.S. companies are not interested in extending access to their popular digital apps to Africa, as geographic location determines the range and access of capabilities for many digital apps.
The proposed hybrid model of data sovereignty aims to balance the concerns of both the U.S. and Africa regarding data privacy and sovereignty. It supports the free flow of data across borders while ensuring local privacy regulations are respected. This approach allows Africa to maintain control over sensitive data while accommodating the U.S.’s preference for open data exchange, fostering a framework that encourages both data protection and economic growth.
The future of global data governance will rely heavily on U.S.-Africa collaboration. By aligning their policies on cross-border data flows and privacy standards, both regions can ensure secure digital trade while addressing privacy concerns. This cooperation is crucial to overcoming the challenges of an increasingly interconnected digital world and will help both regions navigate the complexities of the global digital economy. A unified approach will position the U.S. and Africa as leaders in the digital economy, driving economic growth and protecting privacy.
Author
Michael Faleye / Privacy Analyst