As of October 2026. As of October 2026, almost no African country has a dedicated, binding AI law. Bills are moving in Nigeria and Kenya, and Morocco has a draft framework law, but none has yet been confirmed as enacted. In practice, data protection law does most of the work, especially the rules on automated decisions, registration with the regulator and cross-border transfers, while national AI strategies and policies are multiplying fast under the African Union's 2024 Continental AI Strategy.
| Country | Data protection law | Regulator | AI strategy or policy | Notes |
|---|---|---|---|---|
| Nigeria | Nigeria Data Protection Act 2023 (2023) | Nigeria Data Protection Commission (NDPC) | National AI strategy adopted: National Artificial Intelligence Strategy (2025 to 2029) (2025) | Section 37 of the NDPA gives a right not to be subject to solely automated decisions with legal or similarly significant effects, with rights to human intervention, to express a view and to contest. The NDPC's General Application and Implementation Directive (GAID) took effect on 19 September 2025 and requires data controllers and processors of major importance to register. A National Digital Economy and E-Governance Bill, which includes risk-based AI rules, was expected to be signed in late 2025, but in July 2026 it was reported to be still completing its passage through the National Assembly; as of October 2026 no presidential assent has been confirmed. Sources: [1] [2] [3] [4] [5] [6] [7] [8] |
| Kenya | Data Protection Act 2019 (2019) | Office of the Data Protection Commissioner (ODPC) | National AI strategy adopted: Kenya Artificial Intelligence Strategy 2025 to 2030 (2025) | Section 35 of the Data Protection Act gives a right not to be subject to solely automated decisions, including profiling, with legal or significant effects; the Data Protection (General) Regulations 2021 add detail, including on transfers outside Kenya. An Artificial Intelligence Bill, 2026, sponsored by Senator Karen Nyamu, proposes an AI Commissioner and a four-tier risk classification; as of October 2026 it is a bill, not law. Sources: [1] [2] [3] [4] [5] [6] [7] [8] [9] |
| South Africa | Protection of Personal Information Act 4 of 2013 (POPIA) (2013 (most provisions in force 1 July 2020)) | Information Regulator | Draft AI strategy: Draft South Africa National AI Policy (2026) | Section 71 of POPIA restricts decisions based solely on automated processing that affect people substantially. A draft national AI policy gazetted on 10 April 2026 was withdrawn on 26 April 2026 after fabricated citations were found in it; a revised draft is targeted for Cabinet by November 2026 and public comment in January 2027. Sources: [1] [2] [3] [4] [5] [6] |
| Ghana | Data Protection Act 2012 (Act 843) (2012) | Data Protection Commission | National AI strategy adopted: National Artificial Intelligence Strategy (2023 to 2033) (2026) | Cabinet approved the strategy in early 2026 and President Mahama launched it in Accra on 24 April 2026. A Data Protection Bill, 2025, which would repeal Act 843, create a Data Protection Authority and extend to foreign controllers that offer goods or services to, or monitor, people in Ghana, went through consultation in 2025 and was presented again by the minister in March 2026; as of October 2026 it has not been confirmed as passed. Sources: [1] [2] [3] [4] [5] [6] [7] |
| Egypt | Personal Data Protection Law No. 151 of 2020 (2020) | Personal Data Protection Center (PDPC) | National AI strategy adopted: National AI Strategy, second edition (2025 to 2030) (2025) | The Executive Regulations (Ministerial Decree No. 816 of 2025) were issued on 1 November 2025, starting a one-year grace period, so enforcement is expected from 1 November 2026; because the text was only published on 25 December 2025, some advisers see the exact date as uncertain. They set licensing, registration and cross-border transfer rules. The 2025 strategy lists an AI law among its planned initiatives. Sources: [1] [2] [3] [4] [5] |
| Rwanda | Law No. 058/2021 relating to the protection of personal data and privacy (2021) | National Cyber Security Authority (NCSA) | AI policy in place: National Artificial Intelligence Policy (2023) | Cabinet approved the AI policy on 20 April 2023. Data controllers and processors must register with the NCSA, and personal data may be stored or transferred outside Rwanda only with NCSA authorisation or on another ground set out in the law. In June 2026 Cabinet approved the creation of a National Artificial Intelligence Agency. Sources: [1] [2] [3] [4] |
| Morocco | Law No. 09-08 on the protection of individuals with regard to the processing of personal data (2009) | Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) | National AI strategy adopted: Digital Morocco 2030 (Maroc Digital 2030) (2024) | AI sits within the wider Digital Morocco 2030 strategy, launched in September 2024, rather than a standalone AI strategy. A draft framework law, Digital X.0, unveiled in October 2025, would govern AI, data and digital identity; it was last reported under review by the General Secretariat of the Government, and as of October 2026 it has not been confirmed as adopted. Sources: [1] [2] [3] [4] [5] [6] [7] [8] |
| Mauritius | Data Protection Act 2017 (2017 (in force 15 January 2018)) | Data Protection Office (Data Protection Commissioner) | National AI strategy adopted: National AI Strategy (2025 to 2029) and FAIR Guidelines (2026) | The Data Protection Act 2017 was written to align closely with the EU GDPR, which makes Mauritius one of the more familiar regimes for organisations already working to GDPR standards. Mauritius published one of Africa's first AI strategies in 2018 and launched a new National AI Strategy with FAIR Guidelines for ethical AI in April 2026, with UNDP support. Sources: [1] [2] [3] [4] [5] [6] [7] |
| Senegal | Law No. 2008-12 of 25 January 2008 on the protection of personal data (2008) | Commission de Protection des Données Personnelles (CDP) | National AI strategy adopted: National AI Strategy and Roadmap (to 2028) (2023) | The government unveiled the strategy in 2023. The CDP has been working on draft texts to modernise the 2008 law since at least October 2024, and experts have called for it to address AI, but no new data protection law had been confirmed as adopted as of October 2026. Sources: [1] [2] [3] [4] [5] |
| Côte d'Ivoire | Law No. 2013-450 on the protection of personal data (2013) | Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI) | To be confirmed: National Strategy for AI and Data Governance (to 2030) (2025) | The national AI and data governance strategies were presented on 13 March 2025 and handed to the Prime Minister for adoption by the government. They propose a national AI committee, an AI research hub and a start-up incubator. ARTCI, the telecoms regulator, is designated by the 2013 law as the data protection authority. The strategy has been published; formal adoption by the government is not confirmed. Sources: [1] [2] [3] [4] [5] |
| Uganda | Data Protection and Privacy Act 2019 (2019) | Personal Data Protection Office (PDPO) | Draft AI strategy: National Strategy for Artificial Intelligence and Emerging Technologies (2026) | The ICT ministry said in April 2026 that the strategy would be ready by June 2026, but no formal launch had been confirmed by October 2026, and later reports said it would be launched before the end of 2026. Government figures have also called for the 2019 Act to be revised to address AI. Sources: [1] [2] [3] [4] [5] [6] [7] |
| Tanzania | Personal Data Protection Act 2022 (2022) | Personal Data Protection Commission (PDPC) | Draft AI strategy: National Artificial Intelligence Strategy (draft) (2025) | Anyone who collects or processes personal data must register with the PDPC. The Ministry of Communication and Information Technology released a draft AI strategy in 2025; final adoption could not be confirmed. Sources: [1] [2] [3] [4] [5] [6] |
| Ethiopia | Personal Data Protection Proclamation No. 1321/2024 (2024) | Ethiopian Communications Authority | AI policy in place: National Artificial Intelligence Policy (2024) | The Council of Ministers approved the AI policy on 27 June 2024. The Proclamation requires impact assessments, prior authorisation in some cases and data protection officers. Sources: [1] [2] [3] [4] [5] |
| Zambia | Data Protection Act No. 3 of 2021 (2021) | Office of the Data Protection Commissioner | National AI strategy adopted: National Artificial Intelligence Strategy (2024 to 2026) (2024) | The Act requires registration of data controllers and licensing of data auditors. In April 2025 Cabinet approved a bill to repeal and replace the 2021 Act to cover AI and data analytics; its passage could not be confirmed. Sources: [1] [2] [3] [4] [5] |
| Zimbabwe | Cyber and Data Protection Act 2021 (2021) | Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) | National AI strategy adopted: Zimbabwe National Artificial Intelligence Strategy 2026 to 2030 (2026) | Launched on 13 March 2026. It plans an AI Strategy Implementation Office and a regulatory sandbox under POTRAZ, and builds on the Cyber and Data Protection Act rather than creating a new AI law. Under that Act and its 2024 regulations, data controllers must be licensed by POTRAZ and appoint a data protection officer. Sources: [1] [2] [3] [4] [5] [6] |
| Botswana | Data Protection Act 2024 (2024) | Information and Data Protection Commission | Draft AI strategy: National Artificial Intelligence Policy (in development) | The 2024 Act repealed the Data Protection Act 2018, came into force on 14 January 2025 and extended the Commission's mandate to access to information. The government has said its first National AI Policy, informed by a UNESCO AI readiness assessment, is in its final stage; adoption had not been confirmed as of October 2026. Sources: [1] [2] [3] [4] [5] |
| Tunisia | Organic Law No. 2004-63 on the protection of personal data (2004) | Instance Nationale de Protection des Données Personnelles (INPDP) | Draft AI strategy: National Artificial Intelligence Strategy 2026 to 2030 (2026) | A bill to replace the 2004 law (PLO 095/2025) was filed with Parliament in August 2025; it would add rules on profiling and a right to contest automated decisions. It was still being examined in committee in 2026 and was not confirmed as passed. A national AI strategy for 2026 to 2030 was presented to a ministerial council in May 2026; its formal adoption could not be confirmed. Sources: [1] [2] [3] [4] [5] |
| Algeria | Law No. 18-07 on personal data protection, amended by Law No. 25-11 (2018 (amended 2025)) | Autorité Nationale de Protection des Données à caractère Personnel (ANPDP) | To be confirmed: National Artificial Intelligence Strategy (2026) | Law 25-11 of 24 July 2025 added mandatory data protection officers, impact assessments for high-risk processing and a five-day breach-notification deadline. A government meeting chaired by the Prime Minister approved the first national AI strategy on 25 May 2026, for onward adoption by the Council of Ministers, and implementation meetings began in August 2026. Sources: [1] [2] [3] [4] [5] |
| Cameroon | Law No. 2024/017 of 23 December 2024 on personal data protection (2024) | Personal Data Protection Authority created by the law (not confirmed as operational) | National AI strategy adopted: National Artificial Intelligence Strategy (SNIA) (2025) | Cameroon's first comprehensive data protection law gave an 18-month transition that ended on 23 June 2026. The AI strategy, presented in July 2025, calls for an AI law and a competent AI authority. Sources: [1] [2] [3] [4] [5] [6] |
| Benin | Digital Code (Law No. 2017-20 of 20 April 2018), Book V (2018) | Autorité de Protection des Données à caractère Personnel (APDP) | National AI strategy adopted: National Strategy for Artificial Intelligence and Big Data (SNIAM) 2023 to 2027 (2023) | The Council of Ministers adopted the strategy on 18 January 2023. Data protection sits in the Digital Code, which requires prior declaration to the APDP before processing. Sources: [1] [2] [3] [4] |
| Togo | Law No. 2019-014 on the protection of personal data (2019) | Instance de Protection des Données à Caractère Personnel (IPDCP) | Draft AI strategy: National Artificial Intelligence Strategy (in preparation) | The IPDCP only began operating on 28 March 2025, so enforcement is new. The government is drafting a national AI strategy, but its adoption could not be confirmed as of October 2026. Sources: [1] [2] [3] [4] |
| Namibia | No comprehensive data protection law in force (Data Protection Bill pending) () | None yet (bill would create a Data Protection Supervisory Authority) | Draft AI strategy: National AI Strategy (in development) | A Data Protection Bill was due to be tabled in Parliament in late 2025; its enactment had not been confirmed as of October 2026. Until it passes, there is no dedicated data protection regulator. A national AI strategy is being developed and the ICT ministry has said an AI law is planned; neither had been confirmed as adopted. Sources: [1] [2] [3] [4] [5] |
This summary is general information, not legal advice. Laws change; check the sources and take local advice.
How this page was made. Parts of these pages were drafted and researched with the help of AI tools, then reviewed and checked against the sources linked beside each claim. AI can get things wrong and laws change, so treat this as general information, not legal advice: the linked sources are the authority, and you should take qualified advice before relying on anything here. Spotted an error? Tell me and I will fix it. Last checked 7 October 2026. See the terms.
By Stanislaus Martins. Stanislaus Martins is Managing Director, Sub-Saharan Africa at Aleph, the digital advertising group, with teams in Lagos, Nairobi, Johannesburg and Cape Town. He has spent over two decades in marketing, digital business and technology across Sub-Saharan Africa, including roles as Head of Digital Business at Insight Publicis, VP of Growth Marketing and Advertising at Jumia Nigeria, and Agency Partner for Sub-Saharan Africa at Meta. He holds an MBA, is a Fellow of the Chartered Institute of Marketing (UK) and of NIMN, and is Immediate Past President of ADMARP. He has completed the AI Governance online course from Saïd Business School, University of Oxford, and Google Cloud's Gen AI: Beyond the Chatbot course, and is preparing for the IAPP AIGP certification. He runs the AI in Nigeria 2026 survey. In his own governance work he uses and follows the NIST AI Risk Management Framework. He helps organisations put AI to work with clear ownership, sensible risk controls and evidence they can show customers, regulators and boards.