🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
AFR v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing14 sources retrieved model claude-sonnet-5 · 2026-08-06

African bloc

AFR schema gdpri-v2 trajectory: not yet assessedin transitionoverlaps: AIC

Last updated · 10 categories · 18 claims · 21 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
18Claimsbaseline..claims[]
21Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction lead brief

Latest update · 28 September 2026

Lead Signal

The African Union's Malabo Convention, the continent's sole continent-wide data protection and cybersecurity treaty, has now been in force since June 2023, but only 16 of the African Union's 55 member states had ratified and deposited their instruments as of the most recent status list. This is a confirmed and analytically significant gap: a treaty in force for more than three years has achieved domestication by fewer than a third of the states party to the underlying African Union framework. The picture is one of formal legal existence running well ahead of substantive continental adoption.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Treaty is technically in force but enforcement infrastructure and universal ratification remain absent; this is a partial/in-transition continental instrument, not a settled omnibus regime.

Primary frameworkAfrican Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)
Traffic-light rationale — AmberTreaty is technically in force but enforcement infrastructure and universal ratification remain absent; this is a partial/in-transition continental instrument, not a settled omnibus regime.

Sub-modules (5)

Regulator And AuthorityAmber

No continental DPA exists with enforcement authority. NADPA-RAPDP is a cooperation network established under a constitution reviewed in 2022; it convenes national DPAs but does not itself regulate or enforce.

Claims (2):

  • As of the African Union's 8 July 2024 status list, only 16 of 55 AU member states had ratified and deposited instruments for the Malabo Convention, with ratification remaining patchy across the continent.
  • NADPA-RAPDP's governing constitution, as amended in May 2022, establishes it as a cooperation and capacity-building network of national data protection authorities rather than a legislative or enforcement body.

Act And InstrumentsAmber

Malabo Convention is the primary continental instrument; it entered into force 8 June 2023.

Claims (2):

  • The Malabo Convention entered into force on 8 June 2023 after Mauritania became the 15th state to submit its ratification, triggering the fifteen-ratification threshold under Article 36.
  • The AU's May 2023 status list identified fifteen states that had submitted ratification of the Malabo Convention, including Angola, Ghana, Rwanda, Senegal, Mauritius, and Namibia among others.

Material ScopeAmber

Convention covers e-commerce, data protection, and cybersecurity/cybercrime but has been criticised for lacking implementation detail.

Claims (1):

  • The Malabo Convention aims to create a comprehensive legal framework for electronic commerce, data protection, and cybercrime/cybersecurity, but has drawn criticism that it lacks important detail and does not provide for mechanisms to support its enforcement.

Territorial ScopeAmber

Full domestication mandate applies only once a state ratifies; non-ratifying states are not bound by Convention obligations at the continental level.

Regulator Registration And FilingRed

No continental registration/filing regime exists under the Malabo Convention; any such obligations are set exclusively at national level, which is out of scope for this continent-wide JID. Searched: Malabo Convention treaty text, AU status list, Malabo Roadmap — no continental filing mechanism found.

Category narrative100 words

The Malabo Convention (adopted 27 June 2014) entered into force on 8 June 2023 following Mauritania's ratification as the 15th state under Article 36, but there is no operational continental data-protection authority with direct enforcement power. NADPA-RAPDP functions purely as a cooperation/capacity-building network of national DPAs, not a legislative or enforcement body. Ratification remains patchy: only 16 of 55 AU member states had ratified/deposited instruments per the AU's 8 July 2024 status list. Actual enforcement authority resides with national DPAs (e.g., South Africa's Information Regulator, Nigeria's NDPC, Kenya's ODPC), which fall outside this continent-wide JID's scope per the disambiguation note.

Periodic update · new data 2026-09-28

Regulator & Framework

Africa's continental data protection framework rests on a single treaty instrument, the African Union Convention on Cyber Security and Personal Data Protection, commonly known as the Malabo Convention, which entered into force in June 2023. Confirmed reporting indicates that only 16 of the African Union's 55 member states had ratified and deposited their instruments of ratification as of the most recent African Union status list. This is a materially wide gap between formal treaty force and actual state-level adoption, and it is the central structural fact governing any assessment of continental data protection regulation.

The practical consequence of this ratification gap is that the Malabo Convention cannot be treated as a binding continental data protection law in the way that, for example, a directly applicable regional regulation would function. For the 39 African Union member states that have not yet ratified, the Convention has no binding domestic legal effect regardless of its international force. For the 16 states that have ratified, the Convention's provisions presumably carry the domestic legal weight those states' own constitutional and treaty-incorporation processes assign to it, though the specifics of that domestic incorporation are not detailed in this cycle's evidence.

Supporting this fragmented statutory picture is the Network of African Data Protection Authorities, known as NADPA-RAPDP, which is understood to have been established in September 2016. NADPA-RAPDP's own constitutional documents describe it as a cooperation and capacity-building network for African data protection authorities, and the evidence available this cycle indicates it is not a legislative or enforcement body. This distinction matters for anyone assessing continental regulatory capacity: NADPA-RAPDP provides a forum for African data protection authorities to coordinate and build capacity, but it does not itself have supervisory powers, cannot issue binding decisions, and cannot compel member states toward Malabo ratification or domestication.

Taken together, the regulator-and-framework picture for Africa is one of a treaty with formal international force but limited domestic reach, supported by a cooperation network with no enforcement or legislative function. This leaves the substantive work of data protection regulation to individual national laws and national data protection authorities, each operating independently of any binding continental oversight body. The qualified nature of some of this cycle's findings, particularly around the precise ratification count and the absence of a more developed adequacy mechanism, reflects the genuine difficulty of tracking a fragmented, nationally-driven continental picture from the sources available this cycle.

Outlook

The near-term outlook for continental regulator-and-framework development is one of continuity rather than change. Whether any of the remaining Malabo signatory states will move to ratify before the next reporting cycle is not resolved by this cycle's evidence, and NADPA-RAPDP's cooperation-only mandate gives it no institutional lever to accelerate that process. Absent a new continental initiative not yet reflected in this cycle's sources, the pattern of formal treaty force running well ahead of substantive domestication is likely to persist, with the practical regulatory picture continuing to be set primarily at the national level across the continent's 55 states.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedAfrican Union — The Malabo Convention entered into force on 8 June 2023 after Mauritania became the 15th state to submit its ratification, triggering the fifteen-ratification threshold under Article 36.observed
  2. ConfirmedAfrican Union — As of the African Union's 8 July 2024 status list, only 16 of 55 AU member states had ratified and deposited instruments for the Malabo Convention, with ratification remaining patchy across the continent.observed
  3. ConfirmedNADPA-RAPDP — NADPA-RAPDP's governing constitution, as amended in May 2022, establishes it as a cooperation and capacity-building network of national data protection authorities rather than a legislative or enforcement body.observed
  4. Confirmeddataprotection.africa — The AU's May 2023 status list identified fifteen states that had submitted ratification of the Malabo Convention, including Angola, Ghana, Rwanda, Senegal, Mauritius, and Namibia among others.observed
  5. Probabledataprotection.africa — The Malabo Convention aims to create a comprehensive legal framework for electronic commerce, data protection, and cybercrime/cybersecurity, but has drawn criticism that it lacks important detail and does not provide for mechanisms to support its enforcement.observed

#

No continental-level enumerated lawful-basis, consent, or special-category regime was found; only a general domestication mandate exists.

Primary frameworkAfrican Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)
Traffic-light rationale — RedNo continental-level enumerated lawful-basis, consent, or special-category regime was found; only a general domestication mandate exists.

Sub-modules (4)

Lawful BasesRed

Malabo Convention mandates national data-protection legislation but does not itself enumerate a harmonised list of lawful processing bases equivalent to GDPR Art 6.

Claims (1):

  • The Malabo Convention mandates that AU member states establish domestic legal frameworks for personal data processing, but continental-level materials reviewed do not set out a harmonised enumerated list of lawful processing bases; this is left to national implementing legislation.

Special CategoriesRed

No continental-level special/sensitive-category enumeration was retrieved in this run.

Pseudonymisation And AnonymisationRed

No continental-level pseudonymisation/anonymisation safe-harbour text was retrieved in this run.

Category narrative75 words

Neither the Malabo Convention treaty index, the AU status list, nor the Malabo Roadmap (Sept 2022) provided this run with granular continental-level text enumerating lawful processing bases, consent thresholds, special-category rules, or pseudonymisation/anonymisation safe harbours. The Convention's mandate is that member states enact domestic legislation meeting its standards, but the specific granular rules live at national level (POPIA, NDPA, Kenya DPA, etc.), which is out of scope for this continent-wide JID per the disambiguation note.

Sources and claims (1)
  1. Uncertaindataprotection.africa — The Malabo Convention mandates that AU member states establish domestic legal frameworks for personal data processing, but continental-level materials reviewed do not set out a harmonised enumerated list of lawful processing bases; this is left to national implementing legislation.observed

#

Absence of continental-level enumerated subject-rights text; rights exist only via national implementation.

Primary frameworkAfrican Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)
Traffic-light rationale — RedAbsence of continental-level enumerated subject-rights text; rights exist only via national implementation.

Sub-modules (5)

Access RightRed

No continental-level access-right text retrieved. Searched: Malabo Convention treaty text, Malabo Roadmap.

Claims (1):

  • Continental-level materials reviewed (Malabo Convention treaty index, Malabo Roadmap, AU status list) do not evidence a harmonised continent-wide data-subject-rights framework; such rights, where they exist, are created by national implementing statutes rather than directly by the Malabo Convention.

Rectification And ErasureRed

No continental-level rectification/erasure text retrieved.

Restriction And ObjectionRed

No continental-level restriction/objection text retrieved.

Data PortabilityRed

No continental-level portability text retrieved.

Deadlines And Response WindowsRed

No continental-level statutory response-deadline text retrieved.

Category narrative40 words

No continental-level data-subject-rights framework (access, rectification, erasure, restriction, portability, deadlines) was evidenced in the Malabo Convention treaty index, status list, or Roadmap reviewed in this run. Such rights, where they exist, derive from national implementing statutes outside this JID's scope.

Sources and claims (1)
  1. Uncertaindataprotection.africa — Continental-level materials reviewed (Malabo Convention treaty index, Malabo Roadmap, AU status list) do not evidence a harmonised continent-wide data-subject-rights framework; such rights, where they exist, are created by national implementing statutes rather than directly by the Malabo Convention.observed

#

Direct sourced criticism confirms an enforcement/detail gap in the continental instrument; national-level duties fall outside this JID.

Primary frameworkAfrican Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)
Traffic-light rationale — AmberDirect sourced criticism confirms an enforcement/detail gap in the continental instrument; national-level duties fall outside this JID.

Sub-modules (7)

Accountability And DpiaAmber

No continental DPIA-trigger text retrieved; general enforcement-mechanism criticism applies.

Claims (1):

  • The Malabo Convention has drawn criticism for lacking important detail and for not providing mechanisms to support its enforcement, a gap that extends to controller/processor accountability obligations.

Dpo RequirementsRed

No continental DPO-appointment threshold text retrieved.

Ropa RequirementsRed

No continental ROPA text retrieved.

Joint Controller ArrangementsRed

No continental joint-controller text retrieved.

Security MeasuresAmber

No continental security-of-processing text retrieved beyond general cybersecurity mandate language.

Claims (1):

  • The Democratic Republic of the Congo paired its December 2022 authorisation to ratify the Malabo Convention with presidential orders to operationalise a National Cybersecurity Agency and validate a national cybersecurity strategy, illustrating national institution-building alongside ratification.

Breach NotificationRed

No continental breach-notification threshold/timeline text retrieved.

Retention And DisposalRed

No continental retention/disposal text retrieved.

Category narrative57 words

The Malabo Convention has been directly criticised in reviewed materials for lacking important implementation detail and for not providing mechanisms to support enforcement of controller/processor duties such as DPIAs, DPO appointment, ROPA, breach notification, or retention limits at the continental level. Some ratifying states (e.g., DRC) have paired ratification steps with parallel national institution-building (cybersecurity agency operationalisation).

Sources and claims (2)
  1. Confirmeddataprotection.africa — The Malabo Convention has drawn criticism for lacking important detail and for not providing mechanisms to support its enforcement, a gap that extends to controller/processor accountability obligations.observed
  2. Confirmeddataprotection.africa — The Democratic Republic of the Congo paired its December 2022 authorisation to ratify the Malabo Convention with presidential orders to operationalise a National Cybersecurity Agency and validate a national cybersecurity strategy, illustrating national institution-building alongside ratification.observed

#

A continental data-governance harmonisation instrument exists and is actively being operationalised, but no adequacy/SCC/BCR mechanism analogous to GDPR Chapter V exists at continental level.

Primary frameworkAU Data Policy Framework (complementing the Malabo Convention)
Traffic-light rationale — AmberA continental data-governance harmonisation instrument exists and is actively being operationalised, but no adequacy/SCC/BCR mechanism analogous to GDPR Chapter V exists at continental level.

Sub-modules (6)

Transfer MechanismsAmber

No continental adequacy, SCC, or BCR mechanism exists; the AU Data Policy Framework instead pursues harmonisation of national frameworks.

Claims (1):

  • The AU Data Policy Framework aims to strengthen and harmonise data governance frameworks across Africa and create a shared continental data space, functioning as the principal continental-level instrument bearing on cross-border data flows rather than the Malabo Convention itself.

Adequacy ReceivedRed

No evidence found of adequacy decisions received by AU/Malabo jurisdictions from other regimes at the continental level.

Adequacy GrantedRed

No evidence found of continental-level adequacy grants to other regimes.

Sccs And BcrsRed

No continental SCC/BCR uptake mechanism retrieved.

Transfer Impact AssessmentRed

No continental TIA requirement retrieved.

Data LocalisationRed

No continental-level data-localisation mandate retrieved; localisation mandates, where present, are set at national level.

Category narrative56 words

The Malabo Convention does not itself establish a GDPR-style adequacy mechanism. The principal continental instrument bearing on cross-border data flows is the AU Data Policy Framework, which aims to harmonise data governance and create a shared continental data space; AU-led technical support is being extended to 22 of 35 interested member states to advance this framework.

Sources and claims (2)
  1. ProbableAfrican Union — The AU Data Policy Framework aims to strengthen and harmonise data governance frameworks across Africa and create a shared continental data space, functioning as the principal continental-level instrument bearing on cross-border data flows rather than the Malabo Convention itself.observed
  2. ConfirmedAfrican Union — As of April 2025, 22 of 35 interested African nations were receiving AU-led technical support to advance the AU Data Policy Framework.observed

#

No comprehensive continental sectoral overlay regime exists; this is a legitimate finding rather than a silent omission.

Traffic-light rationale — Not assessedNo comprehensive continental sectoral overlay regime exists; this is a legitimate finding rather than a silent omission.

Sub-modules (7)

Financial Sector OverlayRed

No continental financial-sector DP overlay found. Out of scope: national banking/financial-sector DP rules.

Health Sector OverlayRed

No continental health-sector DP overlay found.

Telecoms And EprivacyRed

No continental telecoms/ePrivacy overlay found.

Employment DataRed

No continental employment-data overlay found.

Credit And ScoringRed

No continental credit-scoring overlay found.

EducationRed

No continental education-sector overlay found.

InsuranceRed

No continental insurance-sector overlay found.

Category narrative69 words

No continental-level sectoral data-protection overlay (financial, health, telecoms/eprivacy, employment, credit, education, insurance) was found in the Malabo Convention, AU status list, or Roadmap. Sector-specific rules in Africa are set at the national level (e.g., national banking-secrecy laws, health regulations), which falls outside this continent-wide treaty-status JID per the disambiguation note. Searched: Malabo Convention treaty text, Malabo Roadmap, AU status list, NADPA-RAPDP materials — no continental sectoral overlay text found.

#

No comprehensive continental adtech/commercial-privacy regime exists.

Traffic-light rationale — Not assessedNo comprehensive continental adtech/commercial-privacy regime exists.

Sub-modules (6)

Cookies And TrackersRed

No continental cookie/tracker regime found.

Dark PatternsRed

No continental dark-pattern prohibition found.

Opt Out SignalsRed

No continental opt-out-signal standard found.

Clean Rooms And DcrRed

No continental clean-room/DCR rule found.

Cross Context AdvertisingRed

No continental cross-context advertising rule found.

Direct MarketingRed

No continental direct-marketing consent/suppression rule found.

Category narrative64 words

No continental-level cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal standard, clean-room rule, cross-context advertising rule, or direct-marketing consent standard was found in the Malabo Convention, AU status list, or Roadmap reviewed. Such rules, where present, exist only at the national level, outside this JID's continental treaty-status scope. Searched: Malabo Convention treaty text, Malabo Roadmap, AU Data Policy Framework materials — no continental adtech/commercial-privacy text found.

#

A continental AI policy framework exists and is actively developing but is non-binding strategy, not enforceable data-protection law; biometric/genetic/surveillance carveouts remain unaddressed at continental level.

Primary frameworkAU Continental Artificial Intelligence Strategy (non-binding)
Traffic-light rationale — AmberA continental AI policy framework exists and is actively developing but is non-binding strategy, not enforceable data-protection law; biometric/genetic/surveillance carveouts remain unaddressed at continental level.

Sub-modules (6)

Profiling RestrictionsRed

No continental profiling-restriction text found.

Automated Decision Making TransparencyAmber

No continental ADM-transparency text found beyond general AI Strategy aspirations.

Claims (1):

  • The Continental AI Strategy's five-year Implementation Plan includes developing legal frameworks to protect Africans from AI biases and misuse as a prioritised call to action.

Ai Risk AssessmentsAmber

Continental AI Strategy calls for AI risk assessments and legal frameworks against AI bias/misuse; High-Level Policy Dialogue reinforced this call in May 2025.

Claims (2):

  • The African Union Executive Council endorsed the Continental AI Strategy during its 45th Ordinary Session in Accra, Ghana, on 18-19 July 2024, establishing a continent-wide non-binding policy framework for AI governance.
  • The May 2025 High-Level Policy Dialogue communiqué called upon all African countries to formulate AI strategies, policies, laws, and regulations based on the provisions of the AU Continental AI Strategy alongside their own national conditions.

Biometric RegimeRed

No continental biometric-data regime found.

Genetic DataRed

No continental genetic-data regime found.

State Surveillance CarveoutsRed

No continental state-surveillance carveout text found.

Category narrative71 words

While the Malabo Convention itself does not address AI/algorithmic governance in the materials reviewed, the AU Executive Council endorsed a (non-binding) Continental AI Strategy in July 2024 that calls for legal frameworks addressing AI bias/misuse and for AI risk assessments, and a May 2025 High-Level Policy Dialogue communiqué called on African countries to formulate AI laws and regulations based on the Strategy. No continental-level biometric-specific, genetic-data-specific, or state-surveillance-carveout regime was found.

Sources and claims (3)
  1. ConfirmedAfrican Union — The African Union Executive Council endorsed the Continental AI Strategy during its 45th Ordinary Session in Accra, Ghana, on 18-19 July 2024, establishing a continent-wide non-binding policy framework for AI governance.observed
  2. ConfirmedAfrican Union — The Continental AI Strategy's five-year Implementation Plan includes developing legal frameworks to protect Africans from AI biases and misuse as a prioritised call to action.observed
  3. ConfirmedAfrican Union — The May 2025 High-Level Policy Dialogue communiqué called upon all African countries to formulate AI strategies, policies, laws, and regulations based on the provisions of the AU Continental AI Strategy alongside their own national conditions.observed

#

No comprehensive continental children/vulnerable-groups regime exists; legitimate gap finding.

Traffic-light rationale — Not assessedNo comprehensive continental children/vulnerable-groups regime exists; legitimate gap finding.

Sub-modules (5)

Age VerificationRed

No continental age-of-consent text found.

Minor Profiling BansRed

No continental minor-profiling-ban found.

Education SettingsRed

No continental education-setting rule found.

Dependent AdultsRed

No continental dependent-adults protection found.

Category narrative58 words

No continental-level age-of-consent, parental-consent, minor-profiling-ban, education-setting, or dependent-adult provision was found in the Malabo Convention, AU status list, or Roadmap reviewed in this run. Such provisions, where they exist, are set at the national level. Searched: Malabo Convention treaty text, Malabo Roadmap, AU Data Policy Framework and Continental AI Strategy materials — no continental children/vulnerable-groups data-protection text found.

#

Sourced criticism confirms an enforcement gap at the continental level, but recent (within-180-day) continental AI/data-governance activity signals ongoing institutional development.

Primary frameworkAfrican Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)
Traffic-light rationale — AmberSourced criticism confirms an enforcement gap at the continental level, but recent (within-180-day) continental AI/data-governance activity signals ongoing institutional development.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Convention lacks continental enforcement mechanisms and does not itself prescribe maximum penalties.

Claims (1):

  • The Malabo Convention has drawn criticism that it lacks important detail and does not provide for mechanisms to support its enforcement, meaning no continental-level regulator powers or maximum-penalty regime exists.

Enforcement Activity IndexRed

No continental enforcement decisions or fines were found; enforcement activity, where it exists, occurs at national DPA level only.

Regulator Funding And CapacityAmber

No continental regulator funding/headcount data found; NADPA-RAPDP operates as a member-funded cooperation secretariat rather than a funded enforcement regulator.

Claims (1):

  • NADPA-RAPDP operates through a Permanent Secretariat and Board under its 2022-amended constitution as a capacity-building and cooperation network, without direct adjudicatory or enforcement power over member states.

Collective Redress And Class ActionsRed

No continental collective-redress mechanism found; such mechanisms, where available, exist only under national law.

Private Right Of ActionRed

No continental private-right-of-action mechanism found; redress depends on national court systems.

Recent Developments 180DAmber

Within the 180 days preceding this run (Feb-Aug 2026), the AU Commission signed a Google partnership (17 Feb 2026) covering AI governance frameworks, and a further High-Level AI Policy Dialogue was scheduled for the February 2026 AU Summit.

Claims (2):

  • On 17 February 2026, the African Union Commission and Google signed a partnership to advance Africa's sovereign AI and digital capacity, with 'policy, governance, and responsible AI frameworks' listed among its priority areas.
  • The next edition of the AU's High-Level Policy Dialogue on AI development and regulation was scheduled to take place during the AU Summit in February 2026 in Addis Ababa, continuing continental momentum on AI/data governance.
Category narrative88 words

The Malabo Convention has been directly criticised for lacking mechanisms to support its enforcement, and no continental enforcement body exists; NADPA-RAPDP is a cooperation/capacity network without adjudicatory power, so collective redress and private-right-of-action mechanisms remain exclusively national. Within the last 180 days, the AU Commission signed a partnership with Google (17 February 2026) that includes 'policy, governance, and responsible AI frameworks' among its priorities, and the AU Summit's next High-Level AI Policy Dialogue was slated for February 2026 in Addis Ababa, both relevant to continental data/AI governance momentum.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. Confirmeddataprotection.africa — The Malabo Convention has drawn criticism that it lacks important detail and does not provide for mechanisms to support its enforcement, meaning no continental-level regulator powers or maximum-penalty regime exists.observed
  2. ConfirmedAfrican Union — On 17 February 2026, the African Union Commission and Google signed a partnership to advance Africa's sovereign AI and digital capacity, with 'policy, governance, and responsible AI frameworks' listed among its priority areas.observed
  3. ProbableAfrican Union — The next edition of the AU's High-Level Policy Dialogue on AI development and regulation was scheduled to take place during the AU Summit in February 2026 in Addis Ababa, continuing continental momentum on AI/data governance.observed
  4. ProbableNADPA-RAPDP — NADPA-RAPDP operates through a Permanent Secretariat and Board under its 2022-amended constitution as a capacity-building and cooperation network, without direct adjudicatory or enforcement power over member states.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct62.5
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for African bloc
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 18 claim(s) (18 category placement(s)), 21 source(s) in the cumulative register.

Audit trail

Machine checkChallenged on 29 Sep 2026: upheld (3 confirmed against the cited source; 6 could not be checked). An automated, adversarial test run by a second model; no person has assessed the result.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework and algorithmic_biometric_and_surveillance_governance modules had T1/T2 continental-instrument anchors (Malabo Convention treaty text and status list; AU Continental AI Strategy and press releases) directly grounding claims. controller_processor_duties and cross_border_and_adequacy relied on a mix of T2 press releases and a T3 secondary news source for the enforcement-gap criticism claim. lawful_processing_and_special_data and data_subject_rights relied on T2/T3 sources only to evidence absence of granular continental text, not to populate substantive claims (marked Uncertain with absent_field_provenance). sectoral_watch, adtech_and_commercial_privacy, and children_and_vulnerable_groups had no T1-T3 continental-level findings at all and are emitted as explicit red-traffic-light gaps with narrative-embedded search provenance, consistent with this JID's continent-wide treaty-status scope (national-level regimes such as POPIA/NDPA/Kenya DPA are explicitly out of scope per the disambiguation note).

Unresolved questions (4):

  • What is the AU's most current Malabo Convention ratification/status list beyond the 8 July 2024 snapshot cited in this run?
  • Has NADPA-RAPDP's membership grown beyond the 30+ member-DPA figure noted in the injected seed, and is there a more recent constitution/internal-rules revision?
  • Has the AU Data Policy Framework itself been formally adopted as a binding instrument, or does it remain a strategic/advisory framework as of August 2026?
  • Are there country-specific JIDs (South Africa, Nigeria, Kenya, etc.) in the fleet's baseline set that should carry the granular lawful-basis, consent, DSR, and sectoral findings this AFR run explicitly excluded per the disambiguation note?

Escalate to primary-source review: yes