#
Clear, long-standing statutory basis, named independent regulator, and defined material/territorial scope with limited ambiguity.
Sub-modules (5)
Regulator And AuthorityGreen
The CDP is the independent authority created by Law No. 2008-12, tasked with verifying lawful processing, informing data subjects/controllers of rights and obligations, validating internal use charters, maintaining a public processing directory, advising controllers, cooperating internationally, and receiving complaints.
Claims (2):
- The Data Protection Law created the Senegalese data protection authority ('CDP'), which is the main regulator for data protection.
- The CDP's powers include verifying lawful processing, informing data subjects and controllers of rights/obligations, validating internal use charters, maintaining a public directory of data processing, advising controllers, cooperating with foreign DPAs, and receiving complaints.
Act And InstrumentsGreen
The primary instrument is Law No. 2008-12 (25 Jan 2008), implemented by Decree No. 2008-721 (30 June 2008); Law No. 2008-11 on Cybercrime and a 2016 Criminal Code amendment provide adjacent criminal-offence provisions.
Claims (2):
- Law No. 2008-12 of 25 January 2008 Concerning Personal Data Protection is the primary statute governing personal data in Senegal.
- Decree No. 2008-721 of 30 June 2008 implements Law No. 2008-12 and sets out enforcement conditions for the Law.
Material ScopeGreen
Personal data is broadly defined by reference to identification numbers or physical, physiological, genetic, psychical, cultural, social or economic identity characteristics.
Claims (1):
- Personal data is defined as data relating to an identified or identifiable individual with reference to an identification number, or to physical, physiological, genetic, psychical, cultural, social, or economic identity characteristics.
Territorial ScopeGreen
The Law applies to processing within Senegalese territory and to controllers established abroad using processing equipment situated in Senegal (excluding pure transit equipment); purely personal/domestic processing and technical transit copies are exempted.
Claims (2):
- The Law applies to all processing in Senegalese territory and to processing established by a controller outside Senegal, regardless of legal form, where processing equipment located in Senegal is used (excluding transit-purpose equipment).
- Processing carried out exclusively for personal/domestic activities (absent systematic third-party disclosure) and temporary technical transit copies are exempt from the Law's scope.
Regulator Registration And FilingGreen
Controllers must notify the CDP (general regime, with limited exemptions) or, in specified cases, obtain prior CDP authorisation. The CDP has one month (renewable once) to acknowledge notifications, and two months (extendable once) to decide authorisation requests; processing may only begin once the relevant acknowledgment/authorisation is obtained.
Claims (2):
- Data controllers must either notify the CDP or obtain CDP authorisation before processing personal data; notification is the general regime, subject to limited exemptions (e.g., non-profit religious/philosophical/political/trade-union processing confined to members, and public-register processing).
- The CDP has one month (renewable once) to acknowledge a notification, with processing permitted to start only after acknowledgment; for authorisation requests the CDP issues its decision within two months, extendable once, and any change to the filed information requires a fresh authorisation request.
Key findings (3)
- CDP confirmed as sole DPA under Law No. 2008-12/Decree No. 2008-721; clear territorial scope and registration/filing regime. — source on file
- CDP confirmed as sole DPA under Law No. 2008-12/Decree No. 2008-721; clear territorial scope and registration/filing regime. — source on file
- CDP confirmed as sole DPA under Law No. 2008-12/Decree No. 2008-721; clear territorial scope and registration/filing regime. — source on file
Regulator & Framework
Senegal's data-protection framework is anchored by the Commission de Protection des Données Personnelles (CDP), created by Loi n°2008-12 du 25 janvier 2008 relative à la protection des données à caractère personnelles, and operational since 5 February 2013. The CDP is Senegal's independent administrative authority for personal data protection, and its status, along with its control, regulation and sanction missions, was established by the same 2008 statute, which was implemented in turn by Décret n°2008-721 of 30 June 2008. This gives Senegal one of the longer-standing data-protection frameworks in the West African region, with a statutory and institutional basis in place well before the more recent wave of national data-protection legislation across the continent.
Declaration of personal-data processing operations to the CDP is described in secondary legal commentary as a mandatory obligation applying broadly, including to start-ups and other commercial entities. This registration requirement is reported consistently across secondary sources, though the CDP's specific current procedural requirements for making such a declaration were not independently verified against a primary CDP publication this cycle, and should be treated as probable rather than confirmed pending that verification.
Outlook
The principal open question for this module is whether Loi n°2008-12 has been amended or supplemented in the years since 2008, for example to add provisions on breach notification or the appointment of data-protection officers, in line with more recently enacted African data-protection statutes. This could not be established this cycle and remains the clearest gap in the standing record.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (9)
- UncertainOneTrust DataGuidance — The Data Protection Law created the Senegalese data protection authority ('CDP'), which is the main regulator for data protection.observed
- UncertainOneTrust DataGuidance — The CDP's powers include verifying lawful processing, informing data subjects and controllers of rights/obligations, validating internal use charters, maintaining a public directory of data processing, advising controllers, cooperating with foreign DPAs, and receiving complaints.observed
- UncertainOneTrust DataGuidance — Law No. 2008-12 of 25 January 2008 Concerning Personal Data Protection is the primary statute governing personal data in Senegal.observed
- UncertainOneTrust DataGuidance — Decree No. 2008-721 of 30 June 2008 implements Law No. 2008-12 and sets out enforcement conditions for the Law.observed
- UncertainOneTrust DataGuidance — Personal data is defined as data relating to an identified or identifiable individual with reference to an identification number, or to physical, physiological, genetic, psychical, cultural, social, or economic identity characteristics.observed
- UncertainOneTrust DataGuidance — The Law applies to all processing in Senegalese territory and to processing established by a controller outside Senegal, regardless of legal form, where processing equipment located in Senegal is used (excluding transit-purpose equipment).observed
- UncertainOneTrust DataGuidance — Processing carried out exclusively for personal/domestic activities (absent systematic third-party disclosure) and temporary technical transit copies are exempt from the Law's scope.observed
- UncertainOneTrust DataGuidance — Data controllers must either notify the CDP or obtain CDP authorisation before processing personal data; notification is the general regime, subject to limited exemptions (e.g., non-profit religious/philosophical/political/trade-union processing confined to members, and public-register processing).observed
- UncertainOneTrust DataGuidance — The CDP has one month (renewable once) to acknowledge a notification, with processing permitted to start only after acknowledgment; for authorisation requests the CDP issues its decision within two months, extendable once, and any change to the filed information requires a fresh authorisation request.observed