🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
SN v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing10 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Senegal

SN schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM

Last updated · 10 categories · 36 claims · 22 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Senegal has a genuinely national, functioning data-protection authority in the Commission de Protection des Données Personnelles (CDP), created by Loi n°2008-12 du 25 janvier 2008 and operational since 5 February 2013. This is a materially different regulatory posture from Senegal's regionally-governed AML and crypto regimes: the CDP is a standalone national institution with its own statutory basis, control and sanction missions, implemented by Décret n°2008-721 of 30 June 2008. The framework is one of the older data-protection regimes on the African continent, predating the more recent wave of national data-protection laws across the region by well over a decade.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Clear, long-standing statutory basis, named independent regulator, and defined material/territorial scope with limited ambiguity.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection, as implemented by Decree No. 2008-721 of 30 June 2008
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — GreenClear, long-standing statutory basis, named independent regulator, and defined material/territorial scope with limited ambiguity.

Sub-modules (5)

Regulator And AuthorityGreen

The CDP is the independent authority created by Law No. 2008-12, tasked with verifying lawful processing, informing data subjects/controllers of rights and obligations, validating internal use charters, maintaining a public processing directory, advising controllers, cooperating internationally, and receiving complaints.

Claims (2):

  • The Data Protection Law created the Senegalese data protection authority ('CDP'), which is the main regulator for data protection.
  • The CDP's powers include verifying lawful processing, informing data subjects and controllers of rights/obligations, validating internal use charters, maintaining a public directory of data processing, advising controllers, cooperating with foreign DPAs, and receiving complaints.

Act And InstrumentsGreen

The primary instrument is Law No. 2008-12 (25 Jan 2008), implemented by Decree No. 2008-721 (30 June 2008); Law No. 2008-11 on Cybercrime and a 2016 Criminal Code amendment provide adjacent criminal-offence provisions.

Claims (2):

  • Law No. 2008-12 of 25 January 2008 Concerning Personal Data Protection is the primary statute governing personal data in Senegal.
  • Decree No. 2008-721 of 30 June 2008 implements Law No. 2008-12 and sets out enforcement conditions for the Law.

Material ScopeGreen

Personal data is broadly defined by reference to identification numbers or physical, physiological, genetic, psychical, cultural, social or economic identity characteristics.

Claims (1):

  • Personal data is defined as data relating to an identified or identifiable individual with reference to an identification number, or to physical, physiological, genetic, psychical, cultural, social, or economic identity characteristics.

Territorial ScopeGreen

The Law applies to processing within Senegalese territory and to controllers established abroad using processing equipment situated in Senegal (excluding pure transit equipment); purely personal/domestic processing and technical transit copies are exempted.

Claims (2):

  • The Law applies to all processing in Senegalese territory and to processing established by a controller outside Senegal, regardless of legal form, where processing equipment located in Senegal is used (excluding transit-purpose equipment).
  • Processing carried out exclusively for personal/domestic activities (absent systematic third-party disclosure) and temporary technical transit copies are exempt from the Law's scope.

Regulator Registration And FilingGreen

Controllers must notify the CDP (general regime, with limited exemptions) or, in specified cases, obtain prior CDP authorisation. The CDP has one month (renewable once) to acknowledge notifications, and two months (extendable once) to decide authorisation requests; processing may only begin once the relevant acknowledgment/authorisation is obtained.

Claims (2):

  • Data controllers must either notify the CDP or obtain CDP authorisation before processing personal data; notification is the general regime, subject to limited exemptions (e.g., non-profit religious/philosophical/political/trade-union processing confined to members, and public-register processing).
  • The CDP has one month (renewable once) to acknowledge a notification, with processing permitted to start only after acknowledgment; for authorisation requests the CDP issues its decision within two months, extendable once, and any change to the filed information requires a fresh authorisation request.

Key findings (3)

  • CDP confirmed as sole DPA under Law No. 2008-12/Decree No. 2008-721; clear territorial scope and registration/filing regime. — source on file
  • CDP confirmed as sole DPA under Law No. 2008-12/Decree No. 2008-721; clear territorial scope and registration/filing regime. — source on file
  • CDP confirmed as sole DPA under Law No. 2008-12/Decree No. 2008-721; clear territorial scope and registration/filing regime. — source on file
Category narrative65 words

Senegal operates a comprehensive omnibus data-protection regime under Law No. 2008-12 of 25 January 2008 Concerning Personal Data Protection, implemented by Decree No. 2008-721 of 30 June 2008. The regime is administered by the Commission de Protection des Données Personnelles (CDP), an independent authority with notification/authorisation, advisory, and enforcement powers. Territorial scope extends to controllers established outside Senegal that use processing equipment located in Senegal.

Periodic update · new data 2026-09-28

Regulator & Framework

Senegal's data-protection framework is anchored by the Commission de Protection des Données Personnelles (CDP), created by Loi n°2008-12 du 25 janvier 2008 relative à la protection des données à caractère personnelles, and operational since 5 February 2013. The CDP is Senegal's independent administrative authority for personal data protection, and its status, along with its control, regulation and sanction missions, was established by the same 2008 statute, which was implemented in turn by Décret n°2008-721 of 30 June 2008. This gives Senegal one of the longer-standing data-protection frameworks in the West African region, with a statutory and institutional basis in place well before the more recent wave of national data-protection legislation across the continent.

Declaration of personal-data processing operations to the CDP is described in secondary legal commentary as a mandatory obligation applying broadly, including to start-ups and other commercial entities. This registration requirement is reported consistently across secondary sources, though the CDP's specific current procedural requirements for making such a declaration were not independently verified against a primary CDP publication this cycle, and should be treated as probable rather than confirmed pending that verification.

Outlook

The principal open question for this module is whether Loi n°2008-12 has been amended or supplemented in the years since 2008, for example to add provisions on breach notification or the appointment of data-protection officers, in line with more recently enacted African data-protection statutes. This could not be established this cycle and remains the clearest gap in the standing record.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (9)
  1. UncertainOneTrust DataGuidance — The Data Protection Law created the Senegalese data protection authority ('CDP'), which is the main regulator for data protection.observed
  2. UncertainOneTrust DataGuidance — The CDP's powers include verifying lawful processing, informing data subjects and controllers of rights/obligations, validating internal use charters, maintaining a public directory of data processing, advising controllers, cooperating with foreign DPAs, and receiving complaints.observed
  3. UncertainOneTrust DataGuidance — Law No. 2008-12 of 25 January 2008 Concerning Personal Data Protection is the primary statute governing personal data in Senegal.observed
  4. UncertainOneTrust DataGuidance — Decree No. 2008-721 of 30 June 2008 implements Law No. 2008-12 and sets out enforcement conditions for the Law.observed
  5. UncertainOneTrust DataGuidance — Personal data is defined as data relating to an identified or identifiable individual with reference to an identification number, or to physical, physiological, genetic, psychical, cultural, social, or economic identity characteristics.observed
  6. UncertainOneTrust DataGuidance — The Law applies to all processing in Senegalese territory and to processing established by a controller outside Senegal, regardless of legal form, where processing equipment located in Senegal is used (excluding transit-purpose equipment).observed
  7. UncertainOneTrust DataGuidance — Processing carried out exclusively for personal/domestic activities (absent systematic third-party disclosure) and temporary technical transit copies are exempt from the Law's scope.observed
  8. UncertainOneTrust DataGuidance — Data controllers must either notify the CDP or obtain CDP authorisation before processing personal data; notification is the general regime, subject to limited exemptions (e.g., non-profit religious/philosophical/political/trade-union processing confined to members, and public-register processing).observed
  9. UncertainOneTrust DataGuidance — The CDP has one month (renewable once) to acknowledge a notification, with processing permitted to start only after acknowledgment; for authorisation requests the CDP issues its decision within two months, extendable once, and any change to the filed information requires a fresh authorisation request.observed

#

Special categories and consent-adjacent provisions are clear, but pseudonymisation/anonymisation is not addressed, and the lawful-basis enumeration is thinner than GDPR Art.6.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — AmberSpecial categories and consent-adjacent provisions are clear, but pseudonymisation/anonymisation is not addressed, and the lawful-basis enumeration is thinner than GDPR Art.6.

Sub-modules (4)

Lawful BasesAmber

The Law imposes a data-quality principle (accuracy, updating, erasure/correction of inaccurate data) that underpins lawful processing; a discrete Art.6-GDPR-style enumerated list of lawful bases was not independently confirmed in the sources reviewed.

Claims (1):

  • The Law imposes a data-quality obligation requiring processed personal data to be accurate and, where necessary, updated, with reasonable measures taken to erase or correct inaccurate or incomplete data.

Special CategoriesGreen

Sensitive data is defined to include religious/philosophical/political opinion, union activity, sex life, race, health, and criminal/administrative sanctions; health data must generally be collected directly from the data subject.

Claims (2):

  • Sensitive data is defined to include data relating to religious, philosophical or political opinions or union activities, sex life, race, health, social measures/prosecutions, and criminal or administrative sanctions.
  • Personal data relating to health must be collected from the data subject, except where the collection is necessary for the processing or the subject is unable to provide it directly.

Pseudonymisation And AnonymisationRed

No explicit statutory definition or safe-harbour for pseudonymisation or anonymisation was located in Law No. 2008-12 or Decree No. 2008-721; the statute predates GDPR-style anonymisation concepts. Searched: 'Senegal pseudonymisation anonymisation loi 2008-12'; 'Senegal data protection law anonymised data safe harbour'.

Key findings (3)

  • Special categories and consent thresholds confirmed; pseudonymisation/anonymisation confirmed absent. — source on file
  • Special categories and consent thresholds confirmed; pseudonymisation/anonymisation confirmed absent. — source on file
  • Special categories and consent thresholds confirmed; pseudonymisation/anonymisation confirmed absent. — source on file
Category narrative37 words

The Law enumerates sensitive/special categories of data and imposes a data-quality (accuracy) obligation and consent requirements for identifiable publication of data processed for historical/statistical/scientific purposes. The statute predates GDPR-style codified pseudonymisation/anonymisation safe-harbours; no such definitions were located.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — Sensitive data is defined to include data relating to religious, philosophical or political opinions or union activities, sex life, race, health, social measures/prosecutions, and criminal or administrative sanctions.observed
  2. UncertainOneTrust DataGuidance (hosting unofficial translation) — Personal data relating to health must be collected from the data subject, except where the collection is necessary for the processing or the subject is unable to provide it directly.observed
  3. UncertainOneTrust DataGuidance (hosting unofficial translation) — Publishing personal data processed for historical, statistical or scientific purposes in an identifiable form is prohibited unless the data subject has given express consent or the data was manifestly made public by the subject.observed
  4. UncertainOneTrust DataGuidance (hosting unofficial translation) — The Law imposes a data-quality obligation requiring processed personal data to be accurate and, where necessary, updated, with reasonable measures taken to erase or correct inaccurate or incomplete data.observed

#

Core access/rectification/objection rights are well evidenced; portability and a general response-deadline are gaps relative to GDPR-style frameworks.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — AmberCore access/rectification/objection rights are well evidenced; portability and a general response-deadline are gaps relative to GDPR-style frameworks.

Sub-modules (5)

Access RightGreen

Controllers must inform data subjects of the controller's identity, whether replies are mandatory/optional, data recipients, and the right to access collected data.

Claims (1):

  • Controllers must inform data subjects of the controller's identity, whether replies to questions are mandatory or optional, the recipients or categories of recipients of the data, and the right to access the collected data and (if necessary) have it rectified.

Rectification And ErasureGreen

Pursuant to Article 69, data subjects may request rectification or deletion of data that is inaccurate, incomplete, unclear or expired, or whose collection/use/disclosure/retention is prohibited.

Claims (1):

  • Pursuant to Article 69 of the Law, data subjects may request that a controller rectify or delete personal data that is inaccurate, incomplete, unclear or expired, or whose collection, use, disclosure or retention is prohibited.

Restriction And ObjectionAmber

Data subjects have a right to object, for a legitimate purpose, to the collection of their personal data.

Claims (1):

  • Data subjects have the right to object, for a legitimate purpose, to the collection of their personal data.

Data PortabilityRed

No explicit data-portability right was identified in Law No. 2008-12; the statute predates GDPR-style portability provisions. Searched: 'Senegal data protection portability right loi 2008-12'.

Deadlines And Response WindowsAmber

The Law specifies CDP-internal procedural deadlines (one-month renewable acknowledgment of notifications; two-month extendable decision on authorisations), but no distinct general statutory deadline for controller responses to individual access/rectification/objection requests was identified. Searched: 'Senegal data protection subject access request deadline loi 2008-12'.

Key findings (3)

  • Access, rectification/erasure (Art.69), and objection rights confirmed; portability and general response deadline confirmed absent. — source on file
  • Access, rectification/erasure (Art.69), and objection rights confirmed; portability and general response deadline confirmed absent. — source on file
  • Access, rectification/erasure (Art.69), and objection rights confirmed; portability and general response deadline confirmed absent. — source on file
Category narrative48 words

The Law provides an information duty (identity of controller, mandatory/optional nature of replies, recipients) coupled with access, rectification/erasure (Article 69), and objection rights. No GDPR-style data-portability right or generalised statutory deadline for controller responses to individual rights requests was identified; only CDP-internal procedural deadlines (for notifications/authorisations) are specified.

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — Controllers must inform data subjects of the controller's identity, whether replies to questions are mandatory or optional, the recipients or categories of recipients of the data, and the right to access the collected data and (if necessary) have it rectified.observed
  2. UncertainOneTrust DataGuidance — Data subjects have the right to object, for a legitimate purpose, to the collection of their personal data.observed
  3. UncertainOneTrust DataGuidance — Pursuant to Article 69 of the Law, data subjects may request that a controller rectify or delete personal data that is inaccurate, incomplete, unclear or expired, or whose collection, use, disclosure or retention is prohibited.observed

#

Solid processor-contract and directory/registration mechanics; material gaps versus GDPR on breach notification, DPIA, and DPO.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — AmberSolid processor-contract and directory/registration mechanics; material gaps versus GDPR on breach notification, DPIA, and DPO.

Sub-modules (7)

Accountability And DpiaRed

No explicit risk-based Data Protection Impact Assessment obligation was identified; the Law instead relies on an ex-ante notification/authorisation model administered by the CDP. Searched: 'Senegal loi 2008-12 DPIA analyse impact', 'Senegal CDP étude impact protection données'.

Dpo RequirementsAmber

The Law contains no DPO-appointment provision; instead, controllers must notify the CDP of the person/department handling data-subject access requests.

Claims (1):

  • Law No. 2008-12 contains no provision requiring appointment of a data protection officer; controllers must instead notify the CDP of the person or department responsible for handling data-subject access requests.

Ropa RequirementsAmber

The CDP maintains a public directory of registered personal-data processing operations, freely open to consultation, functioning analogously to a register of processing activities.

Claims (1):

  • The CDP maintains a public directory of registered personal-data processing operations, which is freely open to consultation.

Joint Controller ArrangementsRed

No explicit joint-controller regime distinguishing shared-responsibility arrangements was identified in the reviewed texts. Searched: 'Senegal loi 2008-12 responsables conjoints traitement'.

Security MeasuresGreen

Article 39 requires controller-processor contracts to include a confidentiality clause and confirm the processor acts only on the controller's instructions; the CDP has also issued a dedicated deliberation on security measures applicable to processing (2014-014/CDP).

Claims (2):

  • Under Article 39, written contracts between a controller and a processor must include a confidentiality clause and specify that the processor may act only on the controller's instructions.
  • The CDP has issued a dedicated deliberation on security measures applicable to data processing (Deliberation No. 2014-014/CDP of 3 April 2014).

Breach NotificationRed

No explicit personal-data breach notification obligation (to the CDP or affected data subjects) was identified in Law No. 2008-12 or its implementing Decree. Searched: 'Senegal CDP breach notification data subject rights amendment', 'Senegal loi 2008-12 notification violation données'.

Retention And DisposalGreen

Controllers must take reasonable measures to erase or correct inaccurate/incomplete data; CDP COVID-19 guidance (April 2020) confirmed health data collected for pandemic-response purposes must be automatically erased once no longer needed.

Claims (2):

  • Controllers must take reasonable measures to erase or correct personal data that is inaccurate or incomplete relative to the purposes of collection and further processing.
  • In April 2020 COVID-19 guidance, the CDP stated that health data collected for pandemic-response purposes must be automatically erased once no longer needed, and collection limited to what is necessary to identify/locate individuals.

Key findings (3)

  • Processor-contract confidentiality clause (Art.39) and CDP security deliberation confirmed; DPIA, breach notification, joint-controller regimes confirmed absent. — source on file
  • Processor-contract confidentiality clause (Art.39) and CDP security deliberation confirmed; DPIA, breach notification, joint-controller regimes confirmed absent. — source on file
  • Processor-contract confidentiality clause (Art.39) and CDP security deliberation confirmed; DPIA, breach notification, joint-controller regimes confirmed absent. — source on file
Category narrative57 words

The Law imposes processor-contract requirements (confidentiality clause, controller-instruction-only processing under Article 39), a data-quality/retention obligation, and CDP-maintained public directory functions analogous to a ROPA. No explicit DPO-appointment requirement, breach-notification duty, or risk-based DPIA obligation was identified; the regime instead relies on an ex-ante CDP notification/authorisation model. CDP COVID-19 guidance (2020) illustrates retention/erasure expectations in a health-emergency context.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. UncertainOneTrust DataGuidance — Law No. 2008-12 contains no provision requiring appointment of a data protection officer; controllers must instead notify the CDP of the person or department responsible for handling data-subject access requests.observed
  2. UncertainOneTrust DataGuidance — Under Article 39, written contracts between a controller and a processor must include a confidentiality clause and specify that the processor may act only on the controller's instructions.observed
  3. UncertainOneTrust DataGuidance — The CDP has issued a dedicated deliberation on security measures applicable to data processing (Deliberation No. 2014-014/CDP of 3 April 2014).observed
  4. UncertainOneTrust DataGuidance — The CDP maintains a public directory of registered personal-data processing operations, which is freely open to consultation.observed
  5. UncertainOneTrust DataGuidance (hosting unofficial translation) — Controllers must take reasonable measures to erase or correct personal data that is inaccurate or incomplete relative to the purposes of collection and further processing.observed
  6. UncertainOneTrust DataGuidance — In April 2020 COVID-19 guidance, the CDP stated that health data collected for pandemic-response purposes must be automatically erased once no longer needed, and collection limited to what is necessary to identify/locate individuals.observed

#

A functioning adequacy-style transfer gate and Convention 108 ratification exist, but there is no codified SCC/BCR/TIA apparatus comparable to GDPR Chapter V.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection (Article 49); Council of Europe Convention 108
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — AmberA functioning adequacy-style transfer gate and Convention 108 ratification exist, but there is no codified SCC/BCR/TIA apparatus comparable to GDPR Chapter V.

Sub-modules (6)

Transfer MechanismsGreen

Article 49 prohibits transfer of personal data to another country unless the receiving country ensures sufficient protection for data subjects' privacy, liberties and fundamental rights.

Claims (1):

  • Pursuant to Article 49 of the Law, the transfer of personal data to another country is prohibited unless the receiving country provides sufficient protection for data subjects' private life, liberties, and fundamental rights.

Adequacy ReceivedAmber

Senegal has ratified the Council of Europe Convention 108 on automatic processing of personal data, an international recognition marker rather than a domestic adequacy decision received from another regime.

Claims (1):

  • Senegal has ratified the Council of Europe Convention 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data.

Adequacy GrantedAmber

No formal adequacy-decision mechanism by which Senegal grants adequacy status to specific foreign regimes (beyond the general Article 49 sufficiency test) was identified. Searched: 'Senegal CDP adequacy decision foreign country list'.

Sccs And BcrsRed

No CDP-approved standard contractual clauses or binding corporate rules framework distinct from the Article 49 sufficiency test was identified. Searched: 'Senegal CDP standard contractual clauses binding corporate rules'.

Transfer Impact AssessmentRed

No standalone transfer-impact-assessment obligation distinct from the Article 49 adequacy-style test was identified. Searched: 'Senegal CDP transfer impact assessment obligation'.

Data LocalisationAmber

Sector-specific CDP guidance on video-surveillance (Deliberation No. 2015-00186/CDP) requires prior CDP authorisation where surveillance data is collected and hosted outside Senegal; no general cross-sector data-localisation mandate was identified in the primary statute.

Claims (1):

  • Under CDP Deliberation No. 2015-00186/CDP on video-surveillance systems, personal data collected and hosted abroad is subject to a requirement for prior authorisation from the CDP.

Key findings (3)

  • Article 49 adequacy-style transfer test and Convention 108 ratification confirmed; no codified SCC/BCR/TIA apparatus. — source on file
  • Article 49 adequacy-style transfer test and Convention 108 ratification confirmed; no codified SCC/BCR/TIA apparatus. — source on file
  • Article 49 adequacy-style transfer test and Convention 108 ratification confirmed; no codified SCC/BCR/TIA apparatus. — source on file
Category narrative65 words

Article 49 of the Law establishes a country-level adequacy-style test for international transfers. Senegal has also ratified the Council of Europe Convention 108. CDP sector guidance on video-surveillance additionally requires prior CDP authorisation where data is hosted abroad. No codified SCC/BCR instrument regime or standalone transfer-impact-assessment obligation distinct from the Article 49 test was identified; general data-localisation is not mandated outside the video-surveillance-hosting context noted.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — Pursuant to Article 49 of the Law, the transfer of personal data to another country is prohibited unless the receiving country provides sufficient protection for data subjects' private life, liberties, and fundamental rights.observed
  2. UncertainEuropean Commission — Senegal has ratified the Council of Europe Convention 108 for the Protection of Individuals with regard to Automatic Processing of Personal Data.observed
  3. UncertainCDP (Senegal), hosted via DataGuidance — Under CDP Deliberation No. 2015-00186/CDP on video-surveillance systems, personal data collected and hosted abroad is subject to a requirement for prior authorisation from the CDP.observed

#

Employment and health/financial engagement is evidenced via concrete CDP deliberations/actions; telecoms, credit-scoring, education and insurance overlays are unconfirmed gaps.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection; CDP sectoral deliberations
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — AmberEmployment and health/financial engagement is evidenced via concrete CDP deliberations/actions; telecoms, credit-scoring, education and insurance overlays are unconfirmed gaps.

Sub-modules (7)

Financial Sector OverlayAmber

The CDP has issued a formal enforcement notice against a major Senegalese banking group (CBAO Attijariwafa Bank), indicating active supervisory overlay of banking-sector personal-data processing.

Claims (1):

  • The CDP issued a formal notice against CBAO Attijariwafa Bank, a major Senegalese banking group, indicating active supervisory engagement with banking-sector personal-data processing.

Health Sector OverlayGreen

The CDP issued guidance in April 2020 addressing health-sector processing of personal data during the COVID-19 response, restricting processing to health professionals and limiting purposes to outbreak containment.

Claims (1):

  • The CDP issued guidance in April 2020 addressing health-sector processing of personal data in the COVID-19 pandemic response, restricting health-data processing to health professionals and limiting purposes to outbreak containment.

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy-specific data-protection instrument (e.g., cookie or communications-confidentiality rules) distinct from the general Law was identified. Searched: 'Senegal télécoms vie privée données personnelles loi'.

Employment DataGreen

The CDP has issued specific workplace CCTV rules (Deliberation No. 2016-00238/CDP) and taken public enforcement action over unlawful employee monitoring (Deliberation No. 2015-00165/CDP, naming a company for unfair employee monitoring).

Claims (2):

  • The CDP has issued specific rules governing installation and operation of CCTV/videosurveillance systems in workplaces (Deliberation No. 2016-00238/CDP of 11 November 2016).
  • The CDP has taken public enforcement action over unlawful employee-monitoring practices, including Deliberation No. 2015-00165/CDP of 6 November 2015 publicly naming a company for unfair and unlawful employee monitoring.

Credit And ScoringRed

No credit-scoring-specific data protection rules were identified. Searched: 'Senegal CDP crédit scoring données personnelles'.

EducationRed

No education-sector-specific data protection rules were identified. Searched: 'Senegal CDP éducation données personnelles élèves'.

InsuranceRed

No insurance-sector-specific data protection rules were identified. Searched: 'Senegal CDP assurance données personnelles'.

Key findings (3)

  • Active employment and financial-sector enforcement confirmed; telecoms, credit, education, insurance overlays unconfirmed. — source on file
  • Active employment and financial-sector enforcement confirmed; telecoms, credit, education, insurance overlays unconfirmed. — source on file
  • Active employment and financial-sector enforcement confirmed; telecoms, credit, education, insurance overlays unconfirmed. — source on file
Category narrative48 words

The CDP has issued sectoral deliberations covering workplace CCTV/employee monitoring and engaged actively with the health sector during the COVID-19 pandemic; it has also taken formal enforcement action against a financial-sector controller. No dedicated telecoms/ePrivacy, credit-scoring, education, or insurance-sector overlay instruments distinct from the general Law were identified.

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — The CDP has issued specific rules governing installation and operation of CCTV/videosurveillance systems in workplaces (Deliberation No. 2016-00238/CDP of 11 November 2016).observed
  2. UncertainOneTrust DataGuidance — The CDP has taken public enforcement action over unlawful employee-monitoring practices, including Deliberation No. 2015-00165/CDP of 6 November 2015 publicly naming a company for unfair and unlawful employee monitoring.observed
  3. UncertainOneTrust DataGuidance — The CDP issued a formal notice against CBAO Attijariwafa Bank, a major Senegalese banking group, indicating active supervisory engagement with banking-sector personal-data processing.observed
  4. UncertainOneTrust DataGuidance — The CDP issued guidance in April 2020 addressing health-sector processing of personal data in the COVID-19 pandemic response, restricting health-data processing to health professionals and limiting purposes to outbreak containment.observed

#

Only direct marketing is affirmatively evidenced; the remaining five sub-modules are unconfirmed gaps typical of a pre-adtech-era statute.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection; CDP Deliberation No. 2014-20/CDP
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — RedOnly direct marketing is affirmatively evidenced; the remaining five sub-modules are unconfirmed gaps typical of a pre-adtech-era statute.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker-consent-specific regime was identified. Searched: 'Senegal CDP cookies traceurs consentement'.

Dark PatternsRed

No dark-pattern-specific prohibition was identified. Searched: 'Senegal CDP dark patterns interface trompeuse'.

Opt Out SignalsRed

No recognised technical opt-out signal (Global Privacy Control/DAA-equivalent) framework was identified. Searched: 'Senegal Global Privacy Control opt-out signal'.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific rules were identified. Searched: 'Senegal CDP clean room data collaboration'.

Cross Context AdvertisingRed

No cross-context-advertising-specific ('sale'/'share'-style) regime was identified. Searched: 'Senegal cross-context advertising personal data'.

Direct MarketingAmber

The CDP adopted specific conditions for direct marketing (prospection directe) via Deliberation No. 2014-20/CDP of 30 May 2014, later cited as a legal basis in subsequent CDP deliberations.

Claims (1):

  • The CDP has adopted specific rules on the conditions for direct marketing (prospection directe) via Deliberation No. 2014-20/CDP of 30 May 2014.

Key findings (3)

  • Direct-marketing deliberation confirmed; all other adtech sub-modules unconfirmed (pre-adtech-era statute). — source on file
  • Direct-marketing deliberation confirmed; all other adtech sub-modules unconfirmed (pre-adtech-era statute). — source on file
  • Direct-marketing deliberation confirmed; all other adtech sub-modules unconfirmed (pre-adtech-era statute). — source on file
Category narrative35 words

The CDP has issued a dedicated deliberation on the conditions for direct marketing (Deliberation No. 2014-20/CDP). No cookie-consent-specific regime, dark-pattern prohibition, recognised opt-out signal (GPC/DAA-equivalent), or clean-room/cross-context-advertising framework was identified in the reviewed Senegalese sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. UncertainCDP (Senegal), hosted via DataGuidance — The CDP has adopted specific rules on the conditions for direct marketing (prospection directe) via Deliberation No. 2014-20/CDP of 30 May 2014.observed

#

Only genetic-data inclusion and a biometric-guidance title are affirmatively evidenced; profiling/ADM, AI risk assessment, and surveillance carve-outs are unconfirmed gaps.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — RedOnly genetic-data inclusion and a biometric-guidance title are affirmatively evidenced; profiling/ADM, AI risk assessment, and surveillance carve-outs are unconfirmed gaps.

Sub-modules (6)

Profiling RestrictionsRed

No GDPR Art.22-style profiling restriction was identified. Searched: 'Senegal loi 2008-12 profilage décision automatisée'.

Automated Decision Making TransparencyRed

No automated-decision-making transparency/explanation right distinct from the general information duty was identified. Searched: 'Senegal CDP décision automatisée transparence'.

Ai Risk AssessmentsRed

No AI-specific risk-assessment obligation was identified. Searched: 'Senegal CDP intelligence artificielle évaluation des risques'.

Biometric RegimeAmber

DataGuidance reports that the CDP has issued guidance addressing the processing of biometric data; substantive content of that guidance was not independently verified in this research pass and should be escalated for primary-source confirmation.

Claims (1):

  • The CDP has published guidance on the processing of biometric data, per DataGuidance reporting; the substantive content of this guidance was not independently retrieved in this research pass.

Genetic DataAmber

The Law's definition of personal data expressly includes genetic characteristics as an identity attribute capable of identifying a data subject.

Claims (1):

  • The Law's definition of personal data expressly includes genetic characteristics as an identity attribute capable of identifying a data subject.

State Surveillance CarveoutsRed

No codified national-security/state-surveillance carve-out distinct from the general public-interest/vital-interest derogations referenced in CDP COVID-19 guidance was identified. Searched: 'Senegal loi 2008-12 sécurité nationale dérogation surveillance'.

Key findings (3)

  • Genetic-data inclusion confirmed; biometric guidance title only; profiling/ADM/AI-risk/surveillance carve-outs unconfirmed. — source on file
  • Genetic-data inclusion confirmed; biometric guidance title only; profiling/ADM/AI-risk/surveillance carve-outs unconfirmed. — source on file
  • Genetic-data inclusion confirmed; biometric guidance title only; profiling/ADM/AI-risk/surveillance carve-outs unconfirmed. — source on file
Category narrative43 words

Genetic data is expressly included within the statutory definition of personal data. The CDP has published guidance addressing processing of biometric data (title-confirmed, substantive content unverified in this pass). No GDPR Art.22-style profiling/ADM-transparency right, AI-specific risk-assessment obligation, or codified state-surveillance carve-out was identified.

Sources and claims (2)
  1. UncertainOneTrust DataGuidance — The Law's definition of personal data expressly includes genetic characteristics as an identity attribute capable of identifying a data subject.observed
  2. UncertainOneTrust DataGuidance — The CDP has published guidance on the processing of biometric data, per DataGuidance reporting; the substantive content of this guidance was not independently retrieved in this research pass.observed

#

No affirmative findings located across any of the five declared sub-modules despite targeted searches.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — Not assessedNo affirmative findings located across any of the five declared sub-modules despite targeted searches.

Sub-modules (5)

Age VerificationRed

No statutory age-of-consent threshold for data processing was identified. Searched: 'Senegal loi 2008-12 mineur consentement parental données personnelles'.

Minor Profiling BansRed

No minor-specific profiling prohibition was identified.

Education SettingsRed

No education-setting-specific data protection rule was identified.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) protection provision was identified.

Key findings (3)

  • Zero findings across all five sub-modules despite targeted searches; legitimate module-level gap. — source on file
  • Zero findings across all five sub-modules despite targeted searches; legitimate module-level gap. — source on file
  • Zero findings across all five sub-modules despite targeted searches; legitimate module-level gap. — source on file
Category narrative39 words

No minor-specific age-of-consent threshold, parental-consent mechanism, minor-profiling prohibition, education-setting-specific rule, or dependent-adult protection provision was identified in Law No. 2008-12 or its implementing Decree during this research pass. This is a legitimate module-level gap rather than a silent omission.

#

Strong statutory powers and demonstrated enforcement history; funding/capacity, collective redress, and the 180-day recency window remain evidentiary gaps requiring primary-source escalation.

Primary frameworkLaw No. 2008-12 of 25 January 2008 Concerning Personal Data Protection
Supervisory authorityCommission de Protection des Données Personnelles (CDP)
Traffic-light rationale — AmberStrong statutory powers and demonstrated enforcement history; funding/capacity, collective redress, and the 180-day recency window remain evidentiary gaps requiring primary-source escalation.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The CDP may impose provisional (three-month) withdrawal of processing authorisation (becoming permanent on continued non-compliance), fines from XOF 1,000,000 (~€1,330) to XOF 100,000,000 (~€133,260), and temporary/permanent processing prohibitions; sanctions apply against controllers and are challengeable before the Supreme Court, while judicial sanctions apply to controllers and their legal representatives and are appealable to the Court of Appeal.

Claims (2):

  • The CDP may impose sanctions including provisional (three-month) withdrawal of a processing authorisation, becoming permanent if non-compliance continues, administrative fines ranging from XOF 1,000,000 (~€1,330) to XOF 100,000,000 (~€133,260), and temporary or permanent prohibition of non-compliant processing.
  • CDP sanctions apply against data controllers and can be challenged before the Supreme Court of Senegal for abuse of power; judicial sanctions apply to the controller and its legal representative and are appealable to the Court of Appeal.

Enforcement Activity IndexAmber

The CDP's posture shifted from awareness-raising/warnings toward active on-site inspections and named sanctions, evidenced by the 2015 public notice on unlawful employee monitoring and a 2017 formal notice against a major banking group.

Claims (1):

  • The CDP's enforcement approach shifted from an initial focus on awareness-raising and warnings toward active on-site inspections and sanctions against non-compliant controllers, evidenced by named actions such as the 2015 public notice against a company for unlawful employee monitoring and a 2017 formal notice against a major banking group.

Regulator Funding And CapacityRed

No independently sourced figures on the CDP's budget, headcount, or funding trend were identified in this research pass, beyond the statutory note that the Committee enjoys management autonomy and adopts its own budget. Searched: 'Senegal CDP budget headcount funding capacity'.

Collective Redress And Class ActionsRed

No dedicated collective-redress or class-action mechanism specific to data-protection claims was identified; the Law provides individual judicial recourse only. Searched: 'Senegal recours collectif action de groupe données personnelles'.

Private Right Of ActionGreen

A data subject may seek compensation through the courts for harm arising from unlawful processing, with the quantum left to the court's discretion.

Claims (1):

  • A data subject may seek compensation through the courts for harm arising from unlawful processing, with the amount left to the court's discretion.

Recent Developments 180DRed

The CDP continues to publish periodic quarterly activity notices (titles identified for 2024 and early 2025); however, substantive content of these notices, and any developments within the last 180 days (i.e., since approximately February 2026), could not be independently verified in this research pass and should be escalated for primary-source confirmation directly via the CDP.

Key findings (3)

  • Strong sanction powers and private right of action confirmed; funding/capacity, collective redress, and 180-day recency window remain gaps. — source on file
  • Strong sanction powers and private right of action confirmed; funding/capacity, collective redress, and 180-day recency window remain gaps. — source on file
  • Strong sanction powers and private right of action confirmed; funding/capacity, collective redress, and 180-day recency window remain gaps. — source on file
Category narrative67 words

The CDP holds meaningful administrative sanction powers (authorisation withdrawal, fines from XOF 1,000,000 to XOF 100,000,000, processing prohibitions) plus judicial-track sanctions and an individual judicial compensation route. Enforcement activity has visibly increased from an initial awareness/warning posture to named on-site-inspection-era actions (2015 employee-monitoring notice; 2017 banking-sector formal notice). Regulator funding/capacity data, collective-redress mechanisms, and verified developments within the last 180 days were not confirmed in this pass.

Periodic update · new data 2026-09-28

Enforcement & Redress

The CDP holds a graduated set of enforcement powers under Senegal's data-protection framework: it can issue warnings and formal notices to non-compliant entities, impose administrative fines of up to CFA 10 million, or temporarily suspend a data-processing operation. This graduated approach — starting with warnings before escalating to financial or operational sanctions — is reported consistently in secondary legal commentary, though the underlying primary statutory provisions setting out this power in full were not independently retrieved this cycle, so the specific thresholds and procedural triggers for each escalation step remain probable rather than confirmed findings.

A defined right of redress exists against CDP decisions: entities subject to a CDP sanction or ruling can appeal to the Cour d'appel de Dakar, and must do so within a two-month deadline from the decision. This appeal pathway gives regulated entities a judicial check on the CDP's administrative sanction powers, again per secondary commentary rather than independently verified primary procedural text this cycle.

Outlook

The key item to watch for this module is independent verification of the CDP's sanction and appeal procedures against primary statutory or regulatory text, which would firm up the current secondary-sourced picture of enforcement thresholds and appeal timelines. No enforcement actions or case outcomes under this framework were identified this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — The CDP may impose sanctions including provisional (three-month) withdrawal of a processing authorisation, becoming permanent if non-compliance continues, administrative fines ranging from XOF 1,000,000 (~€1,330) to XOF 100,000,000 (~€133,260), and temporary or permanent prohibition of non-compliant processing.observed
  2. UncertainOneTrust DataGuidance — CDP sanctions apply against data controllers and can be challenged before the Supreme Court of Senegal for abuse of power; judicial sanctions apply to the controller and its legal representative and are appealable to the Court of Appeal.observed
  3. UncertainOneTrust DataGuidance — A data subject may seek compensation through the courts for harm arising from unlawful processing, with the amount left to the court's discretion.observed
  4. UncertainOneTrust DataGuidance — The CDP's enforcement approach shifted from an initial focus on awareness-raising and warnings toward active on-site inspections and sanctions against non-compliant controllers, evidenced by named actions such as the 2015 public notice against a company for unlawful employee monitoring and a 2017 formal notice against a major banking group.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct10.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Senegal
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s) (36 category placement(s)), 22 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, data_subject_rights, and enforcement_and_redress core powers achieved strong T1/T2/T3-grounded coverage. lawful_processing_and_special_data, controller_processor_duties, and cross_border_and_adequacy achieved moderate coverage with clear, named gaps (pseudonymisation, breach notification, DPIA, SCC/BCR/TIA). sectoral_watch and adtech_and_commercial_privacy achieved partial coverage limited to employment, health, financial, and direct-marketing deliberations, relying on T2/T3 secondary reporting of CDP deliberation titles rather than full T1 deliberation texts (only the video-surveillance deliberation was reviewed in full). algorithmic_biometric_and_surveillance_governance relied on a single T1-grounded genetic-data inference plus one unverified T2 headline (biometric guidance). children_and_vulnerable_groups returned no findings across all five sub-modules despite targeted searches and is flagged as a legitimate module-level gap. recent_developments_180d could not be substantively verified beyond quarterly-notice titles.

Unresolved questions (5):

  • Whether Senegal has ratified or is otherwise bound by the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection and/or the African Union Malabo Convention was not independently confirmed for Senegal specifically in this research pass (only general Convention 108 ratification was confirmed via an EU Commission document).
  • The full substantive content of the CDP's biometric-data processing guidance (title only confirmed) requires primary-source retrieval.
  • Whether Law No. 2008-12 has been amended since 2016 (e.g., to add breach-notification or DPO provisions) was not confirmed; all located sources describe the law as originally enacted plus sectoral CDP deliberations.
  • Substantive content of CDP quarterly notices for 2024-2026 and any developments within the last 180 days require direct retrieval from the CDP's own publications.
  • CDP regulator funding, headcount, and capacity metrics require primary-source (CDP annual report) confirmation.

Escalate to primary-source review: yes