Key takeaway

Africa does not have one uniform data-breach rule. Notification deadlines, risk thresholds and complaint procedures differ substantially by country.

If Your Personal Data Leaks, Must the Company Tell You? We Compared the Rules in Six African Countries

TechView Africa compared data-breach rules in Nigeria, Kenya, South Africa, Ghana, Rwanda and Uganda. Whether a company must tell you and how quickly, depends heavily on where you are.

Nigeria, Kenya, South Africa, Ghana and Rwanda contain circumstances requiring affected people to be notified directly. Uganda takes a different approach: the regulator is notified first and decides whether affected individuals should also be told.

When a company says it has suffered a “security incident,” one of the first questions customers ask is simple: Do they legally have to tell me if my personal information was exposed?

Across Africa, the answer varies considerably.

TechView Africa compared the current data-protection rules in Nigeria, Kenya, South Africa, Ghana, Rwanda and Uganda, focusing on two practical questions: when affected people must be notified and where they can complain.

The rules are not the same across Africa

CountryNotification to regulatorMust affected person be told?Complaint authority
NigeriaWithin 72 hours where breach creates riskImmediately where there is high riskNigeria Data Protection Commission
KenyaWithin 72 hours where there is real risk of harmYes, within a reasonably practical periodOffice of the Data Protection Commissioner
South AfricaAs soon as reasonably possibleYes; POPIA has no risk threshold for reportingInformation Regulator
GhanaAs soon as reasonably practicableYesData Protection Commission
RwandaWithin 48 hours; fuller report by 72 hoursYes where breach creates high riskData Protection & Privacy Office
UgandaImmediatelyOnly where the regulator directs notificationPersonal Data Protection Office

Nigeria uses a risk-based system

Nigeria's Data Protection Act requires a controller to notify the Nigeria Data Protection Commission within 72 hours where a breach is likely to create risk to people's rights and freedoms.

The threshold for directly notifying the affected person is higher. Where the breach is likely to create a high risk, the organisation must communicate it immediately in clear language and include steps the person can take to reduce possible harm.

A person who believes a controller or processor violated the Act can lodge a complaint with the Commission under section 46. Nigeria Data Protection Act 2023

Kenya gives consumers a specific breach-notification right

Kenya requires notification to the Data Commissioner within 72 hours where unauthorised access creates a real risk of harm.

The affected person must also be informed in writing within a reasonably practical period. The notice should explain what happened, what the organisation is doing and what the individual can do to protect themselves. An exception can apply where appropriate safeguards, including encryption, protected the affected information. Consumers can submit complaints directly through Kenya's ODPC complaint system.

South Africa has one of the broadest notification duties

South Africa's POPIA framework does not apply a high-risk threshold before a security compromise must be reported.

The Information Regulator says responsible parties must report security compromises and notify affected data subjects as soon as reasonably possible, irrespective of the perceived level of risk.

Individuals who believe their personal information has been violated can complain through the Information Regulator's eServices system or POPIA complaint process.

Ghana also requires the individual to be told

Ghana's Data Protection Act requires both the Data Protection Commission and the affected data subject to be notified where there are reasonable grounds to believe personal data was accessed or acquired by an unauthorised person.

The notification must be made as soon as reasonably practicable and provide enough information for the person to take protective measures. Ghana's Commission also provides an online complaint process for individuals.

Rwanda sets a 48-hour regulator deadline

Rwanda requires controllers to notify its supervisory authority within 48 hours of becoming aware of a personal-data breach and submit a fuller report no later than 72 hours.

Where the incident is likely to result in high risk to an individual's rights and freedoms, the affected person must also be informed in writing or electronically. Complaints can be lodged with Rwanda's Data Protection & Privacy Office at no cost.

Uganda works differently

Uganda requires the controller, processor or collector to immediately notify the authority after believing personal data has been accessed by an unauthorised person.

But the organisation does not automatically decide whether affected people must also be informed. Under section 23, the regulator determines whether notification to the data subject is required.

Uganda's PDPO accepts complaints online, by email and in person; its guidance also recommends first raising the issue with the organisation and keeping records of the response.

Our Recommendation

If you receive a breach notice, first establish what information was exposed, rather than assuming every breach creates the same risk.

Keep the company's notice, relevant emails and screenshots, secure any exposed credentials, and use the relevant national data-protection regulator if you believe the organisation failed to protect your information or meet its notification obligations.

TechView Africa has separately explained what it means when an email address appears in a breached data and how to distinguish exposure from an actual account takeover. TechView Africa — Your Email Was in a Data Breach: What Does It Mean?

This comparison provides general information rather than personalised legal advice. Individual cases can turn on the type of information exposed, the organisation involved and applicable sector-specific rules.

Verification Links

Nigeria Data Protection Act 2023

Kenya Data Protection Act — Section 43

Kenya ODPC — File a Complaint

South Africa Information Regulator — Security Compromises

South Africa Information Regulator — Complaints

Ghana Data Protection Act 2012 — Section 31

Ghana Data Protection Commission — File a Complaint

Rwanda Data Protection & Privacy Office — Breach Obligations

Rwanda Data Protection & Privacy Office — Complaints Lodging Guide

Uganda Data Protection and Privacy Act — Section 23

Uganda Personal Data Protection Office — Complaints Guidance

Frequently asked questions

Does every African country require companies to notify consumers after a breach?

No. Requirements differ. Uganda, for example, gives the regulator a role in deciding whether affected individuals should be notified.

Which country has the shortest regulator deadline in this comparison?

Rwanda requires initial notification within 48 hours. Nigeria and Kenya use 72-hour deadlines in specified risk circumstances.

Can I complain even if the company has already notified me?

Potentially yes. A breach notification does not itself prevent you from raising concerns with the relevant regulator about how your information was handled.

Reader discussion

Leave a comment

Comments cannot be edited or deleted after posting. Please review your comment before submitting.

No comments yet. Start the conversation.

Found an error, outdated step or safety concern? Contact the desk.