Africa does not have one uniform data-breach rule. Notification deadlines, risk thresholds and complaint procedures differ substantially by country.
If Your Personal Data Leaks, Must the Company Tell You? We Compared the Rules in Six African Countries
TechView Africa compared data-breach rules in Nigeria, Kenya, South Africa, Ghana, Rwanda and Uganda. Whether a company must tell you and how quickly, depends heavily on where you are.
Nigeria, Kenya, South Africa, Ghana and Rwanda contain circumstances requiring affected people to be notified directly. Uganda takes a different approach: the regulator is notified first and decides whether affected individuals should also be told.
When a company says it has suffered a “security incident,” one of the first questions customers ask is simple: Do they legally have to tell me if my personal information was exposed?
Across Africa, the answer varies considerably.
TechView Africa compared the current data-protection rules in Nigeria, Kenya, South Africa, Ghana, Rwanda and Uganda, focusing on two practical questions: when affected people must be notified and where they can complain.
The rules are not the same across Africa
| Country | Notification to regulator | Must affected person be told? | Complaint authority |
|---|---|---|---|
| Nigeria | Within 72 hours where breach creates risk | Immediately where there is high risk | Nigeria Data Protection Commission |
| Kenya | Within 72 hours where there is real risk of harm | Yes, within a reasonably practical period | Office of the Data Protection Commissioner |
| South Africa | As soon as reasonably possible | Yes; POPIA has no risk threshold for reporting | Information Regulator |
| Ghana | As soon as reasonably practicable | Yes | Data Protection Commission |
| Rwanda | Within 48 hours; fuller report by 72 hours | Yes where breach creates high risk | Data Protection & Privacy Office |
| Uganda | Immediately | Only where the regulator directs notification | Personal Data Protection Office |
Nigeria uses a risk-based system
Nigeria's Data Protection Act requires a controller to notify the Nigeria Data Protection Commission within 72 hours where a breach is likely to create risk to people's rights and freedoms.
The threshold for directly notifying the affected person is higher. Where the breach is likely to create a high risk, the organisation must communicate it immediately in clear language and include steps the person can take to reduce possible harm.
A person who believes a controller or processor violated the Act can lodge a complaint with the Commission under section 46. Nigeria Data Protection Act 2023
Kenya gives consumers a specific breach-notification right
Kenya requires notification to the Data Commissioner within 72 hours where unauthorised access creates a real risk of harm.
The affected person must also be informed in writing within a reasonably practical period. The notice should explain what happened, what the organisation is doing and what the individual can do to protect themselves. An exception can apply where appropriate safeguards, including encryption, protected the affected information. Consumers can submit complaints directly through Kenya's ODPC complaint system.
South Africa has one of the broadest notification duties
South Africa's POPIA framework does not apply a high-risk threshold before a security compromise must be reported.
The Information Regulator says responsible parties must report security compromises and notify affected data subjects as soon as reasonably possible, irrespective of the perceived level of risk.
Individuals who believe their personal information has been violated can complain through the Information Regulator's eServices system or POPIA complaint process.
Ghana also requires the individual to be told
Ghana's Data Protection Act requires both the Data Protection Commission and the affected data subject to be notified where there are reasonable grounds to believe personal data was accessed or acquired by an unauthorised person.
The notification must be made as soon as reasonably practicable and provide enough information for the person to take protective measures. Ghana's Commission also provides an online complaint process for individuals.
Rwanda sets a 48-hour regulator deadline
Rwanda requires controllers to notify its supervisory authority within 48 hours of becoming aware of a personal-data breach and submit a fuller report no later than 72 hours.
Where the incident is likely to result in high risk to an individual's rights and freedoms, the affected person must also be informed in writing or electronically. Complaints can be lodged with Rwanda's Data Protection & Privacy Office at no cost.
Uganda works differently
Uganda requires the controller, processor or collector to immediately notify the authority after believing personal data has been accessed by an unauthorised person.
But the organisation does not automatically decide whether affected people must also be informed. Under section 23, the regulator determines whether notification to the data subject is required.
Uganda's PDPO accepts complaints online, by email and in person; its guidance also recommends first raising the issue with the organisation and keeping records of the response.
Our Recommendation
If you receive a breach notice, first establish what information was exposed, rather than assuming every breach creates the same risk.
Keep the company's notice, relevant emails and screenshots, secure any exposed credentials, and use the relevant national data-protection regulator if you believe the organisation failed to protect your information or meet its notification obligations.
TechView Africa has separately explained what it means when an email address appears in a breached data and how to distinguish exposure from an actual account takeover. TechView Africa — Your Email Was in a Data Breach: What Does It Mean?
This comparison provides general information rather than personalised legal advice. Individual cases can turn on the type of information exposed, the organisation involved and applicable sector-specific rules.
Verification Links
Nigeria Data Protection Act 2023
Kenya Data Protection Act — Section 43
South Africa Information Regulator — Security Compromises
South Africa Information Regulator — Complaints
Ghana Data Protection Act 2012 — Section 31
Ghana Data Protection Commission — File a Complaint
Rwanda Data Protection & Privacy Office — Breach Obligations
Rwanda Data Protection & Privacy Office — Complaints Lodging Guide
Uganda Data Protection and Privacy Act — Section 23
Uganda Personal Data Protection Office — Complaints Guidance
Frequently asked questions
Does every African country require companies to notify consumers after a breach?
No. Requirements differ. Uganda, for example, gives the regulator a role in deciding whether affected individuals should be notified.
Which country has the shortest regulator deadline in this comparison?
Rwanda requires initial notification within 48 hours. Nigeria and Kenya use 72-hour deadlines in specified risk circumstances.
Can I complain even if the company has already notified me?
Potentially yes. A breach notification does not itself prevent you from raising concerns with the relevant regulator about how your information was handled.
Follow TechView Africa on WhatsApp
Get TechView Africa updates on WhatsApp. Follow our channel for practical technology news, product guides and digital trends from Nigeria and across Africa.










Leave a comment
Comments cannot be edited or deleted after posting. Please review your comment before submitting.
No comments yet. Start the conversation.