By Oyindolapo Olusesi, Founder of Mustarred
Expanding across borders has become increasingly accessible for African businesses. The African Continental Free Trade Area (AfCFTA), supported by its Protocol on Digital Trade, is intended to reduce barriers to digital commerce and facilitate economic integration across the continent. However, translating the protocol into a unified digital market will still require extensive implementation and regulatory coordination [1].
As commercial barriers gradually decline, another challenge is becoming more visible. African companies entering new markets must navigate a growing number of national data protection laws, regulatory authorities and cross-border transfer requirements.
For businesses expanding from one African country to another, moving personal data across national borders can create an extensive web of legal obligations, contractual safeguards, vendor assessments, governance processes and technical controls. Companies that fail to build an operational structure for cross-border data compliance may face unexpected costs, regulatory intervention and disruption to their services.
Successfully navigating this environment requires more than replicating a company’s headquarters policies in every market. It demands an understanding of the different legal frameworks governing personal data and of the gap that often exists between written compliance policies and their practical implementation.
The Illusion of a Universal Standard
Some founders assume that compliance with the European Union’s General Data Protection Regulation (GDPR) automatically ensures compliance in other jurisdictions. This assumption is legally and operationally unsafe.
Data protection remains jurisdiction-specific, even though many modern privacy laws share common principles. A growing number of African laws also have an extraterritorial reach, meaning that a company may become subject to a country’s data protection rules without establishing a physical office there.
Depending on the applicable legislation, offering goods or services to people in a country, monitoring their behaviour or processing their personal data may be sufficient to create regulatory obligations.
A business operating across Nigeria, Kenya and South Africa, for example, must consider three separate legal frameworks:
- Nigeria: the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Act General Application and Implementation Directive 2025 (GAID), administered by the Nigeria Data Protection Commission [2] [3].
- Kenya: the Data Protection Act 2019 and its accompanying regulations, administered by the Office of the Data Protection Commissioner [4].
- South Africa: the Protection of Personal Information Act 4 of 2013 (POPIA), administered by the Information Regulator [5].
These laws reflect several shared principles, including lawful processing, transparency, security and respect for data-subject rights. Nevertheless, their registration rules, enforcement procedures, transfer mechanisms and regulatory terminology are not identical.
Expansion into several African markets therefore requires companies to comply with multiple frameworks simultaneously rather than selecting one standard and assuming it will satisfy every regulator.
Where the Costs Actually Appear
The cost of cross-border data compliance extends beyond fees paid to lawyers or consultants. Companies may also incur substantial technical and operational expenses as they adapt their infrastructure, contracts and governance systems to different legal requirements.
These expenses are frequently omitted from expansion budgets, particularly when regulatory planning begins only after a product has been built or a new market has been entered.
1. Multi-Region Infrastructure and Data Residency
Cross-border transfer requirements can complicate centralised cloud architecture.
Under Nigeria’s NDPA, a controller or processor transferring personal data from Nigeria must rely on an applicable legal basis and ensure that the recipient is subject to an adequate level of protection or that another recognised transfer condition applies [2]. Further practical discussion of the Nigerian transfer framework is provided by Mustarred [6].
Kenya’s Data Protection Act also regulates transfers of personal data outside the country. In addition, the Kenyan framework permits certain categories of processing to be required to take place through servers or data centres located in Kenya when this is considered necessary to protect the country’s strategic interests [4].
These provisions do not amount to a universal requirement that every category of data must be stored locally. They do, however, require companies to identify the type of information being processed, the countries through which it moves and whether sector-specific or data-specific restrictions apply.
For an African enterprise relying on centralised cloud infrastructure, serving customers in several jurisdictions may require regional database configurations, access restrictions, encryption controls or changes to the way data is separated and routed.
The implementation gap is significant. Many companies recognise that data residency and international transfer requirements exist but underestimate the architectural planning needed to meet them without unnecessarily duplicating infrastructure.
Data-flow and residency requirements should ideally be considered during product design rather than retrofitted after a regulator raises concerns.
2. Registration, DPO and Representation Requirements
Entering a new market may also require direct engagement with the local data protection authority.
Under section 44 of Nigeria’s NDPA, organisations classified as Data Controllers or Data Processors of Major Importance must register with the Nigeria Data Protection Commission [2]. The applicable designation depends on factors such as the number and nature of data subjects, the sensitivity of the data and the significance of the processing activity. Mustarred provides additional guidance on this registration category [7].
Kenya also operates a registration system for data controllers and processors. However, the requirement is subject to thresholds, exemptions and specified categories of processing under the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021 [8].
Companies should therefore determine whether their activities fall within a mandatory category rather than assuming that either every business or no business must register.
Additional operational roles may create recurring costs.
Data Protection Officers: Certain organisations must appoint a suitably qualified data protection officer or assign responsibility for overseeing data protection compliance. The role should be integrated into the organisation’s governance structure and supported by appropriate independence and resources.
Local representatives and regulatory contacts: Depending on the jurisdiction, the company’s establishment and the territorial scope of the applicable law, a business may need a locally accessible representative or contact capable of communicating with regulators and data subjects.
Even when the law does not expressly require a separate representative, companies still need a reliable operational process for responding to regulatory correspondence, complaints and data-subject requests in each market.
Maintaining these capabilities across several countries can create significant administrative costs.
3. Transfer Assessments and Contractual Safeguards
Before transferring personal data internationally, a company must determine which country’s law governs the transfer and which legal mechanism is available.
The European Commission’s Standard Contractual Clauses, the United Kingdom’s International Data Transfer Agreement and UK Addendum, and Binding Corporate Rules are mechanisms developed within European and UK data protection regimes. They should not be treated as automatically sufficient for every transfer between African jurisdictions.
However, they may become relevant when an African company receives personal data from the European Economic Area or the United Kingdom, operates through an entity subject to European or UK law, or contracts with a partner that must comply with those regimes.
Where European Standard Contractual Clauses are used for a transfer from the EEA to a country without an EU adequacy decision, the parties may also need to assess the legal environment of the destination country and determine whether supplementary safeguards are necessary.
At present, no African country appears on the European Commission’s list of jurisdictions covered by an adequacy decision [9]. This affects transfers of personal data from the EEA to African recipients. It does not mean that every transfer of data from an African country into Europe automatically requires European Standard Contractual Clauses.
An African company must first comply with the outbound-transfer rules of the country from which the information is being exported. If the information originally came from the EEA or another regulated jurisdiction, additional contractual obligations may also apply.
Nigeria and other African jurisdictions recognise the importance of contractual and organisational safeguards, but the appropriate instrument must be selected according to the applicable national law. Simply attaching European Standard Contractual Clauses to every vendor agreement does not necessarily produce compliance.
Drafting, negotiating and maintaining suitable data-processing agreements across vendors, affiliates and business partners requires continuing legal, technical and operational resources. The cost is recurring and increases with the number of jurisdictions, processing activities and third parties involved.
What Non-Compliance Can Cost
Failing to establish a cross-border data compliance strategy may expose an expanding company to substantial financial and operational consequences.
Under Nigeria’s NDPA, an enforcement order directed at a Data Controller or Data Processor of Major Importance may include a monetary penalty calculated with reference to the greater of NGN10 million or 2% of the organisation’s annual gross revenue in the preceding financial year [2].
Kenya’s Data Protection Act provides for an administrative fine of up to the lower of KES5 million or 1% of the organisation’s annual turnover in the preceding financial year [4].
South Africa’s POPIA provides for fines of up to ZAR10 million and, for certain offences, possible criminal liability [5].
Companies must also consider consequences beyond monetary penalties. Regulators may issue enforcement notices, require corrective action, restrict particular processing activities or intervene in international transfers.
An order that prevents a company from lawfully processing or transferring data could disrupt part of its service in a particular country. The resulting loss of revenue and trust may ultimately be more damaging than the financial penalty itself.
A Practical Framework for Managing Compliance Costs
Businesses can reduce these risks by incorporating data protection into their expansion planning.
The following measures address implementation gaps commonly encountered in practice.
1. Map Data Flows Before Entering a Market
Before launching in another country, identify:
- what personal data the company collects;
- why each category of data is processed;
- where the information is stored;
- which company entities and vendors can access it;
- the countries through which it passes; and
- the legal basis and safeguards supporting each transfer.
Identifying these requirements during the early stages of product and market development can prevent expensive infrastructure changes later.
In my experience, the companies that struggle most are not necessarily those that deliberately ignored the law. They are often companies that completed their technical architecture first and attempted to add compliance afterwards.
Data-flow mapping should inform architecture, procurement and market-entry decisions rather than being treated as a retrospective documentation exercise.
2. Build Privacy Into the Architecture
Data minimisation, access controls, pseudonymisation and appropriate encryption should be incorporated into technical design from the outset.
Limiting international data movement to information that is genuinely necessary can reduce regulatory exposure and simplify transfer assessments. Regional separation of data may also help organisations respond to local legal requirements without duplicating their entire technology environment.
Privacy by design is not merely a policy statement. It is an engineering and governance discipline.
If a product can operate only by moving complete personal datasets across several countries, written policies alone will not resolve the resulting regulatory risks. Designing the system to collect and transfer only necessary information can make compliance more manageable.
3. Standardise Transfer and Vendor Controls
Companies should establish a consistent vendor-management process covering cloud providers, software platforms, contractors, affiliates and other third parties that process personal data.
This process may include:
- vendor due diligence;
- data-processing agreements;
- security and breach-notification obligations;
- subprocessor controls;
- records of international transfers;
- periodic risk reviews; and
- jurisdiction-specific contractual safeguards where required.
The appropriate transfer mechanism should be selected according to the relevant law rather than applying European Standard Contractual Clauses indiscriminately.
The practical problem is rarely a complete absence of contract templates. More often, organisations have inconsistent agreements across vendors and jurisdictions, making compliance difficult to maintain and audit at scale.
A standard internal framework, with carefully documented local variations, is more manageable than a collection of unrelated arrangements.
4. Work With Specialists Who Understand the Markets
Multi-jurisdictional data compliance requires an understanding of both international principles and the implementation of individual African laws.
Companies should ensure that their legal, compliance and technology advisers understand the specific registration requirements, enforcement practices and transfer rules of the markets in which the organisation operates.
The NDPA, Kenya’s Data Protection Act and POPIA share several principles with the GDPR, but they are independent laws with distinct terminology, procedures and regulatory priorities.
Understanding those differences is not an optional administrative exercise. It is part of managing the operational risks of regional expansion.
Conclusion
Cross-border data compliance has become an operational requirement for African companies expanding into new markets.
Although the associated costs can be significant, they are more predictable and manageable when addressed during business planning, product design and vendor selection. The greatest difficulties arise when compliance is treated as something to be addressed only after a product has been launched and personal data is already moving across borders.
By mapping data flows, designing adaptable cloud architecture, implementing privacy-by-design controls and selecting appropriate contractual safeguards, African businesses can pursue regional and international growth while reducing the risk of fines, transfer restrictions and service disruption.
The central question is not simply whether a company will comply. It is whether compliance will be approached deliberately and early or reactively and at a much higher cost.
About the Author
Oyindolapo Olusesi is the Founder of Mustarred, a regulatory compliance and IT advisory firm serving companies within Africa’s technology ecosystem. He advises organisations on cross-border data transfers, regulatory compliance and the practical implementation of data protection requirements across African markets.
Sources and Information
- ODI Global — Unlocking Africa’s Digital Trade Potential: A Guide to Implementing the AfCFTA Digital Trade Protocol
- Nigeria Data Protection Act 2023
- Nigeria Data Protection Act General Application and Implementation Directive 2025
- Office of the Data Protection Commissioner — Data Protection Laws of Kenya
- Government of South Africa — Protection of Personal Information Act 4 of 2013
- Mustarred — How the NDPA Governs Cross-Border Data Transfers
- Mustarred — DCMI Compliance
- Kenya Data Protection Registration Regulations 2021
- European Commission — Data Protection Adequacy Decisions
This article provides general information and does not constitute legal advice.
