Africa’s Data Protection Default: Why AI Regulation Without AI Laws Falls Short

Nigeria, Kenya, South Africa, Ghana, and Rwanda are using data protection laws to govern AI by default. It is working — up to a point. Here is what data protection law cannot reach, and what the continent’s emerging dedicated AI frameworks change.
Total
0
Shares
Africa's Data Protection Default: Why AI Regulation Without AI Laws Falls Short
8 min read

Across Africa, the laws doing the most work to govern artificial intelligence were not written with AI in mind. Nigeria’s National Data Protection Regulation dates to 2019. Kenya’s Data Protection Act passed the same year. South Africa’s POPIA commenced in 2021. Ghana’s Data Protection Act is from 2012. None of these frameworks mention machine learning. All of them have become, by default, the primary regulatory instrument through which African governments are managing the risks of AI. That is not an accident — but it is not sustainable either.

Last week, TechCabal published a well-framed analysis arguing that data protection legislation is Africa’s de facto AI policy instrument, pointing to seven countries using data protection frameworks as a proxy for AI governance in the absence of dedicated AI laws. The framing is substantially correct. Where it is incomplete is in treating this as a stable arrangement rather than a temporary bridge — and in underestimating how much AI governance territory data protection law structurally cannot reach.

How Data Protection Became AI Regulation by Accident

The logic is straightforward. Most AI harms arrive through the processing of personal data: credit decisions made by opaque algorithms, identity verification systems that exclude or misidentify, health scoring tools that encode historical bias. Data protection law — with its consent requirements, purpose limitation principles, individual access rights, and accountability obligations — provides a workable handle on these harms even where AI is not mentioned explicitly.

Nigeria’s NDPR, for example, requires lawful basis for processing personal data, mandates data impact assessments for high-risk processing activities, and creates individual rights of access and objection. A Nigerian fintech running an automated credit scoring model must, under the NDPR, ensure it has legal basis for the personal data it processes, cannot use that data beyond its original purpose, and must respond to user requests for explanation of decisions. These are not trivial obligations — and Nigeria’s National Information Technology Development Agency has started enforcing them.

Kenya’s Data Protection Act creates similar architecture, adding a requirement for Data Protection Officers in organisations processing significant volumes of personal data. South Africa’s POPIA is the most technically developed DPA on the continent: its accountability principle, combined with Section 71’s provision for automated decision-making objections, gives individuals the right to request human review of decisions made by purely automated systems. When South Africa’s Information Regulator published AI processing guidelines under POPIA in 2024, it was extending an existing framework, not building a new one.

The Country Matrix: Who Has What

Map the continent’s six most significant AI markets and the pattern becomes clear. Nigeria sits in an intermediate state: the NDPR provides the current baseline, but the National Digital Economy and E-Governance Bill 2025 — which has cleared both chambers of the National Assembly and awaits presidential assent — will establish Africa’s first binding AI-specific governance framework, administered by NITDA. Kenya is in a similar transition: the Data Protection Act 2019 is the current operative frame, while the Artificial Intelligence Bill 2026, introduced in February, proposes a separate AI Commissioner with enforcement and prior-approval powers.

South Africa is the furthest advanced in the DPA-to-AI transition without yet completing it. POPIA is active and enforced. The Information Regulator has issued AI guidance under it. But the Draft National AI Policy — expected for public consultation this quarter — has not yet become binding law. For now, POPIA does the heavy lifting while the consultation runs.

Morocco has moved furthest of all. The Digital X.0 framework law, currently under parliamentary review, combines AI governance, updated data protection rules (upgrading the 2009-vintage Law 09-08), and a national digital identity system into a single statutory instrument. A National Agency for AI Governance is expected to be formally established by late 2026.

Ghana and Rwanda represent the pure DPA-default case. Ghana’s Data Protection Act 2012 — the oldest major DPA on the continent — has no AI-specific provisions and an enforcement record characterised more by guidance notes than active investigations. Rwanda’s Law n°058/2021 on data protection is more modern but similarly silent on algorithmic systems. Both countries have indicated AI policy intent; neither has a legislative timeline.

Senegal, which the TechCabal analysis includes, sits closest to Ghana: a functional DPA framework with no dedicated AI instrument, limited enforcement capacity, and no formal AI legislative calendar.

What Data Protection Law Cannot Do

The DPA-as-AI-proxy model has four structural gaps that data protection legislation — however well-designed — cannot close.

First: model training on non-personal data. A large language model trained on synthetic datasets, publicly scraped text, or anonymised corpora falls outside DPA jurisdiction entirely. The NDPR, POPIA, and Kenya’s DPA all operate on personal data. The foundation model shaping AI behaviour across entire industries may have been built without processing a single personally identifiable record — and no African DPA has authority over that training process.

Second: algorithmic decision thresholds. Data protection law can give individuals the right to object to a fully automated decision. It cannot specify what probability threshold a credit model should use to approve or deny a loan, what confidence level is required before an AI fraud detection system freezes an account, or how an AI hiring tool should weight competing factors. These are calibration decisions with profound economic consequences. They are governance questions that DPA frameworks were not designed to answer.

Third: AI-specific liability. When an AI system produces a harmful output — a hallucinated medical diagnosis, a deepfake used for fraud, a discriminatory risk score — the question of who bears legal liability is not resolved by data protection law. DPAs assign obligations to data controllers and processors. They do not create liability frameworks for AI developers, foundation model providers, or deployers who have embedded third-party models into their products. That gap is particularly acute for open-source model deployments, where the developer fine-tuning a Meta Llama model on local data cannot produce audit trails of the original training — documentation both Nigeria’s AI Bill and Kenya’s proposed framework will require.

Fourth: competitive distortions. An AI system that gives one financial institution a systematic advantage in credit pricing, fraud detection, or customer acquisition creates market structure effects that competition law and sectoral regulation must address. Data protection law, which focuses on individual rights rather than market outcomes, has no mandate here.

What TechCabal Got Right — and Where It Stops Short

The TechCabal thesis is accurate as a description of the present state: data protection frameworks are the operative AI governance layer in most African markets. Where it understates the problem is in implying this is a workable long-term arrangement. The four gaps above are not edge cases. Algorithmic credit decisioning, foundation model liability, and market concentration effects from AI advantage are central features of how AI is reshaping African finance, health, and commerce. They are not reachable through DPA enforcement regardless of how active the regulator is.

The more precise framing is that data protection law is a necessary but not sufficient foundation for AI governance — and African regulators who have not yet begun dedicated AI rulemaking are accumulating a governance deficit that grows with each AI deployment. The countries that have moved to dedicated frameworks (Nigeria, Kenya in progress, Morocco, South Africa in consultation) are doing so precisely because their DPA regulators and AI policy teams understand where the existing framework runs out.

The Continental Question

The African Union’s AI Policy Framework, developed in partnership with Google and adopted in 2024, explicitly positions data protection as the foundational layer of AI governance while acknowledging the need for AI-specific rules above that base. The framework recommends that AU member states build AI governance within existing data protection architecture rather than creating entirely new institutions — a position that validates the DPA-default approach as a starting point while directing states toward dedicated AI instruments over time.

The practical implication for harmonisation is sobering. The AU framework provides convergence principles, but enforcement is national. Nigeria’s NITDA-led model, Kenya’s proposed three-body structure, South Africa’s sector-specific multi-regulator approach, and Morocco’s integrated single-law framework represent four different architectural choices. A fintech operating across all four markets faces four different compliance regimes, four sets of documentation requirements, and four enforcement relationships — with no continental mechanism to rationalise them.

That fragmentation is not unique to Africa: the EU AI Act, GDPR, and national implementations have created their own cross-border complexity. But African startups navigating multi-country expansion have less regulatory capacity and smaller compliance budgets than the European incumbents the EU regime was designed around. The divergence tax falls heaviest on the builders who can least afford it.

Data protection law was the best available instrument when AI governance was an abstraction. It is not sufficient now that AI governance is a daily operational reality. Africa’s most consequential regulatory work in this space is not the DPA enforcement that TechCabal documented — it is the dedicated AI legislation moving through Abuja, Nairobi, Casablanca, and Pretoria. That is the story the continent’s founders, regulators, and investors need to track.

— Technology Desk, BETAR.africa

You May Also Like