edidiong umana · writing
home
Agentic commerce in Africa6 min read

Building AI under African data law

There's no need to wait for an AI law. If your product touches personal data about people in Nigeria, Kenya, South Africa or Ghana, a data protection law already governs it. Here are the rules that bite AI builders, with section numbers and links, and a checklist to run before launch.

Your AI feature is nearly ready. It reads customer chats or bank statements, sends them to a model API hosted abroad, and makes or shapes a decision: a loan, a refund, a blocked account. You're launching in Lagos first and Nairobi next quarter. Which rules apply?

More than most teams expect, and none of them say "AI" in the title. Data protection law already covers how you collect personal data, what you train on, where you send it and what you owe people when a machine decides about them.

This is not legal advice. It summarises the laws as the AI Study Group's lessons stood in September 2026. Laws and guidance change, and the details of your product matter. Check with a lawyer or the regulator before you rely on any of it.

The principles they share

The four laws below differ in detail but share a core:

  • Lawful basis. You need a legal reason to process personal data, such as consent, a contract, a legal obligation or legitimate interests.
  • Real consent. Specific, informed and freely given. A pre-ticked box inside long terms doesn't count.
  • Purpose limitation. Support chats aren't automatically training data for a sales model.
  • Minimisation. Collect what you need, keep it accurate, delete it when you're done.
  • Rights and security. People can see, correct and object. You protect the data, and report leaks.

Four countries at a glance

NigeriaKenyaSouth AfricaGhana
LawData Protection Act 2023, plus the NDPC's GAID, in force since 19 September 2025Data Protection Act 2019, in force since 25 November 2019POPIA 2013, enforced since 1 July 2021Data Protection Act 2012 (Act 843)
RegulatorNigeria Data Protection Commission (NDPC)Office of the Data Protection Commissioner (ODPC)Information RegulatorData Protection Commission (DPC)
Automated decisionsRight not to be subject to them where effects are legal or similar; the GAID requires consent firsts.35: tell the person in writing; on request, reconsider with human involvements.71: similar right, plus a chance to make representationss.41: rights in relation to automated decision-taking
Sending data abroadAdequate protection or another basis in Part VIIISafeguards or another listed basis (s.48); sensitive data also needs consent (s.49)Adequate protection, consent or another listed basis (s.72)No specific transfer rules in Act 843; general principles apply
Breach noticeNDPC within 72 hours (s.40)ODPC within 72 hours (s.43)As soon as reasonably possible (s.22)To the DPC and the people affected (s.31)

Nigeria: the GAID is aimed at you

Controllers and processors "of major importance" must register with the NDPC, and that includes foreign firms that target people in Nigeria. Section 28 of the Act requires a data protection impact assessment (DPIA) for high-risk processing.

The GAID goes further for AI builders. It makes a DPIA mandatory, and filed with the NDPC, for profiling, automated decisions, digital financial services and health care. Its Article 43, on AI and other emerging technologies, expects you to assess disparate outcomes as part of that DPIA. The GAID also expects organisations deploying AI on personal data to document their technical and organisational safeguards and file them with the NDPC in their compliance audit returns.

A breach likely to put people's rights at risk must reach the NDPC within 72 hours (s.40). And the GAID created a standard notice, the SNAG, that a person can send to demand a privacy problem be fixed; a company that receives one has to report its decision to the NDPC.

Enforcement isn't new either. In 2021, before the current Act, NITDA fined Soko Lending Company ₦10 million after it sent privacy-invading messages to borrowers' contacts.

Kenya: register first, assess before you process

Register with the ODPC. Only very small entities are exempt, and sectors such as health, education, financial services and transport must always register, whatever their size.

Section 31 requires a DPIA before high-risk processing. It must describe the processing and its purposes, assess whether it's necessary and proportionate, assess the risks to people, and set out safeguards. Courts take this seriously: in October 2021 the High Court quashed the Huduma Namba identity card rollout and ordered that assessment done first.

Section 35 is the one AI products trip over. When a significant decision is made solely by automated means, you tell the person in writing, and on request you reconsider or decide again with human involvement. The Act also defines data revealing race, ethnic social origin, health status, belief or sex as sensitive, which matters if you plan to collect it for fairness testing.

Breaches with a real risk of harm go to the Data Commissioner within 72 hours (s.43), and a processor must tell the controller within 48 hours where practicable.

Two cases show the regulator and courts at work. In September 2023 the ODPC fined Mulla Pride Ltd, which ran the KeCredit and Faircash loan apps, KES 2,975,000 for using third parties' contact details to send threatening messages and calls. In May 2025 the High Court found that Worldcoin had done no DPIA, had not registered, and had obtained consent that was invalid because it was induced with tokens. The court ordered the biometric data deleted, and in January 2026 the regulator confirmed it had been.

Other markets, and a moving rulebook

South Africa's POPIA requires you to register your Information Officer, and its 2018 Regulations require that officer to ensure a personal information impact assessment is done. Ghana's Act 843 requires controllers to register with the DPC before processing and renew every two years. Ghana published a bill to replace it in 2025, but in March 2026 the government said it was still developing the bill, so Act 843 still applies.

Rwanda has its own law, Law No. 058/2021, and storing personal data outside Rwanda needs authorisation from the supervisory authority. Its Data Protection and Privacy Office runs an application for it. Many other countries have their own laws, some strict about storing data abroad. Check each regulator's website before each launch.

Three places AI products trip

Automated decisions. All four laws give people rights when a solely automated decision significantly affects them. Build three things from day one: a notice that the decision was automated, a plain explanation of the main reasons, and a route to a human who can reconsider.

Prompts sent abroad. Sending prompts containing personal data to a model API hosted in another country is a cross-border transfer. You need a valid basis and a record of which one you rely on. Stripping names and numbers before the call reduces the risk.

The 72-hour clock. It starts when you become aware of a breach, not when you finish investigating. Name the person who decides whether to notify before you need them.

A pre-launch checklist

  1. Draw a data map. What personal data the feature uses, where it's stored and processed, which countries it crosses, and how long you keep it.
  2. Record a lawful basis for each use, including any training. If it's consent, make it specific, separate and easy to withdraw, and keep records of who agreed to which version.
  3. Register with each regulator that requires it, before you process.
  4. Do the impact assessment before launch. In Nigeria, check whether the GAID requires you to file it, and include disparate outcomes.
  5. Build the automated-decision trio: a notice, an explanation and a human review route.
  6. Document each transfer basis, and strip identifiers before prompts leave the country.
  7. Handle sensitive data apart. Collect the minimum, keep it away from the decision system, and in Kenya check the consent rule for transfers.
  8. Write the breach plan: who decides, who notifies which regulator, and how to meet 72 hours.
  9. Publish a complaint route that tells people they can escalate to the NDPC, ODPC, Information Regulator or DPC.
  10. Re-check the regulator's site for new rules before every launch.
Do this todayList every API call in your product that sends personal data out of the country, and write next to each the legal basis you rely on. Any blank line is your first task.

Learn it properly

This post is a slice of Track 2 of the AI Study Group, Ethical AI in Africa. It's free, needs no coding, and goes on to measuring bias, documenting your system and launching with complaint routes and pause rules.

Sources