Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
Law 2008-12
One of Africa's earliest data protection laws, Senegal's Law 2008-12 establishes the CDP and subjects personal data processing to prior declarations, authorisations and opinions, backed by administrative fines and criminal sanctions.
Senegal enacted Law No. 2008-12 on 25 January 2008, among the first data protection laws in Africa, implemented by Decree No. 2008-721 of 30 June 2008. It establishes the Commission de protection des Donnees Personnelles (CDP), an independent authority that receives prior formalities, handles complaints, conducts on-site, documentary and hearing inspections, and sanctions controllers. Processing must generally be declared to the CDP; prior authorisation is required for sensitive processing (genetic data, biometric data, offence-related data, national identification numbers, file interconnections and public-interest processing), and State processing requires a reasoned CDP opinion. Consent is the default legal basis, with exemptions for legal obligations, public interest, contract and vital interests.
Cross-border transfers are prohibited unless the receiving country ensures sufficient protection, and the CDP must be informed before any transfer. There is no mandatory breach notification and DPO appointment is discretionary for businesses. Senegal was the first African country to ratify the African Union's Malabo Convention on Cyber Security and Personal Data Protection, in 2016. A modernising bill published in late 2019, which would replace the CDP with a new authority and address biometrics, big data and AI, has not been adopted, so the 2008 law remains in force as of 2026.
Businesses must notify the CDP of processing activities before carrying them out, with narrow exemptions for non-profit associative processing and public registers.
CDP approval is required before processing genetic or biometric data, offence-related data, national identification numbers, file interconnections and public-interest processing.
Processing requires the data subject's consent or a statutory exemption, and data must be collected fairly for specified purposes, be proportionate, accurate and retained no longer than necessary.
Controllers must prevent alteration, damage or unauthorised third-party access, including access controls, verified identities, backups and safeguards during transmission.
Read more
Anove scans your stack against Law 2008-12 and 260+ other frameworks in minutes.
Transfers are allowed only to countries ensuring sufficient protection, and the CDP must be informed of every transfer with details of the sender, recipient, data and purposes.