Data Privacy Enforcement in Kenya & Nigeria
Data Privacy Enforcement in Kenya & Nigeria
To cite this article: Isaac Juma & Bukola Faturoti (23 May 2025): Enforcing data privacy in Kenya
and Nigeria: towards an African approach to regulatory practice, International Review of Law,
Computers & Technology, DOI: 10.1080/13600869.2025.2506918
a
Newcastle Law School, Newcastle University, Newcastle Upon Tyne, United Kingdom; bHertfordshire Law
School, University of Hertfordshire, Hertfordshire, United Kingdom
ABSTRACT KEYWORDS
As digital transformation accelerates across Africa, the need for Data protection; Nigeria;
effective data protection frameworks is increasingly urgent. The Kenya
African Union’s Digital Transformation Strategy (2020–2030) calls
for harmonised legal and institutional measures to protect
personal data and privacy rights. Yet, in practice, enforcement
remains inconsistent, hindered by limited capacity, fragmented
regulation, and low public awareness. This article presents a
comparative analysis of data privacy enforcement in Kenya and
Nigeria, focusing on the Data Protection Act 2019 and the Nigeria
Data Protection Act 2023, respectively. It examines the roles of
the Office of the Data Protection Commissioner and the Nigerian
Data Protection Commission, particularly their institutional
strengths and challenges. Using a qualitative approach, the study
evaluates legislation, enforcement practices, and organisational
structures, supported by case examples and regulatory outcomes.
The findings indicate that Kenya has achieved measurable
progress in data protection enforcement whereas Nigeria is still
grappling with foundational issues. Despite these contrasts, both
countries show alignment with global data protection norms
such as the GDPR, offering a foundation for growth. The paper
recommends targeted strategies to reinforce enforcement,
including increasing institutional autonomy, expanding public
education efforts, and building stronger technical capacity.
1. Introduction
In the era of global digital transformation, the proliferation of personal data and its exploi
tation by public and private actors have underscored the urgent need for robust data pro
tection frameworks. Internationally, the adoption of comprehensive data protection laws
– anchored in principles enshrined in frameworks such as the EU General Data Protection
Regulation (GDPR) – has fostered a trend toward legal harmonisation and regulatory con
vergence. This global momentum is further sustained by a shift toward stricter enforce
ment and the imposition of heavier penalties for data-related violations (Curtiss 2018).
and comprehensive legislation failed (Babalola 2022). For example, the National
Information Technology Development Agency (NITDA) Act, the Nigerian Communications
Commission (NCC) guidelines, and the Central Bank of Nigeria (CBN) failed to comprehen
sively address the digital privacy challenges posed by an increasingly interconnected
community.
Till the enactment of the NDPA, the NDPR occupied a significant position as it outlined
the legal requirements for data collection, storage and processing, paving the way for the
NDPA framework. Under the NDPR framework, data protection compliance was super
vised by the Nigeria Data Protection Bureau (NDPB), under the jurisdiction of the National
Information Technology Development Agency (NITDA).16 Although the NDPR was pre
sented as a solution towards a robust data privacy framework, it was of limited force. It
was a mere guideline rather than a formalised legal framework since it was issued by
NITDA under its existing legal mandate rather than through an Act of Parliament. Further
more, the absence of a formalised institutionalised structure for privacy enforcement
brought about resistance based on a lack of statutory powers and capacity to implement
the NDPR.17 According to (Salami 2020), the NDPR’s sparse, vague, and insufficient pro
visions create additional obstacles to compliance. Thus, the framework was incapable
of addressing the challenges that rapid digital transformation presented in safeguarding
personal data since it was a guideline rather than a statute.
Brandeis 1890). Following the norm, provisions in the Acts confer rights on data subjects.
Granting individuals controlling powers over their personal data, the Acts mandate that
data controllers and processors must obtain consent from individuals prior to handling
of personal data, aimed at the prevention of unauthorised use of personal data, particu
larly by private corporations that actively engage in data mining for marketing and com
mercial purposes.20 The provisions on consent align with the benchmark GDPR principle
on consent being freely given, specific, informed, and unambiguous.21 However, in both
jurisdictions, the practical implementation of these rights poses a significant challenge
since many citizens are unaware of their data protection rights and the possible
redress available upon infringement. Furthermore, the context of consent poses unique
challenges to the wider population, where the gap in the level of digital literacy compli
cates the practical realisation of ‘informed consent.’ With the rural population being
highly marginalised, the probability of giving consent without understanding the impli
cations complicates assessing the effectiveness of a consent-reliant data protection
framework, particularly in the Global South (Radovanović et al. 2020).
In the sphere of data processors and controllers, the legislative frameworks impose
specific obligations on data handlers requiring them to implement appropriate technical
and organisational measures to protect personal data.22 The measures, including encryp
tion, regular security audits, and breach notification requirements, are complemented
with accurate records of any data processing activities undertaken. Moreover, the regulat
ory agencies can inspect the adequacy of safeguards implemented by the handling
parties. In cross-border transfers, the measures may involve the assessment of available
comparable data protection law in the targeted country, and alternatively, having con
tractual clauses ensuring data protection.23 However, the monitoring and enforcement
of these provisions remains limited and will be determined by the ongoing scaling up
of the agencies’ resources and enforcement. Furthermore, the compliance costs of local
firms may prove to be overbearing for small to medium-sized enterprises. This will be
determined by the entities’ capacity to implement technical and organisational measures
to comply with the data handling obligations, largely influenced by access to financial and
technical resources.
infringement notice imposing a $279,000 fine against the Department of Justice and Con
stitutional Development for breaches of the Protection of Personal Information Act.26
approach lacks specificity in terms of time limitation, with the general guidance stating
that the communication of a decision shall be within 45 days of holding a pre-action con
ference.30 It remains to be known how long after complaints the pre-action conference is
to be held, and the length of the investigation by the authority, thus shrouding the entire
process in obscurity. Ideally, the NDPC’s approach ought to be consolidated by further
guidance on the total period to carry out investigations and communication of a decision,
geared towards ensuring lagging in enforcement is not tolerated.
As a key source of funding for the agencies, the fining mechanism is key to the enfor
cement framework, with the agencies’ ability to impose administrative fines utilised to
push for compliance (Balch 1980; Grant and Crowther 2016).31 In the Kenyan framework,
the Commissioner can impose fines of up to KES 5,000,000 or 1% of the company’s annual
turnover, whichever is lower.32 A stark contrast to GDPR provisions in terms of amount,
the fines reflect the significance of contextualisation of the framework, considering the
socio-economic status of the entities in Kenya. However, the fines are insubstantial in
the current framing of the provisions upon the determination of infringement. This
results from the inclusion of the clause ‘whichever is lower,’ compounded by a lack of
specificity on the turnover assessment, severely impacting the efficacy of the administra
tive fine mechanism. The severity of the provisions would be unquestionable, whereas the
ODPC administrative fine determination would tip towards the higher scale rather than
the alternative, to effectively deter infringement.
Case in point, the risk of undermining enforcement through current provisions may
take the form of a processor or controller’s recurrent infringement, considering the
fines as an operating cost to be financed in the long run in light of possible benefits
arising from the conduct (Baldwin 1995; Grant and Crowther 2016). The current enforce
ment framework appears vulnerable to potential shortcomings, particularly regarding the
effectiveness of administrative penalties. If the provisions remain unchanged, introducing
a specified daily fine for ongoing infringements could enhance the efficacy of the fine
mechanism. Conversely, the existing limitations on administrative fines may be intention
ally designed to avoid overburdening small and medium-sized enterprises with compli
ance costs. However, if this is indeed the rationale, it significantly undermines the
normative strength of the Data Protection Act (DPA), as such a framework inadvertently
privileges large national or multinational corporations. As a result, the DPA should recon
sider its provisions, as the current approach has led to a prevalence of minimal adminis
trative penalties with limited deterrent impact on non-compliance.
In Nigeria, the penalty mechanism under the Nigerian Data Protection Act (NDPA)
demonstrates a more nuanced and structured approach, addressing gaps evident in
Kenya’s Data Protection Act (DPA). The Nigerian Data Protection Commission (NDPC)
adopts a tiered framework that distinguishes between small to medium-sized enterprises
and large corporations. This classification creates a functional taxonomy by categorising
data controllers as either of ‘major importance’ or ‘not of major importance.’ Entities
deemed to be of major importance are subject to penalties of ₦10,000,000 or 2% of
their annual gross revenue – whichever is higher – while those not classified as such
face a reduced fine of ₦2,000,000. Although the administrative fines may appear
modest in absolute terms, the NDPA’s emphasis on a percentage of turnover and appli
cation of the greater amount signals a stronger commitment to proactive and proportion
ate regulation, in stark contrast to the Kenyan model. Crucially, the strength of the
INTERNATIONAL REVIEW OF LAW, COMPUTERS & TECHNOLOGY 9
Nigerian framework lies in its enforcement efficacy, with a lower risk of both over- and
under-enforcement, thereby enhancing its deterrent effect.
citizens’ personal data (Roberts et al. 2023).36 Striking an appropriate balance between
safeguarding data privacy and addressing national security concerns poses a substantial
challenge for effective privacy enforcement (Case C-623/17 para22; Case C-511/18 para58,
65). The Kenyan and Nigerian data protection frameworks permit exemptions from data-
related obligations in the interest of national security, law enforcement, and public safety.
While such exemptions are arguably necessary for state functionality, they also create
potential loopholes through which individual privacy rights may be compromised. In par
ticular, these provisions can legitimise state-sanctioned surveillance and other forms of
data misuse by government agencies, thereby weakening the integrity of the broader
data protection regime.
Kenya’s broad provisions raise concerns about the potential of state surveillance in a
political climate grappling with heightened concerns of counterterrorism and national
security. The nation’s geopolitical positioning, with proximity to Somalia serving as Al-
Shabaab’s stronghold, coupled with extremist threats, has facilitated an increase in
state surveillance measures.37 As a result, individual data protection is likely to be subor
dinated to security concerns, whereby transparency or oversight on personal data use by
government agencies is limited.38 Similarly, balancing privacy and security concerns,
Nigeria’s framework is shaped by a different security dynamic. The threat of insurgencies
in the Northeast and widespread concerns about political instability have elevated
national security above privacy considerations in its governance framework (Privacy Inter
national 2018).39 The framework’s integrity is further strained by a lack of transparency on
the use of personal data, with various civil society organisations demanding clarity in the
use and raising concerns on the potential for abuse in the context of political dissent and
human rights activism.40
This tension highlights a core issue in the privacy discourse on assessing the balance
of individual rights and the need for collective security. Although explicitly providing
safeguards, the lack of transparency around the security exemptions brings the
overall integrity of the enforcement framework into question. As Privacy International
observed, this covert subversion of privacy under the guise of security in the Global
South has largely been driven by a political need, particularly during election cycles,
when incumbent governments seek to deliberately restrict opposition figures or acti
vists (Privacy International 2018).41
rectification and erasure. The absence of clear guidance for businesses on the timelines
for these provisions substantially weakens the framework risking overbearing and misal
location of resources in pursuit of issues rather well addressed through time-bound
obligations.
that are not aligned with the principles of necessity and proportionality. This regulatory
ambiguity weakens the protective function of data protection laws and may result in
inconsistent enforcement and diminished accountability. As such, the development of
clear, context-specific criteria and oversight mechanisms is essential to ensure that
claims of legitimate interest do not erode individuals’ privacy rights.
represents a significant step toward enhancing its reach and responsiveness.45 The tran
sition from a centralised national regulator to a more decentralised model with regional
offices signals the emergence of a more robust institution capable of swiftly addressing
data protection infringements.
Nonetheless, this institutional evolution is resource-intensive, necessitating sustained
political commitment to ensure that data protection remains a national priority amid
competing policy agendas. This is especially pertinent in light of developments such as
the Finance Bill 2024, which underscores the ongoing tension between economic
policy imperatives and the need to safeguard fundamental rights.46 Therefore, political
reassurances and budgetary allocations that reflect the strategic importance of data gov
ernance are essential to consolidate the ODPC’s gains and ensure long-term regulatory
efficacy.
Nigeria’s enforcement landscape, though relatively young, faces similar challenges to
Kenya’s ODPC in its formative years. The agency faces resource limitations, particularly in
terms of funding and expertise, coupled with the vast and heterogeneous economic
sectors, presenting a source of potential enforcement challenges. However, having
shifted from a system riddled with regulatory fragility, the concrete implications of enfor
cement under the NDPA framework offer a deterrent framework which bolsters its inves
tigative and corrective measures. Additionally, uniform application of the NDPA on both
informal and multinational corporations will require a flexible but effective enforcement
strategy. Ideally, this would take the form of the NDPC prioritising high-impact cases
paired with support for capacity building targeted at smaller enterprises, pivotal
towards the consolidation of its enforcement powers. Critical to the solidification of its
position is the need to have personnel with the capacity to carry out the mandate of
the agency. The personnel, coupled with technical tools to facilitate auditing and enfor
cement, will be able to fulfil the agency’s broad enforcement mandate. Theoretically, this
facilitates effective governing of data in Nigeria’s fast-paced digital economy. Practically,
the NDPA provides an enforcement ‘apparatus’ that hinges on a robust legislative backing
to compel compliance; the NDPC’s decisive need moving forward will be to balance the
framework against competing interests such as national security and economic policy.
fear of political reprisal when enforcing the law against incumbent corporations or state
actors. This is demonstrated in the increasing capacity to engage in high-profile enfor
cement actions, such as executing data impact assessments on government agencies
and the scrutiny of firms processing significant amounts of personal data.51 Addition
ally, with an expansive mandate covering all aspects of data processing, compliance
monitoring, complaints handling, and the issuance of penalties, the ODPC’s strong
legal foundation and a higher degree of legitimacy facilitated the decentralisation of
powers to constituent offices.
In contrast to the Kenyan model, the NDPC’s autonomy is threatened by underfund
ing and limited technical capacity. The budgetary allocation to the NDPC presents a
privacy enforcement framework that is operationalised through funding from other sec
toral regulators, unlike in Kenya, where the national assembly directly allocates funding
for the authority.52 The ‘agency dependent’ budgetary provisions risk exerting influence
over the NDPC by the other sectoral regulators, rather than coordination in the regu
lation of the digital economy, raising concerns on the NDPC’s ability to compel compli
ance. Ideally, the NDPC should ensure there is no overlapping of regulatory interests,
which may create business uncertainty, thus reducing the overall effectiveness of
privacy enforcement arising from the divergent approaches of the agencies. Perhaps
looking into framing an outlook similar to Kenya’s ODPC will ensure the enforcement
framework benefits from a more structured financing agreement, as within the frame
work of the DPA.53
in digital literacy, particularly between the rural and urban populations (Okello 2023).
While the proliferation of tech-led advancement, compounded with mobile penetration
rates, suggests a digitally savvy population, the reality is more nuanced. Whereas cities
experiencing the burgeoning of the tech sector are relatively informed, the rural citizens
are largely unaware of their data protection rights. Moreover, the marginalised few who
are aware often lack the resources or institutional support to exercise their rights
effectively.
Beyond geographical situs, digital literacy is also shaped by the socioeconomic status
of the citizens (Kerkhoff and Makubuya 2022). Wealthier urban populations are better
positioned to access information about data protection and, therefore, are more likely
to assert their rights. On the other hand, the marginalised, most vulnerable to data exploi
tation, are less likely to exercise their rights under the data protection framework.
Although more profound than the Kenyan enforcement sphere, the Nigerian context is
exacerbated by the larger population and greater digital divide (Ajonbadi, Olawoyin,
and Adekoya 2023). Mirroring the rural realities of the Kenyan population, public aware
ness of the NDPA and digital literacy remains low. As a result, many citizens are unaware
of the rights granted under the NDPA framework and thus cannot seek redress for data
infringement. The low levels of public engagement can create a passive enforcement
environment where violators go unreported and sanction-free, thereby weakening the
effectiveness of the privacy protection framework. Furthermore, the risk of creating an
‘enforcement framework taxonomy,’ where the full benefits of data protection are dispro
portionately felt by those with the resources to engage with the legal system actively, is
best addressed in the implementing stages of structures of enforcement.54
Although ultimately ensuring sound enforcement since the authorities shape the
enforcement regime to their image, they face the challenge of building up an enforce
ment regime from where it was non-existent, rather than building upon, which is
resource-intensive. Furthermore, individuals are less likely to know of their privacy
rights or have the means to lodge complaints, which consolidates the issue of many
small and medium enterprises operating at the periphery of enforcement reach. In
Nigeria, the issue is severe, arising from a more geographically dispersed population
with a significant proportion of the economy operating in the informal sector.
faces the challenges of the government subjecting it to broader policy prioritising econ
omic growth and digital innovation over strict enforcement. This is compounded by the
creation of the Council to which the Commissioner is subordinate, whereby the decision-
making process relies on the Council’s deliberations. Conversely, the Commissioner’s
powers are meant to be consolidated by the Council, whereby the Commissioner’s
office is strategically placed as the sole formal decision maker. Furthermore, the strategic
direction of the NDPC should be vested on the Commissioner, with the council acting as a
collective decision-making management board. Ideally, the council should operate on a
majority vote principle on matters where a consensus is elusive, with the Commissioner
being capable of making decisions contrary to the Council’s view. This decision-making
model, in line with good practice, having the commissioner positioned as the chair
rather than the secretary, would have the effect of ensuring that the independence of
the NDPC is inviolable.
represent a substantial undervaluation. Such a reassessment would not only enhance the
agencies’ ability to meet their financial obligations but also support the scaling up of their
technical and organisational capacities. Additionally, the discussion advocates for the
ODPC to adopt a tiered fining structure – similar to that employed by Nigeria – where
data handlers are categorised according to their significance (e.g. high or low impor
tance). This would allow for the application of administrative discretion on a case-by-
case basis instead of relying on a uniform approach.
Given the persistently low levels of public awareness and digital literacy across the
country, particularly within rural and low-income areas where the informal sector con
tinues to expand, the allocation of enforcement resources remains a significant challenge.
In this context, both the NDPC and ODPC are entrusted with the critical responsibility of
promoting public awareness and fostering compliance. Therefore, these agencies must
intensify their outreach through targeted public awareness campaigns, developed in col
laboration with local communities. Under the leadership of the Commissioner, the NDPC
could consider establishing regional engagement and enforcement hubs, a model already
being explored in Kenya as its enforcement mandate becomes more firmly established.
Such a framework would play a crucial role in bridging the enforcement gap, ensuring
that businesses operating within the informal and rural sectors are brought within the
ambit of the data protection regulatory regime.
The analysis further reveals that institutional capacity to enforce compliance remains a
significant challenge, particularly in the private sector. Criticism often stems from the per
ceived disproportionate focus of regulatory agencies on larger, more visible corporations,
which may result in underenforcement among smaller or less prominent entities. Both
countries, therefore, face an urgent need to strengthen institutional capacity – not only
through increased budgetary allocations but also through enhanced collaboration with
international partners and civil society organisations. Such efforts would contribute to
the development of robust technical and organisational capabilities, thereby ensuring
that enforcement mechanisms remain effective in a rapidly evolving digital environment.
Moreover, recognising that regulatory coherence is inherently dynamic and must evolve
in tandem with technological advancements, Data Protection Authorities (DPAs) should
institutionalise regular monitoring and evaluation mechanisms to assess and refine the
effectiveness of their enforcement frameworks over time.
Finally, the analysis underscores the critical role of civil society organisations and con
sumer advocacy groups in promoting data privacy awareness, advocating for robust
enforcement, and serving as regulatory watchdogs. In Kenya, the contributions of the
Kenya ICT Action Network (KICTANet) have been particularly noteworthy, with sustained
engagement with the Office of the Data Protection Commissioner (ODPC) enhancing
transparency in enforcement practices and strengthening the protection of data subjects’
rights (Varga 2012). Comparable efforts in Nigeria are exemplified by the work of the Para
digm Initiative, which has been at the forefront of digital rights advocacy (Bygrave 2014).
Although such initiatives remain relatively limited and the broader landscape of consumer
advocacy is still underdeveloped, there is growing public trust in regulatory institutions.
This is reflected in the increased public engagement on matters related to data privacy,
indicating a positive trajectory toward stronger citizen participation and accountability
in data governance.
20 I. JUMA AND B. FATUROTI
5.1. Conclusion
Based on the comparative analysis, several key recommendations emerge for strengthen
ing privacy enforcement in both Kenya and Nigeria, as well as for other African countries
aiming to enhance their data protection regimes. This is particularly crucial as the conti
nent continues its rapid digital transformation, making robust data protection frameworks
increasingly indispensable. As two of Africa’s leading economies, Kenya and Nigeria are
uniquely positioned to set a regional precedent in privacy enforcement. While Kenya
has made notable strides, particularly through the operationalisation of the Office of
the Data Protection Commissioner (ODPC), Nigeria’s data protection framework
remains in need of significant reform to improve its overall effectiveness. The experiences
and lessons derived from these two jurisdictions can serve as valuable reference points for
other African nations seeking to safeguard personal data in an increasingly data-driven
global context. Moving forward, it is imperative to prioritise the development of
strong, independent regulatory institutions, ensure sufficient resource allocation, and cul
tivate a culture of compliance across both public and private sectors. Only through
addressing these foundational challenges can African countries fully realise the promise
of their data protection laws and uphold the rights of individuals in the digital age.
Notes
1. Angola, Benin, Chad, Congo, Egypt, Gabon, Gambia, Guinea-Bissau, Lesotho, Mauritania,
Namibia, Niger, São Tomé and Príncipe, Senegal, and Zambia.
2. UK Government, ’Transforming for a Digital Future: 2022–2025 Roadmap for Digital and Data’
(UK Government, updated September 2023) [Link]
roadmap-for-digital-and-data-2022-to-2025/transforming-for-a-digital-future-2022-to-2025-
roadmap-for-digital-and-data accessed 24 September 2024.
3. GSMA, The Mobile Economy: Sub-Saharan Africa 2024 (GSMA 2024) [Link]
[Link]/pdf/GSMA_ME_SSA_2024_Web.pdf.
4. Kenya Information and Communications Act No. 2 Of 1998, s31; Kenya Information and Com
munications (Consumer Protection) Regulations, 2010.
5. The HIV and Aids Prevention and Control Act Chapter 246A, V.
6. Credit Reference Bureau Regulations, 2013.
7. The Prevention of Terrorism Act Chapter 59B s35(3a); The National Intelligence Service Act,
2012 s36.
8. UNCTAD, Harmonizing Cyberlaws and Regulations: The Experience of the East African Com
munity (UNCTAD 2012) 17 [Link]
[Link] accessed 24 September 2024.
9. ibid 21.
10. Constitution of Kenya, 2010 Art31.
11. DPA s4.
12. DPA s26
13. DPA VII.
14. The Data Protection Act Subsidiary Legislation NO. 24 OF 2019.
15. Nigeria Data Protection Regulation 2019
16. NITDA Act, 2007 s6(a)(c).
17. NITDA, Nigeria Data Protection Regulation Performance Report 2019–2020 9.
18. DPA s49.
19. NDPA s42.
20. DPA s32; NDPA s26.
INTERNATIONAL REVIEW OF LAW, COMPUTERS & TECHNOLOGY 21
21. General Data Protection Regulation (EU) 2016/679 of The European Parliament and of The
Council Art 4(11) rec32.
22. DPA s19(e); NDPA s29(c).
23. DPA s49; NDPA s42.
24. Office of the Data Protection Commissioner (ODPC), ’Determinations’ (ODPC 2024) https://
[Link]/determinations/ accessed 24 September 2024.
25. Nigeria Data Protection Commission, Annual Report 2023 (NDPC 2023) 6 [Link]
Files/[Link] accessed 24 September 2024.
26. Information Regulator (South Africa), ’Media Statement: Infringement Notice Issued to the
Department of Justice and Constitutional Development’ 4 July 2023 (Information Regulator
2023) [Link]
[Link]
accessed 24 September 2024.
27. General Data Protection Regulation (EU) 2016/679 rec8.
28. Dongyeon Kim et al, ’Willingness to Provide Personal Information: Perspective of Privacy
Calculus in IoT Services’ (2019) [Link] accessed 24
September 2024; Sasha Romanosky & Alessandro Acquisti, ’Privacy Costs and Personal
Data Protection: Economic and Legal Perspectives’ (2009) 24 Berkeley Tech LJ 1061, 1063;
Nir Kshetri, ’Big Data’s Role in Expanding Access to Financial Services in China’ Volume 36,
Issue 3, (June 2016) 297 [Link] accessed 24 Septem
ber 2024.
29. DPA s56(5).
30. GAID Art40(13).
31. George I Balch, ’The Stick, the Carrot, and Other Strategies: A Theoretical Analysis of Govern
mental Intervention’ (1980) 2 Law & Policy 35 [Link]
tb00203.x accessed 24 September 2024; Hazel Grant and Helen Crowther, ’How Effective
Are Fines in Enforcing Privacy?’ in David Wright and Paul De Hert (eds), Enforcing Privacy
(Springer 2016) vol 25, Law, Governance and Technology Series 290 [Link]
1007/978-3-319-25047-2_13 accessed 24 September 2024.
32. DPA s63.
33. ODPC, ‘ODPC TO Audit 40 Digital Lenders and Issues Enforcement Notice Against a Health
Service Provider’ (ODPC 2023) [Link]
[Link] accessed 24 September
2024; NDPC 2023 n36 20.
34. ODPC, ’ODPC Consolidated Complaints No. 1843 of 2023 (ODPC 2023) [Link]
ke/wp-ontent/uploads/2024/02/ODPC-CONSOLIDATED-COMPLAINTS-NO.1843-OF-2023-197
[Link] accessed 24 September 2024.
35. NDPC 2023 n36 20.
36. For example, See George Orwell, 1984.
37. Privacy International, Track, Capture, Kill: Inside Communications Surveillance and Counterter
rorism in Kenya (Privacy International 2017) [Link]
files/2017-10/track_capture_final.pdf accessed 24 September 2024.
38. Victor Kapiyo, Cherie Oyier, and Francis Monyango, Surveillance Laws and Technologies
Used in Countering Terrorism and Their Potential Impact on Civic Space (Kenya ICT Action
Network (KICTANet), January 2024) [Link] accessed 24 Septem
ber 2024.
39. Privacy International, The Right to Privacy in Nigeria: Stakeholder Report for the 31st Session
of the UPR (Privacy International 2018) [Link]
2018-05/UPR_The%20Right%20to%20Privacy_Nigeria.pdf accessed 24 September 2024.
40. Institute of Development Studies, Nigeria Spending Billions of Dollars on Harmful Surveillance
of Citizens (IDS 2023) [Link]
dollars-on-harmful-surveillance-of-citizens/ accessed 24 September 2024.
41. Privacy International n60.
22 I. JUMA AND B. FATUROTI
Disclosure statement
No potential conflict of interest was reported by the author(s).
ORCID
Bukola Faturoti [Link]
References
African Union. 2014. African Union Convention on Cyber Security and Personal Data Protection.
Malabo: African Union. Accessed November 24, 2024. [Link]
convention-cyber-security-and-personal-data-protection.
Agência de Protecção de Dados. 2024. APD Multa Africell em 150 Mil Dólares Norte Americanos por
Violação da Lei de Protecção de Dados Pessoais (LPDP). Luanda: APD. Accessed January 5, 2024.
[Link]
violacao-da-lei-de-proteccao-de-dados-pessoais-lpdp/.
Ajonbadi, H. A., F. S. Olawoyin, and O. D. Adekoya. 2023. “The Anathema of Digital Divide in the
Nigerian Higher Education: Lessons from the Pandemic.” In Beyond the Pandemic Pedagogy of
Managerialism, edited by B. S. Nayak and K. Appleford, 189–208. Cham: Palgrave Macmillan.
[Link]
INTERNATIONAL REVIEW OF LAW, COMPUTERS & TECHNOLOGY 23
Ayres, I., and J. Braithwaite. 1992. Responsive Regulation: Transcending the Deregulation Debate. New
York: Oxford University Press.
Babalola, Olumide. 2022. “Nigeria’s Data Protection Legal and Institutional Model: An Overview.”
International Data Privacy Law 12 (1): 44–52. Accessed September 21, 2024. [Link]
1093/idpl/ipab023.
Babb, S. 2013. “The Washington Consensus as Transnational Policy Paradigm: Its Origins, Trajectory
and Likely Successor.” Review of International Political Economy 20 (2): 268–297. [Link]
10.1080/09692290.2011.640435.
Balch, George I. 1980. “The Stick, the Carrot, and Other Strategies: A Theoretical Analysis of
Governmental Intervention.” Law & Policy 2 (1): 35–60. [Link]
1980.tb00203.x.
Baldwin, Robert. 1995. “Making Rules Work.” Rules And Government (Oxford; online edn, Oxford
Academic, 31 Oct. 2023). Accessed April 10, 2025. [Link]
003.0006.
Begazo, T., C. Stinshoff, H. Niesten, G. Pop, R. Chen, and G. Coelho. 2024. “Regulating the Digital
Economy in Africa: Managing Old and New Risks to Economic Governance for Inclusive
Opportunities.” World Bank Publications - Reports 41620, The World Bank Group. https://
[Link]/curated/en/099051924165027814/pdf/P1724171bc956a07d1bfd61
[Link].
Braithwaite, J. 2011. “The Essence of Responsive Regulation.” University of British Columbia Law
Review 44:475.
Bygrave, Lee Andrew. 2014. “Data Privacy Law: An International Perspective.” (Oxford; online edn,
Oxford Academic, 16 Apr. 2014). Accessed April 16, 2025. [Link]
9780199675555.001.0001.
Case C-511/18 La Quadrature du Net and Others v Premier Ministre and Others [2020] ECLI:EU:
C:2020:791.
Case C-623/17 Privacy International v Secretary of State for Foreign and Commonwealth Affairs
[2020] ECLI:EU:C:2020:790.
Castells, M. 1998. End of Millennium Vol. 3 of The Information Age: Economy, Society, and Culture.
Oxford: Blackwell.
Central Bank of Kenya. 2013. Credit Reference Bureau Regulations. Nairobi: Government Printer.
Cho, H., M. Rivera-Sánchez, and Sun Sun Lim. 2009. “A Multinational Study on Online Privacy: Global
Concerns and Local Responses.” New Media & Society 11 (3): 395–416. [Link]
1461444808101618.
Curtiss, Tiffany. 2018. “Privacy Harmonization and the Developing World: The Impact of the EU’s
General Data Protection Regulation on Developing Economies.” Washington Journal of Law,
Technology & Arts 13:143. Accessed September 14, 2024. [Link]
cgi/[Link]?article=1268&context=wjlta.
Data Protection Act No. 24 of 2019 (Kenya)
Gasser, U., and W. Schulz. 2015. “Governance of Online Intermediaries: Observations from a Series of
National Case Studies.” Korea University law review 18: 11. [Link]
handle/1/16140636/Berkman_2015-5_final.pdf?sequence=1&isAllowed=y.
General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council.
Grant, H., and H. Crowther. 2016. “How Effective Are Fines in Enforcing Privacy?” In Enforcing Privacy.
Law, Governance and Technology Series(), edited by D. Wright and P. De Hert, Vol. 25, 287–305.
Cham: Springer. [Link]
GSMA. 2024. The Mobile Economy. London: GSMA. Accessed October 4, 2024. [Link]
com/solutions-and-impact/connectivity-for-good/mobile-economy/wp-content/uploads/2024/
02/[Link].
Hage, J. 2018. “Of Norms.” In Handbook of Legal Reasoning and Argumentation, edited by G.
Bongiovanni, G. Postema, A. Rotolo, G. Sartor, C. Valentini, and D. Walton. Dordrecht: Springer.
[Link]
24 I. JUMA AND B. FATUROTI
IAPP. 2023. “International Association of Privacy Professionals (IAPP-EY) Privacy Governance Report
2023.” (IAPP). Accessed September 24, 2024. [Link]
governance-full-report/.
IDS (Institute of Development Studies). 2023. “Nigeria Spending Billions of Dollars on Harmful
Surveillance of Citizens.” Accessed September 2, 2024. [Link]
nigeria-spending-billions-of-dollars-on-harmful-surveillance-of-citizens/.
Information Regulator (South Africa). 2023 July 4 “Media Statement: Infringement Notice Issued to
the Department of Justice and Constitutional Development.“ 2023 (Information Regulator).
Accessed July 12, 2024. [Link]
STATEMENT-INFRINGEMENT-NOTICE-ISSUED-TO-THE-DEPARTMENT-OF-JUSTICE-AND-CONSTITU
[Link].
Jordana, J., David Levi-Faur, and X. Fernández-i-Marín. 2011. “The Global Diffusion of Regulatory
Agencies: Channels of Transfer and Stages of Diffusion.” Comparative Political Studies 44 (10):
1343. Accessed October 18, 2024. [Link]
Kapiyo, V., C. Oyeir, and F. Moyango. January 2024. Surveillance Laws and Technologies Used in
Countering Terrorism and Their Potential Impact on Civic Space. Nairobi: Kenya ICT Action
Network (KICTANet). Accessed September 2, 2024. [Link]
Kenya Information and Communications (Consumer Protection) Regulations, 2010.
Kenya Information and Communications Act No. 2 Of 1998
Kerkhoff, Shea N., and T. Makubuya. 2022. “Professional Development on Digital Literacy and
Transformative Teaching in a Low-Income Country: A Case Study of Rural Kenya.” Reading
Research Quarterly 57 (1): 287–305. Accessed October 28, 2024. [Link]
Kim, D., K. Park, Y. Park, and J. Ahn. 2019. “Willingness to Provide Personal Information: Perspective
of Privacy Calculus in IoT Services.” Computers in Human Behavior 92:273–281. [Link]
1016/[Link].2018.11.022.
Kosti, N., D. Levi-Faur, and G. Mor. 2019. “Legislation and Regulation: Three Analytical Distinctions.”
The Theory and Practice of Legislation 7 (3): 169–178. [Link]
1736369.
Kshetri, N. 2016. “Big Data’s Role in Expanding Access to Financial Services in China.” International
Journal of Information Management 36 (3): 297–308. Accessed January 6, 2024. [Link]
1016/[Link].2015.11.014.
Mashaw, J. L. 2005. “Between Facts and Norms: Agency Statutory Interpretation as an Autonomous
Enterprise.” University of Toronto Law Journal 55 (3): 497–533. [Link]
0019.
Murphy, M. H. 2018. Surveillance and the Law: Language, Power and Privacy. 1st ed. London:
Routledge. [Link]
NDPA (Nigeria Data Protection Act). 2023.
NDPC (Nigeria Data Protection Commission). 2023. Annual Report 2023. 6. Accessed September 24,
2024. [Link]
NDPC (Nigeria Data Protection Commission). 2023. Strategic Roadmap and Action Plan (SRAP) 2023-
2027. Accessed September 24, 2024. [Link]
Nigeria Data Protection Regulation. 2019.
NITDA (National Information Technology Development Agency Act). 2007.
NITDA (National Information Technology Development Agency). n.d. Nigeria Data Protection
Regulation Performance Report 2019-2020.
ODPC (Office of the Data Protection Commissioner). 2021. Strategic Plan 2022/3–2024/5. 24–25.
Accessed September 24, 2024. [Link]
[Link].
ODPC (Office of the Data Protection Commissioner). 2022. Press Statement on IEBC Verification of
Voting Particulars Portal. Nairobi: ODPC. Accessed September 24, 2024. [Link]
ke/wp-content/uploads/2024/02/PRESS-STATEMENT-ON-IEBC-VERIFICATION-OF-VOTING-
[Link].
ODPC (Office of the Data Protection Commissioner). 2024. “Determinations.” ODPC. Accessed
September 24, 2024. [Link]
INTERNATIONAL REVIEW OF LAW, COMPUTERS & TECHNOLOGY 25
ODPC (Office of the Data Protection Commissioner) Kenya. 2023. “ODPC TO Audit 40 Digital Lenders
and Issues Enforcement Notice Against a Health Service Provider.” Accessed September 24, 2024.
[Link]
[Link].
ODPC (Office of the Data Protection Commissioner) Kenya. 2023. “ODPC Consolidated Complaints
No. 1843 of 2023.” Accessed September 24, 2024. [Link]
2024/02/ODPC-CONSOLIDATED-COMPLAINTS-NO.1843-OF-2023-1971199120062025-2292-OF-
[Link].
ODPC (Office of the Data Protection Commissioner) Kenya. 2023. CS Eliud Owalo Launches the Office
of the Data Protection Commissioner’s First Regional Office in Mombasa. Nairobi: ODPC. Accessed
September 24, 2024. [Link]
Launches-the-Office-of-the-Data-Protection-Commissioners-First-Regional-Office-in-Mombasa.
pdf.
ODPC (Office of the Data Protection Commissioner) Kenya. 2023. PS Eng. John Tanui MBS Launches
the Office of the Data Protection Commissioner’s Second Regional Office in Nakuru. Nairobi: ODPC.
Accessed September 24, 2024. [Link]
John-Tanui-MBS-Launches-the-Office-of-the-Data-Protection-Commissioners-Second-Regional-
[Link].
Okello, F. 2023. Bridging Kenya’s Digital Divide: Context, Barriers and Strategies. Waterloo: CIGI. DPH-
[Link] ([Link]). Accessed September 24, 2024.
Posner, R. A. 1978. “The Right of Privacy.” Sibley Lecture Series 22: 404.
Privacy International. 2017. Track, Capture, Kill: Inside Communications Surveillance and
Counterterrorism in Kenya. London: Privacy International. Accessed December 20, 2024. https://
[Link]/sites/default/files/2017-10/track_capture_final.pdf.
Privacy International. 2018. The Right to Privacy in Nigeria: Stakeholder Report for the 31st Session of
the UPR. London: Privacy International. Accessed September 24, 2024. https://
[Link]/sites/default/files/2018-05/UPR_The%20Right%20to%20Privacy_
[Link].
Quach, S., P. Thaichon, K. D. Martin, et al. 2022. “Digital Technologies: Tensions in Privacy and Data.”
Journal of the Academy of Marketing Science 50 (6): 1299–1323. [Link]
022-00845-y.
Radovanović, D., C. Holst, S. Belur, R. Srivastava, G. Houngbonon, E. Le Quentrec, J. Miliza, A. Winkler,
and J. Noll. 2020. “Digital Literacy Key Performance Indicators for Sustainable Development.”
Social Inclusion 8 (2): 151–167. [Link]
Republic of Kenya. 2010. The Constitution of Kenya. Nairobi: Government Printer.
Republic of Kenya. 2012. The National Intelligence Service Act. Nairobi: Government Printer.
Republic of Kenya. 2012. The Prevention of Terrorism Act, Cap. 59B. Nairobi: Government Printer.
Republic of Kenya. 2024. The Finance Bill. Nairobi: Government Printer.
Roberts, T., J. Gitahi, P. Allam, L. Oboh, O. Oladapo, Gifty Appiah-Adjei, Amira Galal, et al. 2023.
“Mapping the Supply of Surveillance Technologies to Africa: Case Studies from Nigeria, Ghana,
Morocco, Malawi, and Zambia.” The Institute of Development Studies and Partner
Organisations. Online resource. [Link]
Romanosky, Sasha, and Alessandro Acquisti. 2009. “Privacy Costs and Personal Data Protection:
Economic and Legal Perspectives.” Berkeley Technology Law Journal 24 (3): 1061. [Link]
com/abstract=1522605.
Salami, E. 2020. “Fingerprint Generated Data: An Evaluation of the Efficacy of the Nigerian Data
Protection Regulation.” Computer and Telecommunications Law Review 26 (7): 184–191.
Sassen, S. 2007. A Sociology of Globalization (Contemporary Societies. 1st edn. New York: W.W. Norton
& Company.
Solove, Daniel J. 2024. “Murky Consent: An Approach to the Fictions of Consent in Privacy Law.”
Boston University Law Review 104:593.
Solove, Daniel J., and Paul M Schwartz. 2021. Information Privacy Law. 7th ed. Boston: Wolters
Kluwer.
The Data Protection Act Subsidiary Legislation No. 24 of 2019. – Kenya
26 I. JUMA AND B. FATUROTI
The HIV and Aids Prevention and Control Act Chapter 246A – Kenya
UK Government. updated September 2023. Transforming for a Digital Future: 2022 to 2025 Roadmap
for Digital and Data. London: UK Government. Accessed September 24, 2024. [Link]
uk/government/publications/roadmap-for-digital-and-data-2022-to-2025/transforming-for-a-
digital-future-2022-to-2025-roadmap-for-digital-and-data.
UNCTAD (United Nations Conference on Trade and Development). 2012. Harmonizing Cyberlaws
and Regulations: The Experience of the East African Community. Geneva: UNCTAD. 17. Accessed
September 24, 2024. [Link]
Varga, C. 2012. “Theory of Law: Norm, Logic, System, Doctrine & Technique in Legal Processes, with
Appendix on European Law 12 (Szent István Társulat).”.
Warren, S. D., and L. D. Brandeis. 1890. “The Right to Privacy.” Harvard Law Review, 4 (5): 193–220.
[Link]