

Digital Rights at a Glance
Senegal, an African pioneer in digital governance and the first country to ratify the Malabo Convention, has had a comprehensive legal framework in place since 2008; however, its effectiveness remains limited by outdated legislation, insufficient institutional resources, and implementation that is still only partial.

Key Commitments
Malabo Convention 🟢
Senegal was the first country to ratify the Malabo Convention in 2016.
Budapest Convention 🟢
Senegal has been a party to the Budapest Convention since 2017.

Data Protection Law
Senegalese Law No. 2008-12 of January 25, 2008, on the protection of personal data is one of the first African laws on data protection; it requires that data processing be subject to prior notification or authorisation.
Existence of a data protection authority 🟢
The Commission for the Protection of Personal Data (CDP) was established by the 2008 Data Protection Act. It is active, and its chairperson is publicly leading the debate on the need to reform the existing framework.

Cybercrime Law
Law No. 2008-11 of January 25, 2008, on cybercrime defines and classifies offenses related to information technology and networks as criminal offenses.

State of Play
Senegal stands out for the early adoption and comprehensiveness of its legal framework: as early as 2008, the country regulated digital activities (electronic transactions, cybercrime, personal data, and cryptocurrency), established a data protection authority, and in 2016 became the first country to ratify the Malabo Convention. Seventeen years later, the law of August 26, 2025, on access to information was adopted—a long-standing commitment by Senegal as part of the Open Government Partnership and considered a “historic turning point.”
However, this legal framework needs to be updated in light of recent developments. A revision of the 2008 law has been in the works for several years, but has not yet been finalised. New challenges related to generative artificial intelligence and cross-border data flows are fueling calls for a “Malabo+.” And in August 2026, the National Assembly considered a bill to strengthen the protection of critical infrastructure and establish a national cybersecurity authority.
Gaps still remain in the enforcement of these laws: the absence of implementing regulations for the law on access to information; a lack of technical, human, and budgetary resources to enforce the 2008 law; a lack of sufficiently deterrent penalties and modern reporting mechanisms, and, finally, inadequate protection for minors online.
Recommendations
1. Accelerate and finalise the reform of Law No. 2008-12, prioritising its alignment with the Malabo Convention and updated standards (AI, biometrics, big data, cross-border data flows), with a public and binding legislative timeline.
2. Strengthen the resources and independence of the Personal Data Protection Commission (CDP)—including its budget , staffing, and enforcement powers—to match the current volume of digital data processing, in order to move from superficial compliance to effective enforcement.
3. Adopt a national plan to protect minors online, based on the revised law, that involves families, schools, and online platforms, to address the gaps identified in parental controls and children’s digital safety.
4. Ensure the full implementation of Law No. 2025-15 on access to information by promptly publishing its implementing regulations and establishing the independent body responsible for monitoring its implementation.
5. Establish a national system for reporting and addressing cyberviolence, particularly gender-based cyberviolence, involving the CDP, a specialized police unit, and relevant civil society organisations.
Digitalise Youth partners who contributed to this section:Association des Femmes Sénégalaises des TIC (FESTIC)
Association Sénégalaise des Bibliothécaires, Archivistes et Documentalistes (ASBAD)
