Skip to the content
Global Data RulesData governance rules, country by country

Senegal

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: MediumEnforcement: Active

Senegal has had a personal data protection law since 2008 and a regulator that genuinely works. Data may go abroad, but only to a country that protects it well enough, and the regulator has to be told. Banks are the real trap: their data must stay reachable inside the West African monetary union. A cybersecurity bill now in parliament would force public bodies to host data at home.

Data governance in Senegal

The eight things that decide how you handle data about people in Senegal. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it can reach a company with no office in Senegal. The law applies to anyone handling personal data using equipment sited in Senegal, wherever the company itself is based. A company based abroad that uses equipment here must name a representative who is established in Senegal. There is no company size or revenue level below which you escape.

High confidenceNational rulesAppoint a local representativeLocal representative

Where the data is allowed to live

In general yes, with paperwork. Data may be sent abroad if the receiving country gives people a good enough level of protection, and the move has to be notified to the regulator. If the destination does not measure up, you need the regulator's permission. Two areas are much tighter than the headline: banking and credit reporting, where the data has to stay reachable inside the West African monetary union.

Medium confidenceYes, with paperworkAllowlistBankingPaymentsTelecomsGovernmentHealth and social care

Sending data out of the country

The model is an approved-destinations list that was never published. You have to judge for yourself whether the receiving country protects data well enough, and tell the regulator before the data moves. If the country does not measure up, you can still ask the regulator to approve the transfer because of the safeguards you have built. Narrow exceptions cover one-off transfers, clear consent, contracts and emergencies.

Medium confidenceAllowlistOfficial 'this country is safe' decisionGovernment sign-off neededExplicit consentNeeded for a contractSomeone's life is at riskLegal claimsImportant public interest

The regulator, and whether it actually acts

The Commission for the Protection of Personal Data, known in Senegal by its French initials CDP, is the main regulator. It is real and working. It publishes activity figures every three months, runs surprise inspections, holds hearings, and orders companies to take down cameras. In the first three months of 2026 it handled 317 files and 9 complaints. What it almost never does is hand out cash fines.

Medium confidenceActiveFixed maximum fineOrder to stop

How long you must keep it — and when to delete it

There is no single national table of retention periods. The ceiling comes from the data protection law: keep personal data only as long as you need it for the purpose you collected it for, then delete it. The main floors come from elsewhere. Business and accounting records must be kept for ten years under the regional business law treaty, and telecom operators may hold technical data for up to two years.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep logs

If something goes wrong

There is no general duty to report a data breach in Senegal. We checked on 19 August 2026 and found no deadline, in hours or otherwise, in the 2008 data protection law, either to the regulator or to the people affected. Banks must tell their supervisor about serious problems, but no published deadline in hours was found. Two changes are coming that would add reporting duties.

Medium confidenceReport breaches to the regulatorReport cyber incidentsProposed

What catches people out

The traps in Senegal are not about fines, they are about permission slips and cameras. Almost every use of personal data has to be filed with the regulator before you start, and some uses need written permission first. The regulator turns up unannounced. And data offences sit in the criminal code, so a person can be prosecuted, not just a company told off.

Medium confidenceRegister or notifyAppoint a local representativeCriminal liabilityBiometric dataHealth data

What's changing next

One big thing is close. A bill on protecting critical information infrastructure and digital security was approved by the government on 17 June 2026 and passed a parliamentary committee on 13 August 2026. It still needs a vote in the full chamber, so it is not law. It would create a national cybersecurity authority and make local hosting of public sector data compulsory.

Medium confidenceProposedDraft lawGovernment policy document

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Circulaire n° 04-2017/CB/C relative à la gestion des risques dans les établissements de crédit et compagnies financières de l'UMOA

Regulator directive · Circulaire n° 04-2017/CB/C, article 33

In forceA copy must stay

The hardest data location rule that touches Senegal. Banks and financial holding companies must keep all their data available inside the West African monetary union, with the servers holding that data in the Union or, failing that, backup servers in the Union. Outsourcing contracts must go to the banking supervisor before they are signed.

In force since 2 July 2018

Enforced by Banking Commission of the West African Monetary Union

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence
Finance

Instruction n° 009-06-2015 relative aux dispositifs de sécurité des systèmes d'information des bureaux d'information sur le crédit

Directly binding regulation · Instruction n° 009-06-2015, article 8

In forceA copy must stay

Credit bureaus serving Senegal must keep their backup copies on a site in another country of the West African monetary union. The effect is that a full copy of the credit file stays inside the region even if other processing happens elsewhere.

In force since 1 June 2015

Enforced by Central Bank of West African States

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence
Telecoms

Loi n° 2018-28 du 12 décembre 2018 portant Code des communications électroniques

Act of parliament · Loi n° 2018-28

In forceYes, with paperwork

Telecom operators in Senegal must identify every subscriber, protect the confidentiality of communications, and may hold technical data for up to two years. We found no requirement to keep telecom data inside Senegal, checked on 19 August 2026.

In force since 12 December 2018

Enforced by Telecommunications and Postal Regulatory Authority

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

Low confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel

Act of parliament · Loi n° 2008-12, Journal Officiel de la République du Sénégal

In forceYes, with paperwork

Senegal's general privacy law. It reaches foreign companies that use equipment in Senegal and makes them appoint a local representative. Nearly all processing must be filed with the regulator first, and sensitive uses such as biometrics and health need written permission. Data may leave the country only to destinations that protect it well enough, or with the regulator's approval.

In force since 25 January 2008

Enforced by Commission for the Protection of Personal Data

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Someone's life is at risk, Legal claims, Important public interest

High confidence
Government

Projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique

Draft law · Adopted in Council of Ministers on 17 June 2026; adopted in joint parliamentary committee on 13 August 2026

ProposedA copy must stay

A bill, not a law. The government approved it on 17 June 2026 and a parliamentary committee approved it on 13 August 2026; it still needs a vote in the full chamber. It would make local hosting of public sector data compulsory, curb the use of foreign cloud services and create a national cybersecurity authority with national and sector incident response teams.

Enforced by Ministry of Communication, Telecommunications and Digital Affairs

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Low confidence

New Deal Technologique — Stratégie numérique du Sénégal, Horizon 2034

Government policy document · New Deal Technologique, published by the Presidency

In forceYes, with paperwork

A government strategy, not a law, and it carries no penalty. It matters because it states the direction of travel: the state wants all sensitive data hosted in Senegal by 2034, a sovereign cloud, and a future breach reporting duty. Expect it to show up first in public contracts and licence conditions rather than in a statute.

In force since 24 February 2025

Enforced by Ministry of Communication, Telecommunications and Digital Affairs

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Who you would hear from

  • Commission de Protection des Données Personnelles (CDP)

    General personal data protection: filings, prior authorisations, complaints, inspections, orders

    Genuinely staffed and working. Publishes quarterly activity notices; for January to March 2026 it reported 317 files handled, 283 receipts issued, 27 authorisations, 9 complaints, 3 hearings, 1 formal notice and 1 refusal, plus an unannounced inspection on 12 March 2026 that ended in an order to remove cameras. Caseload is dominated by video surveillance and biometric clocking-in systems. We found no published decision imposing a monetary fine, so the practical exposure is orders and referrals rather than large penalties. Its own website is rendered by JavaScript and returns no readable content to automated fetchers, which makes direct citation of its pages harder than it should be.

  • Autorité de Régulation des Télécommunications et des Postes (ARTP)

    Telecom operators, subscriber identification, licence conditions

    Active. Enforced SIM registration deadlines in 2025, including disconnection of unidentified lines and a cap on lines per subscriber. Its website blocks automated fetching, so link checks against artp.sn fail even where the URL is correct.

  • Commission Bancaire de l'UMOA

    Supervision of banks and financial holding companies in Senegal and the other member states; outsourcing and data location

    The supervisor for Senegalese banks. Its circulars, not Senegalese statute, contain the strictest data location rule that applies in Senegal.

  • Banque Centrale des Etats de l'Afrique de l'Ouest (BCEAO)

    Payments, electronic money, credit bureaus in Senegal and the rest of the monetary union

    Issues the instructions governing payment services and credit bureaus. Its payment services instruction of 2024 contains no data location rule; its credit bureau instruction does.

  • Ministère de la Communication, des Télécommunications et du Numérique

    Digital policy, the national digital strategy and the pending critical infrastructure bill

    Sponsor of the critical information infrastructure and digital security bill approved by the Council of Ministers on 17 June 2026. The department does not maintain a stable public legislative repository, so government publications are cited via the Prime Minister's office and the Presidency.

  • Sénégal Numérique SA (formerly ADIE)

    State digital infrastructure, the national data centre and government hosting

    The state operator behind the national data centre. It is the delivery vehicle for any public sector hosting requirement, and it publishes official copies of the relevant laws.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That Law 2008-12 has not been replaced or amended between 1 and 19 August 2026

    The regulator's own website renders only through JavaScript and returns no content to automated fetching, so we could not read its legislation page directly. We found no evidence of a new law from any source, but we cannot prove a negative from the regulator's own publications.

  • The exact wording of article 49's requirement to notify the regulator before a transfer

    Two independent reads of the official text agree that prior notification to the Commission is required, but the sentence itself was summarised rather than reproduced by our extraction. Treat the notification duty as real and the precise trigger wording as unverified.

  • The full verbatim text of article 33 of banking circular 04-2017/CB/C

    Our extraction returned the operative sentence on data availability within the monetary union and the server requirement, but truncated the rest of the article. The location duty is quoted from the regulator's own PDF; the exact scope of the backup server alternative is paraphrased.

  • Whether insurance and securities firms in Senegal face data location rules

    Senegal's insurers sit under the Inter-African Conference of Insurance Markets and its securities market under the regional financial markets authority. We did not search either rulebook in this run. Do not read the absence of a rule here as the absence of a rule.

  • Any incident reporting deadline in hours for Senegalese banks

    Professional commentary refers to a duty to declare incidents to the Banking Commission, but we could not locate a published deadline on the regulator's own site.

  • The text of the critical information infrastructure and digital security bill

    The government's own communiqué confirms the bill exists and was adopted in Council of Ministers on 17 June 2026, but the bill text is not published on a government site we could reach. The local hosting requirement and the new agencies are reported by the state press agency and specialist media, not quoted from the instrument.

  • Whether the regulator has ever imposed a monetary fine

    No published fine was found in the quarterly notices we could read. Absence of evidence, not evidence of absence; the power clearly exists in the statute.

  • Whether health, education, gaming, mapping or defence data faces any location rule

    Searched on 19 August 2026 and none found. Senegal's digital health law was still at discussion stage in 2025. Confidence medium because these sectors are typically governed by ministerial instruments that are not published online in Senegal.

  • Exact prison terms for data protection offences

    Law 2008-12 hands punishment to the criminal code as amended by the cybercrime law of the same date. We did not open an official copy of the amended criminal code, so we assert that criminal liability exists without asserting the tariff.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 30 days. Next check due 18 September 2026.

Read the exact prompt used to research this page

Put this next to another country

Senegal versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.