Skip to the content
Global Data RulesData governance rules, country by country

Senegal

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Senegal — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Active

Senegal has had a personal data protection law since 2008, and a regulator that really works. Data may go abroad, but only to a country that protects it well enough. You must also tell the regulator. Banks are the real trap. Their data must stay reachable inside the West African monetary union. A cybersecurity bill now in parliament would force public bodies to host data at home.

Data governance in Senegal

The eight things that decide how you handle data about people in Senegal. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law can reach a company with no office in Senegal. It applies to anyone using personal data with equipment sited in Senegal, wherever the company is based. If you are based abroad and use equipment here, you must name a representative based in Senegal. There is no company size or revenue level below which you escape.

What you have to do here:
Appoint a representative

Where the data is allowed to live

In general yes, with paperwork. You may send data abroad if the receiving country gives people a good enough level of protection. You must tell the regulator before the data moves. If the destination does not measure up, you need the regulator's permission. Two areas are much tighter: banking and credit reporting. There, the data has to stay reachable inside the West African monetary union.

What to do: Get the paperwork for one of the routes below signed before any data leaves Senegal.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

Senegal is meant to have a list of approved destination countries. It was never published. So you have to judge for yourself whether the receiving country protects data well enough. You must tell the regulator before the data moves. If the country does not measure up, you can still ask the regulator to approve the transfer, based on the safeguards you have built. Narrow exceptions cover one-off transfers, clear consent, contracts and emergencies.

Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · To save someone’s life · Legal claims · Important public interest

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

The Commission for the Protection of Personal Data, known in Senegal by its French initials CDP. It is the main regulator. It is real and working. It publishes activity figures every three months. It runs surprise inspections, holds hearings, and orders companies to take down cameras. In the first three months of 2026 it handled 317 files and 9 complaints. What it almost never does is hand out cash fines.

What it costs if you get it wrong:
Fixed maximum fine · Order to stop
Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is no single national table of keeping periods. The maximum comes from the data protection law. Keep personal data only as long as you need it for the purpose you collected it for, then delete it. The minimums come from elsewhere. Business and accounting records must be kept for ten years under the regional business law treaty. Telecom operators may hold technical data for up to two years.

What you have to do here:
Delete data after a period · Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There is no general duty to report a data breach in Senegal. We checked on 19 August 2026. The 2008 data protection law sets no deadline, in hours or otherwise. That is true both for telling the regulator and for telling the people affected. Banks must tell their supervisor about serious problems, but we found no published deadline in hours. Two changes are coming that would add reporting duties.

What you have to do here:
Report breaches to the regulator · Report cyber incidents

What to do: Your breach process has to reach Senegal's regulator inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

The traps in Senegal are not about fines. They are about permission slips and cameras. Almost every use of personal data has to be filed with the regulator before you start. Some uses need written permission first. The regulator turns up unannounced. And data offences sit in the criminal code, so a person can be prosecuted, not just a company told off.

What you have to do here:
Appoint a representative
What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

What's changing next

One big thing is close. A bill on protecting critical information infrastructure and digital security was approved by the government on 17 June 2026. A parliamentary committee passed it on 13 August 2026. It still needs a vote in the full chamber, so it is not law. It would create a national cybersecurity authority. It would also make local hosting of public sector data compulsory.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking data needs a copy kept in the country

Official name: Circulaire n° 04-2017/CB/C relative à la gestion des risques dans les établissements de crédit et compagnies financières de l'UMOA · Circulaire n° 04-2017/CB/C, article 33 · Regulator directive

In forceA copy must stay

This is the strictest data location rule that touches Senegal. Banks and financial holding companies must keep all their data available inside the West African monetary union. The servers holding that data must be in the Union. If they are not, backup servers must be. Outsourcing contracts must go to the banking supervisor before they are signed.

In force since 2 July 2018

Enforced by Banking Commission of the West African Monetary Union

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Finance

Finance data needs a copy kept in the country

Official name: Instruction n° 009-06-2015 relative aux dispositifs de sécurité des systèmes d'information des bureaux d'information sur le crédit · Instruction n° 009-06-2015, article 8 · Directly binding regulation

In forceA copy must stay

Credit bureaus serving Senegal must keep their backup copies on a site in another country of the West African monetary union. So a full copy of the credit file stays inside the region, even if the data is used elsewhere.

In force since 1 June 2015

Enforced by Central Bank of West African States

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Telecoms

Telecoms rules

Official name: Loi n° 2018-28 du 12 décembre 2018 portant Code des communications électroniques · Loi n° 2018-28 · Act of parliament

In forceYes, with paperwork

Telecom operators in Senegal must identify every subscriber, protect the confidentiality of communications, and may hold technical data for up to two years. We found no requirement to keep telecom data inside Senegal, checked on 19 August 2026.

In force since 12 December 2018

Enforced by Telecommunications and Postal Regulatory Authority

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Health data rules

Official name: Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel · Loi n° 2008-12, Journal Officiel de la République du Sénégal · Act of parliament

In forceYes, with paperwork

Senegal's general privacy law. It reaches foreign companies that use equipment in Senegal and makes them appoint a local representative. Almost every use of personal data must be filed with the regulator first. Sensitive uses such as biometrics and health need written permission. Data may leave the country only to places that protect it well enough, or with the regulator's approval.

In force since 25 January 2008

Enforced by Commission for the Protection of Personal Data

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, To save someone’s life, Legal claims, Important public interest

Government

Cyber security rules

Official name: Projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique · Adopted in Council of Ministers on 17 June 2026; adopted in joint parliamentary committee on 13 August 2026 · Draft law

ProposedA copy must stay

A bill, not a law. The government approved it on 17 June 2026. A parliamentary committee approved it on 13 August 2026. It still needs a vote in the full chamber. It would make local hosting of public sector data compulsory. It would limit the use of foreign cloud services. And it would create a national cybersecurity authority, with national and sector incident response teams.

Enforced by Ministry of Communication, Telecommunications and Digital Affairs

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Personal data must stay in the country

Official name: New Deal Technologique — Stratégie numérique du Sénégal, Horizon 2034 · New Deal Technologique, published by the Presidency · Government policy document

In forceYes, with paperwork

A government strategy, not a law, and it carries no penalty. It matters because it shows where the state is heading. It wants all sensitive data hosted in Senegal by 2034, a sovereign cloud, and a future breach reporting duty. Expect this to show up first in public contracts and licence conditions, not in a law.

In force since 24 February 2025

Enforced by Ministry of Communication, Telecommunications and Digital Affairs

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Commission de Protection des Données Personnelles (CDP)

    General personal data protection: filings, prior authorisations, complaints, inspections, orders

    Properly staffed and working. It publishes quarterly activity notices. For January to March 2026 it reported 317 files handled, 283 receipts issued, 27 authorisations, 9 complaints, 3 hearings, 1 formal notice and 1 refusal. It also made an unannounced inspection on 12 March 2026 that ended in an order to remove cameras. Its caseload is dominated by video surveillance and biometric clocking-in systems. We found no published decision imposing a money fine. So your real exposure is orders and referrals rather than large penalties.

  • Autorité de Régulation des Télécommunications et des Postes (ARTP)

    Telecom operators, subscriber identification, licence conditions

    Active. Enforced SIM registration deadlines in 2025, including disconnection of unidentified lines and a cap on lines per subscriber.

  • Commission Bancaire de l'UMOA

    Supervision of banks and financial holding companies in Senegal and the other member states; outsourcing and data location

    The supervisor for Senegalese banks. Its circulars, not Senegalese statute, contain the strictest data location rule that applies in Senegal.

  • Banque Centrale des Etats de l'Afrique de l'Ouest (BCEAO)

    Payments, electronic money, credit bureaus in Senegal and the rest of the monetary union

    Issues the instructions governing payment services and credit bureaus. Its payment services instruction of 2024 contains no data location rule; its credit bureau instruction does.

  • Ministère de la Communication, des Télécommunications et du Numérique

    Digital policy, the national digital strategy and the pending critical infrastructure bill

    It sponsors the critical information infrastructure and digital security bill, which the Council of Ministers approved on 17 June 2026. The department keeps no stable public library of laws. So we cite government publications through the Prime Minister's office and the President's office.

  • Sénégal Numérique SA (formerly ADIE)

    State digital infrastructure, the national data centre and government hosting

    The state operator behind the national data centre. It is the delivery vehicle for any public sector hosting requirement, and it publishes official copies of the relevant laws.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That Law 2008-12 has not been replaced or amended between 1 and 19 August 2026

    We could not confirm that the 2008 law was left unchanged in early August 2026. The regulator's own website returns no readable content to automated tools, so we could not read its legislation page. We found no sign of a new law from any other source. Ask the regulator if a very recent change would affect you.

  • The exact wording of article 49's requirement to notify the regulator before a transfer

    We could not confirm the exact wording that triggers the duty to tell the regulator before a transfer. Two separate reads of the official text agree the duty exists. Treat the duty as real. Check the precise wording before you rely on the detail.

  • The full verbatim text of article 33 of banking circular 04-2017/CB/C

    We could not confirm exactly how far the backup server option goes. The duty to keep data available inside the monetary union comes straight from the regulator's own document, along with the server rule. The wording on backup servers is our summary, not a quotation. Check it with the Banking Commission before you rely on it.

  • Whether insurance and securities firms in Senegal face data location rules

    We could not confirm the rules for insurance and securities firms. Senegal's insurers sit under the Inter-African Conference of Insurance Markets. Its securities market sits under the regional financial markets authority. We did not search either rulebook. If you work in these industries, check before you rely on this.

  • Any incident reporting deadline in hours for Senegalese banks

    We could not confirm any deadline for telling the Banking Commission about an incident. Professional commentary says the duty exists. We found no published deadline on the regulator's own site. If you are a bank, ask your supervisor.

  • The text of the critical information infrastructure and digital security bill

    We could not confirm what the bill actually says. The government's own statement confirms the Council of Ministers adopted it on 17 June 2026. But the text is not published on a government site we could reach. The local hosting rule and the new agencies come from the state press agency and specialist media, not from the bill itself.

  • Whether the regulator has ever imposed a monetary fine

    We could not confirm whether the regulator has ever issued a money fine. We found none in the quarterly notices we read. The power to fine clearly exists in the law. Do not assume fines never happen.

  • Whether health, education, gaming, mapping or defence data faces any location rule

    We found no location rule for these industries, searched on 19 August 2026. Senegal's digital health law was still being discussed in 2025. These industries are usually governed by ministry documents that are not published online in Senegal. If you work in one, check with the ministry.

  • Exact prison terms for data protection offences

    We could not confirm the prison terms. Law 2008-12 leaves punishment to the criminal code, as amended by the cybercrime law of the same date. We did not read an official copy of the amended criminal code. Criminal liability exists, but we cannot tell you the size of the penalty.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 30 days. Next check due 18 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.