Senegal
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Senegal has had a personal data protection law since 2008 and a regulator that genuinely works. Data may go abroad, but only to a country that protects it well enough, and the regulator has to be told. Banks are the real trap: their data must stay reachable inside the West African monetary union. A cybersecurity bill now in parliament would force public bodies to host data at home.
Data governance in Senegal
The eight things that decide how you handle data about people in Senegal. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it can reach a company with no office in Senegal. The law applies to anyone handling personal data using equipment sited in Senegal, wherever the company itself is based. A company based abroad that uses equipment here must name a representative who is established in Senegal. There is no company size or revenue level below which you escape.
Article 2 of Law 2008-12 sets the scope. It covers processing carried out by a controller established in Senegal, and processing by a controller outside Senegal that uses means of processing located on Senegalese territory (other than means used only to route data through the country). In that second case the law says the controller must designate a representative established on Senegalese territory. What the 2008 text does not do is cover a purely foreign operator that merely targets Senegalese users from abroad with no local equipment. That gap is one of the main reasons a reform has been discussed since 2020. The regulator has not published a formal interpretation resolving it, so treat pure remote targeting as a grey area rather than a safe harbour.
Sources
- Official sourceSénégal Numérique SA (state digital agency, formerly ADIE)Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel, article 2 (Journal Officiel text)
senegalnumeriquesa.sn
“le responsable du traitement doit désigner un représentant établi sur le territoire sénégalais”
Link checked 19 August 2026
- Secondary sourceAssociation francophone des autorités de protection des données personnellesSenegal — Law 2008-12, full text with explanatory memorandum
afapdp.org
Link checked 19 August 2026
Where the data is allowed to live
In general yes, with paperwork. Data may be sent abroad if the receiving country gives people a good enough level of protection, and the move has to be notified to the regulator. If the destination does not measure up, you need the regulator's permission. Two areas are much tighter than the headline: banking and credit reporting, where the data has to stay reachable inside the West African monetary union.
SECTOR BY SECTOR, as checked on 19 August 2026. BANKING — the hard wall. Circular 04-2017/CB/C of the Banking Commission of the West African Monetary Union, in force since 2 July 2018, states that all of an institution's physical and electronic data must be available within the Union, and that the servers storing the data and hosting the applications must be in the Union; where the primary servers are not, backup servers within the Union are required. Every outsourcing contract must also be sent to the Banking Commission's Secretariat General for prior assessment. Senegal is a member of the Union, so this binds Senegalese banks and financial holding companies. Rating for banking: a copy must stay. CREDIT REPORTING — Instruction 009-06-2015 requires credit bureaus to place their backup media on a site located in another member state of the monetary union, which keeps the backups inside the bloc. Rating: a copy must stay. PAYMENTS AND ELECTRONIC MONEY — softer than expected. We read Instruction 001-01-2024 on payment services in the monetary union line by line and found no requirement to host data in the region. It requires all of the payment institution's data to be available at all times and requires security guarantees from outsourced providers, but no territorial rule. The older electronic money instruction, 008-05-2015, likewise ties the registered office and the float account to the Union, not the servers. Rating for payments: yes, with paperwork. TELECOMS — the Electronic Communications Code of 2018 imposes subscriber identification, confidentiality of communications and deferred retention of technical data for up to two years, but we found no obligation to keep the data in Senegal. Rating: yes, with paperwork. HEALTH — no health-specific hosting rule found. Health data is treated as sensitive and its processing needs the regulator's prior authorisation, which is a permission barrier, not a location barrier. A dedicated digital health law was still being discussed in 2025 and had not been passed. GOVERNMENT — no binding hosting decree found today, but two things point one way. The national digital strategy commits to 100 percent of sensitive data being hosted in Senegal by 2034, and the critical infrastructure bill would make local hosting of public sector data compulsory. Rating today: yes, with paperwork. Rating if the bill passes: a copy must stay, or stricter. INSURANCE, SECURITIES, EDUCATION, GAMING, MAPPING AND DEFENCE — no data location rule found on an official source. For insurance and securities, Senegal sits under two further regional bodies whose rulebooks we did not fully search; both are listed as unconfirmed rather than cleared. For online gambling, the state lottery has been acting against unlicensed sites, but on licensing grounds, not data location.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 49 to 51 (transfers to third countries)
senegalnumeriquesa.sn
“Le responsable d'un traitement ne peut transférer des données à caractère personnel vers un pays tiers que si cet Etat assure un niveau de protection suffisant de la vie privée, des libertés et droits fondamentaux des personnes à l'égard du traitement dont ces données font ou peuvent faire l'objet.”
Link checked 19 August 2026
- Official sourceCommission Bancaire de l'UMOA / BCEAOCirculaire n° 04-2017/CB/C relative à la gestion des risques dans les établissements de crédit et compagnies financières de l'UMOA, article 33 (externalisation)
bceao.int
“L'ensemble des données physiques et électroniques des établissements doivent être disponibles dans l'UMOA”
Link checked 19 August 2026
- Official sourceBCEAOInstruction n° 001-01-2024 relative aux services de paiement dans l'UMOA — read for localisation, none found
bceao.int
Link checked 19 August 2026
- Official sourceBCEAOInstruction n° 009-06-2015 relative aux dispositifs de sécurité des systèmes d'information des bureaux d'information sur le crédit, article 8
bceao.int
“la délocalisation des supports de sauvegarde sur un site situé dans un autre Etat membre de l'UMOA”
Link checked 19 August 2026
- Official sourcePrésidence de la République du SénégalNew Deal Technologique — Senegal's digital strategy to 2034
presidence.sn
Link checked 19 August 2026
Sending data out of the country
The model is an approved-destinations list that was never published. You have to judge for yourself whether the receiving country protects data well enough, and tell the regulator before the data moves. If the country does not measure up, you can still ask the regulator to approve the transfer because of the safeguards you have built. Narrow exceptions cover one-off transfers, clear consent, contracts and emergencies.
Article 49 of Law 2008-12 bars transfer to a third country unless that state ensures a sufficient level of protection, and requires the transfer to be notified to the Commission beforehand. Article 50 carves out transfers that are occasional and not bulk, and transfers based on the person's consent, the performance of a contract, a vital interest, a public interest or a legal claim. Article 51 lets the Commission authorise a transfer to a country without sufficient protection where the exporter offers adequate safeguards for privacy, on a reasoned application. Crucially the Commission has never published a list of countries it considers adequate, so the allowlist exists on paper with nothing on it. In practice that turns every transfer into either a self-assessment plus a filing, or a case-by-case application. There are no government standard contract templates in Senegal comparable to the European ones, and no certification or corporate binding rules route. One useful anchor: Senegal became the fiftieth state to accede to the Council of Europe data protection convention, Convention 108, which is often used as the reference point for what 'sufficient protection' looks like.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 49, 50 and 51
senegalnumeriquesa.sn
“La Commission peut autoriser un transfert ... sur la base d'une demande dûment motivée”
Link checked 19 August 2026
- Secondary sourceCouncil of EuropeParties to Convention 108 — Senegal listed as an acceding state
coe.int
- Official sourceLink may be brokenCommission de Protection des Données PersonnellesCDP — legislative and regulatory texts (no adequacy list published)
cdp.sn
Link checked 19 August 2026
The regulator, and whether it actually acts
The Commission for the Protection of Personal Data, known in Senegal by its French initials CDP, is the main regulator. It is real and working. It publishes activity figures every three months, runs surprise inspections, holds hearings, and orders companies to take down cameras. In the first three months of 2026 it handled 317 files and 9 complaints. What it almost never does is hand out cash fines.
The CDP is established by Law 2008-12 as an independent authority, with power to warn, order compliance, suspend a permission for three months, ban a processing operation temporarily or permanently, and impose a financial penalty of between 1 million and 100 million CFA francs, roughly 1,700 to 170,000 United States dollars. It must also report offences it discovers to the public prosecutor. Evidence that it is operational, not paper: quarterly public activity notices. For January to March 2026 it reported 317 files processed, 286 declarations and 31 authorisation requests, 283 receipts issued, 27 authorisations granted, 9 complaints, 1 formal notice, 3 hearings and 1 refusal. It carried out an unannounced inspection of a private company on 12 March 2026 and ordered cameras removed from a meeting room. For October to December 2025 it reported 165 files, 14 complaints, 2 formal notices and orders against facial recognition clocking-in systems in hotels and clinics. The honest caveat: almost all of this activity is registration paperwork and video surveillance. We found no published decision imposing a monetary fine. So the practical risk in Senegal is an order to stop doing something, plus reputational exposure, more than a large bill. Other bodies matter in their own lanes: the telecoms regulator ARTP for operators and subscriber identification, and the Banking Commission of the West African Monetary Union for banks.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 5 to 17 (the Commission) and 29 to 31 (sanctions)
senegalnumeriquesa.sn
“une amende pécuniaire d'un (1) million à cent (100) millions de Franc CFA”
Link checked 19 August 2026
- Official sourceLink may be brokenCommission de Protection des Données PersonnellesCDP — quarterly activity notices (Avis trimestriels)
cdp.sn
Link checked 19 August 2026
- Secondary sourceOSIRISCDP first quarter 2026: 317 files handled, 283 receipts issued, 9 complaints
osiris.sn
Link checked 19 August 2026
- Secondary sourceallAfricaCDP quarterly notice for October to December 2025 — 165 files, 14 complaints, 2 formal notices
fr.allafrica.com
Link checked 19 August 2026
How long you must keep it — and when to delete it
There is no single national table of retention periods. The ceiling comes from the data protection law: keep personal data only as long as you need it for the purpose you collected it for, then delete it. The main floors come from elsewhere. Business and accounting records must be kept for ten years under the regional business law treaty, and telecom operators may hold technical data for up to two years.
CEILING. Article 35 of Law 2008-12 says personal data must not be kept longer than the period necessary for the purposes for which it was collected and processed. Article 72 allows data to be kept beyond that period only where it is to be processed for historical, statistical or scientific purposes. FLOORS. Senegal is a member of OHADA, the regional organisation that harmonises business law in West and Central Africa, whose uniform accounting act requires accounting books and supporting documents to be kept for ten years. Tax audit powers rest on the same records. In telecoms, the Electronic Communications Code allows deferred retention of technical data for up to two years, subject to conditions. In banking, the outsourcing rules require the institution's records and archives to remain accessible for the periods set by the applicable regulations, without setting a single number. HOW A CONFLICT IS RESOLVED. The data protection law itself gives way where another law requires retention: keeping data because a statute obliges you to is a lawful basis, so the ten-year accounting floor beats the general 'delete when done' ceiling for the documents it covers. What Senegal does not have is a published rulebook telling you how to segregate the data you must keep from the data you must delete. That work falls on you.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 35 and 72 (retention)
senegalnumeriquesa.sn
“Elles doivent être conservées pendant une durée qui n'excède pas la période nécessaire”
Link checked 19 August 2026
- Official sourceAutorité de Régulation des Télécommunications et des PostesCode des communications électroniques (Loi n° 2018-28 du 12 décembre 2018)
artp.sn
Link checked 19 August 2026
- Secondary sourceOHADA documentation libraryOHADA uniform act on accounting law — ten-year retention of accounting records
biblio.ohada.org
If something goes wrong
There is no general duty to report a data breach in Senegal. We checked on 19 August 2026 and found no deadline, in hours or otherwise, in the 2008 data protection law, either to the regulator or to the people affected. Banks must tell their supervisor about serious problems, but no published deadline in hours was found. Two changes are coming that would add reporting duties.
Counting the clocks in Senegal is short work today, and that is itself the finding. The 2008 data protection law was written before breach notification became standard and contains no notification article. The only reporting duty in it runs the other way: the regulator must report offences it learns of to the public prosecutor without delay. What exists around the edges. Banks and financial holding companies are under general internal control and risk management circulars that require serious incidents to be escalated to the Banking Commission, but we could not locate a published notification deadline expressed in hours. Telecom operators have security and confidentiality duties under the Electronic Communications Code and answer to the telecoms regulator. Companies affected by cybercrime can go to the police cyber unit, which is a criminal complaint, not a regulatory notification. What is coming. The national digital strategy commits to requiring organisations to report any breach within a reasonable timeframe, which signals a future statutory duty. The critical information infrastructure and digital security bill would create a national cybersecurity authority, a national computer emergency response team and sector teams; incident reporting to those teams is the obvious next step. Neither is law today.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12 — full text, checked for a breach notification article, none found
senegalnumeriquesa.sn
Link checked 19 August 2026
- Official sourcePrésidence de la République du SénégalNew Deal Technologique — commitment to require breach reporting within a reasonable timeframe
presidence.sn
Link checked 19 August 2026
- Official sourceGouvernement du Sénégal, PrimatureConseil des ministres du 17 juin 2026 — adoption of the bill on protection of critical information infrastructure and digital security
primature.sn
“le projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique”
Link checked 19 August 2026
What catches people out
The traps in Senegal are not about fines, they are about permission slips and cameras. Almost every use of personal data has to be filed with the regulator before you start, and some uses need written permission first. The regulator turns up unannounced. And data offences sit in the criminal code, so a person can be prosecuted, not just a company told off.
TRAP 1 — the filing regime is real and almost nobody does it. Under the 2008 law, ordinary processing must be declared to the regulator, which issues a receipt. This is not a formality that has quietly died: the regulator issued 283 receipts in the first quarter of 2026 alone. Operating without a receipt is a breach on day one, whatever else you get right. TRAP 2 — a second, tougher gate for the interesting data. Prior written authorisation, not just a filing, is needed for genetic data, health research, criminal offence data, linking separate databases, using the national identity number, and biometrics. Face recognition and fingerprint clocking-in systems fall squarely in here, and the regulator has ordered several of them switched off. TRAP 3 — cameras. Video surveillance dominates the regulator's caseload: 200 receipts for businesses in one quarter, plus orders to remove cameras from meeting rooms, treatment rooms, kitchens and staff areas. A workplace camera rollout in Senegal is a regulatory project, not a facilities project. TRAP 4 — criminal liability. The 2008 law hands the punishment of offences to the criminal code as amended by the cybercrime law of the same date, and obliges the regulator to pass offences to the prosecutor. That means individuals, not just companies, are exposed. TRAP 5 — a representative you have to actually appoint. A foreign company using equipment in Senegal must designate a representative established in Senegal. There is no revenue threshold, and no grace period written into the text. TRAP 6 — for banks only, but expensive: an outsourcing contract must go to the banking supervisor for assessment before you sign it, and the supervisor expects your servers, or at minimum your backup servers, to be inside the West African monetary union.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 18 to 21 (declaration and authorisation), article 75 (offences)
senegalnumeriquesa.sn
“les traitements de données à caractère personnel font l'objet d'une déclaration”
Link checked 19 August 2026
- Official sourceLink may be brokenCommission de Protection des Données PersonnellesCDP quarterly activity notices — video surveillance and biometric clocking-in cases
cdp.sn
Link checked 19 August 2026
- Official sourceCommission Bancaire de l'UMOACirculaire n° 04-2017/CB/C, article 33 — prior submission of outsourcing contracts
bceao.int
“Tout projet de contrat d'externalisation doit être soumis à l'appréciation préalable du Secrétariat Général de la Commission Bancaire”
Link checked 19 August 2026
What's changing next
One big thing is close. A bill on protecting critical information infrastructure and digital security was approved by the government on 17 June 2026 and passed a parliamentary committee on 13 August 2026. It still needs a vote in the full chamber, so it is not law. It would create a national cybersecurity authority and make local hosting of public sector data compulsory.
IN THE NEXT TWELVE MONTHS. The critical information infrastructure and digital security bill. Adopted by the Council of Ministers on 17 June 2026, presented to a joint parliamentary committee on 13 August 2026 and adopted there, awaiting the full sitting. Reported contents: a register of critical infrastructure, compulsory risk analysis, backup and encryption, resilience testing, oversight of outsourced digital services, mandatory local hosting of public sector data, restrictions on relying on foreign cloud services, and the creation of a national cybersecurity authority, a national computer emergency response team and sector teams. Treat it as a proposal until the vote. Replacement of the 2008 data protection law. Under discussion since 2020 and referred to again in the national digital strategy, which promises stronger confidentiality rules, informed consent, regulation of data sharing and breach reporting. No bill has been introduced. Do not plan around it. DORMANT SWITCHES — powers already held that could change the picture without warning. One. The regulator decides, case by case and with no published criteria, which countries offer sufficient protection and which transfers are authorised. It could tighten transfer practice tomorrow through refusals alone, with no new law and no consultation. Two. The list of processing operations needing prior authorisation, rather than a simple filing, can be extended by regulation. Adding a category, for instance cloud hosting abroad, would convert a filing into a permission overnight. Three. The national digital strategy already commits the state to 100 percent of sensitive data being hosted in Senegal by 2034. Procurement conditions and licence conditions can implement that long before any statute does, and are not published as legislation. Four. Once the critical infrastructure bill passes, designating an operator as critical is expected to be an administrative act. A private company could be brought inside the local hosting perimeter by a decision, not by a new law.
Sources
- Official sourceGouvernement du Sénégal, PrimatureConseil des ministres du 17 juin 2026 — bill adopted by government
primature.sn
“le projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique”
Link checked 19 August 2026
- Official sourcePrésidence de la République du SénégalNew Deal Technologique — 100 percent of sensitive data hosted in Senegal by 2034
presidence.sn
Link checked 19 August 2026
- Secondary sourceAgence de Presse SénégalaiseCybersécurité: un projet de loi élaboré pour renforcer la protection des infrastructures critiques (13 August 2026)
aps.sn
Link checked 19 August 2026
- Secondary sourceAfrique IT NewsMandatory local hosting of public sector data in the committee-adopted bill
afriqueitnews.com
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Circulaire n° 04-2017/CB/C relative à la gestion des risques dans les établissements de crédit et compagnies financières de l'UMOA
Regulator directive · Circulaire n° 04-2017/CB/C, article 33
The hardest data location rule that touches Senegal. Banks and financial holding companies must keep all their data available inside the West African monetary union, with the servers holding that data in the Union or, failing that, backup servers in the Union. Outsourcing contracts must go to the banking supervisor before they are signed.
Enforced by Banking Commission of the West African Monetary Union
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryAll physical and electronic data of the institution must be available within the West African Monetary Union; servers storing data and hosting applications must be in the Union, otherwise backup servers in the Union are required.
- Written vendor contractEvery outsourcing contract must be sent to the Banking Commission's Secretariat General for prior assessment, and approved by the institution's board.
- Independent auditThe board must review the full list of outsourcing contracts at least twice a year.
What it costs if you get it wrong
- Loss of your licenceSupervisory action by the Banking Commission for breach of prudential circulars; sanctions range from warnings to withdrawal of the banking licence
Sources
- Official sourceCommission Bancaire de l'UMOA / BCEAOCirculaire n° 04-2017/CB/C, article 33 (externalisation)
bceao.int
“L'ensemble des données physiques et électroniques des établissements doivent être disponibles dans l'UMOA”
Link checked 19 August 2026
- Official sourceCommission Bancaire de l'UMOACirculaires de la Commission Bancaire de l'UMOA
cb-umoa.org
Link checked 19 August 2026
Instruction n° 009-06-2015 relative aux dispositifs de sécurité des systèmes d'information des bureaux d'information sur le crédit
Directly binding regulation · Instruction n° 009-06-2015, article 8
Credit bureaus serving Senegal must keep their backup copies on a site in another country of the West African monetary union. The effect is that a full copy of the credit file stays inside the region even if other processing happens elsewhere.
Enforced by Central Bank of West African States
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryBackup media must be held on a site located in another member state of the West African Monetary Union, which keeps the backup copy inside the bloc.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceCredit bureaus operate under a licence from the central bank; breach of the security instruction is a licensing matter
Sources
- Official sourceBCEAOInstruction n° 009-06-2015, article 8
bceao.int
“la délocalisation des supports de sauvegarde sur un site situé dans un autre Etat membre de l'UMOA”
Link checked 19 August 2026
Loi n° 2018-28 du 12 décembre 2018 portant Code des communications électroniques
Act of parliament · Loi n° 2018-28
Telecom operators in Senegal must identify every subscriber, protect the confidentiality of communications, and may hold technical data for up to two years. We found no requirement to keep telecom data inside Senegal, checked on 19 August 2026.
Enforced by Telecommunications and Postal Regulatory Authority
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What it makes you do
- Secure the dataOperators must guarantee the confidentiality of communications.
- Keep logs — 2 yearsThe code permits deferred retention of technical data for up to two years, subject to conditions.
- Keep records of processingOperators must identify their subscribers; the telecoms regulator has enforced SIM registration deadlines and caps on the number of lines per subscriber.
What it costs if you get it wrong
- Loss of your licenceBreach of licence and code obligations, enforced by the telecoms regulator
- Order to stopDisconnection of unidentified subscriber lines
Sources
- Official sourceAutorité de Régulation des Télécommunications et des PostesCode des communications électroniques — regulator's documentation page
artp.sn
Link checked 19 August 2026
- Official sourceGouvernement du Sénégal, PrimatureCode des communications électroniques (Loi n° 2018-28) — government publication page
primature.sn
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel
Act of parliament · Loi n° 2008-12, Journal Officiel de la République du Sénégal
Senegal's general privacy law. It reaches foreign companies that use equipment in Senegal and makes them appoint a local representative. Nearly all processing must be filed with the regulator first, and sensitive uses such as biometrics and health need written permission. Data may leave the country only to destinations that protect it well enough, or with the regulator's approval.
Enforced by Commission for the Protection of Personal Data
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Someone's life is at risk, Legal claims, Important public interest
What it makes you do
- Register or notifyOrdinary processing must be declared to the regulator, which issues a receipt within one month.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people object
- Secure the data
- Appoint a local representativeRequired where the controller is outside Senegal but uses processing equipment located in Senegal.
- Put a transfer safeguard in placeDestination must ensure a sufficient level of protection, or the regulator must authorise the transfer.
- Delete data after a periodNo longer than necessary for the stated purpose; extension only for historical, statistical or scientific use.
What it costs if you get it wrong
- Fixed maximum fine: 100 000 000 FCFA (minimum 1 000 000 FCFA) — about $170 thousandBreach of the data protection law after a formal notice
- Order to stopWithdrawal of a permission for three months, then permanently; temporary or permanent ban on the processing
- Criminal liabilityOffences are punished under the criminal code as amended by the cybercrime law of 25 January 2008; the regulator must refer offences to the public prosecutor
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12 du 25 janvier 2008 — Journal Officiel text
senegalnumeriquesa.sn
“Le responsable d'un traitement ne peut transférer des données à caractère personnel vers un pays tiers que si cet Etat assure un niveau de protection suffisant”
Link checked 19 August 2026
- Official sourceLink may be brokenCommission de Protection des Données PersonnellesCDP — legislative and regulatory texts
cdp.sn
Link checked 19 August 2026
Projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique
Draft law · Adopted in Council of Ministers on 17 June 2026; adopted in joint parliamentary committee on 13 August 2026
A bill, not a law. The government approved it on 17 June 2026 and a parliamentary committee approved it on 13 August 2026; it still needs a vote in the full chamber. It would make local hosting of public sector data compulsory, curb the use of foreign cloud services and create a national cybersecurity authority with national and sector incident response teams.
Enforced by Ministry of Communication, Telecommunications and Digital Affairs
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryReported to make local hosting of public sector data compulsory and to restrict reliance on foreign cloud services. Not law yet.
- Register or notifyIdentification and registration of critical information infrastructure.
- Assess high-risk projectsCompulsory risk analysis and periodic resilience testing.
- Secure the dataBackup and encryption requirements.
- Report cyber incidentsWould create a national cybersecurity authority, a national computer emergency response team and sector teams.
Sources
- Official sourceGouvernement du Sénégal, PrimatureConseil des ministres du 17 juin 2026
primature.sn
“le projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique”
Link checked 19 August 2026
- Secondary sourceAgence de Presse SénégalaiseBill presented to a joint parliamentary committee, 13 August 2026
aps.sn
Link checked 19 August 2026
- Secondary sourceAfrique IT NewsMandatory local hosting of public sector data under the bill
afriqueitnews.com
Link checked 19 August 2026
New Deal Technologique — Stratégie numérique du Sénégal, Horizon 2034
Government policy document · New Deal Technologique, published by the Presidency
A government strategy, not a law, and it carries no penalty. It matters because it states the direction of travel: the state wants all sensitive data hosted in Senegal by 2034, a sovereign cloud, and a future breach reporting duty. Expect it to show up first in public contracts and licence conditions rather than in a statute.
Enforced by Ministry of Communication, Telecommunications and Digital Affairs
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the country — from 1 January 2034Policy target, not a legal duty: 100 percent of sensitive data hosted in Senegal by 2034.
- Prove the data stays under local controlCommitment to build sovereign cloud offerings and sovereign, resilient national infrastructure.
- Report breaches to the regulatorStated intention to require organisations to report breaches within a reasonable timeframe. No statute yet.
Sources
- Official sourcePrésidence de la République du SénégalNew Deal Technologique — Senegal's digital strategy to 2034
presidence.sn
Link checked 19 August 2026
- Official sourceGouvernement du Sénégal, PrimatureStratégie numérique du Sénégal, le New Deal Technologique, Horizon 2034
primature.sn
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That Law 2008-12 has not been replaced or amended between 1 and 19 August 2026
The regulator's own website renders only through JavaScript and returns no content to automated fetching, so we could not read its legislation page directly. We found no evidence of a new law from any source, but we cannot prove a negative from the regulator's own publications.
The exact wording of article 49's requirement to notify the regulator before a transfer
Two independent reads of the official text agree that prior notification to the Commission is required, but the sentence itself was summarised rather than reproduced by our extraction. Treat the notification duty as real and the precise trigger wording as unverified.
The full verbatim text of article 33 of banking circular 04-2017/CB/C
Our extraction returned the operative sentence on data availability within the monetary union and the server requirement, but truncated the rest of the article. The location duty is quoted from the regulator's own PDF; the exact scope of the backup server alternative is paraphrased.
Whether insurance and securities firms in Senegal face data location rules
Senegal's insurers sit under the Inter-African Conference of Insurance Markets and its securities market under the regional financial markets authority. We did not search either rulebook in this run. Do not read the absence of a rule here as the absence of a rule.
Any incident reporting deadline in hours for Senegalese banks
Professional commentary refers to a duty to declare incidents to the Banking Commission, but we could not locate a published deadline on the regulator's own site.
The text of the critical information infrastructure and digital security bill
The government's own communiqué confirms the bill exists and was adopted in Council of Ministers on 17 June 2026, but the bill text is not published on a government site we could reach. The local hosting requirement and the new agencies are reported by the state press agency and specialist media, not quoted from the instrument.
Whether the regulator has ever imposed a monetary fine
No published fine was found in the quarterly notices we could read. Absence of evidence, not evidence of absence; the power clearly exists in the statute.
Whether health, education, gaming, mapping or defence data faces any location rule
Searched on 19 August 2026 and none found. Senegal's digital health law was still at discussion stage in 2025. Confidence medium because these sectors are typically governed by ministerial instruments that are not published online in Senegal.
Exact prison terms for data protection offences
Law 2008-12 hands punishment to the criminal code as amended by the cybercrime law of the same date. We did not open an official copy of the amended criminal code, so we assert that criminal liability exists without asserting the tariff.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 30 days. Next check due 18 September 2026.
Put this next to another country
Senegal versus
Compare