Senegal
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Senegal — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Senegal has had a personal data protection law since 2008, and a regulator that really works. Data may go abroad, but only to a country that protects it well enough. You must also tell the regulator. Banks are the real trap. Their data must stay reachable inside the West African monetary union. A cybersecurity bill now in parliament would force public bodies to host data at home.
Data governance in Senegal
The eight things that decide how you handle data about people in Senegal. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law can reach a company with no office in Senegal. It applies to anyone using personal data with equipment sited in Senegal, wherever the company is based. If you are based abroad and use equipment here, you must name a representative based in Senegal. There is no company size or revenue level below which you escape.
- What you have to do here:
- Appoint a representative
Article 2 of Law 2008-12 sets out who is covered. It covers any company based in Senegal that uses personal data. It also covers a company outside Senegal that uses equipment located in Senegal to handle that data. Equipment used only to route data through the country does not count. In that second case, the law says you must name a representative based in Senegal. What the 2008 text does not cover is a purely foreign operator with no equipment here that simply targets Senegalese users. That gap is one of the main reasons a reform has been discussed since 2020. The regulator has not published a formal reading that settles it. So treat pure remote targeting as a grey area, not as safe.
Sources
- Official sourceSénégal Numérique SA (state digital agency, formerly ADIE)Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel, article 2 (Journal Officiel text)
senegalnumeriquesa.sn
“le responsable du traitement doit désigner un représentant établi sur le territoire sénégalais”
Link checked 19 August 2026
- Secondary sourceAssociation francophone des autorités de protection des données personnellesSenegal — Law 2008-12, full text with explanatory memorandum
afapdp.org
Link checked 19 August 2026
Where the data is allowed to live
In general yes, with paperwork. You may send data abroad if the receiving country gives people a good enough level of protection. You must tell the regulator before the data moves. If the destination does not measure up, you need the regulator's permission. Two areas are much tighter: banking and credit reporting. There, the data has to stay reachable inside the West African monetary union.
Industry by industry, as checked on 19 August 2026. BANKING - the strictest rule. Circular 04-2017/CB/C of the Banking Commission of the West African Monetary Union has been in force since 2 July 2018. It says all of an institution's physical and electronic data must be available within the Union. The servers that store the data and run the applications must be in the Union. If the main servers are not, you need backup servers within the Union. Every outsourcing contract must also go to the Banking Commission's Secretariat General to be assessed first. Senegal is a member of the Union, so this binds Senegalese banks and financial holding companies. Rating for banking: a copy must stay. CREDIT REPORTING - Instruction 009-06-2015 makes credit bureaus put their backup media on a site in another member state of the monetary union. That keeps the backups inside the bloc. Rating: a copy must stay. PAYMENTS AND ELECTRONIC MONEY - softer than expected. We read Instruction 001-01-2024 on payment services in the monetary union line by line. We found no requirement to host data in the region. It says all of the payment institution's data must be available at all times. It also requires security guarantees from outsourced providers. But it sets no rule about location. The older electronic money instruction, 008-05-2015, ties the registered office and the float account to the Union, not the servers. Rating for payments: yes, with paperwork. TELECOMS - the Electronic Communications Code of 2018 makes operators identify subscribers and keep communications confidential. It lets them hold technical data for up to two years. We found no duty to keep the data in Senegal. Rating: yes, with paperwork. HEALTH - we found no health-specific hosting rule. Health data counts as sensitive, and you need the regulator's permission before you use it. That is a permission barrier, not a location barrier. A dedicated digital health law was still being discussed in 2025 and had not been passed. GOVERNMENT - we found no binding hosting decree today. But two things point the same way. The national digital strategy commits to 100 percent of sensitive data being hosted in Senegal by 2034. And the critical infrastructure bill would make local hosting of public sector data compulsory. Rating today: yes, with paperwork. Rating if the bill passes: a copy must stay, or stricter. INSURANCE, SECURITIES, EDUCATION, GAMING, MAPPING AND DEFENCE - we found no data location rule on an official source. For insurance and securities, Senegal sits under two further regional bodies. We did not fully search their rulebooks, so both are listed as unconfirmed rather than cleared. For online gambling, the state lottery has been acting against unlicensed sites. That is about licensing, not data location.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 49 to 51 (transfers to third countries)
senegalnumeriquesa.sn
“Le responsable d'un traitement ne peut transférer des données à caractère personnel vers un pays tiers que si cet Etat assure un niveau de protection suffisant de la vie privée, des libertés et droits fondamentaux des personnes à l'égard du traitement dont ces données font ou peuvent faire l'objet.”
Link checked 19 August 2026
- Official sourceCommission Bancaire de l'UMOA / BCEAOCirculaire n° 04-2017/CB/C relative à la gestion des risques dans les établissements de crédit et compagnies financières de l'UMOA, article 33 (externalisation)
bceao.int
“L'ensemble des données physiques et électroniques des établissements doivent être disponibles dans l'UMOA”
Link checked 19 August 2026
- Official sourceBCEAOInstruction n° 001-01-2024 relative aux services de paiement dans l'UMOA — read for localisation, none found
bceao.int
Link checked 19 August 2026
- Official sourceBCEAOInstruction n° 009-06-2015 relative aux dispositifs de sécurité des systèmes d'information des bureaux d'information sur le crédit, article 8
bceao.int
“la délocalisation des supports de sauvegarde sur un site situé dans un autre Etat membre de l'UMOA”
Link checked 19 August 2026
- Official sourcePrésidence de la République du SénégalNew Deal Technologique — Senegal's digital strategy to 2034
presidence.sn
Link checked 19 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Senegal.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
Senegal is meant to have a list of approved destination countries. It was never published. So you have to judge for yourself whether the receiving country protects data well enough. You must tell the regulator before the data moves. If the country does not measure up, you can still ask the regulator to approve the transfer, based on the safeguards you have built. Narrow exceptions cover one-off transfers, clear consent, contracts and emergencies.
- Ways to send data out:
- Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · To save someone’s life · Legal claims · Important public interest
Article 49 of Law 2008-12 bans sending data to another country unless that country ensures a sufficient level of protection. It also makes you tell the Commission before the transfer. Article 50 sets out exceptions. These cover transfers that are occasional and not bulk. They also cover transfers based on the person's consent or on carrying out a contract. And transfers based on a vital interest, a public interest or a legal claim. Article 51 lets the Commission approve a transfer to a country without sufficient protection. You have to apply with reasons and offer adequate safeguards for privacy. The Commission has never published a list of countries it considers safe enough. So the approved list exists on paper with nothing on it. That turns every transfer into one of two things. Either a self-assessment plus a filing, or a case-by-case application. There are no government standard contract templates in Senegal like the European ones. There is no certification route and no company-wide rules route. One useful anchor. Senegal became the fiftieth state to join the Council of Europe data protection convention, Convention 108. That convention is often used as the reference point for what 'sufficient protection' looks like.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 49, 50 and 51
senegalnumeriquesa.sn
“La Commission peut autoriser un transfert ... sur la base d'une demande dûment motivée”
Link checked 19 August 2026
- Secondary sourceCouncil of EuropeParties to Convention 108 — Senegal listed as an acceding state
coe.int
- Official sourceLink may be brokenCommission de Protection des Données PersonnellesCDP — legislative and regulatory texts (no adequacy list published)
cdp.sn
Link checked 19 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
The Commission for the Protection of Personal Data, known in Senegal by its French initials CDP. It is the main regulator. It is real and working. It publishes activity figures every three months. It runs surprise inspections, holds hearings, and orders companies to take down cameras. In the first three months of 2026 it handled 317 files and 9 complaints. What it almost never does is hand out cash fines.
- What it costs if you get it wrong:
- Fixed maximum fine · Order to stop
Law 2008-12 sets up the CDP as an independent authority. It can warn you, order you to comply, suspend a permission for three months, and ban a use of data temporarily or permanently. It can also fine between 1 million and 100 million CFA francs, roughly 1,700 to 170,000 United States dollars. It must report any offences it finds to the public prosecutor. The evidence that it works is in its quarterly public activity notices. For January to March 2026 it reported 317 files handled. That included 286 declarations and 31 authorisation requests, 283 receipts issued, 27 authorisations granted, 9 complaints, 1 formal notice, 3 hearings and 1 refusal. It made an unannounced inspection of a private company on 12 March 2026 and ordered cameras removed from a meeting room. For October to December 2025 it reported 165 files, 14 complaints, 2 formal notices, and orders against face recognition clocking-in systems in hotels and clinics. The honest caveat. Almost all of this work is registration paperwork and video surveillance. We found no published decision imposing a money fine. So your real risk in Senegal is an order to stop doing something, plus damage to your reputation. It is not a large bill. Other bodies matter in their own areas. The telecoms regulator ARTP covers operators and subscriber identification. The Banking Commission of the West African Monetary Union covers banks.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 5 to 17 (the Commission) and 29 to 31 (sanctions)
senegalnumeriquesa.sn
“une amende pécuniaire d'un (1) million à cent (100) millions de Franc CFA”
Link checked 19 August 2026
- Official sourceLink may be brokenCommission de Protection des Données PersonnellesCDP — quarterly activity notices (Avis trimestriels)
cdp.sn
Link checked 19 August 2026
- Secondary sourceOSIRISCDP first quarter 2026: 317 files handled, 283 receipts issued, 9 complaints
osiris.sn
Link checked 19 August 2026
- Secondary sourceallAfricaCDP quarterly notice for October to December 2025 — 165 files, 14 complaints, 2 formal notices
fr.allafrica.com
Link checked 19 August 2026
How long you must keep it — and when to delete it
There is no single national table of keeping periods. The maximum comes from the data protection law. Keep personal data only as long as you need it for the purpose you collected it for, then delete it. The minimums come from elsewhere. Business and accounting records must be kept for ten years under the regional business law treaty. Telecom operators may hold technical data for up to two years.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period
MAXIMUM. Article 35 of Law 2008-12 says personal data must not be kept longer than you need it for the purposes you collected and used it for. Article 72 lets you keep data beyond that only for historical, statistical or scientific purposes. MINIMUMS. Senegal is a member of OHADA. That is the regional body that harmonises business law in West and Central Africa. Its uniform accounting act requires accounting books and supporting documents to be kept for ten years. Tax audit powers rest on the same records. In telecoms, the Electronic Communications Code allows technical data to be held for up to two years, subject to conditions. In banking, the outsourcing rules require records and archives to stay accessible for the periods the applicable rules set. They give no single number. WHICH RULE WINS. The data protection law gives way where another law requires you to keep data. Keeping data because a law obliges you to is a lawful reason. So the ten-year accounting minimum beats the general 'delete when done' maximum, for the documents it covers. What Senegal does not have is a published rulebook telling you how to separate the data you must keep from the data you must delete. That work falls on you.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 35 and 72 (retention)
senegalnumeriquesa.sn
“Elles doivent être conservées pendant une durée qui n'excède pas la période nécessaire”
Link checked 19 August 2026
- Official sourceAutorité de Régulation des Télécommunications et des PostesCode des communications électroniques (Loi n° 2018-28 du 12 décembre 2018)
artp.sn
Link checked 19 August 2026
- Secondary sourceOHADA documentation libraryOHADA uniform act on accounting law — ten-year retention of accounting records
biblio.ohada.org
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There is no general duty to report a data breach in Senegal. We checked on 19 August 2026. The 2008 data protection law sets no deadline, in hours or otherwise. That is true both for telling the regulator and for telling the people affected. Banks must tell their supervisor about serious problems, but we found no published deadline in hours. Two changes are coming that would add reporting duties.
- What you have to do here:
- Report breaches to the regulator · Report cyber incidents
There is almost nothing to report and no deadline to meet today. That is itself the finding. The 2008 data protection law was written before breach reporting became standard. It has no article on it. The only reporting duty in the law runs the other way. The regulator must report offences it learns of to the public prosecutor without delay. WHAT EXISTS AROUND THE EDGES. Banks and financial holding companies fall under general internal control and risk management circulars. Those require serious incidents to be escalated to the Banking Commission. We could not find a published deadline expressed in hours. Telecom operators have security and confidentiality duties under the Electronic Communications Code and answer to the telecoms regulator. Companies hit by cybercrime can go to the police cyber unit. That is a criminal complaint, not a report to a regulator. WHAT IS COMING. The national digital strategy commits to making organisations report any breach within a reasonable time. That signals a future legal duty. The critical information infrastructure and digital security bill would create a national cybersecurity authority, a national computer emergency response team and sector teams. Reporting incidents to those teams is the obvious next step. Neither is law today.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12 — full text, checked for a breach notification article, none found
senegalnumeriquesa.sn
Link checked 19 August 2026
- Official sourcePrésidence de la République du SénégalNew Deal Technologique — commitment to require breach reporting within a reasonable timeframe
presidence.sn
Link checked 19 August 2026
- Official sourceGouvernement du Sénégal, PrimatureConseil des ministres du 17 juin 2026 — adoption of the bill on protection of critical information infrastructure and digital security
primature.sn
“le projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique”
Link checked 19 August 2026
What to do: Your breach process has to reach Senegal's regulator inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
The traps in Senegal are not about fines. They are about permission slips and cameras. Almost every use of personal data has to be filed with the regulator before you start. Some uses need written permission first. The regulator turns up unannounced. And data offences sit in the criminal code, so a person can be prosecuted, not just a company told off.
- What you have to do here:
- Appoint a representative
- What it costs if you get it wrong:
- Criminal liability
TRAP 1 - the filing duty is real and almost nobody does it. Under the 2008 law you must declare ordinary use of personal data to the regulator. It then issues a receipt. This has not quietly died. The regulator issued 283 receipts in the first quarter of 2026 alone. Operating without a receipt puts you in breach from day one, whatever else you get right. TRAP 2 - a second, tougher gate for the interesting data. Some uses need written permission first, not just a filing. Those are genetic data, health research, criminal offence data, linking separate databases, using the national identity number, and biometrics. Face recognition and fingerprint clocking-in systems sit squarely here. The regulator has ordered several of them switched off. TRAP 3 - cameras. Video surveillance dominates the regulator's caseload. It issued 200 receipts for businesses in one quarter. It also ordered cameras removed from meeting rooms, treatment rooms, kitchens and staff areas. A workplace camera rollout in Senegal is a regulatory project, not a facilities project. TRAP 4 - criminal liability. The 2008 law leaves punishment to the criminal code, as amended by the cybercrime law of the same date. It also makes the regulator pass offences to the prosecutor. So individuals are exposed, not just companies. TRAP 5 - a representative you actually have to appoint. A foreign company using equipment in Senegal must name a representative based in Senegal. There is no revenue threshold. There is no grace period in the text. TRAP 6 - for banks only, but expensive. An outsourcing contract must go to the banking supervisor to be assessed before you sign it. The supervisor expects your servers, or at least your backup servers, to be inside the West African monetary union.
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12, articles 18 to 21 (declaration and authorisation), article 75 (offences)
senegalnumeriquesa.sn
“les traitements de données à caractère personnel font l'objet d'une déclaration”
Link checked 19 August 2026
- Official sourceLink may be brokenCommission de Protection des Données PersonnellesCDP quarterly activity notices — video surveillance and biometric clocking-in cases
cdp.sn
Link checked 19 August 2026
- Official sourceCommission Bancaire de l'UMOACirculaire n° 04-2017/CB/C, article 33 — prior submission of outsourcing contracts
bceao.int
“Tout projet de contrat d'externalisation doit être soumis à l'appréciation préalable du Secrétariat Général de la Commission Bancaire”
Link checked 19 August 2026
What's changing next
One big thing is close. A bill on protecting critical information infrastructure and digital security was approved by the government on 17 June 2026. A parliamentary committee passed it on 13 August 2026. It still needs a vote in the full chamber, so it is not law. It would create a national cybersecurity authority. It would also make local hosting of public sector data compulsory.
IN THE NEXT TWELVE MONTHS. The critical information infrastructure and digital security bill. The Council of Ministers adopted it on 17 June 2026. It went to a joint parliamentary committee on 13 August 2026 and was adopted there. It now awaits the full sitting. Reported contents: a register of critical infrastructure, compulsory risk analysis, backup and encryption, resilience testing, and oversight of outsourced digital services. Also compulsory local hosting of public sector data, limits on relying on foreign cloud services, and a new national cybersecurity authority. Plus a national computer emergency response team and sector teams. Treat it as a proposal until the vote. Replacement of the 2008 data protection law. It has been discussed since 2020 and comes up again in the national digital strategy. That promises stronger confidentiality rules, informed consent, rules on data sharing, and breach reporting. No bill has been introduced. Do not plan around it. POWERS ALREADY HELD THAT COULD CHANGE THINGS WITHOUT WARNING. One. The regulator decides case by case, with no published criteria, which countries offer sufficient protection and which transfers are approved. It could tighten transfers tomorrow through refusals alone. No new law and no consultation would be needed. Two. The list of uses that need permission, rather than a simple filing, can be extended by regulation. Adding a category such as cloud hosting abroad would turn a filing into a permission overnight. Three. The national digital strategy already commits the state to hosting 100 percent of sensitive data in Senegal by 2034. Public contract terms and licence conditions can deliver that long before any law does. Those are not published as legislation. Four. Once the critical infrastructure bill passes, naming an operator as critical is expected to be an administrative decision. A private company could be pulled into the local hosting rules by a decision, not by a new law.
Sources
- Official sourceGouvernement du Sénégal, PrimatureConseil des ministres du 17 juin 2026 — bill adopted by government
primature.sn
“le projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique”
Link checked 19 August 2026
- Official sourcePrésidence de la République du SénégalNew Deal Technologique — 100 percent of sensitive data hosted in Senegal by 2034
presidence.sn
Link checked 19 August 2026
- Secondary sourceAgence de Presse SénégalaiseCybersécurité: un projet de loi élaboré pour renforcer la protection des infrastructures critiques (13 August 2026)
aps.sn
Link checked 19 August 2026
- Secondary sourceAfrique IT NewsMandatory local hosting of public sector data in the committee-adopted bill
afriqueitnews.com
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking data needs a copy kept in the country
Official name: Circulaire n° 04-2017/CB/C relative à la gestion des risques dans les établissements de crédit et compagnies financières de l'UMOA · Circulaire n° 04-2017/CB/C, article 33 · Regulator directive
This is the strictest data location rule that touches Senegal. Banks and financial holding companies must keep all their data available inside the West African monetary union. The servers holding that data must be in the Union. If they are not, backup servers must be. Outsourcing contracts must go to the banking supervisor before they are signed.
Enforced by Banking Commission of the West African Monetary Union
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryAll of the institution's physical and electronic data must be available within the West African Monetary Union. The servers that store the data and run the applications must be in the Union. If they are not, you need backup servers in the Union.
- Written vendor contractEvery outsourcing contract must go to the Banking Commission's Secretariat General to be assessed first. The institution's board must also approve it.
- Independent auditThe board must review the full list of outsourcing contracts at least twice a year.
What it costs if you get it wrong
- Loss of your licenceSupervisory action by the Banking Commission for breach of prudential circulars; sanctions range from warnings to withdrawal of the banking licence
Sources
- Official sourceCommission Bancaire de l'UMOA / BCEAOCirculaire n° 04-2017/CB/C, article 33 (externalisation)
bceao.int
“L'ensemble des données physiques et électroniques des établissements doivent être disponibles dans l'UMOA”
Link checked 19 August 2026
- Official sourceCommission Bancaire de l'UMOACirculaires de la Commission Bancaire de l'UMOA
cb-umoa.org
Link checked 19 August 2026
Finance data needs a copy kept in the country
Official name: Instruction n° 009-06-2015 relative aux dispositifs de sécurité des systèmes d'information des bureaux d'information sur le crédit · Instruction n° 009-06-2015, article 8 · Directly binding regulation
Credit bureaus serving Senegal must keep their backup copies on a site in another country of the West African monetary union. So a full copy of the credit file stays inside the region, even if the data is used elsewhere.
Enforced by Central Bank of West African States
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryBackup media must be held on a site in another member state of the West African Monetary Union. That keeps the backup copy inside the bloc.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceCredit bureaus operate under a licence from the central bank; breach of the security instruction is a licensing matter
Sources
- Official sourceBCEAOInstruction n° 009-06-2015, article 8
bceao.int
“la délocalisation des supports de sauvegarde sur un site situé dans un autre Etat membre de l'UMOA”
Link checked 19 August 2026
Telecoms rules
Official name: Loi n° 2018-28 du 12 décembre 2018 portant Code des communications électroniques · Loi n° 2018-28 · Act of parliament
Telecom operators in Senegal must identify every subscriber, protect the confidentiality of communications, and may hold technical data for up to two years. We found no requirement to keep telecom data inside Senegal, checked on 19 August 2026.
Enforced by Telecommunications and Postal Regulatory Authority
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What you have to do
- Secure the dataOperators must guarantee the confidentiality of communications.
- Keep logs — 2 yearsThe code permits deferred retention of technical data for up to two years, subject to conditions.
- Keep records of how you use dataOperators must identify their subscribers. The telecoms regulator has enforced SIM registration deadlines and caps on the number of lines per subscriber.
What it costs if you get it wrong
- Loss of your licenceBreach of licence and code obligations, enforced by the telecoms regulator
- Order to stopDisconnection of unidentified subscriber lines
Sources
- Official sourceAutorité de Régulation des Télécommunications et des PostesCode des communications électroniques — regulator's documentation page
artp.sn
Link checked 19 August 2026
- Official sourceGouvernement du Sénégal, PrimatureCode des communications électroniques (Loi n° 2018-28) — government publication page
primature.sn
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Health data rules
Official name: Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel · Loi n° 2008-12, Journal Officiel de la République du Sénégal · Act of parliament
Senegal's general privacy law. It reaches foreign companies that use equipment in Senegal and makes them appoint a local representative. Almost every use of personal data must be filed with the regulator first. Sensitive uses such as biometrics and health need written permission. Data may leave the country only to places that protect it well enough, or with the regulator's approval.
Enforced by Commission for the Protection of Personal Data
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, To save someone’s life, Legal claims, Important public interest
What you have to do
- Register or notifyYou must declare ordinary use of personal data to the regulator. It issues a receipt within one month.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people object
- Secure the data
- Appoint a representativeYou need this if you are based outside Senegal but use equipment located in Senegal to handle the data.
- Put a transfer safeguard in placeThe destination country must ensure a sufficient level of protection. If it does not, the regulator must approve the transfer.
- Delete data after a periodKeep data no longer than you need it for the stated purpose. You may keep it longer only for historical, statistical or scientific use.
What it costs if you get it wrong
- Fixed maximum fine: 100 000 000 FCFA (minimum 1 000 000 FCFA) — about $170 thousandBreach of the data protection law after a formal notice
- Order to stopWithdrawal of a permission for three months, then permanently; temporary or permanent ban on the processing
- Criminal liabilityOffences are punished under the criminal code as amended by the cybercrime law of 25 January 2008; the regulator must refer offences to the public prosecutor
Sources
- Official sourceSénégal Numérique SALoi n° 2008-12 du 25 janvier 2008 — Journal Officiel text
senegalnumeriquesa.sn
“Le responsable d'un traitement ne peut transférer des données à caractère personnel vers un pays tiers que si cet Etat assure un niveau de protection suffisant”
Link checked 19 August 2026
- Official sourceLink may be brokenCommission de Protection des Données PersonnellesCDP — legislative and regulatory texts
cdp.sn
Link checked 19 August 2026
Cyber security rules
Official name: Projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique · Adopted in Council of Ministers on 17 June 2026; adopted in joint parliamentary committee on 13 August 2026 · Draft law
A bill, not a law. The government approved it on 17 June 2026. A parliamentary committee approved it on 13 August 2026. It still needs a vote in the full chamber. It would make local hosting of public sector data compulsory. It would limit the use of foreign cloud services. And it would create a national cybersecurity authority, with national and sector incident response teams.
Enforced by Ministry of Communication, Telecommunications and Digital Affairs
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryReported to make local hosting of public sector data compulsory and to restrict reliance on foreign cloud services. Not law yet.
- Register or notifyIdentification and registration of critical information infrastructure.
- Assess high-risk projectsCompulsory risk analysis and periodic resilience testing.
- Secure the dataBackup and encryption requirements.
- Report cyber incidentsWould create a national cybersecurity authority, a national computer emergency response team and sector teams.
Sources
- Official sourceGouvernement du Sénégal, PrimatureConseil des ministres du 17 juin 2026
primature.sn
“le projet de loi sur la protection des infrastructures d'information critiques et la sécurité numérique”
Link checked 19 August 2026
- Secondary sourceAgence de Presse SénégalaiseBill presented to a joint parliamentary committee, 13 August 2026
aps.sn
Link checked 19 August 2026
- Secondary sourceAfrique IT NewsMandatory local hosting of public sector data under the bill
afriqueitnews.com
Link checked 19 August 2026
Personal data must stay in the country
Official name: New Deal Technologique — Stratégie numérique du Sénégal, Horizon 2034 · New Deal Technologique, published by the Presidency · Government policy document
A government strategy, not a law, and it carries no penalty. It matters because it shows where the state is heading. It wants all sensitive data hosted in Senegal by 2034, a sovereign cloud, and a future breach reporting duty. Expect this to show up first in public contracts and licence conditions, not in a law.
Enforced by Ministry of Communication, Telecommunications and Digital Affairs
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the country — from 1 January 2034Policy target, not a legal duty: 100 percent of sensitive data hosted in Senegal by 2034.
- Prove the data stays under local controlCommitment to build sovereign cloud offerings and sovereign, resilient national infrastructure.
- Report breaches to the regulatorStated intention to require organisations to report breaches within a reasonable timeframe. No statute yet.
Sources
- Official sourcePrésidence de la République du SénégalNew Deal Technologique — Senegal's digital strategy to 2034
presidence.sn
Link checked 19 August 2026
- Official sourceGouvernement du Sénégal, PrimatureStratégie numérique du Sénégal, le New Deal Technologique, Horizon 2034
primature.sn
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That Law 2008-12 has not been replaced or amended between 1 and 19 August 2026
We could not confirm that the 2008 law was left unchanged in early August 2026. The regulator's own website returns no readable content to automated tools, so we could not read its legislation page. We found no sign of a new law from any other source. Ask the regulator if a very recent change would affect you.
The exact wording of article 49's requirement to notify the regulator before a transfer
We could not confirm the exact wording that triggers the duty to tell the regulator before a transfer. Two separate reads of the official text agree the duty exists. Treat the duty as real. Check the precise wording before you rely on the detail.
The full verbatim text of article 33 of banking circular 04-2017/CB/C
We could not confirm exactly how far the backup server option goes. The duty to keep data available inside the monetary union comes straight from the regulator's own document, along with the server rule. The wording on backup servers is our summary, not a quotation. Check it with the Banking Commission before you rely on it.
Whether insurance and securities firms in Senegal face data location rules
We could not confirm the rules for insurance and securities firms. Senegal's insurers sit under the Inter-African Conference of Insurance Markets. Its securities market sits under the regional financial markets authority. We did not search either rulebook. If you work in these industries, check before you rely on this.
Any incident reporting deadline in hours for Senegalese banks
We could not confirm any deadline for telling the Banking Commission about an incident. Professional commentary says the duty exists. We found no published deadline on the regulator's own site. If you are a bank, ask your supervisor.
The text of the critical information infrastructure and digital security bill
We could not confirm what the bill actually says. The government's own statement confirms the Council of Ministers adopted it on 17 June 2026. But the text is not published on a government site we could reach. The local hosting rule and the new agencies come from the state press agency and specialist media, not from the bill itself.
Whether the regulator has ever imposed a monetary fine
We could not confirm whether the regulator has ever issued a money fine. We found none in the quarterly notices we read. The power to fine clearly exists in the law. Do not assume fines never happen.
Whether health, education, gaming, mapping or defence data faces any location rule
We found no location rule for these industries, searched on 19 August 2026. Senegal's digital health law was still being discussed in 2025. These industries are usually governed by ministry documents that are not published online in Senegal. If you work in one, check with the ministry.
Exact prison terms for data protection offences
We could not confirm the prison terms. Law 2008-12 leaves punishment to the criminal code, as amended by the cybercrime law of the same date. We did not read an official copy of the amended criminal code. Criminal liability exists, but we cannot tell you the size of the penalty.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 30 days. Next check due 18 September 2026.