Dr. Arnold Kavaarpuo, Executive Director of Ghana's Data Protection Commission (DPC), has called for stronger collaboration among African regulators. He made this appeal at the second Pan-African AI and Innovation Summit 2026 in Accra, Ghana. The summit, organized in partnership with several institutions, focused on scaling Africa's ethical AI and innovation ecosystem. Dr. Kavaarpuo emphasized that no single regulator or African country can effectively govern the growing influence of global technology companies.

The growing influence of global technology companies spans multiple areas, including communications, cloud infrastructure, digital identity, payments, AI models, and market access. Dr. Kavaarpuo noted that African regulators must move beyond protecting personal data to addressing broader questions of data control, processing, and economic value generation. He stressed that regulators must become connected to effectively tackle these issues.

Africa has made significant progress in establishing data-protection regimes. Currently, 44 of the 55 African Union (AU) member states have enacted data-protection laws. Of these, 38 have both legislation and operational regulators, while six have laws but non-operational regulators. This leaves 11 countries without data-protection legislation. The continent's regulatory architecture is also developing at regional and continental levels.

The ECOWAS framework, the SADC Data Protection Model Law, and the AU Malabo Convention on personal data protection, cybersecurity, and electronic transactions are examples of regional and continental developments. Additionally, the AU Data Policy Framework, adopted in 2022, and the AfCFTA Protocol on Digital Trade, adopted in 2024, mark a shift towards treating data as a strategic resource. These developments support trusted cross-border data flows while ensuring protection.

Dr. Kavaarpuo highlighted recent regulatory actions in Africa involving major technology companies. For instance, Nigeria took action against Meta, and Kenya initiated regulatory proceedings involving Worldcoin. These examples demonstrate that African institutions can enforce data and competition rules. The DPC Executive Director also presented the Network of African Data Protection Authorities (NADPA) draft Model Policy on Cross-Border Data Transfers.

The proposed policy provides a framework for African countries to adopt compatible national approaches while retaining sovereignty over data within their jurisdictions. The framework uses a risk-based classification of data and offers six pathways for lawful cross-border transfers. This includes adequacy decisions, standard contractual clauses, binding corporate rules, certification, specific authorization, and limited derogations.

Other speakers at the summit, including Mr. Samuel Nartey George, Minister of Communication, Digital Technology and Innovation, and Madam Thelma Quaye, Chief Digital Infrastructure, Skills and Empowerment Officer at Smart Africa, echoed Dr. Kavaarpuo's calls for coordination and interoperability. They emphasized the need for a shared continental ambition on AI, stronger coordination, and investment in computing capacity, research, talent, datasets, and start-ups.

Key points

  • Dr. Arnold Kavaarpuo calls for stronger collaboration among African regulators to address growing tech power.
  • African regulators need to move beyond protecting personal data to addressing broader questions of data control and processing.
  • The continent has made significant progress in establishing data-protection regimes, with 44 AU member states enacting data-protection laws.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.