In October 2021, Kenya’s High Court ruled that the government had acted unlawfully in rolling out Huduma Namba, its flagship digital identity programme. The state had collected personal and biometric data from millions of citizens without first conducting a data protection impact assessment, as the Data Protection Act of 2019 required. The court barred further implementation until that assessment was done. Two years later, when the government launched a successor system, Maisha Namba, it faced fresh legal challenges on similar grounds.
The Kenyan saga captures the defining tension of digital public infrastructure. DPI runs on information: names, fingerprints, addresses, payment records, health histories. The more data a system holds and connects, the more useful it becomes to governments and businesses, and the more harm it can cause if that data is leaked, abused or used to shut people out.
Africa’s legal response has been swift on paper. More than 35 African countries now have data protection laws. South Africa’s Protection of Personal Information Act took full effect in 2021. Nigeria passed its Data Protection Act in 2023 and established a dedicated commission to enforce it. At the continental level, the African Union’s Malabo Convention on cyber security and personal data protection finally entered into force in June 2023, nine years after adoption. The AU’s Data Policy Framework, endorsed in 2022, sets out how member states should govern and share data across borders.
Enforcement is where the picture weakens. Many data protection authorities are young, thinly staffed and underfunded. Some report to the very ministries whose systems they are supposed to police. Penalties are rare, and most citizens have never heard of the regulator, let alone filed a complaint. A law that nobody enforces offers citizens little more than a promise.
System design matters as much as legislation. The strongest DPI architectures collect only what is necessary, keep data in separate databases rather than a single central store, and log every access so individuals can see who has viewed their records. The weakest link everything to one number, allowing a person to be tracked across banking, health, travel and telecommunications with little oversight.
Exclusion is the other risk, and it is often more immediate than surveillance. When access to hospitals, pensions or cash transfers depends on a digital ID, those who cannot enrol are pushed out. A 2021 report by Ugandan and international rights groups documented older people and rural residents being denied health care and social payments because they lacked a national ID card. Missing birth records, worn fingerprints and long distances to registration centres all contribute.
Trust determines whether these systems succeed. Citizens adopt digital services faster when they understand what is collected, why, and who can see it, and when they have a real way to challenge errors. Public consultation, independent oversight and accessible grievance processes are not administrative extras. They are what make DPI workable.
Some governments are adjusting. Ethiopia has designed its Fayda ID around minimal data collection for verification. Several countries now hold consultations before launching major systems, partly because courts have made the cost of skipping them clear.
Cross-border flows will test the continent next. As the African Continental Free Trade Area deepens, companies will need to move customer data between countries with different rules. Without harmonised standards, compliance costs will climb and smaller firms will struggle to compete.
The question of who holds Africa’s data is ultimately a question of power. DPI can strengthen citizens or expose them. The Kenyan courts have shown that the rules protecting people must be built at the same time as the systems that collect their information, not after.
