Kenya's Office of the Data Protection Commissioner (ODPC) spent the final week of June hosting data protection authorities from across Africa in Nairobi, closing out a study trip on June 30, 2026 that focused on cross-border cooperation and harmonized data governance frameworks. Delegates traded notes on regulatory supervision, institutional capacity, and policy implementation, and the ODPC used the gathering to reaffirm what it called the "collective commitment" of the continent's privacy regulators to keep cooperating (ODPC).
The timing is notable. Kenya has spent the past two years positioning itself as the continent's most outward-facing data protection regulator — first by launching, in May 2024, the first-ever EU adequacy dialogue on the African continent (EEAS), and now by playing host to the pan-African conversation on harmonization. But Kenya's own accession to Africa's actual harmonization instrument — the African Union's Malabo Convention on Cyber Security and Personal Data Protection — has been stuck since the Cabinet approved it in 2025. The ODPC ran stakeholder consultations on accession through October 6, 2025, gathering input from ministries, county governments, industry, and civil society (ODPC). Ten months later, Kenya still has not deposited an instrument of ratification.
The Case for a Continental Instrument
The argument for a single continental framework is genuine and worth taking seriously. Africa's 54 countries operate under wildly divergent data protection regimes — some, like Kenya, Nigeria, and South Africa, have GDPR-style comprehensive statutes; others have none. For a company operating across even three or four African markets, that patchwork means duplicative registration, inconsistent consent standards, and legal uncertainty about whether a cross-border transfer is even lawful. As the African Continental Free Trade Area's digital trade protocol advances, fragmented privacy law is a real drag on intra-African commerce, not just a compliance headache. A shared baseline — mutual recognition of adequacy, common breach-notification timelines, a single set of rules for law-enforcement data requests — would lower costs for the small and mid-sized firms that make up most of Africa's digital economy, not just multinationals with compliance budgets to spare.
Why Malabo Isn't That Instrument
The trouble is that the treaty built to do this job is a weak vehicle for it. The Malabo Convention was drafted in 2011 and adopted in 2014, and only crossed its 15-ratification threshold to enter into force in June 2023 — nine years later. As of the most recent tally, just 15 of the AU's 55 member states have ratified it, and none of the continent's largest digital economies — Nigeria, Egypt, South Africa, Morocco, Ethiopia, or Kenya itself — are among them (EU Cyber Direct). Critics have flagged the convention's own design flaws: it bundles cybersecurity, e-transactions, and data protection into one instrument, was drafted with minimal private-sector or civil-society input, and predates the last decade of change in how data actually moves — cloud infrastructure, AI training pipelines, platform-scale data flows. A treaty that struggles to attract its own drafters as ratifiers is not a credible foundation for continental harmonization, and Kenya's hesitation to accede — even after Cabinet approval — is a rational response to those flaws, not an oversight.
The Better Model Is Already Running
Kenya's own EU adequacy dialogue is a more instructive template than Malabo. As of June 2026, Kenyan officials describe that process as being "at its final stages, with only a few outstanding technical elements remaining" (Tech Review Africa). That is a bilateral, functional approach: two regulators assess each other's legal safeguards and agree that data can flow freely between them, without either side rewriting its domestic statute to match a common template. It is slower to scale — Kenya can't sign one dialogue and cover 53 other countries — but it produces enforceable, calibrated outcomes instead of a treaty that fifteen years on still lacks the participation of the countries it most needs.
What Nairobi Should Actually Push For
The study trip's instinct — that African regulators benefit from talking to each other about cross-border cooperation — is sound, and low-risk: shared training, common templates for breach notification, informal channels for joint investigations. Where the continent should be cautious is treating a single binding instrument as the destination. Kenya is well placed to make that case precisely because it is simultaneously the host of the harmonization conversation and a country still weighing whether the leading harmonization treaty is worth joining. Rather than pushing other regulators toward Malabo ratification, Kenya's stronger contribution would be exporting the adequacy-dialogue model — network of bilateral and plurilateral mutual-recognition arrangements, built incrementally, that don't require the continent's most digitally advanced economies to wait on ratification thresholds that have already taken over a decade to clear once.