← Back to the blog
ECOWAS · Regulatory news

ECOWAS revises its supplementary act on data protection: what the new text should change

AM
The AMELEGAL team
Digital law firm · 6 August 2026

Meeting in Lungi, Sierra Leone, on 19 July 2026, the sixty-ninth ordinary session of the ECOWAS Authority of Heads of State and Government adopted the revision of the supplementary act on the protection of personal data within the Community area, on the recommendation of the Council of Ministers. The final communiqué (paragraph 33) also mentions regional instruments on open data, electronic communications, digital governance, roaming and cybersecurity, together with the creation of a regional cybersecurity coordination mechanism.

Sixteen years after the supplementary act A/SA.1/01/10, signed in Abuja on 16 February 2010 by the fifteen member states of the time, West Africa is equipping itself with a recast framework: within a Community now down to twelve members following the withdrawal of Burkina Faso, Mali and Niger. To date, the adopted text has not been released : its appearance in the Official Journal of the Community is keenly awaited, since it conditions both its entry into force and the definitive reading of its provisions. The analysis that follows therefore rests on the draft revision from the ECOWAS Commission ; the final decisions may depart from it.

Cover page of the preliminary draft revision of supplementary act A/SA.1/01/10 on the protection of personal data in the ECOWAS area, ECOWAS Commission
Cover page of the preliminary draft revision of supplementary act A/SA.1/01/10, prepared by the ECOWAS Commission.
5 %
of annual turnover: the ceiling on the fine provided for
72 h
to notify a data breach
12 States
members today, against 15 in 2010
3 years
to bring national laws into conformity

Why the 2010 text was no longer sufficient

The 2010 act played a foundational role: it required member states to adopt legislation and an independent protection authority, and it served as the template for most national laws passed since. But it predates widespread mobile money, biometric identity, cloud computing and generative AI. It says nothing of impact assessments, records of processing activities, breach notification, the data protection officer, or portability.

Above all it suffered from a lack of effectiveness: obligations without regional coordination, and national authorities with widely unequal means. Hence the draft's stated ambition: a regulatory framework that is "updated, strengthened, strict and binding", coupled with a sub-regional supervisory body.

The significant changes envisaged by the draft

A scope that follows the data, not the establishment

The text would apply to processing by a controller or a processor not established in the Community, wherever they target individuals located in the ECOWAS area: the offering of goods or services, or the monitoring of behaviour. This is the extraterritoriality that gave the GDPR its force, transposed to a West African scale: foreign platforms targeting the region's markets would fall within the scope of Community law.

Principles set out expressly

Purpose, lawfulness, minimisation, retention period, accuracy, transparency, confidentiality and security: each principle is given its own article. Consent is redefined demandingly: freely given, specific, informed, unambiguous, separate for each purpose, and as easy to withdraw as to give. In online services, the processing of data relating to minors would require the consent of the holder of parental responsibility, with each state setting a minimum age.

Data subject rights: one novelty, two consolidations

Let us avoid a common shortcut. The 2010 act did not overlook erasure: its article 41, "right of rectification and destruction", already allowed data subjects to obtain the rectification, updating, blocking or the destruction of inaccurate, incomplete or out-of-date data. The revision therefore does not create this right: it restructures and broadens it.

The broadening bears on three points. Erasure becomes available as soon as the data is no longer necessary, consent is withdrawn, an objection succeeds, or the processing is unlawful. There appears thedigital forgetting : a controller who has made data public must inform other controllers, including as to links and copies. Exceptions are finally laid down, from freedom of expression to the defence of a legal claim. The right to restriction makes the blocking measure of article 41 free-standing.

The genuine novelty lies elsewhere: the right to portability. Receiving one's data in a structured, commonly used and machine-readable format, and having it transmitted from one controller to another: there was nothing of the kind in 2010. For telecommunications operators, banks and digital finance, this is as much an architectural constraint as a compliance one.

From formalism to documented accountability

The regime of prior formalities would be refocused on authorisation, for a list of sensitive processing operations: genetic and health data, offence data, the interconnection of files, national identification numbers, biometrics, profiling. To this are added two tools of continuing compliance: the record of processing activities and theimpact assessment in advance wherever processing may give rise to a high risk.

Profiling: a long-standing concern, a new regime

Here too, continuity prevails. article 35 of the 2010 act already prohibited a judicial decision assessing a person's conduct, or any decision producing legal effects, from being based solely on automated processing intended to profile that person. What changes is the emphasis: from a targeted prohibition on a decision, one moves to theframing of processing. Profiling receives a free-standing definition, enters the list of processing subject to prior authorisation and triggers the impact assessment. To this is added a provision without precedent: advanced and innovative technologies, capable of large-scale automated processing, would likewise be subject to authorisation. A broad formulation, which targets (without naming it) the exploitation of data by artificial intelligence systems.

Breach notification within 72 hours

Absent in 2010, notification to the authority would take place without undue delay and, where feasible, no later than 72 hours after becoming aware of it: the nature and likely consequences of the breach, the approximate number of individuals and records concerned, and the corrective measures. Where the risk is high, the data subject would themselves be informed; the processor would alert the controller within the same period.

The data protection officer, recognised and protected

Their duties would be precisely defined (to inform and advise, to monitor compliance, to train staff, to act as point of contact for both the authority and data subjects) and accompanied by a guarantee of independence : no instructions in the exercise of their duties, timely involvement, and regular updating of their expertise.

Penalties commensurate with the risk

Where the 2010 act deferred to national laws, the draft sets a Community ceiling. Following a warning, formal notice, suspension, blocking or prohibition, the authority could impose, at the conclusion of adversarial proceedings, a fine of up to 5% of annual turnover exclusive of tax, calibrated against nine criteria, from the gravity of the breach to the degree of cooperation.

Transfers: free movement inside, safeguards outside

Flows within the ECOWAS area would be unrestricted, with the controller remaining fully bound by the security measures. To a third country, transfer would presuppose that the country has a protection law and and a supervisory authority; failing that, the controller would have to demonstrate an adequate level of protection and inform its own authority beforehand. The Commission would lay down the rules: a list of adequate countries, standard contractual clauses, codes of conduct.

A regional supervisory architecture

This is the heart of the institutional change. The draft creates a West African Data Protection Authorities Network (WADPAN) : harmonising policies, guidelines and model safeguards for transfers, investigations and audits, an annual report to the Commission, joint actions, and a one-month deadline for responding to mutual assistance requests. A second body, theWest African data protection authority, would oversee privacy within the Community institutions.

"Release of the adopted text is keenly awaited: it is liable to reshape profoundly the conduct of compliance and data protection in the member states, from the level of penalties incurred through to the very organisation of inspections."

The timetable: what is still to come

The draft provides for publication in the Official Journal of the Community within thirty days following signature, then in that of each state thirty days after notification. Entry into force would follow these publications, the act being annexed to the revised ECOWAS Treaty. Each state would then have three years at most to transpose it.

For each member state, this implies a review of its national law: prior formalities, portability, the erasure regime, breach notification, the powers and resources of the authority, and the interface with the future regional network. The timetable also matters for states that have left the Community: their operators will still process data relating to individuals located in the ECOWAS area and will on that basis fall within the scope of the text.

What an organisation can do right now

Four workstreams are no-regret moves: they already flow from national legislation and will form the basis of the Community baseline.

This article is based on the final communiqué of the 69e ordinary session (Lungi, 19 July 2026) and on the preliminary draft revision prepared by the ECOWAS Commission. As the definitively adopted text has not been published, the provisions described may change. We will update this analysis as soon as it appears in the Official Journal of the Community.

CAP Conformité · online

Prepare for the Community baseline

Start by measuring the maturity of your current framework: it is the starting point for any regional upgrade.

Take the self-assessment

Prepare for the revision with AMELEGAL

A gap analysis between your framework and the future ECOWAS baseline, record of processing activities, impact assessments, breach notification procedure, mapping and securing of transfers, appointment and training of the officer.

Sources: final communiqué of the 69e ordinary session of the ECOWAS Authority of Heads of State and Government, Lungi, 19 July 2026; supplementary act A/SA.1/01/10 of 16 February 2010; preliminary draft revision prepared by the ECOWAS Commission. This article provides general information and does not constitute legal advice. AMELEGAL

Thank you ! A confirmation email has just been sent to you. Click the link it contains to confirm your subscription, and do check your spam folder if it does not appear in your inbox.
Newsletter

AMENEWS

Your African legal and digital newsletter.

Each month, a selection of analysis and practical resources : personal data protection, the Malabo Convention, cybersecurity, artificial intelligence and digital governance in Africa.

Add a comment