§ 05 · METHODOLOGY · updated 22 July 2026

How this dataset is built

This page sets out the principles the tracker is held to, so a reader can judge how far to trust it and cite it.

Sources and inclusion

A record enters the tracker when an African regulator, tribunal or court publishes an enforcement outcome under a data protection or closely adjacent regime: determinations, penalty and enforcement notices, court rulings, investigations, settlements and advisories. Records are built from primary sources, the official published documents of authorities and courts. Every record carries the URL of the document it summarises, and where the original is in another language the source-language text is kept beside the English summary. If we cannot link a source, we do not publish the record.

Enforcement versus regulatory activity. This tracker holds enforcement outcomes. A regulator's routine authorisations, declarations, receipts and advisory opinions are regulatory activity, not enforcement, and are not counted as "decisions". Counting authorisations as enforcement would inflate the figure; we do not. A small number of financial-sector penalties are included as enforcement-scale benchmarks and are labelled plainly as such, not as data protection actions.

What a bare count leaves out. Every figure on this site carries its qualifier: "published", "that we could find", a date range, or a denominator. The dataset structurally undercounts jurisdictions whose regulators do not publish individual decisions: a low or zero count means "nothing published we could verify", not "no enforcement". Read every figure as a count of the public record, not of all enforcement.

Verification before publication

Every record is verified against its source document before it is published. Records that cannot be verified are not published: nothing on this site is marked "unverified", and nothing enters the public tracker on the strength of a summary alone. Verified figures and quoted provisions trace back to the primary text.

Dates and precision

Where a regulator publishes only a month, the record says so ("month-precision date") rather than inventing a day. Statistics use the decision date, not our publication date.

Money

Original-currency figures are authoritative. USD equivalents are approximate conversions at the decision date and are marked as such. Wherever a mean appears, the median appears beside it: a single Meta-scale fine distorts an average, and a reader deserves both numbers.

Privacy in the records themselves

Individual complainants are not named in tracker records, even where the regulator names them. Respondent names are public regulatory outcomes and are kept. The linked official document remains the complete record.

Editorial policy

Editorial control over the tracker rests with our editors and no one else, including where a record's source is the authority that made the decision. The full policy is published at Editorial Policy.

Corrections

Errors are corrected in place. Each correction is noted and dated on the record page itself. To report one, email info@lawlab.africa with the record ID and the source that contradicts us; we respond to every correction report.

Citing the tracker

Law Lab Africa Research, African Data Protection Enforcement Tracker, https://research.lawlab.africa/tracker/ (accessed 22 July 2026).

Every decision page carries its own formatted citation with a copy button. Reuse is free with attribution and a link; commercial reuse of the database is licensed. See data licensing.

Update cadence

The dataset updates as regulators publish and as records pass verification. The build date stamped on every page is its last refresh; these dates are set by the build, never typed by hand. Current dataset: 595 decisions across 10 jurisdictions.

Legal information, not legal advice. The tracker summarises public documents. It is not a substitute for the documents themselves or for advice on your facts from qualified counsel.