Research hub / Senegal
§ Dossier · WEST AFRICA · updated 22 July 2026

Senegal

Regulator
Commission de Protection des Données Personnelles (CDP) ↗
Law
Law No. 2008-12 on the Protection of Personal Data (modernization bill pending) ↗
Status
Live in the tracker
Authority
Commission de Protection des Données Personnelles (CDP), established 2008
24
published decisions tracked
CDP: 24
2025-09
latest decision
data updated 22 July 2026

The law

Law No. 2008-12 of 25 January 2008 on the Protection of Personal Data IN FORCE

commenced 2008-01-25 · Official full text ↗

Scope
All data relating to an identified or identifiable individual (art. 4), processed by private or public controllers; state-sector automated processing proceeds by regulatory act after a reasoned CDP opinion (arts. 20-21).
Key obligations
Prior notification of processing to the CDP, with narrow exemptions for non-profit associations and public registers (art. 18); Prior CDP authorisation for genetic data, offence data, file interconnection, national ID numbers, biometric data and public-interest processing (art. 20); Communication to the CDP of the departments and categories of persons with direct access to data (art. 22); Standard processing principles: lawfulness, purpose limitation, proportionality, accuracy, limited retention, security
DPO required
No: appointment of a DPO is discretionary for businesses; ministries must designate CDP focal points for the census and declaration of personal-data files (Directive No. 2757 of 24 June 2014).
Registration
Yes: notification to the CDP for processing generally, prior authorisation for the art. 20 categories, and a reasoned-opinion ('avis') regime for state processing (arts. 18-21).
Cross-border transfers
Transfers to a third country only where it ensures a sufficient level of protection, with prior INFORMATION to the CDP before any transfer (art. 49); punctual non-massive transfers to non-sufficient destinations ride express consent or necessity (life, public interest, legal claims, contract) (art. 50); the CDP may authorise other non-adequate transfers on a reasoned application where the controller offers sufficient guarantees (art. 51). Inbound rule: the CDP verifies protection before processing of data originating abroad (art. 49 al. 3). (Verified from the archived text 2026-07-11, S27.)
Breach notification
No mandatory breach-notification protocol under the 2008 law.
Penalties
CDP administrative fines of XOF 1,000,000 to 100,000,000, plus warning, injunction, provisional (three-month) then definitive withdrawal of authorisation, and urgent measures (processing interruption, data locking, prohibition); criminal sanctions of one to seven years' imprisonment and fines of XOF 500,000 to 10,000,000 (Penal Code art. 431-14).
Authority
Commission de Protection des Données Personnelles (CDP)

Verified 2026-07-10

Access to information

Law No. 2025-15 on Access to Information IN FORCE

The regulator

Authority
Commission de Protection des Données Personnelles (CDP)
Website
https://www.cdp.sn ↗
Established
2008
Operational
Yes
Enforcing
Yes
Publishes decisions
Yes · publication venue ↗

Enforcement record

Decision types: Enforcement notice · 18 · Determination · 5 · Investigation · 1

01Filter or search the decisions below
02Click a result to preview its summary
03Open the full record for citation and sources

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Senegal

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.