Research hub / Somalia
§ Dossier · EAST AFRICA · updated 22 July 2026

Somalia

Regulator
Somalia Data Protection Authority ↗
Law
Data Protection Act (Law No. 005 of 2023; effective 23 March 2023) ↗
Status
Law in force, enforcement not found
Authority
Somalia Data Protection Authority, established 2024
in force
DP law status
Data Protection Act (Law No. 005 of 2023; effective 23 March 2023)
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Data Protection Act (Law No. 005 of 2023) IN FORCE

commenced 2023-03-23 · Official full text ↗

Scope
Processing of personal data in Somalia across all sectors; first comprehensive Somali privacy law.
Key obligations
Registration of significant data controllers/processors (milestones keyed to March 2025); Implementing regulations and DPA guidance issued; Accreditation/licensing of compliance organisations
DPO required
Per DPA guidance for significant controllers.
Registration
Yes: significant controllers/processors register with the DPA.
Cross-border transfers
Transfers require destination adequacy (country/region/sector), an adequate international organisation, or a recipient bound by a law, BCRs, contractual clauses, code of conduct or certification mechanism (art. 30(1)), with the relied-on condition recorded (art. 30(3)); the Authority may designate adequacy but designation is not a precondition, and no prior authorisation exists (art. 30(4)-(5)). Art. 31 derogations: informed unwithdrawn consent, contract with the data subject, contract in the data subject's interest, the data subject's benefit, and residual compelling-legitimate-interest transfers (non-repetitive, limited, Authority informed). (Verified from the archived Act text 2026-07-11, S27.)
Breach notification
Article 25 ('Data breach notifications'): where a breach is likely to result in a risk to individuals' rights and freedoms, the controller must notify the Authority within 72 hours of becoming aware (extendable for law-enforcement/scope needs, with reasons); where the breach is likely to result in high risk, the controller must also communicate it to each affected data subject without undue delay, in plain language (a public communication may substitute where direct contact is disproportionate). Article 26 sets the required contents.
Penalties
Investigations and penalties levied by the DPA; specifics in regulations.
Authority
Somalia Data Protection Authority (dpa.gov.so; launched Feb 2024)

Verified 2026-07-06

The regulator

Authority
Somalia Data Protection Authority
Website
https://dpa.gov.so ↗
Established
2024
Operational
Yes
Enforcing
No enforcement activity found
Publishes decisions
No

Enforcement record

No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Somalia

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.