Protect the data. Preserve trust.
We help companies operating in Senegal achieve compliance with Law No. 2008-12 on personal data protection and the requirements of the Personal Data Commission (CDP).
- ✓Prior declaration to the CDP
- ✓Appointment of a data protection officer
- ✓Respect of data subjects' rights
- ✓Breach notification within 72h
An end-to-end path to compliance
From initial audit to sustainable compliance, we cover the full data protection lifecycle.
Compliance audit
Mapping your data processing activities, gap assessment against Law 2008-12, and identification of priority risks.
CDP declaration & authorization
Preparation and filing of prior declaration files and authorization requests with the CDP. Follow-up until receipt is issued.
Data Protection Officer (DPO)
Designation and support for your internal DPO. Full outsourcing of the DPO role for organizations without a dedicated resource.
Data subject rights management
Implementation of access, rectification, objection, and erasure procedures. Data breach notification procedures.
Training & awareness
Training programs tailored to HR, IT, legal, and leadership teams. Staff awareness on data protection best practices.
Cross-border compliance
GDPR ↔ Law 2008-12 alignment for multinationals. Regional ECOWAS and Malabo Convention compliance for pan-African groups.
Four steps, one concrete result
A structured approach that turns a legal obligation into a competitive advantage.
Diagnosis
Full audit of your personal data processing and gap assessment.
Action plan
Prioritized roadmap with deadlines and owners for each corrective action.
Remediation
CDP filing, internal procedures, security policies, and team training.
Monitoring
Continuous monitoring, regulatory watch, and annual review of processing records.
The obligations that apply to you
Law 2008-12 imposes specific obligations on every data controller operating in Senegal. Sanctions can be severe — both administrative and criminal.
Key obligations
- →Prior declaration of processing to the CDP
- →Prior authorization for sensitive processing (biometric, health data, etc.)
- →Appointment of a data protection officer
- →Informing and obtaining consent from data subjects
- →Technical and organizational security measures
- →Notification of personal data breaches
Penalties
- →CDP administrative sanctions: injunctions, processing suspension
- →Criminal fines for unlawful or undeclared processing
- →Prison sentences for serious offenses
- →Liability for both legal entities and individuals
- →Aggravated sanctions for processing sensitive data
⚠ The legal references above are provided for information only and do not constitute legal advice. Specific fines and sanctions should be verified with the CDP and legal counsel at the time of compliance.
Personal data protection compliance services by XamXam Graph. Specialists in Law 2008-12, CDP, and regional ECOWAS and African Union frameworks.
Ready to bring your company into compliance?
Book a free 30-minute assessment with our experts. We'll identify your CDP obligations and propose a tailored action plan.
Request my free assessment