Skip to content
Compliance · CDP Senegal · Law 2008-12

Protect the data. Preserve trust.

We help companies operating in Senegal achieve compliance with Law No. 2008-12 on personal data protection and the requirements of the Personal Data Commission (CDP).

Regulatory framework
Law 2008-12
Personal data protection in Senegal
  • Prior declaration to the CDP
  • Appointment of a data protection officer
  • Respect of data subjects' rights
  • Breach notification within 72h
CDP Senegal · Supervisory authorityLaw No. 2008-12 · January 25, 2008ECOWAS · Supplementary Act A/SA.1/01/10Malabo Convention · African Union
Our services

An end-to-end path to compliance

From initial audit to sustainable compliance, we cover the full data protection lifecycle.

Compliance audit

Mapping your data processing activities, gap assessment against Law 2008-12, and identification of priority risks.

Gap analysisPrior declaration

CDP declaration & authorization

Preparation and filing of prior declaration files and authorization requests with the CDP. Follow-up until receipt is issued.

Prior declarationAuthorization

Data Protection Officer (DPO)

Designation and support for your internal DPO. Full outsourcing of the DPO role for organizations without a dedicated resource.

DPO as a serviceOngoing advisory

Data subject rights management

Implementation of access, rectification, objection, and erasure procedures. Data breach notification procedures.

DSARBreach response

Training & awareness

Training programs tailored to HR, IT, legal, and leadership teams. Staff awareness on data protection best practices.

WorkshopsE-learning

Cross-border compliance

GDPR ↔ Law 2008-12 alignment for multinationals. Regional ECOWAS and Malabo Convention compliance for pan-African groups.

GDPRECOWASMalabo
Our method

Four steps, one concrete result

A structured approach that turns a legal obligation into a competitive advantage.

1

Diagnosis

Full audit of your personal data processing and gap assessment.

2

Action plan

Prioritized roadmap with deadlines and owners for each corrective action.

3

Remediation

CDP filing, internal procedures, security policies, and team training.

4

Monitoring

Continuous monitoring, regulatory watch, and annual review of processing records.

Legal framework

The obligations that apply to you

Law 2008-12 imposes specific obligations on every data controller operating in Senegal. Sanctions can be severe — both administrative and criminal.

Key obligations

Law No. 2008-12 · Art. 2–13
  • Prior declaration of processing to the CDP
  • Prior authorization for sensitive processing (biometric, health data, etc.)
  • Appointment of a data protection officer
  • Informing and obtaining consent from data subjects
  • Technical and organizational security measures
  • Notification of personal data breaches

Penalties

Law No. 2008-12 · Art. 51–60
  • CDP administrative sanctions: injunctions, processing suspension
  • Criminal fines for unlawful or undeclared processing
  • Prison sentences for serious offenses
  • Liability for both legal entities and individuals
  • Aggravated sanctions for processing sensitive data

⚠ The legal references above are provided for information only and do not constitute legal advice. Specific fines and sanctions should be verified with the CDP and legal counsel at the time of compliance.

2008
Year of enactment
72h
Breach notification window
15
Affected ECOWAS member states
0
Tolerance for non-compliance

Personal data protection compliance services by XamXam Graph. Specialists in Law 2008-12, CDP, and regional ECOWAS and African Union frameworks.

XamXam Graph · Compliance Consulting Group, Dakar
CDP

Ready to bring your company into compliance?

Book a free 30-minute assessment with our experts. We'll identify your CDP obligations and propose a tailored action plan.

Request my free assessment