Home / Current Issue / Paper 1723010
The Political Economy of Data Protection Governance in Africa: Institutional Revenue Generation, Regulatory Monetisation, and Comparative Compliance Design
Subject area: Arts, Social Sciences and Humanities · Area of research: Law, Data Protection, Artificial Intelligence
Abstract
Over the past five years, sub-Saharan Africa has produced one of the fastest-growing bodies of data protection legislation in the world, yet the institutional design underlying this expansion has received comparatively little scholarly attention. This article examines a structural feature that distinguishes several of the continent's leading data protection regimes from the European model that inspired them: the deliberate integration of fee-based revenue mechanisms into routine compliance workflows. Drawing on the statutory and regulatory architecture of Nigeria, Kenya, Tanzania, and Uganda, the article maps a common pattern of tiered enterprise registration fees, recurring renewal cycles, mandatory statutory audits, and privatised compliance intermediation, and situates this pattern within the broader political economy of regulatory finance in resource-constrained states. It then contrasts these monetised architectures with the European Union's accountability-based framework under the General Data Protection Regulation and the United Kingdom's lower-friction cost-recovery model, arguing that the European experience demonstrates that meaningful data protection compliance does not require upfront enterprise monetisation. The article concludes that, left unreformed, monetised registration and audit regimes risk converting data protection enforcement into a transactional exercise in fee collection, with disproportionate consequences for micro, small, and medium enterprises, and proposes a four-pillar reform agenda centred on budgetary independence for supervisory authorities, risk-based audit supervision, fee simplification, and outcome-oriented regulatory performance metrics.
Keywords
Data Protection; Africa; Nigeria Data Protection Act; regulatory monetisation; GDPR; compliance costs; MSMEs; political economy of regulation; data protection authorities
References
[1] OJ L281/31, art 18 (notification requirement, subsequently abolished by the GDPR). 38 GDPR (n 2), art 5(2). under Article 30 39 execute Data Protection Impact Assessments for high-risk processing under Article 35 40 , and, where required, designate a Data Protection Officer under Article 37. 41 Supervisory authorities across the Union (including the Commission Nationale de l'Informatique et des Libertés in France, the Federal Commissioner for Data Protection and Freedom of Information in Germany, and the Data Protection Commission in Ireland) are funded through direct fiscal allocation from national state budgets rather than through enterprise registration collections, 42 and compliance is enforced through ex- post supervisory investigation, risk-based sectoral audits, and the handling of individual data-subject complaints, backed by punitive fines under Article 83 of up to €20 million or 4% of an undertaking's total global annual turnover, whichever is higher. 43 B. The United Kingdom: A Low-Friction Cost- Recovery Fee without an Intermediary Audit Market The United Kingdom presents a hybrid framework that sits between the two poles. Under the Data Protection (Charges and Information) Regulations 2018, the Information Commissioner's Office ('ICO') requires most data controllers to pay an annual Data Protection Fee, structured across three tiers by headcount and turnover. 44 The original 2018 fee schedule set Tier 1 (micro-organisations) at £40 per annum, Tier 2 (small and medium organisations) at £60, and Tier 3 (large organisations, broadly those with turnover above £36 million or more than 250 staff) at £2,900. 45 Those figures were revised upward by 29.8%, with effect from 17 February 2025, by the Data Protection (Charges and Information) (Amendment) Regulations 2025, which substituted new charges of £52, £78, and £3,763 for the three tiers respectively, to reflect movement in the Retail 39 ibid, art 30. 40 ibid, art 35. 41 ibid, art 37. 42 GDPR (n 2), art 52(4), requiring each Member State to ensure its supervisory authority is provided with adequate financial resources from its general state budget. 43 GDPR (n 2), art 83(5). 44 Data Protection (Charges and Information) Regulations 2018, SI 2018/480, reg 3(1). 45 ibid. 46 Data Protection (Charges and Information) (Amendment) Regulations 2025, SI 2025/63; 'Rise in Price Index since 2018; each figure is reduced by a further £5 where payment is made by direct debit. 46 While the UK model therefore does impose a mandatory enterprise fee, unlike the EU's fully fee- free approach, it differs from the monetised African regimes described in Part II in two material respects. First, the UK framework does not mandate that data controllers file annual compliance audit returns through licensed private third-party intermediaries; the fee paid to the ICO is a direct cost-recovery charge that funds public supervisory operations, without the intervening layer of privatised audit rent- capture that characterises the Nigerian DPCO model. 47 Second, the baseline Tier 1 fee, even after the 2025 uplift, remains nominal at £52 per annum, preventing the kind of administrative friction or barrier-to-entry distortion that the Nigerian, Kenyan, and Tanzanian fee schedules impose on MSMEs entering the formal digital economy. C. Efficacy Assessment: Compliance without Upfront Enterprise Monetisation A comparison across the three models suggests that upfront regulatory monetisation is not a precondition for achieving legal compliance or for securing strong data-subject protections. Under the monetised African model, the primary statutory mandate is upfront enterprise registration and periodic third- party statutory audit, with an ex-ante, annually recurring audit obligation prepared by a licensed private broker; the principal revenue destination is a mix of consolidated state revenue and the DPA's own operational budget, supplemented, in Nigeria, by a private brokerage industry; and the principal distortion risk is that compliance is reduced to a form of pay-to-play administrative status, with MSMEs ICO Data Protection Fees from February 2025' (Acuity Law, 13 February 2025) <https://acuitylaw.com/rise-in-ico-fees-data- protection-fees-february/> accessed 01 September 2026; 'ICO registration and the 2026 data protection fee explained' (31 July 2026) <https://ico.opencourtdata.uk/do-i-need-to-register- with-the-ico> accessed 01 September 2026, confirming no further amendment as at mid-2026. 47 'Guide to the data protection fee' (ICO) <https://ico.org.uk/for-organisations/data- protection-fee/data-protection-fee/> accessed 01 September 2026. pushed toward informality. 48 Under the EU's accountability framework, by contrast, the primary statutory mandate is the internal demonstration of compliance rather than an external, fee-generating filing; the cost to the enterprise is confined to internal operational and compliance expenditure rather than a direct state fee; the audit mechanism is ex-post and risk-based, triggered by breaches, complaints, or sectoral risk indicators rather than by an annual filing calendar; and the principal distortion risk lies instead in the administrative burden of maintaining internal Records of Processing Activities and Data Protection Impact Assessment documentation to a standard that would withstand ex-post scrutiny. 49 The UK's hybrid model occupies an intermediate position: a modest, direct cost-recovery fee funds ICO operations without a mandatory audit-brokerage market, and enforcement remains ex-post and complaint- or breach-triggered, producing what practitioner and regulatory commentary consistently describes as minimal administrative friction relative to the fee's revenue-raising function. 50 The European experience suggests that high rates of data privacy compliance are achievable through mechanisms other than revenue extraction: the deterrent effect of proportionate, turnover-linked penalties under Article 83, which forces corporate governance structures to internalise privacy risk at board level; the structural integration of independent Data Protection Officers within enterprise management under Article 37; and an active ecosystem of civil-society oversight, individual complaint mechanisms, and, increasingly, collective redress litigation, which sustains continuous supervisory pressure on data controllers independently of any registration cycle. Monetised registration frameworks, by contrast, risk substituting substantive privacy enforcement with the accumulation of administrative compliance receipts; organisations may prioritise securing a registration certificate or an audit trustmark sufficient to avoid an immediate statutory fine 51 , while the underlying internal processing practices that the certificate is supposed to attest to remain substantively unmonitored until a breach forces the issue into the open. 48 See section III above. 49 See section IV(A) above. V. STRATEGIC POLICY REFORM AGENDA FOR AFRICAN DATA PRIVACY REGIMES Aligning African data protection governance with international best practice, while preserving a degree of administrative self-sustainability appropriate to fiscally constrained supervisory authorities, does not require the wholesale abolition of every fee described in Part II. It does, however, warrant structural reform across four pillars. First, national parliaments should decouple DPA operational budgets from registration and intermediary audit fee revenue. Providing supervisory authorities with direct budgetary allocations from consolidated state funds, even if only partial, would begin to remove the structural dependence of DPAs on registration volumes and licensing collections, enabling an institutional reorientation away from revenue targets and toward active enforcement, rights protection, and breach prevention. Second, regulatory authorities should replace universal, annual, mandatory audits with targeted, risk-based supervision. Frameworks that require every DCPMI, regardless of demonstrated risk, to file an annual third-party compliance audit return (as Nigeria's DPCO model currently does for Ultra-High Level and Extra-High Level entities) should transition toward a model in which internal compliance documentation suffices for lower-risk entities, reserving mandatory external audit for high- risk processing operations, large-scale biometric deployments, or entities with a documented history of prior compliance violations. Third, governments should simplify fee schedules to reduce financial friction for growing businesses. The administrative practice, common to Kenya and Tanzania, of requiring a single enterprise that performs both controller and processor functions to pay separate registration and renewal fees for each capacity should be reconsidered, and baseline exemption thresholds should be periodically reviewed and, where appropriate, raised, to protect early-stage micro-enterprises and non-profit organisations from registration costs disproportionate to their scale. 50 ICO (n 40). 51 Janus Compliance (n 13). Fourth, data protection commissions should reorient their institutional key performance indicators away from revenue collection totals and certificate issuance volumes. Supervisory effectiveness is better measured by average breach-investigation response times, the issuance and enforcement of binding corrective orders, measurable improvements in public privacy literacy, and the timely resolution of individual data-subject complaints; metrics that track the substantive purpose of the legislation rather than the fiscal health of the regulator. VI. CONCLUSION The emergence of monetised data protection regimes across sub-Saharan Africa represents a distinctive institutional response to a genuine fiscal constraint: the need to fund a newly created category of regulatory supervision in states where general budgetary allocation to nascent agencies is often unreliable. Driven by that constraint, Nigeria, Kenya, Tanzania, and Uganda have each built tiered registration fees, recurring renewal schedules, and, in Nigeria's case, a privatised compliance-audit industry, into the statutory architecture of data protection enforcement. These mechanisms provide short-term operational funding for regulatory authorities that might otherwise struggle to establish supervisory capacity at all. But left unreformed, they risk transforming data privacy enforcement into a transactional, revenue-focused exercise, in which regulated entities come to treat mandatory fees and third-party audit returns as routine operational expenses to be minimised, rather than as catalysts for the deeper structural privacy transformation the legislation was designed to compel. As the European Union's accountability-based framework, and to a lesser degree the United Kingdom's low-friction cost- recovery model, demonstrate, robust data privacy compliance does not depend on upfront enterprise registration fees or statutory audit-filing schemes; it is driven instead by systemic corporate accountability, risk-based supervisory oversight, and credible, proportionate enforcement. For African jurisdictions seeking to build data protection frameworks capable of sustaining, rather than taxing, dynamic and globally competitive digital economies, reforming supervisory financing to emphasise substantive data-subject rights over administrative fee extraction is not merely a matter of regulatory aesthetics. It is a precondition for ensuring that the considerable legislative achievement represented by forty-five national data protection statutes translates into the substantive privacy protection those statutes were enacted to deliver.
How to cite this paper
@article{1723010,
author = {Adeyemi Owoade},
title = {The Political Economy of Data Protection Governance in Africa: Institutional Revenue Generation, Regulatory Monetisation, and Comparative Compliance Design},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {2207-2216},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1723010.pdf},
abstract = {Over the past five years, sub-Saharan Africa has produced one of the fastest-growing bodies of data protection legislation in the world, yet the institutional design underlying this expansion has received comparatively little scholarly attention. This article examines a structural feature that distinguishes several of the continent's leading data protection regimes from the European model that inspired them: the deliberate integration of fee-based revenue mechanisms into routine compliance workflows. Drawing on the statutory and regulatory architecture of Nigeria, Kenya, Tanzania, and Uganda, the article maps a common pattern of tiered enterprise registration fees, recurring renewal cycles, mandatory statutory audits, and privatised compliance intermediation, and situates this pattern within the broader political economy of regulatory finance in resource-constrained states. It then contrasts these monetised architectures with the European Union's accountability-based framework under the General Data Protection Regulation and the United Kingdom's lower-friction cost-recovery model, arguing that the European experience demonstrates that meaningful data protection compliance does not require upfront enterprise monetisation. The article concludes that, left unreformed, monetised registration and audit regimes risk converting data protection enforcement into a transactional exercise in fee collection, with disproportionate consequences for micro, small, and medium enterprises, and proposes a four-pillar reform agenda centred on budgetary independence for supervisory authorities, risk-based audit supervision, fee simplification, and outcome-oriented regulatory performance metrics.},
keywords = {Data Protection; Africa; Nigeria Data Protection Act; regulatory monetisation; GDPR; compliance costs; MSMEs; political economy of regulation; data protection authorities},
month = {September},
}