Home / Current Issue / Paper 1723010
The Political Economy of Data Protection Governance in Africa: Institutional Revenue Generation, Regulatory Monetisation, and Comparative Compliance Design
Subject area: Arts, Social Sciences and Humanities · Area of research: Law, Data Protection, Artificial Intelligence
DOI: 10.64388/IREV10I3-1723010
Abstract
Over the past five years, sub-Saharan Africa has produced one of the fastest-growing bodies of data protection legislation in the world, yet the institutional design underlying this expansion has received comparatively little scholarly attention. This article examines a structural feature that distinguishes several of the continent's leading data protection regimes from the European model that inspired them: the deliberate integration of fee-based revenue mechanisms into routine compliance workflows. Drawing on the statutory and regulatory architecture of Nigeria, Kenya, Tanzania, and Uganda, the article maps a common pattern of tiered enterprise registration fees, recurring renewal cycles, mandatory statutory audits, and privatised compliance intermediation, and situates this pattern within the broader political economy of regulatory finance in resource-constrained states. It then contrasts these monetised architectures with the European Union's accountability-based framework under the General Data Protection Regulation and the United Kingdom's lower-friction cost-recovery model, arguing that the European experience demonstrates that meaningful data protection compliance does not require upfront enterprise monetisation. The article concludes that, left unreformed, monetised registration and audit regimes risk converting data protection enforcement into a transactional exercise in fee collection, with disproportionate consequences for micro, small, and medium enterprises, and proposes a four-pillar reform agenda centred on budgetary independence for supervisory authorities, risk-based audit supervision, fee simplification, and outcome-oriented regulatory performance metrics.
Keywords
Data Protection; Africa; Nigeria Data Protection Act; regulatory monetisation; GDPR; compliance costs; MSMEs; political economy of regulation; data protection authorities
How to cite this paper
@article{1723010,
author = {Adeyemi Owoade},
title = {The Political Economy of Data Protection Governance in Africa: Institutional Revenue Generation, Regulatory Monetisation, and Comparative Compliance Design},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {2207-2216},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1723010.pdf},
abstract = {Over the past five years, sub-Saharan Africa has produced one of the fastest-growing bodies of data protection legislation in the world, yet the institutional design underlying this expansion has received comparatively little scholarly attention. This article examines a structural feature that distinguishes several of the continent's leading data protection regimes from the European model that inspired them: the deliberate integration of fee-based revenue mechanisms into routine compliance workflows. Drawing on the statutory and regulatory architecture of Nigeria, Kenya, Tanzania, and Uganda, the article maps a common pattern of tiered enterprise registration fees, recurring renewal cycles, mandatory statutory audits, and privatised compliance intermediation, and situates this pattern within the broader political economy of regulatory finance in resource-constrained states. It then contrasts these monetised architectures with the European Union's accountability-based framework under the General Data Protection Regulation and the United Kingdom's lower-friction cost-recovery model, arguing that the European experience demonstrates that meaningful data protection compliance does not require upfront enterprise monetisation. The article concludes that, left unreformed, monetised registration and audit regimes risk converting data protection enforcement into a transactional exercise in fee collection, with disproportionate consequences for micro, small, and medium enterprises, and proposes a four-pillar reform agenda centred on budgetary independence for supervisory authorities, risk-based audit supervision, fee simplification, and outcome-oriented regulatory performance metrics.},
keywords = {Data Protection; Africa; Nigeria Data Protection Act; regulatory monetisation; GDPR; compliance costs; MSMEs; political economy of regulation; data protection authorities},
month = {September},
doi = {https://doi.org/10.64388/IREV10I3-1723010}
}