By the time you reach the end of this sentence, a cyberattack will have been launched somewhere on the African continent. That is not an exaggeration, but rather what has become the new reality. Financial services are digitising at speed, through mobile banking, cross-border insurance platforms and digital payment ecosystems, creating an attack surface of remarkable breadth and complexity. The laws meant to combat cybercrime and protect the institutions and people who rely on those services, however, remain patchy at best.
For multinational organisations, this is a live compliance risk with material consequences. Some jurisdictions have enacted sophisticated, modern cybercrime frameworks with mandatory reporting obligations, dedicated regulators and meaningful penalties. While others have no dedicated cybercrime legislation at all.
Understanding how the international treaties fit together is crucial for compliance, helping one grasp the global and continental response to cybercrime.
The Budapest Convention
Adopted in Budapest in 2001 and later enforced from 2004 onwards, the Council of Europe’s Convention on Cybercrime remains the most influential instrument. It has provided the template, or at least the guiding reference point, for domestic cybercrime legislation. The Convention’s real strength lies in its detail on substantive offences, procedural powers, and international cooperation, areas where many African domestic frameworks remain underdeveloped.
The Malabo Convention
The African Union Convention on Cyber Security and Personal Data Protection, adopted in Malabo in 2014, is unique globally: it brings cybersecurity, cybercrime, electronic transactions and personal data protection together in a single instrument. It came into effect on 8 June 2023, after Mauritania’s ratification. Yet, as of early 2026, only 20 of the 55 AU member states have ratified it, a level of uptake that materially limits its practical harmonising effect.
The UN Convention Against Cybercrime
The most important recent development is the United Nations Convention Against Cybercrime, adopted by the UN General Assembly on 24 December 2024 and opened for signature on 25 October 2025 in Hanoi, Vietnam. It is the first comprehensive global treaty devoted exclusively to cybercrime. However, its success will depend on the pace of ratification and the quality of domestic implementing legislation.
South Africa
South Africa’s Cybercrimes Act is the most comprehensive cybercrime framework in sub-Saharan Africa, it criminalises unlawful access to data and computer systems, the unlawful acquisition or use of passwords and access codes, and the dissemination of harmful data messages.
Section 54 requires electronic communications service providers and financial institutions to report cyber offences to the South African Police Service within 72 hours of becoming aware of them; non-compliance is a criminal offence carrying fines of up to R50,000. That duty sits alongside, and does not replace, the separate mandatory data-breach notification regime under section 22 of the Protection of Personal Information Act. One cyber incident can therefore trigger parallel reports to different authorities, under different statutes, with different timelines and thresholds.
Namibia
Namibia may present the Southern African Development Community’s most significant legislative gap. No dedicated cybercrime act is currently in force. The Electronic Transactions Act of 2019 deals with electronic commerce but does not create cybercrime-specific offences. Draft Cybercrime and Data Protection Bills were circulated as early as 2013 and remain unpromulgated. The gap means that cybercrime prosecutions must rely on general criminal-law principles.
Botswana, Zimbabwe, Zambia and Eswatini
By continental standards, Botswana moved early, enacting its Cybercrime and Computer Related Crimes Act in 2007. In 2018, new legislation repealed the 2007 enactment. However, the limited number of new provisions means the framework takes a more reactive than proactive approach to cybersecurity.
Zimbabwe’s Cyber Security and Data Protection Act of 2021 is distinctive in bringing cybersecurity, cybercrime and data protection under one statute, which is regulated by the Postal and Telecommunications Regulatory Authority. Civil society organisations, however, have strongly condemned provisions said to permit government interference with private communications without adequate judicial oversight. The tension is familiar across the continent: cybercrime laws can be deployed, or be perceived as deployable, as instruments of surveillance and political control.
Zambia’s Cyber Security and Cyber Crimes Act is currently before the High Court in a pending constitutional challenge. Akin to the situation in Zimbabwe, civil society organisations have raised a number of concerns on provisions, which apparently threaten the constitutional right to freedom of expression for Zambians. Until the challenge is resolved, the Act remains in force, but legal uncertainty hangs over it.
Eswatini enacted the Computer Crime and Cybercrime Act, which came into effect on 4 March 2022. At a high level, the Act criminalises various cyber offences and makes provision for the establishment of a National Cybersecurity Incident Response Team and National Cybersecurity Advisory Council. The government has also adopted a five-year National Cybersecurity Strategy.
Mozambique, Lesotho, Malawi and Mauritius
Mozambique has no distinct national cybercrime framework and instead relies on partial measures. It has ratified the Malabo Convention but has not enacted dedicated implementing legislation.
Lesotho presents a confirmed legislative gap: no cybercrime statute has been identified. While a Computer Crime and Cybersecurity Bill was tabled before the National Assembly in 2024, it has not yet been enacted into law amidst significant scrutiny and opposition from media and civil society.
In 2024, Malawi enacted cybercrimes legislation replacing the data-protection provisions of the country's Electronic Transactions and Cyber Security Act. Impressively, the Act is inspired by the GDPR introducing amongst others: data-subject rights, mandatory breach notification; this signals that Malawi is indeed headed towards the right direction in its commitment to improving the country's cybersecurity laws.
Mauritius, by contrast, offers a regional model. Its Cybersecurity and Cybercrime Act of 2021, establishes a National Cybersecurity Committee and the Computer Emergency Response Team of Mauritius and aligns with both the Budapest Convention and the Malabo Convention. Mauritius shows what a small island state can achieve when political will exists: a framework that meets international standards.
For multi-jurisdictional entities, this fragmented legislative landscape creates a significant compliance challenge. A single cyberattack spanning multiple African jurisdictions can trigger different legal obligations, reporting requirements and potential liabilities depending on where the incident occurs. Until greater harmonisation is achieved, businesses operating across the continent will need to navigate not one cybercrime regime, but a patchwork of laws that can differ significantly from one border to the next.
Written by Ahmore Burger-Smidt, a Director and Head of Regulatory and Boitumelo Khwene, a Candidate Attorney at Werksmans Attorneys
EMAIL THIS ARTICLE SAVE THIS ARTICLE ARTICLE ENQUIRY FEEDBACK
To subscribe email subscriptions@creamermedia.co.za or click here
To advertise email advertising@creamermedia.co.za or click here









