https://www.polity.org.za
Deepening Democracy through Access to Information
Home / Legal Briefs / All Legal Briefs RSS ← Back
Werksmans Attorneys|Africa|Botswana|Eswatini|Lesotho|Malawi|Mauritius|Mozambique|Namibia|South Africa|Zambia|Zimbabwe|Cybercrime|Cybersecurity|Data Protection|Digital Payments|Mobile Banking|African Union|Council Of Europe|Postal And Telecommunications Regulatory Authority|South African Police Service|United Nations|Ahmore Burger-Smidt|Boitumelo Khwene
|||||
werksmans-attorneys|africa|botswana|eswatini|lesotho|malawi|mauritius|mozambique|namibia|south-africa|zambia|zimbabwe|cybercrime|cybersecurity|data-protection|digital-payments|mobile-banking|african-union|council-of-europe|postal-and-telecommunications-regulatory-authority|south-african-police-service|united-nations|ahmore-burger-smidt|boitumelo-khwene
Close

Email this article

separate emails by commas, maximum limit of 4 addresses

Sponsored by

Close

Article Enquiry

Cybercrime across borders: navigating Africa’s fragmented legislative landscape


Close

Cybercrime across borders: navigating Africa’s fragmented legislative landscape

Should you have feedback on this article, please complete the fields below.

Please indicate if your feedback is in the form of a letter to the editor that you wish to have published. If so, please be aware that we require that you keep your feedback to below 300 words and we will consider its publication online or in Creamer Media’s print publications, at Creamer Media’s discretion.

We also welcome factual corrections and tip-offs and will protect the identity of our sources, please indicate if this is your wish in your feedback below.


Close

Embed Video

Cybercrime across borders: navigating Africa’s fragmented legislative landscape

Werksmans Attorneys

21st September 2026

ARTICLE ENQUIRY      SAVE THIS ARTICLE      EMAIL THIS ARTICLE

Font size: -+

By the time you reach the end of this sentence, a cyberattack will have been launched somewhere on the African continent. That is not an exaggeration, but rather what has become the new reality. Financial services are digitising at speed, through mobile banking, cross-border insurance platforms and digital payment ecosystems, creating an attack surface of remarkable breadth and complexity. The laws meant to combat cybercrime and protect the institutions and people who rely on those services, however, remain patchy at best.

For multinational organisations, this is a live compliance risk with material consequences. Some jurisdictions have enacted sophisticated, modern cybercrime frameworks with mandatory reporting obligations, dedicated regulators and meaningful penalties. While others have no dedicated cybercrime legislation at all. 

Advertisement

Understanding how the international treaties fit together is crucial for compliance, helping one grasp the global and continental response to cybercrime.

The Budapest Convention

Advertisement

Adopted in Budapest in 2001 and later enforced from 2004 onwards, the Council of Europe’s Convention on Cybercrime remains the most influential instrument. It has provided the template, or at least the guiding reference point, for domestic cybercrime legislation. The Convention’s real strength lies in its detail on substantive offences, procedural powers, and international cooperation, areas where many African domestic frameworks remain underdeveloped. 

The Malabo Convention

The African Union Convention on Cyber Security and Personal Data Protection, adopted in Malabo in 2014, is unique globally: it brings cybersecurity, cybercrime, electronic transactions and personal data protection together in a single instrument. It came into effect on 8 June 2023, after Mauritania’s ratification. Yet, as of early 2026, only 20 of the 55 AU member states have ratified it, a level of uptake that materially limits its practical harmonising effect. 

The UN Convention Against Cybercrime

The most important recent development is the United Nations Convention Against Cybercrime, adopted by the UN General Assembly on 24 December 2024 and opened for signature on 25 October 2025 in Hanoi, Vietnam. It is the first comprehensive global treaty devoted exclusively to cybercrime. However, its success will depend on the pace of ratification and the quality of domestic implementing legislation.

South Africa

South Africa’s Cybercrimes Act is the most comprehensive cybercrime framework in sub-Saharan Africa, it criminalises unlawful access to data and computer systems, the unlawful acquisition or use of passwords and access codes, and the dissemination of harmful data messages. 

Section 54 requires electronic communications service providers and financial institutions to report cyber offences to the South African Police Service within 72 hours of becoming aware of them; non-compliance is a criminal offence carrying fines of up to R50,000. That duty sits alongside, and does not replace, the separate mandatory data-breach notification regime under section 22 of the Protection of Personal Information Act. One cyber incident can therefore trigger parallel reports to different authorities, under different statutes, with different timelines and thresholds.

Namibia

Namibia may present the Southern African Development Community’s most significant legislative gap. No dedicated cybercrime act is currently in force. The Electronic Transactions Act of 2019  deals with electronic commerce but does not create cybercrime-specific offences. Draft Cybercrime and Data Protection Bills were circulated as early as 2013 and remain unpromulgated. The gap means that cybercrime prosecutions must rely on general criminal-law principles.

Botswana, Zimbabwe, Zambia and Eswatini

By continental standards, Botswana moved early, enacting its Cybercrime and Computer Related Crimes Act in 2007.  In 2018, new legislation repealed the 2007 enactment. However, the limited number of new provisions means the framework takes a more reactive than proactive approach to cybersecurity.

Zimbabwe’s Cyber Security and Data Protection Act of 2021 is distinctive in bringing cybersecurity, cybercrime and data protection under one statute, which is regulated by the Postal and Telecommunications Regulatory Authority. Civil society organisations, however, have strongly condemned provisions said to permit government interference with private communications without adequate judicial oversight. The tension is familiar across the continent: cybercrime laws can be deployed, or be perceived as deployable, as instruments of surveillance and political control.

Zambia’s Cyber Security and Cyber Crimes Act is currently before the  High Court in a pending constitutional challenge. Akin to the situation in Zimbabwe, civil society organisations have raised a number of concerns on provisions, which apparently threaten the constitutional right to freedom of expression for Zambians. Until the challenge is resolved, the Act remains in force, but legal uncertainty hangs over it.

Eswatini enacted the Computer Crime and Cybercrime Act, which came into effect on 4 March 2022. At a high level, the Act criminalises various cyber offences and makes provision for the establishment of a National Cybersecurity Incident Response Team and National Cybersecurity Advisory Council. The government has also adopted a five-year National Cybersecurity Strategy.

Mozambique, Lesotho, Malawi and Mauritius

Mozambique has no distinct national cybercrime framework and instead relies on partial measures. It has ratified the Malabo Convention but has not enacted dedicated implementing legislation. 

Lesotho presents a confirmed legislative gap: no cybercrime statute has been identified. While a Computer Crime and Cybersecurity Bill was tabled before the National Assembly in 2024, it has not yet been enacted into law amidst significant scrutiny and opposition from media and civil society. 

In 2024, Malawi enacted cybercrimes legislation replacing the data-protection provisions of the country's Electronic Transactions and Cyber Security Act. Impressively, the Act is inspired by the GDPR introducing amongst others: data-subject rights, mandatory breach notification; this signals that Malawi is indeed headed towards the right direction in its commitment to improving the country's cybersecurity laws. 

Mauritius, by contrast, offers a regional model. Its Cybersecurity and Cybercrime Act of 2021, establishes a National Cybersecurity Committee and the Computer Emergency Response Team of Mauritius and aligns with both the Budapest Convention and the Malabo Convention. Mauritius shows what a small island state can achieve when political will exists: a framework that meets international standards.

For multi-jurisdictional entities, this fragmented legislative landscape creates a significant compliance challenge. A single cyberattack spanning multiple African jurisdictions can trigger different legal obligations, reporting requirements and potential liabilities depending on where the incident occurs. Until greater harmonisation is achieved, businesses operating across the continent will need to navigate not one cybercrime regime, but a patchwork of laws that can differ significantly from one border to the next.

Written by Ahmore Burger-Smidt, a Director and Head of Regulatory and Boitumelo Khwene, a Candidate Attorney at Werksmans Attorneys

 

EMAIL THIS ARTICLE      SAVE THIS ARTICLE      ARTICLE ENQUIRY      FEEDBACK

To subscribe email subscriptions@creamermedia.co.za or click here
To advertise email advertising@creamermedia.co.za or click here


About

Polity.org.za is a product of Creamer Media.
www.creamermedia.co.za

Other Creamer Media Products include:
Engineering News
Mining Weekly
Research Channel Africa

Read more

Subscriptions

We offer a variety of subscriptions to our Magazine, Website, PDF Reports and our photo library.

Subscriptions are available via the Creamer Media Store.

View store

Advertise

Advertising on Polity.org.za is an effective way to build and consolidate a company's profile among clients and prospective clients. Email advertising@creamermedia.co.za

View options

Email Registration Success

Thank you, you have successfully subscribed to one or more of Creamer Media’s email newsletters. You should start receiving the email newsletters in due course.

Our email newsletters may land in your junk or spam folder. To prevent this, kindly add newsletters@creamermedia.co.za to your address book or safe sender list. If you experience any issues with the receipt of our email newsletters, please email subscriptions@creamermedia.co.za