https://www.polity.org.za
Deepening Democracy through Access to Information
Home / Legal Briefs / Werksmans RSS ← Back
Werksmans|Africa|Botswana|Eswatini|Lesotho|Malawi|Mauritania|Mauritius|Mozambique|Namibia|Rwanda|Senegal|South Africa|Zambia|Zimbabwe|Building|Cybercrime|Cybersecurity|Data Protection|Financial Services|African Union|Council Of Europe|Eswatini Communications Commission|Postal And Telecommunications Regulatory Authority|South African Police Service|United Nations|Ahmore Burger-Smidt|Boitumelo Khwene
|||Building|||
werksmans|africa|botswana|eswatini|lesotho|malawi|mauritania|mauritius|mozambique|namibia|rwanda|senegal|south-africa|zambia|zimbabwe|building|cybercrime|cybersecurity|data-protection|financial-services|african-union|council-of-europe|eswatini-communications-commission|postal-and-telecommunications-regulatory-authority|south-african-police-service|united-nations|ahmore-burger-smidt|boitumelo-khwene
Close

Email this article

separate emails by commas, maximum limit of 4 addresses

Sponsored by

Close

Article Enquiry

Cybercrime across borders: Navigating Africa’s fragmented legislative landscape – Part 1


Close

Cybercrime across borders: Navigating Africa’s fragmented legislative landscape – Part 1

Should you have feedback on this article, please complete the fields below.

Please indicate if your feedback is in the form of a letter to the editor that you wish to have published. If so, please be aware that we require that you keep your feedback to below 300 words and we will consider its publication online or in Creamer Media’s print publications, at Creamer Media’s discretion.

We also welcome factual corrections and tip-offs and will protect the identity of our sources, please indicate if this is your wish in your feedback below.


Close

Embed Video

Cybercrime across borders: Navigating Africa’s fragmented legislative landscape – Part 1

Werksmans

18th September 2026

ARTICLE ENQUIRY      SAVE THIS ARTICLE      EMAIL THIS ARTICLE

Font size: -+

The Compliance Imperative

By the time you reach the end of this sentence, a cyberattack will have been launched somewhere on the African continent. That is not an exaggeration, but rather what has become the new reality on the African continent. Across Africa, financial services are digitising at speed, through mobile banking, cross-border insurance platforms and digital payment ecosystems, creating an attack surface of remarkable breadth and complexity. The laws meant to combat cybercrime and protect the institutions and people who rely on those services, however, remain patchy at best.

Advertisement

Multinational organisations, and specifically financial services and insurance groups operating across Africa do not experience this fragmentation as an academic curiosity. This is a live compliance risk with material consequences. Some jurisdictions have enacted sophisticated, modern cybercrime frameworks with mandatory reporting obligations, dedicated regulators and meaningful penalties. While others have no dedicated cybercrime legislation at all. Interestingly, there are several countries where, enacted cybercrime laws are facing constitutional challenges, adding another layer of uncertainty to the pandemonium. The result? A single multi-jurisdictional entity may face criminal liability for failing to report an incident in one jurisdiction, even as the law of the neighbouring country where the same incident began does not define “cybercrime” at all.

In this two part series, we scrutinised this issue further on what some may describe as a legislative quandary amongst the African countries.

Advertisement

The International Treaty Architecture in Practice

Understanding how the international treaties fit together is crucial for compliance, helping one grasp the global and continental response to cybercrime.

The Budapest Convention: A Global Baseline

Adopted in Budapest in 2001 and later enforced from 2004 onwards, the Council of Europe’s Convention on Cybercrime remains the most influential instrument. It has provided the template, or at least the guiding reference point, for domestic cybercrime legislation. Its influence in Africa is expanding: with countries such Senegal acceding to the convention  in 2016, and with Rwanda  acceding to the convention in 2024. The Convention’s real strength lies in its detail on substantive offences, procedural powers, and international cooperation, areas where many African domestic frameworks remain underdeveloped. In essence, the convention has become a yardstick for legislatures across the world on how to draft legislation aimed at adequately addressing cybersecurity issues in their respective countries.

The Malabo Convention: A Continental Framework

The African Union Convention on Cyber Security and Personal Data Protection, adopted in Malabo in 2014, is unique globally: it brings cybersecurity, cybercrime, electronic transactions and personal data protection together in a single instrument. It came into effect on 8 June 2023, after Mauritania’s ratification. Yet,  as at early 2026, only 20 of the 55 AU member states have ratified it, a level of uptake that materially limits its practical harmonising effect.

The UN Convention Against Cybercrime: A New Global Layer

The most important recent development is the United Nations Convention Against Cybercrime, adopted by the UN General Assembly on 24 December 2024 and opened for signature on 25 October 2025 in Hanoi, Vietnam. It is the first comprehensive global treaty devoted exclusively to cybercrime. Its nine chapters cover prevention, criminalisation, procedural measures, international cooperation and capacity building. For African countries reluctant to join the Budapest Convention because it is seen as a “European” instrument, the UN Convention offers a multilateral alternative that may carry greater legitimacy. However, its success will depend on the pace of ratification and the quality of domestic implementing legislation.

The harder and more interesting  question is whether the political will may one day translate into more sophisticated legislation focused on combating cybercrime across Africa, encouraging optimism for future developments.

Southern Africa: Uneven Progress at the Continent’s Economic Hub

South Africa: The Leading Framework

South Africa’s Cybercrimes Act is the most comprehensive cybercrime framework in sub-Saharan Africa. Signed on 26 May 2021 and brought into operation in key respects on 1 December 2021, it criminalises unlawful access to data and computer systems, the unlawful acquisition or use of passwords and access codes, and the dissemination of harmful data messages. It repealed and consolidated the earlier cyber-offence provisions in sections 85 to 88 of the Electronic Communications and Transactions Act.

For companies, the Act’s dual reporting architecture is the point that matters most. Section 54 requires electronic communications service providers and financial institutions to report cyber offences to the South African Police Service within 72 hours of becoming aware of them; non-compliance is a criminal offence carrying fines of up to R50 000. That duty sits alongside, and does not replace, the separate mandatory data-breach notification regime under section 22 of the Protection of Personal Information Act. One cyber incident can therefore trigger parallel reports to different authorities, under different statutes, with different timelines and thresholds. Compliance teams need to be alert to that reality.

Namibia: A Legislative Gap

Namibia may present the Southern African Development Community’s most significant legislative gap. No dedicated cybercrime act is currently in force. The Electronic Transactions Act of 2019 deals with electronic commerce but does not create cybercrime-specific offences. Draft Cybercrime and Data Protection Bills were circulated as early as 2013 and remain unpromulgated. Before the Electronic Transactions Act, the principal instrument was the Computer Evidence Act of 1985, a statute drafted long before the internet had any meaningful commercial presence in the world. Namibia has ratified the Malabo Convention and began a Commonwealth-assisted process in 2020 to develop cybersecurity strategy components, but progress has been slow. The gap means that cybercrime prosecutions must rely on general criminal-law principles, far from a satisfactory position.

Botswana, Zimbabwe, Zambia and Eswatini

By continental standards, Botswana moved early, enacting its Cybercrime and Computer Related Crimes Act in 2007. In 2018 a further development was made in Botswana, with the country’s legislature promulgating a new piece of legislation which repealed the 2007 enactment. Though plausible, the 2018 enactment does not adequately address concerns regarding cybersecurity at the level it should given the limited number of new provisions which were introduced in the amendment Act, the Act therefore takes a reactive stance rather than proactive posture when it comes to the subject of cybersecurity.

Zimbabwe’s Cyber Security and Data Protection Act of 2021 is distinctive in bringing cybersecurity, cybercrime and data protection under one statute which is regulated by the Postal and Telecommunications Regulatory Authority. Civil society organisations, however, have strongly condemned provisions said to permit government interference with private communications without adequate judicial oversight. The tension is familiar across the continent: cybercrime laws can be deployed, or be perceived as deployable, as instruments of surveillance and political control.

Zambia’s Cyber Security and Cyber Crimes Act is currently before the High Court in a pending constitutional challenge. Akin to the situation in Zimbabwe, civil society organisations have raised a number of concerns on provisions, which apparently threaten the constitutional right to freedom of expression for Zambians. Until the challenge is resolved, the Act remains in force, but legal uncertainty hangs over it, a difficult position for compliance teams seeking a clear regulatory baseline.

Eswatini enacted the Computer Crime and Cybercrime Act which came into effect on 4 March 2022. At a high level, the Act criminalises various cyber offences and makes provision for the establishment of a National Cybersecurity Incident Response Team and National Cybersecurity Advisory Council. Moreover, the Eswatini Government has also adopted a five year National Cybersecurity Strategy with the aim of protecting key national infrastructure and to mitigate any risks of cybercrime within the Eswatini cyberspace. This Act coupled with the country’s own Data Protection Act, displays Eswatini’s strong commitment to addressing and combating cybersecurity, a country riddled by growing threats of cybercrimes as reported by Eswatini Communications Commission.

Mozambique, Lesotho, Malawi and Mauritius

Mozambique has no distinct national cybercrime framework and instead relies on partial measures. It has ratified the Malabo Convention but has not enacted dedicated implementing legislation. Lesotho presents a confirmed legislative gap: no cybercrime statute has been identified. While a Computer Crime and Cybersecurity Bill was tabled before the National Assembly in 2024, it has not yet been enacted into law amidst significant scrutiny and opposition from media and civil society. In 2024, Malawi enacted cybercrimes legislation replacing the data-protection provisions of the country’s Electronic Transactions and Cyber Security Act. Impressively, the Act is inspired by the GDPR introducing amongst others : data-subject rights, mandatory breach notification; this signals that Malawi is indeed headed towards the right direction in its commitment to improving the country’s cybersecurity laws.

Mauritius, by contrast, offers a regional model. Its Cybersecurity and Cybercrime Act of 2021, enacted on 19 November 2021, replaced the earlier Computer Misuse and Cybercrime Act of 2003. It establishes a National Cybersecurity Committee and the Computer Emergency Response Team of Mauritius, and aligns with both the Budapest Convention and the Malabo Convention. Mauritius shows what a small island state can achieve when political will exists: a framework that meets international standards.

Conclusion

It is clear that there are disparities amongst the African countries discussed above in relation to the approach to cybersecurity. Certain countries can be seen to take proactive measures to address an issue which is becoming more prevalent as societies become more digitised and make use of emerging technologies. While in countries such as Malawi, the importance of cybersecurity is simply not prioritised. In the end, multi-jurisdictional entities are confronted with a compliance dilemma insofar as it concerns how to deal with cyberattacks in various jurisdictions in light of the fragmentation and lack of uniformity of cybercrime legislation across the African continent.

In part two, we delve into this issue further – where shockingly we find that cybercrime legislation in some African countries is potentially being used as a means for censorship rather than for its intended purpose – curbing cybercrime!

Written by Ahmore Burger-Smidt, Director and Head of Regulatory; and Boitumelo Khwene, Candidate Attorney; Werksmans

EMAIL THIS ARTICLE      SAVE THIS ARTICLE      ARTICLE ENQUIRY      FEEDBACK

To subscribe email subscriptions@creamermedia.co.za or click here
To advertise email advertising@creamermedia.co.za or click here


About

Polity.org.za is a product of Creamer Media.
www.creamermedia.co.za

Other Creamer Media Products include:
Engineering News
Mining Weekly
Research Channel Africa

Read more

Subscriptions

We offer a variety of subscriptions to our Magazine, Website, PDF Reports and our photo library.

Subscriptions are available via the Creamer Media Store.

View store

Advertise

Advertising on Polity.org.za is an effective way to build and consolidate a company's profile among clients and prospective clients. Email advertising@creamermedia.co.za

View options

Email Registration Success

Thank you, you have successfully subscribed to one or more of Creamer Media’s email newsletters. You should start receiving the email newsletters in due course.

Our email newsletters may land in your junk or spam folder. To prevent this, kindly add newsletters@creamermedia.co.za to your address book or safe sender list. If you experience any issues with the receipt of our email newsletters, please email subscriptions@creamermedia.co.za