Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity and Compliance in Senegal

Security audits, penetration testing, and managed security monitoring for organizations operating in Senegal, aligned with the country's data protection and cybersecurity framework.

Last updatedAugust 22, 2026

The local regulatory framework

Personal data protection in Senegal is governed by Law No. 2008-12, overseen by the Commission de protection des données personnelles (CDP). Cybercrime is addressed under Law No. 2008-11, and national cybersecurity policy is coordinated by the Agence nationale de la sécurité des systèmes d'information (ANSSI-SN), which also drives the National Cybersecurity Strategy 2022 (SNC2022). This places Senegal among the more structured regulatory frameworks in the sub-region.

Concrete obligations

Prior declaration or authorization of personal data processing with the CDP

Implementation of risk-proportionate security measures for personal data processing

Notification of incidents affecting critical information systems in line with ANSSI-SN guidance

Alignment of internal security policies with the objectives of the National Cybersecurity Strategy 2022

Cooperation with competent authorities on matters falling under the Law No. 2008-11 cybercrime framework

Priority sectors

Financial services and fintechTelecommunicationsPublic sector and government

Delivery modalities

Engagement mode

On-site missions in Dakar and remote delivery for the rest of the territory

Working language

French, with deliverables available in English on request

Regulatory coordination

Dedicated contact for interactions with the CDP and ANSSI-SN

Local FAQ

Which authority oversees data protection in Senegal?

The Commission de protection des données personnelles (CDP), which enforces Law No. 2008-12.

What is SNC2022?

The National Cybersecurity Strategy 2022, led by ANSSI-SN, which sets national cybersecurity priorities.

Does our data need to be hosted in Senegal?

Law No. 2008-12 does not impose systematic data localization; certain cross-border transfers may require specific safeguards depending on the type of processing. We assess this on a case-by-case basis for your activity.

Do you work remotely or only on site?

Both. Technical audits and penetration tests can be delivered remotely, with on-site missions for phases requiring physical access.

Can a security audit serve as proof of compliance to the CDP?

An audit documents the state of your security controls and can support a compliance file, but it does not replace a formal declaration or authorization with the CDP.

Do you work with public and semi-public entities?

Yes, our engagements cover both private companies and government bodies subject to enhanced security requirements.

Which sectors carry the highest cyber risk in Senegal?

Financial services, telecommunications, and public administrations account for most incidents observed in the sub-region, given their exposure and the value of the data they process.

Get in touch