Security audits, penetration testing, and managed security monitoring for organizations operating in Senegal, aligned with the country's data protection and cybersecurity framework.
Last updated — August 22, 2026
Personal data protection in Senegal is governed by Law No. 2008-12, overseen by the Commission de protection des données personnelles (CDP). Cybercrime is addressed under Law No. 2008-11, and national cybersecurity policy is coordinated by the Agence nationale de la sécurité des systèmes d'information (ANSSI-SN), which also drives the National Cybersecurity Strategy 2022 (SNC2022). This places Senegal among the more structured regulatory frameworks in the sub-region.
Engagement mode
On-site missions in Dakar and remote delivery for the rest of the territory
Working language
French, with deliverables available in English on request
Regulatory coordination
Dedicated contact for interactions with the CDP and ANSSI-SN
The Commission de protection des données personnelles (CDP), which enforces Law No. 2008-12.
The National Cybersecurity Strategy 2022, led by ANSSI-SN, which sets national cybersecurity priorities.
Law No. 2008-12 does not impose systematic data localization; certain cross-border transfers may require specific safeguards depending on the type of processing. We assess this on a case-by-case basis for your activity.
Both. Technical audits and penetration tests can be delivered remotely, with on-site missions for phases requiring physical access.
An audit documents the state of your security controls and can support a compliance file, but it does not replace a formal declaration or authorization with the CDP.
Yes, our engagements cover both private companies and government bodies subject to enhanced security requirements.
Financial services, telecommunications, and public administrations account for most incidents observed in the sub-region, given their exposure and the value of the data they process.