The legislative wave is real. More than thirty African countries now have some form of data protection law in force, and several more have drafts moving through their parliaments. Most borrow heavily from the GDPR, which means broadly familiar obligations: lawful basis, data subject rights, breach notification, and a supervisory authority with the power to fine.
Having a law and enforcing one are different projects. Several of the newer authorities are operating with a handful of staff and no meaningful budget, which in practice means the obligations exist but the pressure does not. Companies read that gap accurately and act accordingly.
The cost falls unevenly
Compliance is a fixed cost. A company with a legal team absorbs it easily. A six-person startup does not, and the requirement to appoint a data protection officer, run impact assessments and maintain processing records can consume a meaningful share of a seed round.
This is the part of the debate that rarely gets air time. The stated purpose of the legislation is to protect citizens, which is worth doing. The practical effect, where enforcement is uneven, is to raise the entry cost for small local companies while multinationals with existing compliance machinery carry on unbothered.
Cross-border transfer is the sharp edge
The provisions with the most immediate commercial consequence are the ones governing transfers out of the country. Several laws require either an adequacy finding or explicit regulatory approval before personal data can leave. For any company running on cloud infrastructure hosted elsewhere — which is nearly all of them — that is not a paperwork problem. It is an architecture problem, and it is expensive to fix late.