A large number of African countries have passed data protection legislation over the past decade, and most of it shares a common ancestor in the European General Data Protection Regulation. The wording differs, the enforcement capacity differs enormously, and the underlying structure is remarkably consistent. For a company trying to work out what it will eventually be asked for, that consistency is useful.
The recurring obligations
Almost all of these laws require the same handful of things. You must have a lawful basis for processing personal data — usually consent, contract, or legitimate interest. You must tell people what you collect and why, in language they can understand. You must keep it only as long as you need it. You must be able to hand it over, correct it or delete it when the person asks. You must report a serious breach, usually within a short and specific window. And in many jurisdictions you must register with a national authority, sometimes for a fee.
Where small companies actually fail
Not on the policy document. The privacy notice is the easy part, and plenty of companies have a good one. Failures cluster around three things: nobody knows exactly what personal data the company holds or where it lives; there is no process for responding to a deletion request within the statutory window; and analytics or advertising tools were added by whoever built the marketing site, without anyone recording what they collect.
All three are inventory problems rather than legal ones, and all three get harder the longer they are left.
Cross-border transfer is the part to read carefully
The clause most likely to catch out a company running on foreign cloud infrastructure is the one governing transfers of personal data outside the country. Some statutes require the destination to offer comparable protection; some require the regulator's permission; some require data of certain kinds to stay put. This is worth reading in the specific national text rather than assuming, because it is the provision that varies most and the one that can force an architecture change rather than a policy update.
The reasonable posture for a small company is to build to the strictest regime it plausibly operates under, and keep a written record of what it holds. That is most of compliance, and it is largely admin.