Africa has established important continental frameworks for digital trade, data governance, cybersecurity and artificial intelligence. To succeed, the continent must turn those commitments into interoperable systems that work across national borders.
Africa is not short of digital ambition. Over the past decade, governments and continental institutions have adopted policies intended to support digital trade, protect personal data, strengthen cybersecurity and create a more integrated digital economy.
The African Union’s Digital Transformation Strategy envisages a Digital Single Market supported by policy harmonisation, mutual recognition and regional cooperation. The Malabo Convention establishes a continental framework for cybersecurity and personal-data protection, while the African Continental Free Trade Area Protocol on Digital Trade provides a foundation for reducing barriers to digital commerce. The African Union Data Policy Framework, Digital Compact and Continental Artificial Intelligence Strategy add further layers to the continent’s policy architecture.
Together, these initiatives provide much of the foundation Africa needs. The problem is that the frameworks do not yet operate as a connected system across the continent’s 55 national jurisdictions.
“Africa does not lack digital policy. What we lack instead is a system in which these policies work together,” said Chidera Ike-Okonkwo, Africa Director, Government Affairs and Public Policy, Nina Jojer, while chairing the “Governing the Digital Continent” panel at Hyperscalers Convergence Africa 2026.
The panel featured Dr Talkmore Chidede, Senior Digital Trade Expert, African Continental Free Trade Area Secretariat; Amr Safwat, Manager, African Multilateral Affairs, Ministry of Communications and Information Technology, Egypt; Tony Emoekpere, President, Association of Telecommunications Companies of Nigeria; Gimba Mohammed, Director, Government and External Relations, IHS Towers; and Dr Aristotle Onumo, Director, National Information Technology Development Agency, representing Kashifu Inuwa Abdullahi, Director-General, National Information Technology Development Agency.
Continental infrastructure, national regulation
Africa’s digital infrastructure increasingly crosses borders. Submarine cables connect coastal markets to the global internet, terrestrial fibre networks extend capacity inland, and data centres, cloud platforms and payment systems serve customers in multiple jurisdictions.
Regulation, however, remains predominantly national. A company seeking to provide services across several African markets may encounter different requirements for licensing, data protection, cybersecurity, cloud deployment, digital identity and cross-border data transfers. Even where national rules pursue similar objectives, differences in definitions, documentation and approval procedures can increase compliance costs and delay expansion.
The African Union has acknowledged that fragmented policies and standards constrain cross-border collaboration. As African Union Commission Deputy Chairperson Selma Malika Haddadi observed, “This fragmentation creates barriers instead of bridges,” preventing businesses from realising the full potential of the continental market. The Commission is developing common architecture to improve coordination while allowing countries to protect their legitimate national interests.
The challenge is particularly visible in digital payments. A transfer within one country may be completed almost instantly, but a transaction between customers in different African markets can involve several regulatory systems. Customer identities must be verified, payment providers may require separate approvals, and the associated data may be processed in another jurisdiction.
Building payment rails is therefore not sufficient. The rules governing identity, data transfers, consumer protection and cybersecurity must also be capable of working together.
Interoperability does not require identical laws
Creating an integrated digital market does not mean imposing one law on every African country. Countries have different legal traditions, institutional capacities, security concerns and stages of digital development. Uniform regulation would be difficult to negotiate and may not respond adequately to local conditions.
The more practical objective is alignment and interoperability: national systems retain their identities but establish sufficient compatibility to interact. This could include common minimum principles, mutually recognised certifications, comparable data classification systems, standard approval procedures and confidence in the regulatory and enforcement capacity of other jurisdictions.
The African Union’s Digital Transformation Strategy similarly calls for regional integration, mutual recognition and the harmonisation of existing digital initiatives and systems. Its objective is to create a coordinated continental agenda, improve synergies and address the absence of a common digital coordination framework.
This distinction – alignment over uniformity – allows countries to preserve sovereignty and even maintain higher national standards while reducing unnecessary friction for businesses operating across borders.

Rethinking digital sovereignty
The panel also highlighted the need to distinguish data localisation from digital sovereignty.
Localisation concerns where data is physically stored or processed. Sovereignty concerns who has authority over that data and whether a government possesses enforceable rights, security assurances, audit mechanisms and remedies when something goes wrong.
Under a more flexible model, governments would determine requirements according to the sensitivity of the data and the risks associated with the workload. Highly sensitive government or national – security data could require stronger domestic controls, while lower-risk workloads could be processed under trusted regional arrangements.
“Sovereignty is risk-based; it is classification-based,” said Dr Aristotle Onumo, explaining Nigeria’s emerging approach. Rather than applying one requirement to every category of data, the level of control should reflect the sensitivity and risk profile of the information involved.
This approach could support both national interests and regional scale. A country would retain authority over sensitive information without requiring every type of data to remain physically within its borders.
Localisation can create demand – and risk
Data-localisation requirements can stimulate demand for domestic data centres, cloud platforms and connectivity. They can encourage companies to store more information locally, improve access to certain digital services and attract investment into national infrastructure.
But localisation policies must be carefully sequenced. Requiring businesses to move workloads into a country before sufficient capacity, reliable power, connectivity and geographical redundancy are available could create new vulnerabilities.
In Nigeria, for example, much of the data centre market is concentrated in Lagos, with additional capacity developing in Abuja and other locations. Moving a large volume of critical data into a small number of facilities or cities without adequate redundancy could increase concentration risk. Disruption to power, connectivity or a major infrastructure cluster could affect many services simultaneously.
Gimba Mohammed argued that closer coordination is required among institutions responsible for infrastructure, finance, data, telecommunications and digital policy. “It is those processes that allow these agencies or regulatory regimes to operate as one coherent process,” he said.
This coordination must begin before major directives are issued. Regulators should assess available domestic capacity, infrastructure resilience, power requirements and implementation timelines, while industry needs sufficient clarity to plan and finance new facilities.
Regulation shapes investment
The relationship between policy and investment was another important theme. Clear regulation can create demand, improve market certainty and strengthen the commercial case for infrastructure. Poorly coordinated or conflicting rules can have the opposite effect by increasing risk and delaying investment decisions.
“Policy drives investment, whether we like it or not,” said Tony Emoekpere. The question is whether that policy provides clear definitions, realistic implementation periods and consistent direction across institutions.
Investors financing fibre, data centres, cloud platforms and computing infrastructure need confidence that demand will materialise and that the rules will remain predictable. Regional interoperability can strengthen that proposition by giving infrastructure providers access to a larger market instead of limiting projects to demand from one jurisdiction.
Regulatory convergence could therefore make digital infrastructure more bankable. A data centre capable of serving several compatible markets has a stronger potential customer base than one confined by incompatible national requirements. The same logic applies to fibre networks, digital identity platforms, payment systems and cloud services.
From continental commitments to functioning systems
Africa’s next digital milestone should not be another declaration of ambition. The continent already has many of the required policies. The priority is implementation: turning frameworks into compatible standards, functioning institutions and systems that businesses and citizens can use.
That work can begin with a limited number of high-impact areas. Regulators could establish common terminology for data classification and cloud services, pilot mutual recognition between selected jurisdictions, coordinate implementation timelines and create formal mechanisms for resolving conflicts between national requirements.
The continent can also prioritise interoperable digital identity, cross-border payments and trusted data-transfer mechanisms – areas where regulatory coordination can produce immediate economic value.
Africa’s infrastructure is becoming regional. Its digital businesses are becoming regional. Its customers increasingly expect services to work across borders. Regulation must now make the same transition.
The ambition of a Digital Single Market will be realised not when every country adopts identical laws, but when national systems can recognise, trust and work with one another. Africa has built the policy foundations. It must now connect them.