Skip to content

Evidence request lists

African Union Malabo Convention

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

AU Malabo Convention Provisions

MALABO-Art11
Preconditions for Personal Data Processing

Preliminary formalities and conditions to be met prior to processing personal data.

Artefacts an auditor will ask for
  • Processing authorisation/notification records
Where this commonly fails
  • Processing without required preconditions
MALABO-Art12
National Personal Data Protection Authority

Establishment of an independent national authority responsible for ensuring personal data processing complies with the Convention.

Artefacts an auditor will ask for
  • National DPA establishment & powers
Where this commonly fails
  • No independent supervisory authority
MALABO-Art13-P1
Principle of Consent and Legitimacy

Processing is legitimate where the data subject consents, unless waived for legal obligation, public interest, contract, or vital interests.

Artefacts an auditor will ask for
  • Consent records
  • Lawful-basis register
Where this commonly fails
  • No documented lawful basis
  • Invalid/forced consent
MALABO-Art13-P2
Principle of Lawfulness and Fairness

Collection, recording, processing, storage and transmission of personal data shall be lawful, fair and non-fraudulent.

Artefacts an auditor will ask for
  • Processing fairness assessment
Where this commonly fails
  • Unlawful or deceptive processing
MALABO-Art13-P3
Principle of Purpose, Relevance and Storage Limitation

Data collected for specified, explicit, legitimate purposes; adequate, relevant, not excessive; kept no longer than necessary.

Artefacts an auditor will ask for
  • Purpose specification
  • Retention schedule
Where this commonly fails
  • Function creep
  • Indefinite retention
MALABO-Art13-P4
Principle of Accuracy

Data shall be accurate and kept up to date; inaccurate or incomplete data erased or rectified.

Artefacts an auditor will ask for
  • Accuracy/rectification process
Where this commonly fails
  • Stale or inaccurate records uncorrected
MALABO-Art13-P5
Principle of Transparency

Mandatory disclosure of information by the data controller to the data subject regarding the processing.

Artefacts an auditor will ask for
  • Privacy notice / transparency information
Where this commonly fails
  • No notice to data subjects
MALABO-Art13-P6
Principle of Confidentiality and Security

The controller shall ensure the confidentiality and security of personal data against unauthorised access, alteration or disclosure.

Artefacts an auditor will ask for
  • Technical & organisational security measures
Where this commonly fails
  • Inadequate safeguards for personal data
MALABO-Art14
Sensitive Data and Specific Processing

Prohibition and conditions for processing sensitive personal data (e.g. racial, health, religious, biometric).

Artefacts an auditor will ask for
  • Sensitive-data processing controls & exemptions
Where this commonly fails
  • Sensitive data processed without safeguards
MALABO-Art16
Data Subject Right to Information

The data subject's right to be informed about the collection and processing of their personal data.

Artefacts an auditor will ask for
  • Right-to-information procedure
Where this commonly fails
  • Data subjects not informed
MALABO-Art17
Data Subject Right of Access

The data subject's right to obtain from the controller confirmation and communication of their processed data.

Artefacts an auditor will ask for
  • Access-request handling process
Where this commonly fails
  • No access-request mechanism
MALABO-Art18
Data Subject Right to Object

The data subject's right to object to the processing of their personal data on legitimate grounds.

Artefacts an auditor will ask for
  • Objection-handling process
Where this commonly fails
  • No objection mechanism
MALABO-Art19
Data Subject Right of Rectification and Erasure

The data subject's right to rectification, completion, updating, blocking or erasure of their data.

Artefacts an auditor will ask for
  • Rectification/erasure process
Where this commonly fails
  • No correction/deletion capability
MALABO-Art2
Scope of Electronic Commerce

Defines electronic commerce activities and the obligations of persons engaging in commercial activity by electronic means.

Artefacts an auditor will ask for
  • E-commerce activity policy
Where this commonly fails
  • E-commerce obligations undefined
MALABO-Art20
Confidentiality and Security Obligations of the Controller

The controller's obligations of confidentiality, security, preservation and sustainability of personal data.

Artefacts an auditor will ask for
  • Controller security & retention controls
Where this commonly fails
  • Controller obligations unmet
MALABO-Art23
Transborder Flows of Personal Data

Conditions and restrictions on transferring personal data to a non-member State.

Artefacts an auditor will ask for
  • Transfer impact assessment
  • Adequacy/safeguard records
Where this commonly fails
  • Unrestricted transfers to inadequate jurisdictions
MALABO-Art24
National Cyber Security Framework

Commitment to establish a national legal, regulatory and institutional framework for cyber security.

Artefacts an auditor will ask for
  • National cyber security framework
Where this commonly fails
  • No national cyber security framework
MALABO-Art25
National Cyber Security Policy and Strategy

Adoption of a national cyber security policy and strategy reflecting a holistic approach.

Artefacts an auditor will ask for
  • National cyber security strategy
Where this commonly fails
  • No defined cyber strategy
MALABO-Art26
Cyber Security Governance and Leadership

Establishment of leadership, institutions and responsibilities to coordinate cyber security.

Artefacts an auditor will ask for
  • Cyber governance bodies & responsibilities
Where this commonly fails
  • No coordinating cyber authority
MALABO-Art27
Protection of Critical Information Infrastructure

Measures to identify and protect critical information infrastructure sectors.

Artefacts an auditor will ask for
  • CII identification & protection measures
Where this commonly fails
  • CII unidentified/unprotected
MALABO-Art28
International Cooperation and Culture of Cyber Security

Promotion of a culture of cyber security and international/regional cooperation.

Artefacts an auditor will ask for
  • Cyber cooperation agreements & awareness
Where this commonly fails
  • No cross-border cooperation
MALABO-Art29
Offences Against Computer Systems and Data

Criminalisation of unauthorised access, interference and interception of computer systems and computerised data.

Artefacts an auditor will ask for
  • Legislation criminalising system/data attacks
Where this commonly fails
  • System-attack offences not criminalised
MALABO-Art3
Electronic Advertising Obligations

Conditions for advertising by electronic means, including identification of the advertiser and consent for direct marketing.

Artefacts an auditor will ask for
  • Electronic advertising/consent records
Where this commonly fails
  • Unsolicited e-marketing without consent
MALABO-Art30
Computer Content and Property Offences

Criminalisation of computer-related fraud/forgery and content-related offences (e.g. child pornography, racism).

Artefacts an auditor will ask for
  • Legislation on computer fraud & content offences
Where this commonly fails
  • Content/property offences not covered
MALABO-Art31
Criminal Sanctions and Corporate Liability

Adaptation of criminal sanctions and liability of legal persons for cyber offences.

Artefacts an auditor will ask for
  • Penalty framework
  • Corporate-liability provisions
Where this commonly fails
  • No sanctions or corporate liability
MALABO-Art5
Contractual Obligations in Electronic Form

Validity and formation of contracts concluded in electronic form, including offer, acceptance and writing requirements.

Artefacts an auditor will ask for
  • Electronic contracting process
Where this commonly fails
  • E-contract validity not assured
MALABO-Art7
Security of Electronic Transactions and Electronic Signatures

Requirements for securing electronic transactions, including qualified electronic signatures.

Artefacts an auditor will ask for
  • Electronic signature scheme
  • Transaction integrity controls
Where this commonly fails
  • No qualified e-signature support
MALABO-Art9
Scope of Personal Data Protection

Scope and exemptions of the personal data protection regime under the Convention.

Artefacts an auditor will ask for
  • Data processing inventory / scope assessment
Where this commonly fails
  • Processing outside defined lawful scope
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the African Union Malabo Convention framework page.