African Union Malabo Convention
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
AU Malabo Convention Provisions
Preliminary formalities and conditions to be met prior to processing personal data.
- Processing authorisation/notification records
- Processing without required preconditions
Establishment of an independent national authority responsible for ensuring personal data processing complies with the Convention.
- National DPA establishment & powers
- No independent supervisory authority
Processing is legitimate where the data subject consents, unless waived for legal obligation, public interest, contract, or vital interests.
- Consent records
- Lawful-basis register
- No documented lawful basis
- Invalid/forced consent
Collection, recording, processing, storage and transmission of personal data shall be lawful, fair and non-fraudulent.
- Processing fairness assessment
- Unlawful or deceptive processing
Data collected for specified, explicit, legitimate purposes; adequate, relevant, not excessive; kept no longer than necessary.
- Purpose specification
- Retention schedule
- Function creep
- Indefinite retention
Data shall be accurate and kept up to date; inaccurate or incomplete data erased or rectified.
- Accuracy/rectification process
- Stale or inaccurate records uncorrected
Mandatory disclosure of information by the data controller to the data subject regarding the processing.
- Privacy notice / transparency information
- No notice to data subjects
The controller shall ensure the confidentiality and security of personal data against unauthorised access, alteration or disclosure.
- Technical & organisational security measures
- Inadequate safeguards for personal data
Prohibition and conditions for processing sensitive personal data (e.g. racial, health, religious, biometric).
- Sensitive-data processing controls & exemptions
- Sensitive data processed without safeguards
The data subject's right to be informed about the collection and processing of their personal data.
- Right-to-information procedure
- Data subjects not informed
The data subject's right to obtain from the controller confirmation and communication of their processed data.
- Access-request handling process
- No access-request mechanism
The data subject's right to object to the processing of their personal data on legitimate grounds.
- Objection-handling process
- No objection mechanism
The data subject's right to rectification, completion, updating, blocking or erasure of their data.
- Rectification/erasure process
- No correction/deletion capability
Defines electronic commerce activities and the obligations of persons engaging in commercial activity by electronic means.
- E-commerce activity policy
- E-commerce obligations undefined
The controller's obligations of confidentiality, security, preservation and sustainability of personal data.
- Controller security & retention controls
- Controller obligations unmet
Conditions and restrictions on transferring personal data to a non-member State.
- Transfer impact assessment
- Adequacy/safeguard records
- Unrestricted transfers to inadequate jurisdictions
Commitment to establish a national legal, regulatory and institutional framework for cyber security.
- National cyber security framework
- No national cyber security framework
Adoption of a national cyber security policy and strategy reflecting a holistic approach.
- National cyber security strategy
- No defined cyber strategy
Establishment of leadership, institutions and responsibilities to coordinate cyber security.
- Cyber governance bodies & responsibilities
- No coordinating cyber authority
Measures to identify and protect critical information infrastructure sectors.
- CII identification & protection measures
- CII unidentified/unprotected
Promotion of a culture of cyber security and international/regional cooperation.
- Cyber cooperation agreements & awareness
- No cross-border cooperation
Criminalisation of unauthorised access, interference and interception of computer systems and computerised data.
- Legislation criminalising system/data attacks
- System-attack offences not criminalised
Conditions for advertising by electronic means, including identification of the advertiser and consent for direct marketing.
- Electronic advertising/consent records
- Unsolicited e-marketing without consent
Criminalisation of computer-related fraud/forgery and content-related offences (e.g. child pornography, racism).
- Legislation on computer fraud & content offences
- Content/property offences not covered
Adaptation of criminal sanctions and liability of legal persons for cyber offences.
- Penalty framework
- Corporate-liability provisions
- No sanctions or corporate liability
Validity and formation of contracts concluded in electronic form, including offer, acceptance and writing requirements.
- Electronic contracting process
- E-contract validity not assured
Requirements for securing electronic transactions, including qualified electronic signatures.
- Electronic signature scheme
- Transaction integrity controls
- No qualified e-signature support
Scope and exemptions of the personal data protection regime under the Convention.
- Data processing inventory / scope assessment
- Processing outside defined lawful scope
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the African Union Malabo Convention framework page.