Skip to content

Evidence request lists

Senegal Law on Personal Data Protection (Law No. 2008-12)

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach

SENEGAL-6
Breach and Enforcement

Per Senegal Law 2008-12: breach + sanctions.

Artefacts an auditor will ask for
  • Senegal evidence for SENEGAL-6
Where this commonly fails
  • CDP notification partial

Consent

SENEGAL-2
Consent, Notice, Sensitive Data

Per Senegal Law 2008-12: consent + notice + sensitive data.

Artefacts an auditor will ask for
  • Senegal evidence for SENEGAL-2
Where this commonly fails
  • CDP notification partial

Governance

SENEGAL-5
CDP Notification, DPO, Governance

Per Senegal Law 2008-12: CDP notification + governance.

Artefacts an auditor will ask for
  • Senegal evidence for SENEGAL-5
Where this commonly fails
  • CDP notification partial

Governance, Records and Supervision

SN-DPL-11.1
Personal Data Correspondent Function

Controllers may appoint a personal data correspondent responsible for ensuring compliance, who reports to senior management and serves as liaison with the CDP.

Artefacts an auditor will ask for
  • Appointment letter to CDP
  • Role description and independence statement
  • Reporting line to senior management
  • Annual activity report
  • Training records
Where this commonly fails
  • Role not notified to CDP
  • Independence compromised by reporting line
  • No documented activities for the year
SN-DPL-12.1
Records of Processing

Controllers must maintain documentation of processing operations sufficient to demonstrate compliance with the law, including purposes, categories of data, recipients, and security measures.

Artefacts an auditor will ask for
  • Processing register
  • Categories of data and subjects map
  • Retention periods documented
  • Security measures summary
  • Cross border transfer log
Where this commonly fails
  • Register exists but not maintained
  • Recipient lists generic or absent
  • Security measures referenced but not linked
SN-DPL-14.1
Cooperation with CDP Investigations

Entities must cooperate with CDP inspections and investigations, providing access to premises, systems, and documentation upon request and within prescribed timeframes.

Artefacts an auditor will ask for
  • CDP inspection notices
  • Response packs
  • Site access logs for inspectors
  • Remediation plans agreed with CDP
  • Follow up correspondence
Where this commonly fails
  • No central CDP contact log
  • Response packs incomplete on first submission
  • Remediation deadlines slipped
SN-DPL-15.1
Sanctions and Penalties Awareness

Entities should be aware that the CDP may impose administrative sanctions including warnings, formal notices, suspensions, withdrawals of authorisation, and fines, with potential criminal penalties for serious breaches.

Artefacts an auditor will ask for
  • Sanction risk assessment
  • Board reporting on CDP risk
  • Insurance for regulatory penalties where lawful
  • Legal advice on enforcement trends
  • Remediation budgets
Where this commonly fails
  • Senior management unaware of sanction levels
  • No insurance considered
  • Past warnings not tracked in risk register

Lawful Basis and Consent

SN-DPL-3.1
Lawful Basis for Processing

Processing must rely on a lawful basis including consent, contract performance, legal obligation, vital interests, public interest, or legitimate interests subject to proportionality assessment.

Artefacts an auditor will ask for
  • Lawful basis register per processing activity
  • Consent capture mechanism
  • Legitimate interest balancing tests
  • Contract templates
  • Legal obligation references
Where this commonly fails
  • Consent used where contract necessity applies
  • Legitimate interest assertions without balancing tests
  • Bases not updated when purposes change
SN-DPL-3.2
Consent Requirements

Where consent is the basis, it must be free, specific, informed, and unambiguous, with the ability to withdraw consent as easily as it was given.

Artefacts an auditor will ask for
  • Consent capture screens
  • Consent timestamps and IP records
  • Withdrawal interface
  • Granular consent options
  • Refresh procedures for stale consent
Where this commonly fails
  • Bundled consent for multiple purposes
  • Pre-ticked boxes used
  • Withdrawal harder than capture

Marketing and Automated Decisions

SN-DPL-10.1
Direct Marketing Restrictions

Direct marketing by electronic means requires prior consent from the recipient, except where contact details were collected in the context of a sale of similar goods or services and an opt-out is offered.

Artefacts an auditor will ask for
  • Marketing consent records
  • Soft opt-in eligibility analysis
  • Opt-out mechanism in every communication
  • Suppression list
  • Frequency capping policies
Where this commonly fails
  • Soft opt-in applied beyond similar products
  • Opt-out missing or not honoured promptly
  • Third party lists used without consent verification
SN-DPL-13.1
Automated Decision Making

Decisions producing legal effects or significantly affecting individuals cannot be based solely on automated processing of personal data, except under specific safeguards including human intervention.

Artefacts an auditor will ask for
  • Automated decision register
  • Human review procedure
  • Logic disclosure to subjects
  • Right to contest process
  • Model documentation
Where this commonly fails
  • Significant effect threshold not assessed
  • Human review nominal not substantive
  • Logic explanations generic

Retention and Cross Border Transfers

SN-DPL-8.1
Cross-Border Transfer Restrictions

Transfers to a country outside Senegal are permitted only where the destination ensures an adequate level of protection or where specific safeguards apply, subject to CDP authorisation for non-adequate countries.

Artefacts an auditor will ask for
  • Country adequacy review
  • CDP transfer authorisation
  • Standard contractual clauses
  • Binding corporate rules where applicable
  • Transfer impact assessment
Where this commonly fails
  • Cloud transfers to non-adequate countries without authorisation
  • SCCs signed but not implemented
  • Onward transfers from initial recipient unmapped
SN-DPL-9.1
Data Retention Limits

Personal data must be kept no longer than necessary for the purposes for which it was collected, with archival, anonymisation, or deletion at expiry.

Artefacts an auditor will ask for
  • Retention schedule per processing activity
  • Automated deletion job logs
  • Anonymisation methodology
  • Archival policy
  • Disposal certificates
Where this commonly fails
  • Indefinite retention defaults
  • Backups excluded from deletion
  • Anonymisation not truly anonymous

Rights

SENEGAL-3
Data Subject Rights

Per Senegal Law 2008-12: data subject rights.

Artefacts an auditor will ask for
  • Senegal evidence for SENEGAL-3
Where this commonly fails
  • CDP notification partial

Scope

SENEGAL-1
Scope, Lawful Basis (Senegal Law 2008-12)

Per Senegal Law 2008-12 on Personal Data Protection: scope + lawful basis. Align with CDP (Commission de Protection des Donnees Personnelles).

Artefacts an auditor will ask for
  • Senegal evidence for SENEGAL-1
Where this commonly fails
  • CDP notification partial

Scope and Registration with the CDP

SN-DPL-1.1
Scope and Application

The law applies to all automated and non-automated processing of personal data carried out by entities established in Senegal or using means located in Senegal, including private and public sector controllers.

Artefacts an auditor will ask for
  • Establishment assessment
  • Means of processing review
  • Processing inventory
  • Cross-border processing map
Where this commonly fails
  • Subsidiaries assumed exempt without analysis
  • Cloud processing means in Senegal overlooked
  • Manual processing files excluded
SN-DPL-2.1
CDP Registration of Processing

Controllers must declare or seek authorisation from the Commission de Protection des Donnees Personnelles (CDP) before commencing processing operations, with stricter authorisation required for sensitive data and certain processing types.

Artefacts an auditor will ask for
  • CDP declaration receipts
  • Authorisation requests and decisions
  • Updated declarations after changes
  • Renewal records
  • Sensitive data justifications
Where this commonly fails
  • Declaration submitted after processing began
  • Updates not filed after material changes
  • Authorisation required but only declaration filed

Security

SENEGAL-4
Security and Cross-Border

Per Senegal Law 2008-12: security + cross-border transfer with CDP authorization.

Artefacts an auditor will ask for
  • Senegal evidence for SENEGAL-4
Where this commonly fails
  • CDP notification partial

Security and Processors

SN-DPL-17.1
Data Breach Awareness and Response

While Law 2008-12 does not codify a specific breach notification regime, controllers must apply security obligations and CDP guidance encourages notification of significant incidents affecting personal data.

Artefacts an auditor will ask for
  • Incident response plan
  • CDP notification template if voluntary
  • Subject notification template
  • Post-incident review
  • Security measure updates after incident
Where this commonly fails
  • No documented decision process for voluntary notification
  • Subjects not notified where high risk
  • Lessons learned not implemented
SN-DPL-7.1
Data Security Measures

Controllers must implement appropriate technical and organisational measures to prevent unauthorised access, alteration, disclosure, or destruction, proportionate to processing risks.

Artefacts an auditor will ask for
  • Security policy aligned with risk
  • Access control configurations
  • Encryption inventory
  • Logging and monitoring records
  • Penetration test or security assessment results
Where this commonly fails
  • Risk-based proportionality not assessed
  • Encryption applied inconsistently
  • Logging not retained or reviewed
SN-DPL-7.2
Confidentiality of Processors

Persons acting under the authority of the controller or processor may only process personal data on instruction from the controller, subject to confidentiality and contractual obligations.

Artefacts an auditor will ask for
  • Processor agreements with mandatory clauses
  • Confidentiality undertakings
  • Instruction logs
  • Onboarding training records
  • Termination procedures
Where this commonly fails
  • Sub-processors not flowed down
  • Contracts lack instruction clauses
  • Confidentiality not refreshed at role changes

Sensitive and Health Data

SN-DPL-16.1
Health Data Specific Rules

Processing of health data must respect medical confidentiality, require CDP authorisation, and may only be carried out by health professionals or persons subject to professional secrecy obligations.

Artefacts an auditor will ask for
  • CDP authorisation for health processing
  • Professional secrecy undertakings
  • Access logs for health records
  • Encryption of health data
  • Restrictions on secondary use
Where this commonly fails
  • Non-clinical staff with broad access
  • Research use without separate authorisation
  • Inadequate audit trails
SN-DPL-6.1
Sensitive Data Processing

Processing of sensitive data (racial origin, political opinions, religious beliefs, health, sex life, criminal records) is prohibited except under specific exceptions including explicit consent and substantial public interest, requiring CDP authorisation.

Artefacts an auditor will ask for
  • Sensitive data register
  • CDP authorisation for sensitive processing
  • Explicit consent records
  • Public interest justification memos
  • Access restrictions for sensitive categories
Where this commonly fails
  • Health data processed without authorisation
  • Explicit consent not distinguished from general consent
  • Access controls not stricter for sensitive data

Transparency and Data Subject Rights

SN-DPL-4.1
Information to Data Subjects

Controllers must inform data subjects of the controller identity, processing purposes, recipients, retention, rights, and information transfer arrangements at the point of collection.

Artefacts an auditor will ask for
  • Privacy notice in French
  • Just-in-time notices at collection points
  • Version control of notices
  • Translation evidence
  • Notice delivery records for indirect collection
Where this commonly fails
  • Notice only in English not French
  • Indirect collection notice missing
  • Retention periods generic or absent
SN-DPL-5.1
Data Subject Rights

Data subjects have rights of access, rectification, objection, deletion, and opposition to processing including for marketing, with controllers required to respond within reasonable timeframes.

Artefacts an auditor will ask for
  • Rights request procedure
  • Request log with timelines
  • Identity verification steps
  • Response templates
  • Escalation to CDP records
Where this commonly fails
  • No central log of requests
  • Verification methods overly burdensome
  • Marketing opt-out not actioned promptly
SN-DPL-5.2
Right of Access

Individuals may request confirmation of processing, communication of the data, information on origin, recipients, and purposes, and any automated decision logic affecting them.

Artefacts an auditor will ask for
  • Access request workflow
  • Disclosure pack template
  • Logic explanation for automated decisions
  • Free of charge confirmation
  • Third party data redaction process
Where this commonly fails
  • Fees charged inconsistently
  • Source data not disclosed
  • Automated decision logic not explained
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.