Senegal Law on Personal Data Protection (Law No. 2008-12)
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach
Per Senegal Law 2008-12: breach + sanctions.
- Senegal evidence for SENEGAL-6
- CDP notification partial
Consent
Per Senegal Law 2008-12: consent + notice + sensitive data.
- Senegal evidence for SENEGAL-2
- CDP notification partial
Governance
Per Senegal Law 2008-12: CDP notification + governance.
- Senegal evidence for SENEGAL-5
- CDP notification partial
Governance, Records and Supervision
Controllers may appoint a personal data correspondent responsible for ensuring compliance, who reports to senior management and serves as liaison with the CDP.
- Appointment letter to CDP
- Role description and independence statement
- Reporting line to senior management
- Annual activity report
- Training records
- Role not notified to CDP
- Independence compromised by reporting line
- No documented activities for the year
Controllers must maintain documentation of processing operations sufficient to demonstrate compliance with the law, including purposes, categories of data, recipients, and security measures.
- Processing register
- Categories of data and subjects map
- Retention periods documented
- Security measures summary
- Cross border transfer log
- Register exists but not maintained
- Recipient lists generic or absent
- Security measures referenced but not linked
Entities must cooperate with CDP inspections and investigations, providing access to premises, systems, and documentation upon request and within prescribed timeframes.
- CDP inspection notices
- Response packs
- Site access logs for inspectors
- Remediation plans agreed with CDP
- Follow up correspondence
- No central CDP contact log
- Response packs incomplete on first submission
- Remediation deadlines slipped
Entities should be aware that the CDP may impose administrative sanctions including warnings, formal notices, suspensions, withdrawals of authorisation, and fines, with potential criminal penalties for serious breaches.
- Sanction risk assessment
- Board reporting on CDP risk
- Insurance for regulatory penalties where lawful
- Legal advice on enforcement trends
- Remediation budgets
- Senior management unaware of sanction levels
- No insurance considered
- Past warnings not tracked in risk register
Lawful Basis and Consent
Processing must rely on a lawful basis including consent, contract performance, legal obligation, vital interests, public interest, or legitimate interests subject to proportionality assessment.
- Lawful basis register per processing activity
- Consent capture mechanism
- Legitimate interest balancing tests
- Contract templates
- Legal obligation references
- Consent used where contract necessity applies
- Legitimate interest assertions without balancing tests
- Bases not updated when purposes change
Where consent is the basis, it must be free, specific, informed, and unambiguous, with the ability to withdraw consent as easily as it was given.
- Consent capture screens
- Consent timestamps and IP records
- Withdrawal interface
- Granular consent options
- Refresh procedures for stale consent
- Bundled consent for multiple purposes
- Pre-ticked boxes used
- Withdrawal harder than capture
Marketing and Automated Decisions
Direct marketing by electronic means requires prior consent from the recipient, except where contact details were collected in the context of a sale of similar goods or services and an opt-out is offered.
- Marketing consent records
- Soft opt-in eligibility analysis
- Opt-out mechanism in every communication
- Suppression list
- Frequency capping policies
- Soft opt-in applied beyond similar products
- Opt-out missing or not honoured promptly
- Third party lists used without consent verification
Decisions producing legal effects or significantly affecting individuals cannot be based solely on automated processing of personal data, except under specific safeguards including human intervention.
- Automated decision register
- Human review procedure
- Logic disclosure to subjects
- Right to contest process
- Model documentation
- Significant effect threshold not assessed
- Human review nominal not substantive
- Logic explanations generic
Retention and Cross Border Transfers
Transfers to a country outside Senegal are permitted only where the destination ensures an adequate level of protection or where specific safeguards apply, subject to CDP authorisation for non-adequate countries.
- Country adequacy review
- CDP transfer authorisation
- Standard contractual clauses
- Binding corporate rules where applicable
- Transfer impact assessment
- Cloud transfers to non-adequate countries without authorisation
- SCCs signed but not implemented
- Onward transfers from initial recipient unmapped
Personal data must be kept no longer than necessary for the purposes for which it was collected, with archival, anonymisation, or deletion at expiry.
- Retention schedule per processing activity
- Automated deletion job logs
- Anonymisation methodology
- Archival policy
- Disposal certificates
- Indefinite retention defaults
- Backups excluded from deletion
- Anonymisation not truly anonymous
Rights
Per Senegal Law 2008-12: data subject rights.
- Senegal evidence for SENEGAL-3
- CDP notification partial
Scope
Per Senegal Law 2008-12 on Personal Data Protection: scope + lawful basis. Align with CDP (Commission de Protection des Donnees Personnelles).
- Senegal evidence for SENEGAL-1
- CDP notification partial
Scope and Registration with the CDP
The law applies to all automated and non-automated processing of personal data carried out by entities established in Senegal or using means located in Senegal, including private and public sector controllers.
- Establishment assessment
- Means of processing review
- Processing inventory
- Cross-border processing map
- Subsidiaries assumed exempt without analysis
- Cloud processing means in Senegal overlooked
- Manual processing files excluded
Controllers must declare or seek authorisation from the Commission de Protection des Donnees Personnelles (CDP) before commencing processing operations, with stricter authorisation required for sensitive data and certain processing types.
- CDP declaration receipts
- Authorisation requests and decisions
- Updated declarations after changes
- Renewal records
- Sensitive data justifications
- Declaration submitted after processing began
- Updates not filed after material changes
- Authorisation required but only declaration filed
Security
Per Senegal Law 2008-12: security + cross-border transfer with CDP authorization.
- Senegal evidence for SENEGAL-4
- CDP notification partial
Security and Processors
While Law 2008-12 does not codify a specific breach notification regime, controllers must apply security obligations and CDP guidance encourages notification of significant incidents affecting personal data.
- Incident response plan
- CDP notification template if voluntary
- Subject notification template
- Post-incident review
- Security measure updates after incident
- No documented decision process for voluntary notification
- Subjects not notified where high risk
- Lessons learned not implemented
Controllers must implement appropriate technical and organisational measures to prevent unauthorised access, alteration, disclosure, or destruction, proportionate to processing risks.
- Security policy aligned with risk
- Access control configurations
- Encryption inventory
- Logging and monitoring records
- Penetration test or security assessment results
- Risk-based proportionality not assessed
- Encryption applied inconsistently
- Logging not retained or reviewed
Persons acting under the authority of the controller or processor may only process personal data on instruction from the controller, subject to confidentiality and contractual obligations.
- Processor agreements with mandatory clauses
- Confidentiality undertakings
- Instruction logs
- Onboarding training records
- Termination procedures
- Sub-processors not flowed down
- Contracts lack instruction clauses
- Confidentiality not refreshed at role changes
Sensitive and Health Data
Processing of health data must respect medical confidentiality, require CDP authorisation, and may only be carried out by health professionals or persons subject to professional secrecy obligations.
- CDP authorisation for health processing
- Professional secrecy undertakings
- Access logs for health records
- Encryption of health data
- Restrictions on secondary use
- Non-clinical staff with broad access
- Research use without separate authorisation
- Inadequate audit trails
Processing of sensitive data (racial origin, political opinions, religious beliefs, health, sex life, criminal records) is prohibited except under specific exceptions including explicit consent and substantial public interest, requiring CDP authorisation.
- Sensitive data register
- CDP authorisation for sensitive processing
- Explicit consent records
- Public interest justification memos
- Access restrictions for sensitive categories
- Health data processed without authorisation
- Explicit consent not distinguished from general consent
- Access controls not stricter for sensitive data
Transparency and Data Subject Rights
Controllers must inform data subjects of the controller identity, processing purposes, recipients, retention, rights, and information transfer arrangements at the point of collection.
- Privacy notice in French
- Just-in-time notices at collection points
- Version control of notices
- Translation evidence
- Notice delivery records for indirect collection
- Notice only in English not French
- Indirect collection notice missing
- Retention periods generic or absent
Data subjects have rights of access, rectification, objection, deletion, and opposition to processing including for marketing, with controllers required to respond within reasonable timeframes.
- Rights request procedure
- Request log with timelines
- Identity verification steps
- Response templates
- Escalation to CDP records
- No central log of requests
- Verification methods overly burdensome
- Marketing opt-out not actioned promptly
Individuals may request confirmation of processing, communication of the data, information on origin, recipients, and purposes, and any automated decision logic affecting them.
- Access request workflow
- Disclosure pack template
- Logic explanation for automated decisions
- Free of charge confirmation
- Third party data redaction process
- Fees charged inconsistently
- Source data not disclosed
- Automated decision logic not explained
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.