Back to Frameworks

African Union Malabo Convention

Africa (AU)
v2014 (in force 2023)
22 domains
28 controls

The African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014) is the first continental framework addressing cybersecurity and data protection in Africa. It establishes obligations for AU member states in electronic commerce, personal data protection, cybersecurity, and cybercrime. Entered into force June 2023 after achieving 15 ratifications.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (22)

AU Malabo Convention Provisions

28 controls
Controls in the AU Malabo Convention Provisions domain of African Union Malabo Convention28 controls
CodeTitle
MALABO-Art11Preconditions for Personal Data Processing
MALABO-Art12National Personal Data Protection Authority
MALABO-Art13-P1Principle of Consent and Legitimacy
MALABO-Art13-P2Principle of Lawfulness and Fairness
MALABO-Art13-P3Principle of Purpose, Relevance and Storage Limitation
MALABO-Art13-P4Principle of Accuracy
MALABO-Art13-P5Principle of Transparency
MALABO-Art13-P6Principle of Confidentiality and Security
MALABO-Art14Sensitive Data and Specific Processing
MALABO-Art16Data Subject Right to Information
MALABO-Art17Data Subject Right of Access
MALABO-Art18Data Subject Right to Object
MALABO-Art19Data Subject Right of Rectification and Erasure
MALABO-Art2Scope of Electronic Commerce
MALABO-Art20Confidentiality and Security Obligations of the Controller
MALABO-Art23Transborder Flows of Personal Data
MALABO-Art24National Cyber Security Framework
MALABO-Art25National Cyber Security Policy and Strategy
MALABO-Art26Cyber Security Governance and Leadership
MALABO-Art27Protection of Critical Information Infrastructure
MALABO-Art28International Cooperation and Culture of Cyber Security
MALABO-Art29Offences Against Computer Systems and Data
MALABO-Art3Electronic Advertising Obligations
MALABO-Art30Computer Content and Property Offences
MALABO-Art31Criminal Sanctions and Corporate Liability
MALABO-Art5Contractual Obligations in Electronic Form
MALABO-Art7Security of Electronic Transactions and Electronic Signatures
MALABO-Art9Scope of Personal Data Protection

Consumer

0 controls

Cooperation

0 controls

Cybercrime

0 controls

Cybercrime Offences

0 controls

Cybersecurity

0 controls

Cybersecurity Promotion

0 controls

E-Commerce

0 controls

E-Signatures

0 controls

Electronic Transactions

0 controls

Legal framework for electronic commerce

Incident Response

0 controls

Personal Data Protection - General Principles

0 controls

Personal Data Protection - Rights and Obligations

0 controls

Personnel

0 controls

Principles

0 controls

Registration

0 controls

Rights

0 controls

Security

0 controls

Sensitive Data

0 controls

Supervision

0 controls

Transfers

0 controls

Transparency

0 controls

Maps to 2 other frameworks

28 total controls
GDPR
8 source controls mapped|8 target controls covered
29%
NIST SP 800-53 Rev 5
6 source controls mapped|6 target controls covered
21%

Frequently Asked Questions

What is African Union Malabo Convention?

African Union Malabo Convention is a compliance framework from Africa (AU) with 22 domains and 28 controls. The African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014) is the first continental framework addressing cybersecurity and data protection in Africa. It establishes obligations for AU member states in electronic commerce, personal data protection, cybersecurity, and cybercrime. Entered into force June 2023 after achieving 15 ratifications. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does African Union Malabo Convention have?

African Union Malabo Convention has 28 controls organised across 22 domains. The largest domains are AU Malabo Convention Provisions (28 controls), Consumer (0 controls), Cooperation (0 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does African Union Malabo Convention map to?

African Union Malabo Convention maps to 2 other compliance frameworks. The top mapping partners are GDPR (29% coverage), NIST SP 800-53 Rev 5 (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with African Union Malabo Convention compliance?

Start your African Union Malabo Convention compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about African Union Malabo Convention requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required