African Union Malabo Convention
The African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014) is the first continental framework addressing cybersecurity and data protection in Africa. It establishes obligations for AU member states in electronic commerce, personal data protection, cybersecurity, and cybercrime. Entered into force June 2023 after achieving 15 ratifications.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Consumer
| Code | Title |
|---|---|
| MAL-Art35 | Consumer Protection in E-Commerce |
Cooperation
| Code | Title |
|---|---|
| MAL-Art36 | International Cooperation on Cybercrime |
Cybercrime
| Code | Title |
|---|---|
| MAL-Art29 | Offences Against Confidentiality, Integrity, Availability |
| MAL-Art30 | Computer-Related Offences |
| MAL-Art31 | Content-Related Offences |
Cybercrime Offences
| Code | Title |
|---|---|
| Art. 28 | Notifying Authorities |
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
| Art. 31 | Designation of Chief Privacy Officer |
| MMCL-Ch9-1 | Unauthorized Access |
| MMCL-Ch9-2 | Data Interference |
| MMCL-Ch9-3 | System Interference |
Cybersecurity
| Code | Title |
|---|---|
| MAL-Art25 | National Cybersecurity Policy |
| MAL-Art26 | Cybersecurity Measures for Critical Infrastructure |
Cybersecurity Promotion
| Code | Title |
|---|---|
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 25 | Criminal Penalties |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
| Art. 27 | Fundamental Rights Impact Assessment for High-Risk AI Systems |
E-Commerce
| Code | Title |
|---|---|
| MAL-Art33 | Electronic Transactions and E-Commerce |
E-Signatures
| Code | Title |
|---|---|
| MAL-Art34 | Electronic Signatures |
Electronic Transactions
Legal framework for electronic commerce
| Code | Title |
|---|---|
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
Implementation and Final Provisions
| Code | Title |
|---|---|
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 32 | Entry into Force |
| Art. 34 | Notification of Personal Information Breach |
| Art. 36 | Right to Correction or Deletion |
Incident Response
| Code | Title |
|---|---|
| MAL-Art27 | National CSIRT Cooperation |
Personal Data Protection - General Principles
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 11 | Technical Documentation |
| Art. 12 | Record-Keeping |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
Personal Data Protection - Rights and Obligations
| Code | Title |
|---|---|
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 14 | Human Oversight |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
Personnel
| Code | Title |
|---|---|
| MAL-Art20 | Personnel Confidentiality |
Principles
| Code | Title |
|---|---|
| MAL-Art13 | Basic Principles of Personal Data Processing |
Registration
| Code | Title |
|---|---|
| MAL-Art10 | Notification of Processing |
Rights
| Code | Title |
|---|---|
| MAL-Art16 | Right of Access |
| MAL-Art17 | Right to Rectification or Erasure |
| MAL-Art18 | Right to Object |
Security
| Code | Title |
|---|---|
| MAL-Art19 | Confidentiality and Security Obligations |
Sensitive Data
| Code | Title |
|---|---|
| MAL-Art14 | Specific Principles for Sensitive Data |
Supervision
| Code | Title |
|---|---|
| MAL-Art8 | National Personal Data Protection Authority |
Transfers
| Code | Title |
|---|---|
| MAL-Art22 | Cross-Border Transfer Restrictions |
Transparency
| Code | Title |
|---|---|
| MAL-Art15 | Data Subject Information |
Your Compliance Coverage
If you comply with African Union Malabo Convention, you already cover:
EU AI Act
31%
16 controls mapped
Compare →BS 65000:2014 - Guidance on Organizational Resilience
29%
15 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
29%
15 controls mapped
Compare →+ 630 more: ILO Nursing Personnel Convention C149 (1977) (27%), 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) - superseded by AMLD7 (27%)
See all 633 mapped frameworks ↓Maps to 633 other frameworks
Frequently Asked Questions
What is African Union Malabo Convention?
African Union Malabo Convention is a compliance framework from Africa (AU) with 22 domains and 51 controls. The African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014) is the first continental framework addressing cybersecurity and data protection in Africa. It establishes obligations for AU member states in electronic commerce, personal data protection, cybersecurity, and cybercrime. Entered into force June 2023 after achieving 15 ratifications. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does African Union Malabo Convention have?
African Union Malabo Convention has 51 controls organised across 22 domains. The largest domains are Cybercrime Offences (7 controls), Implementation and Final Provisions (6 controls), Personal Data Protection - General Principles (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does African Union Malabo Convention map to?
African Union Malabo Convention maps to 633 other compliance frameworks. The top mapping partners are EU AI Act (31% coverage), BS 65000:2014 - Guidance on Organizational Resilience (29% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with African Union Malabo Convention compliance?
Start your African Union Malabo Convention compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about African Union Malabo Convention requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 51 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required