Support Centre



Law: Data Protection Act, 2023

Regulator: Data Protection Authority 

Summary: OneTrust DataGuidance confirmed with the Data Protection Authority (the Authority) that on March 23, 2023, the Data Protection Act, 2023 (the Act) was enacted as Somalia's main data protection legislation. The Act applies to the processing of personal data and provides principles governing such processing, including legal bases. In line with international norms, the Act also provides data subject rights including the right to access, correction, deletion, and object. Moreover, the Act establishes data controller obligations such as breach notification, the conducting of Data Protection Impact Assessments, vendor management, and restrictions on cross-border transfers.

With regard to enforcement, the Federal Government of Somalia established the Authority to supervise the protection of personal privacy and monitor compliance by organizations with the Act. Article 37 of the Act empowers the Authority to impose a penalty of up to $1 million or its equivalent in Somali currency. Moreover, the Federal Constitution 2012 (the Constitution) also contains provisions for data protection, including the basic personal liberties and limitations under Article 13 of the Constitution.