Africa and Europe: Cyber Governance Lessons
Summary
This policy brief examines the slow adoption of the AU Convention on Cyber Security and Personal Data Protection and suggests that the African Union adopt the 'norm entrepreneur' approach of the European Union. It highlights Mauritius as a regional success story and recommends the AU implement agile governance principles and create a continental cybersecurity agency similar to ENISA to better protect citizens and combat cybercrime.
Key insights
- The African Union's 2014 Convention on Cyber Security and Personal Data Protection has seen very low adoption rates. As of October 2019, only 14 of the 55 AU member states had signed the document, and only seven had ratified it, meaning it has not yet come into force as it requires a minimum of 15 ratifications.
- The EU is described as a 'norm entrepreneur' in cyberspace due to its ability to establish uniform policies across its single market, exemplified by the 2018 General Data Protection Regulation (GDPR), the 1995 Data Protection Directive, and the 2016 Directive on Network and Information Security.
- The EU's Cybersecurity Act aims to strengthen its governance by creating a permanent, well-funded cybersecurity agency through the reinforcement of the European Network and Information Security Agency (ENISA) and establishing a framework for cybersecurity certification for consumer devices and online services.
- Mauritius is presented as a continental best practice for cyber governance. It adopted comprehensive cybercrime legislation in 2003, implemented a national cybersecurity strategy between 2014 and 2019, and established specific laws including the Electronic Act (2000), the Computer Misuse and Cyber Crime Act (2003), and the Data Protection Act (2004).
- The Budapest Convention on Cyber Crime serves as a key international framework for national legislation and international cooperation. Seven AU members have signed and ratified it: Benin, Cabo Verde, Ghana, Mauritius, Morocco, Nigeria, and Senegal, while South Africa has signed but not ratified it.
- The author recommends that the AU adopt 'Agile Governance Principles' from the World Economic Forum to ensure legislation evolves with technology and encourages citizen engagement, and suggests creating a continental body similar to ENISA.
Cite the original document
- APA
- Turianskyi, Y. (2020). Africa and Europe: Cyber Governance Lessons. South African Institute of International Affairs. https://saiia.org.za/wp-content/uploads/2020/01/Policy-Insights-77-turianskyi.pdf
- Chicago
- Turianskyi, Yarik. Africa and Europe: Cyber Governance Lessons. South African Institute of International Affairs, 2020. https://saiia.org.za/wp-content/uploads/2020/01/Policy-Insights-77-turianskyi.pdf.
- Wikipedia
- {{cite report |last1=Turianskyi |first1=Yarik |title=Africa and Europe: Cyber Governance Lessons |publisher=South African Institute of International Affairs |date=January 2020 |url=https://saiia.org.za/wp-content/uploads/2020/01/Policy-Insights-77-turianskyi.pdf |access-date=17 August 2026 |via=Climate Insights Directory}}
- BibTeX
- @techreport{turianskyi2020africa, author = {Turianskyi, Yarik}, title = {{Africa and Europe: Cyber Governance Lessons}}, institution = {South African Institute of International Affairs}, year = {2020}, month = jan, url = {https://saiia.org.za/wp-content/uploads/2020/01/Policy-Insights-77-turianskyi.pdf}, urldate = {2026-08-17}, note = {Indexed by Climate Insights Directory} }
Full text
Collected · Record updated