Four markets. Four regulators. One control set.
You should not have to run a separate compliance programme for every country you operate in. We map your national obligations onto a single ISO 27001 control base, so you collect the evidence once and file it everywhere it is needed.
Two regimes. Most plan for only one.
Personal data: Loi 09-08 and the CNDP
If you process personal data in Morocco, you have obligations to the Commission Nationale de contrôle de la protection des Données à caractère Personnel: declaration or authorisation depending on what you process, a lawful basis for the processing, data subject rights you must be able to honour on request, and prior authorisation for transferring personal data outside the country.
The cross-border transfer authorisation. Cloud adoption moves data outside Morocco by default, often before anyone has asked whether the transfer is authorised. If your CRM, your HR system, or your backups sit outside the country, this applies to you.
- 01Map your processing activities and prepare the CNDP filings.
- 02Assess cross-border transfers and put the authorisation and the safeguards in place.
- 03Build data subject request handling that works within the required timeframes.
- 04Run the same mapping against GDPR where you also serve European customers, so one exercise satisfies both.
Cybersecurity: Loi 05-20 and the DGSSI
Loi 05-20 sets national cybersecurity obligations, overseen by the Direction Générale de la Sécurité des Systèmes d'Information. If you are a public body, or an operator of vital importance, the obligations are substantial: appointing a security officer, protecting sensitive systems to the national standard, notifying incidents, submitting to audit, and obtaining homologation for systems in scope.
Discovering they are in scope. Designation reaches further than most private companies expect, and it reaches suppliers to designated operators as well. If your client is designated, their obligations become your contract terms.
- 01Determine whether you are in scope, and prepare you for it if you are.
- 02Homologation readiness preparation for systems within scope.
- 03Align your controls with the national directive and with ISO 27001 in one exercise.
- 04Build the incident notification process before you need it.
Financial institutions carry additional cybersecurity and IT risk requirements from Bank Al-Maghrib. Trust and electronic signature services fall under Loi 43-20. We handle these alongside the general regime rather than as a separate programme. Morocco's Digital 2030 strategy is raising the security expectations attached to public bids — documentation that's better started before the tender than during it.
One law, one commission, real teeth for financial institutions.
The Nigeria Data Protection Act and the Nigeria Data Protection Commission set the framework. Organisations processing personal data at scale carry registration obligations, must appoint a data protection officer, and must complete and file periodic compliance audits. Financial institutions and payment service providers carry additional obligations under the Central Bank of Nigeria's risk-based cybersecurity framework, including board-level reporting and independent assessment.
- 01Registration with the Nigeria Data Protection Commission.
- 02Data protection officer support.
- 03Audit preparation and filing.
- 04Data protection impact assessments.
- 05Alignment of the Nigerian requirements to the same ISO 27001 control base you use elsewhere.
A data law with licensing, permits, and real deadlines.
Personal Data Protection Law No. 151 of 2020 governs processing, with licensing and permit requirements, data protection officer obligations, and controls on cross-border transfer. The Anti-Cyber and Information Technology Crimes Law carries obligations around data retention and cooperation. Financial institutions answer additionally to the Central Bank of Egypt's cybersecurity framework.
- 01Gap assessment against Law 151.
- 02Permit and licensing support.
- 03Data protection officer function.
- 04Cross-border transfer assessment.
- 05Incident readiness aligned to national requirements.
Declared, authorised, and aligned to what you already run.
Loi 2013-450 governs personal data protection, administered by the Autorité de Régulation des Télécommunications de Côte d'Ivoire, with a declaration and authorisation regime and cross-border transfer controls. Loi 2013-451 addresses cybercrime and creates obligations around incident cooperation.
- 01ARTCI declarations and authorisations.
- 02Processing mapping.
- 03Transfer assessment.
- 04Alignment to the regional and international frameworks you already run.
Where it all lines up.
The African Union's Convention on Cyber Security and Personal Data Protection is in force and is progressively shaping national legislation across the continent. Where you already meet the stricter of your national obligations and GDPR, most of that work carries across.
One exercise, five steps.
Keep your compliance work in one place, not four.
Same named consultant, same control-mapping approach described above — scoped to the markets you operate in.