29. At Continental level the convention aims to create a uniform system of data
processing and determine a common set of rules to govern cross-border transfer
of personal data to avoid divergent regulatory approaches between the AU
Member States.
30. The collection, recording, processing, storage and transmission of personal data
shall be undertaken lawfully, fairly and non-fraudulently and in all cases
processing of personal data shall be done with respect to the Principle of
transparency and confidentiality. To do so, each Member State shall develop a
legal and institutional framework for the protection of personal data and establish
the national protection authority as an independent administrative authority with
the task of ensuring that any processing of personal data is conducted in
accordance with the provisions of the Convention within AU Member States.
31. Any interconnection of personal data files should be subject to appropriate
security measures to prevent such data from being altered or destroyed, or
accessed by unauthorized third parties. National protection authorities shall
ensure that ICTs do not constitute a threat to public freedoms and the private life
of citizens by regulating the processing of data files, particularly files related to
sensitive data and by establishing mechanisms for cooperation with the personal
data protection (PDP) authorities of third countries and participating in
international negotiations on PDP.
32. Most African Countries lack legislations on personal data protection (PDP), to
ensure the online privacy and personal data protection as to allow African citizens
to use ICTs and internet for their socio-economic development (Health,
education, governance etc.)
To address the data protection issue at continental level it is necessary to
implement the AU convention and establish legal and institutional frameworks at
national level to create trust online.
3.5
Capacity Building and Awareness:
33. To create an online climate of trust and enable an open sharing of knowledge,
information and expertise between African citizens, it is a fundamental challenge
for securing networks and information systems and promoting the culture of
cybersecurity among all stakeholders, namely, governments, enterprises and the
civil society which develop, own, manage, operationalize and use information
systems and networks.
34. For protecting the critical infrastructure and to enable the country to respond to
the growing number of cyber-threats especially in critical sectors, it is necessary
to build national competencies for cybersecurity. Developing knowledgeable
workforce is critical to reduce national cyber risks. Every employee in the
government or business enterprises should have cybersecurity responsibilities to
ensure that systems and networks are adequately protected.
35. While it is important to develop strong cybersecurity skills and awareness for
professionals, Member States shall undertake leadership role in the development
Page 6 of 10