29. At Continental level the convention aims to create a uniform system of data processing and determine a common set of rules to govern cross-border transfer of personal data to avoid divergent regulatory approaches between the AU Member States. 30. The collection, recording, processing, storage and transmission of personal data shall be undertaken lawfully, fairly and non-fraudulently and in all cases processing of personal data shall be done with respect to the Principle of transparency and confidentiality. To do so, each Member State shall develop a legal and institutional framework for the protection of personal data and establish the national protection authority as an independent administrative authority with the task of ensuring that any processing of personal data is conducted in accordance with the provisions of the Convention within AU Member States. 31. Any interconnection of personal data files should be subject to appropriate security measures to prevent such data from being altered or destroyed, or accessed by unauthorized third parties. National protection authorities shall ensure that ICTs do not constitute a threat to public freedoms and the private life of citizens by regulating the processing of data files, particularly files related to sensitive data and by establishing mechanisms for cooperation with the personal data protection (PDP) authorities of third countries and participating in international negotiations on PDP. 32. Most African Countries lack legislations on personal data protection (PDP), to ensure the online privacy and personal data protection as to allow African citizens to use ICTs and internet for their socio-economic development (Health, education, governance etc.) To address the data protection issue at continental level it is necessary to implement the AU convention and establish legal and institutional frameworks at national level to create trust online. 3.5 Capacity Building and Awareness: 33. To create an online climate of trust and enable an open sharing of knowledge, information and expertise between African citizens, it is a fundamental challenge for securing networks and information systems and promoting the culture of cybersecurity among all stakeholders, namely, governments, enterprises and the civil society which develop, own, manage, operationalize and use information systems and networks. 34. For protecting the critical infrastructure and to enable the country to respond to the growing number of cyber-threats especially in critical sectors, it is necessary to build national competencies for cybersecurity. Developing knowledgeable workforce is critical to reduce national cyber risks. Every employee in the government or business enterprises should have cybersecurity responsibilities to ensure that systems and networks are adequately protected. 35. While it is important to develop strong cybersecurity skills and awareness for professionals, Member States shall undertake leadership role in the development Page 6 of 10

Select target paragraph3