This research examines the development, structure, and enforcement of data protection laws across ten East African countries: Kenya, Tanzania, Uganda, Rwanda, Ethiopia, Djibouti, Burundi, Somalia, South Sudan, and Eritrea. The paper evaluates how states regulate personal data in response to digitalization, public sector reform, and cross-border data flows. It adopts a doctrinal and comparative legal approach to analyze statutes, subsidiary legislation, constitutional provisions, regulatory mandates, and enforcement mechanisms. The research finds strong convergence around global data protection principles in countries with comprehensive legislation but deep divergence in institutional design and enforcement capacity. We argue that regulatory effectiveness depends less on legislative adoption and more on the independence of the supervisory authority and administrative capacity. The paper concludes that East African countries follow similar data protection alignments but enforce them in very different ways. Research Scope and Methodology This research examines civil and commercial personal data processing frameworks across ten jurisdictions in East Africa. The research uses a legal analysis approach by looking at and discussing the main laws, additional regulations, privacy rules in the constitution, and specific confidentiality rules for different sectors. It also examines the legal authority, powers, and independence of supervisory authorities, as well as how data subjects can enforce their rights, the penalties they may face, and the remedies they may seek. The research relies on statutes, regulatory publications, academic journals, and authoritative policy literature and evaluates the law as in force at the time of writing and publication.
Ijuo et al. (Mon,) studied this question.