Stakeholders urge ratification of Malabo Convention for effective digital governance in Kenya
Audio By Vocalize
While legislation such as the Computer Misuse and Cybercrimes Act has been put in place to address expanding risks on digital platforms, stakeholders still argue that the Malabo Convention is essential to fully address the challenges of cross-border digital governance.
Malabo Convention is an African Union (AU) treaty that creates a unified legal framework for cybersecurity, electronic transactions, and personal data protection across Africa.
The treaty was adopted on June 27, 2014, during the 23rd Ordinary Session held in Malabo, the capital city of Equatorial Guinea.
More than 10 years after its adoption, Kenya is yet to formally join the continental agreement.
Despite approval by Cabinet in 2025, the agreement is yet to be ratified as it awaits approval by the National Assembly.
In a policy brief commissioned by Mzalendo Trust and Oxfam Kenya, stakeholders now argue that the Malabo Convention would be a strategic approach for the country to bridge gaps in cybersecurity, personal data protection, and electronic transactions.
The experts noted that a prominent belief that Kenya's existing laws are more modern or robust than the Malabo Convention has further delayed its adoption.
However, they observed the need to reframe Malabo as the 'missing link' due to gaps such as the absence of Artificial Intelligence (AI) regulation, lack of cross-border enforcement mechanisms, and the absence of rights safeguards.
“Ratification also grants Kenya a seat at the table to propose Convention amendments addressing these weaknesses,” the brief by stakeholders from Kenya’s technology sector states.
The stakeholders therefore urge Kenya’s Cabinet to approve ratification of the Malabo Convention promptly, and most importantly, include an interpretative declaration affirming Kenya's sovereignty over national-security data
“Parliament should prioritise debates in the Information and Communication Technology (ICT) Committee and ensure the process complies with Article 118 of the Constitution on public participation,” the stakeholders recommend.
Due to funding gaps in Kenya’s data governance, the stakeholders also recommend an amendment to the Data Protection Regulations to permit the Office of the Data Protection Commissioner (ODPC) to retain a defined percentage of administrative fines and controller registration fees.
This, they said, would reduce ODPC’s dependence on treasury funding and enhance its enforcement capacity.

Join the Discussion
Share your perspective with the Citizen Digital community.
No comments yet
This discussion is waiting for your voice. Be the first to share your thoughts!