Somalia’s Data Protection Act Now Has Operating Regulations
Somalia’s Council of Ministers approved regulations under the Data Protection Act, Law No. 005/2023, on 5 January 2026. The development moves Somalia’s privacy regime from a statutory framework towards an operational regulatory system.
The Data Protection Act had already established the rights and institutional structure. Regulations matter because they turn high-level duties into procedures that organisations and the Data Protection Authority can actually use.
The government’s announcement says the regulations establish procedures governing the collection, storage, use and protection of personal data. It also states that they fully empower the Authority to perform its regulatory, supervisory and enforcement functions.
A law without procedures creates uncertainty
A statute can establish principles, rights and powers while leaving organisations uncertain about how to register, report, document or communicate with the regulator. That uncertainty often produces two bad outcomes.
Some organisations wait for perfect clarity and postpone compliance. Others import procedures from a foreign regime and assume that similar privacy principles must produce identical local requirements.
Implementing regulations reduce that gap. They give the Authority a procedural basis for supervision and give controllers and processors a more concrete route for demonstrating that their processing is lawful, secure and accountable.
Registration makes the data map visible
Somalia’s Data Protection Authority identifies registration and licensing of controllers, processors and data-protection officers as a core regulatory function. Registration changes privacy from an internal policy matter into a formal relationship with the regulator.
An organisation needs to know which entity decides the purpose and means of processing, which suppliers act as processors, what data is involved and whether information is stored or accessed outside Somalia. If that information cannot be assembled for a registration process, the organisation probably does not yet control its data estate.
Breach reporting must be designed before the incident
The Authority’s compliance information identifies a 72-hour breach-notification period. Meeting that deadline requires more than a contact address. The organisation must be able to recognise that personal data is involved, identify the responsible controller, obtain facts from processors and decide whether the event creates risk for individuals.
Contracts are therefore part of incident response. A processor that waits several days to escalate an event can consume most of the controller’s reporting window before the legal and security teams are even aware of the problem.
Cross-border architecture needs attention
Cloud platforms, remote support, centralised identity, analytics and backups can make Somali personal data available outside the country. The Authority’s official forms specifically ask about overseas transfers and storage, making the physical and logical path of data an operational compliance issue.
An application inventory that lists only the primary supplier is unlikely to be sufficient. Organisations should include hosting regions, subprocessors, recovery environments, administrative access and the tools used for security monitoring.
What organisations should do now
- Determine which entities act as controllers, processors and joint controllers under the Act.
- Inventory processing purposes, personal-data categories, recipients, retention and security controls.
- Review registration and data-protection officer requirements against the official procedures.
- Test the 72-hour breach-notification workflow and processor escalation clauses.
- Map overseas storage, access and transfers, including subprocessors and disaster recovery.
- Keep records that can support complaints, inspections and requests from individuals.
The regulatory phase has started
The approval of regulations does not mean every compliance question is permanently settled. Guidance, enforcement practice and sector-specific requirements will continue to develop.
It does mean that organisations should stop treating Somalia’s Data Protection Act as a framework waiting to become operational. The procedures and regulator now need to be built into real governance, architecture and incident response.
Official sources
- Somalia Data Protection Authority: Council of Ministers approval announcement
- Somalia Data Protection Authority: laws, regulations and compliance resources
- Somalia Data Protection Authority: mandate and regulatory services
This article provides general information and is not legal advice.
Continue the series: Africa Cyber & Digital Law Series index


