Policy Updates
Operationalizing Data Governance in Africa with the RICE Framework
By Veronica Shiroya
In the global discourse on data governance, Africa often occupies a paradoxical space. It is simultaneously a continent of immense digital opportunity and a landscape of significant regulatory fragmentation. As Chinasa Okolo astutely argues in her article, while 38 of the 55 African Union (AU) Member States have data protection laws on the books, the chasm between legislative intent and effective operationalization is vast. This gap is not merely a technicality, it is the very ground upon which data privacy violations flourish and the power asymmetries of the global digital economy are amplified.
Okolo’s work moves beyond diagnosis to propose a vital prescription, the RICE Data Governance Framework. RICE standing for Reformation, Integration, Cooperation and Enforcement, offers a structured, multi-level approach for African national governments (NGs), Regional Economic Communities (RECs) and the AU to transform data governance from a paper promise into a living, breathing reality.
This review will delve into the RICE framework, paying particular attention to its mechanisms for Cooperation and Enforcement. To illuminate its potential and challenges, we will juxtapose these elements with the mature, though not unblemished, systems of the European Union, specifically the cooperation procedures and penalty regimes orchestrated by the European Data Protection Board (EDPB).
Fragmentation of data regulation
Okolo’s research identifies a continent at a crossroads. The advent of AI, with its insatiable appetite for data, has exacerbated existing vulnerabilities. Companies are unilaterally amending Terms of Service to claim broad rights over user data for AI training, often in contexts where citizens have little recourse to opt-out or challenge these practices. The cited data privacy violations, from unauthorized data collection to non-compliance with breach notifications are not merely infractions, they are symptoms of a system-wide deficit in enforcement capacity and cross-border coherence.
Continental frameworks like the Malabo Convention exist but have failed to achieve critical mass adoption. The result is a patchwork of regulations that undermines both consumer rights and the potential for a unified African digital market.
The RICE framework
The RICE framework is conceived as a holistic response to this systemic failure.
Reformation: This is the foundational step, urging a proactive and continuous review of existing data laws. It’s not about starting from scratch but iteratively strengthening the foundation, using tools like SWOT analysis to ensure policies cover emerging issues like AI ethics, data worker protections and responsible data sharing.
Integration: Okolo rightly emphasizes that a law alone is inert. Integration involves bringing Civil Society Organizations and Academic Research Institutions into the fold to build data literacy, advocate for citizens and ensure that reformed policies are understood and accessible to the public they are designed to protect.
It is, however, the final two pillars, Cooperation and Enforcement, where the most direct and instructive comparisons with the EU model can be drawn.
Cooperation
Under RICE, Cooperation is envisioned as a top-down and bottom-up process. The AU is called upon to lead harmonization efforts, potentially through a new Data Governance Harmonization Body. The goal is to align standards across RECs and member states, creating a predictable and secure environment for data flows within the continent.
Comparison with the EU. The EU has already built this architecture. The European Data Protection Board (EDPB) is the institutional embodiment of cooperation. It binds the national data protection authorities (DPAs) of all member states into a single entity with the power to issue guidelines, binding decisions in cross-border cases and ensure the consistent application of the GDPR. The famed "one-stop-shop" mechanism, while complex, is a testament to this cooperative ideal.
The critical difference lies in maturity and legal hegemony. The EDPB operates within a supranational legal order where its decisions have direct effect. RICE’s proposed Harmonization Body, by contrast, would operate in a context of entrenched national sovereignty and varying regulatory capacity. Its success would depend not on legal supremacy, but on painstaking consensus-building and the political will of RECs, a more challenging, though perhaps more culturally attuned, path to harmony than the EU's model.
Enforcement
This is the sharp end of the stick. Okolo’s framework proposes the inauguration of a continental Data Protection Supervisory Authority (DPSA). This body would not replace national authorities but would "continually monitor" their activities, serve as an arbitrator for disputes and crucially, elevate regional enforcement capacity.
Comparison with the EU on Penalties. This is where the ambition of RICE becomes most apparent. The EU’s GDPR is renowned for its deterrent-level penalties: fines of up to €20 million or 4% of a company’s global annual turnover. These figures are not arbitrary; they are designed to make compliance a non-negotiable C-suite priority for even the largest multinationals. The EDPB plays a key role in ensuring these penalties are applied consistently across the single market.
The RICE framework, as outlined, implicitly recognizes that without a credible threat of significant sanctions, data governance remains a paper tiger. For a continental DPSA to be effective, it must be empowered to recommend or, ideally, levy penalties that are equally dissuasive within the African context. This would require a monumental shift, moving from the current environment of weak and inconsistent national penalties to a regime where a continental body can hold powerful corporate actors to account. The political and legal challenges to achieving this are profound, but the EU model demonstrates that it is the bedrock of credible enforcement.
Chinasa Okolo’s RICE framework is a critical policy manifesto which correctly identifies that Africa’s data sovereignty and the protection of its citizens’ digital rights hinge on moving beyond isolated national laws to a coordinated, enforceable continental strategy.