A five-part series on why data privacy has become vital for a Sudan navigating both war and rapid digital transformation. This first piece maps the gap: a country pushed onto digital financial and AI platforms it neither owns nor regulates, with no privacy law to govern them, and a framework, already within reach, that Sudan has yet to enact or implement.
Author:
Rowa Taha is an IP and Technology lawyer, tech policy researcher and data rights activist. Rowa’s work focuses on how technological advancements affect human rights, human dignity, and society as a whole.
The now-familiar experience of mentioning a product in conversation, then encountering an advertisement for that same product within minutes, is frequently attributed to passive eavesdropping by mobile devices. That explanation is almost certainly wrong, but the underlying intuition is sound: it is the routine aggregation of behavioural data across platforms, absent any legal framework governing consent, use, or retention. The same absence of protection extends to a second, less visible channel: the personal data Sudanese citizens disclose to AI chat systems, a risk compounded in a country where internet penetration remains under 30 percent and most of the population is newly online, with little prior exposure to how such systems handle this information (DataReportal, Digital 2026: Sudan). Sudan currently has no legal framework governing either channel, a gap that has become acute as the wartime economy drives an unprecedented share of the population into digital financial systems it does not control, at precisely the moment artificial intelligence transforms the stakes of ungoverned personal data.
Four developments make this urgent rather than theoretical. First, the collapse of physical banking infrastructure has pushed citizens onto mobile platforms whose servers sit outside Sudanese jurisdiction, and the risk is not only external theft , it’s that this data is fed, often unknowingly, into the AI systems built on top of these platforms. Second, even when transactions themselves are encrypted the resulting financial data generates metadata: who transacts with whom, when, and from where, which constitutes a wartime security exposure well beyond ordinary commercial privacy concerns. Encryption protects content, not the pattern around it. Third, artificial intelligence compounds each risk: on privacy, by training on personal data without consent on security, by enabling network analysis at a speed no human analyst could replicate; and on intellectual property, by ingesting Sudanese journalism, photography, and research with no domestic legal recourse for the creators. Fourth, Africa is the youngest continent in the world, with a median age of 19.7 years, less than half of Europe’s 43.1 (World Population Clock), and a population that has adopted AI tools at a faster pace than almost anywhere else; growth in generative AI adoption across the world’s lowest-income countries has outpaced the highest-income countries by a factor of four (Microsoft AI Diffusion Report). With no privacy law in place, the data this generates, much of it from young people with limited digital literacy, is being collected with essentially no oversight. The empirical record is not in dispute on direction, though figures vary by source.
In Sudan, following the war, more than 600 of the country’s approximately 900 bank branches have reportedly been destroyed or rendered inoperative since 2023, although a more recent Central Bank figure puts the number closer to 100 of 833, a discrepancy likely attributable to differing reporting periods (Sudan Horizon; Sudan Horizon). What is uncontested is the scale of the shift: an estimated 13.4 million Sudanese, over 30 percent of the population, now access banking through mobile applications. Bankak, the Bank of Khartoum’s platform, reports seven million users and an 85 percent increase in activations since the war began, according to the bank’s own board chair (The New Humanitarian). In March 2026, the government extended USSD-based banking to citizens lacking smartphone or internet access (TechAfrica News). This is defensible policy achievement in its own right. It has also produced a structural vulnerability: this activity, and the metadata it generates regardless of encryption, transits infrastructure Sudan neither owns nor regulates, with no statutory requirement governing what is called Data localization or is often referred to as cross-border transfer.
Data Localization is the body of laws mandating that data generated within the borders of a country and about its citizens, particularly personal, financial, or sensitive information, must be stored and processed physically within that nation’s borders before being transferred internationally.This restricts the free flow of information across global networks.(OECD)
Sudan does not need to construct a regulatory philosophy from first principles, nor import wholesale a framework designed for another jurisdiction. Sudan is already a signatory to the African Union’s Convention on Cyber Security and Personal Data Protection, the Malabo Convention, adopted in 2014 and in force since 2023 as the only binding regional data protection instrument outside Europe (African Union, full treaty text). Article 13 sets out six governing principles: consent and legitimacy, lawfulness and fairness, purpose and relevance, accuracy, transparency, and confidentiality and security. Articles 16 through 19 establish data subject rights: information, access, objection, and rectification or erasure, the last narrower than the EU’s “right to be forgotten” but addressing the same concern (African Union, 2014, Arts. 13, 16–19). Article 11 obliges each State Party to establish an independent data protection authority, and Article 14(6) restricts cross-border transfers absent adequate protection abroad (African Union, 2014, Arts. 11, 14). The GDPR, Nigeria’s NDPA, and Kenya’s DPA illustrate implementation, not transplantation; each reflects Malabo-consistent principles adapted to distinct domestic institutions (Future of Privacy Forum; Taylor & Francis). Sudan’s task is domestication of a commitment already undertaken, not fresh adoption.
Domestic legal coverage remains fragmented and dated: a Computer Crime Act from 2007, replaced by a Cybercrime Act in 2018 and amended in 2020, a law repeatedly criticized for restricting press freedom and used to threaten journalists rather than to protect citizens’ data (ARTICLE 19; Committee to Protect Journalists), and a 2018 draft data protection bill that was never enacted. A November 2025 decree established a Sudanese Data and Artificial Intelligence Authority and a Sudanese Cybersecurity Authority, a meaningful step, though as of mid-2026 neither body has issued binding rules (Anurag Verma, AI Regulation Tracker). The institutional architecture exists; the enforceability does not. Given the constraints on legislative capacity during active conflict, a phased approach is the more realistic path: an initial tranche addressing data localization and genuine enforcement authority for the bodies created in 2025, followed by a second phase domesticating the Convention’s citizen-facing protections: consent, access, erasure, cross-border safeguards, and rules extending explicitly to AI systems, including the chat platforms increasingly used by ordinary citizens with little understanding of what is retained.
Sovereignty over data, and over the metadata that describes it even when content is protected, is not a peripheral concern to address once the conflict subsides. It is infrastructure on which financial inclusion, security, and the credibility of any future digital economy depend. Ultimately, the point isn’t haste for its own sake, but precision: the relevant authorities should move quickly, but the resulting legislation must be built specifically for Sudan’s own legal, institutional, and wartime circumstances, not a convenient transplant of the EU’s GDPR, nor an uncritical lift of the AU’s own Convention. Sudan’s legislative history offers a cautionary example: its existing cybercrime statutes, discussed above, were criticized for years as poorly adapted to domestic conditions and were repeatedly used against journalists and activists in ways their drafters did not prevent. A privacy law touches the life of every Sudanese citizen who owns a phone or holds a bank account. As a result, it deserves the highest standard of care this time.
- The views expressed in this article are those of the author and do not necessarily reflect the positions or policies of the Center.