Who Controls Africa’s Digital Public Infrastructure?

Africa is building the rails for its digital economy faster than it is securing the levers of control over them.

Executive Summary

Africa is building the infrastructure that will determine how its digital economy functions for decades to come. Digital public infrastructure (DPI), digital identity, real-time payments, and data-exchange systems, is being promoted as a foundation for public services, private innovation, and regional integration. Initiatives such as 50-in-5 and the Modular Open-Source Identity Platform (MOSIP) are accelerating this transition, with more than a dozen African states committed to interoperable DPI by 2028.

But there is a sovereignty problem hiding inside this success story. Africa is increasingly developing the rules for governing data while remaining dependent on infrastructure, software, cloud services, and technical standards that are often controlled from outside the continent. The result is a paradox: governments can assert legal authority over data they may not have meaningful technical or commercial control over.

This brief advances a simple proposition: data sovereignty cannot be secured after DPI has been deployed. It must be built into the architecture, procurement contracts, hosting arrangements, standards, and regional governance mechanisms from the beginning. The objective is not blanket localisation, but ensuring African governments retain meaningful control, visibility, portability, and bargaining power over the infrastructure on which essential public functions depend.

Building DPI before securing the levers of control

Digital public infrastructure is increasingly framed as the backbone of Africa’s digital economy. Foundational digital identity, real-time payments, and data-exchange layers can support a wide range of public and private services. Momentum is significant: as of late 2025, more than a dozen African countries, including Algeria, Ethiopia, Nigeria, Rwanda, Senegal, South Africa, Togo, and Zambia, had joined the global 50-in-5 campaign, which aims to help 50 countries deploy at least one DPI component safely and inclusively by 2028, with support from organisations including the Digital Public Goods Alliance, GovStack, and UNDP.

The strategic concern is not DPI itself. It is who controls the layers beneath it. DPI concentrates large volumes of sensitive personal and administrative information into interoperable systems, frequently built, hosted, or maintained by non-African vendors under commercial or geopolitical arrangements that governments may not fully control.

Case in point
The African Union headquarters in Addis Ababa, a building constructed and equipped with donated technology, had its data transferred nightly to servers in Shanghai for several years before the practice was discovered and stopped. This doesn’t prove every foreign technology partnership carries the same risk. It does demonstrate the importance of independent technical visibility and audit capacity, even at the continental level.

A second problem is institutional timing. Africa’s legal architecture for data governance is advancing, but not at the same pace as DPI deployment. The Malabo Convention took nine years to secure the fifteen ratifications required for entry into force in June 2023, and several major digital economies, including South Africa, have not ratified it. The AU Data Policy Framework provides an important conceptual bridge by distinguishing data sovereignty from blanket data localisation, recognising the legitimate right of states to set rules in line with domestic interests while cautioning against economically costly or protectionist localisation.

The AfCFTA Protocol on Digital Trade, adopted in February 2024, together with its annexes on cross-border data transfers and digital identities finalised in 2025, offers another important foundation, but the Protocol is not yet in force. This creates a sequencing problem: the continent is deploying interoperable digital infrastructure before the full continental legal architecture needed to govern it is operational.

Sovereignty is an infrastructure question

Data sovereignty is often discussed as a question of where data is stored. For DPI, that definition is too narrow. Sovereignty also concerns who controls the underlying cloud infrastructure, software, encryption and authentication layers, technical standards, maintenance arrangements, audit mechanisms, procurement contracts, and the ability to migrate away from a provider.

A system can satisfy a formal data-location requirement while leaving the state dependent on an external provider for the technology, skills, updates, security controls, or continued operation of the system. Physical location alone does not necessarily produce meaningful control, which is why the AU’s distinction between sovereignty and blanket localisation matters strategically. The goal is not to build digital walls around African data, but to ensure African institutions have sufficient technical, legal, and commercial leverage to govern critical digital infrastructure in the public interest.

Why regional economic communities matter

Continental frameworks provide the direction, but regional economic communities (RECs) may offer the most practical level at which sovereignty safeguards can be operationalised. Individual African states often lack the bargaining power to negotiate complex cloud, software, identity, and payments arrangements with global technology companies on equal terms.

RECs can aggregate demand, harmonise procurement requirements, establish common technical and security standards, coordinate regulatory oversight, and create shared infrastructure, functioning as building blocks between national systems and continental frameworks. This regional layer is particularly important for cross-border DPI: as digital identity, payments, and data exchange become interoperable across borders, sovereignty cannot be addressed solely through national law. The governance question becomes regional: which jurisdiction applies, who can access the data, where infrastructure is hosted, who audits it, and what happens when a provider or state seeks to change the terms of the arrangement.

Why this matters

  • Strategic dependency: national identity, payment, and welfare-delivery systems built on foreign-controlled cloud and software stacks can create leverage over core government functions, from service delivery to national security.
  • Legal fragmentation: cross-border DPI interoperability can develop ahead of the legal safeguards needed to govern data sharing, access, accountability, and redress.
  • Unequal bargaining power: governments negotiating separately with major technology vendors have less leverage than they would through coordinated African or regional procurement.
  • Path dependency: once a DPI system is deeply integrated into government services, changing the underlying provider, software, or infrastructure can become technically expensive and politically difficult. Early procurement choices can become long-term sovereignty choices.
  • A narrowing window: with 50-in-5 and similar initiatives accelerating deployment, the technical and contractual architecture of Africa’s DPI generation is being established now. The longer sovereignty safeguards are postponed, the harder they will be to retrofit.

Policy recommendations

The objective should be sovereignty by design: not exclusion from global technology markets, but the preservation of meaningful African control within them.

Make sovereignty-by-design a procurement requirement

Every DPI project receiving African Union, REC, or donor co-funding should document its data-hosting model, provider dependencies, exit and migration strategy, data portability arrangements, open-source position, and cross-border data flows before funding is disbursed.

Turn RECs into collective bargaining platforms

RECs should develop model DPI procurement clauses covering data access, audit rights, security, subcontracting, data portability, technology transfer, provider lock-in, and exit, giving governments leverage without requiring blanket exclusion of foreign providers.

Build shared African sovereign-cloud capacity

The AU and RECs should pool investment, including through AfCFTA-linked financing, to expand regionally owned data-centre and cloud capacity, providing credible alternatives rather than replacing global cloud providers entirely.

Accelerate binding continental rules

Member States that have signed but not ratified the Malabo Convention and the AfCFTA Digital Trade Protocol should set clear ratification targets, supported by AU technical assistance to address domestic legal alignment.

Make independent technical audit a condition of trust

National data protection authorities and technical regulators should have the resources and authority to independently audit DPI systems, examining legal compliance, technical dependencies, data flows, privileged access, subcontractors, and migration feasibility.

Treat open standards and interoperability as sovereignty tools

Open-source software and open technical standards should be prioritised where viable, not primarily to cut licensing costs, but to preserve the ability to inspect, modify, integrate, and migrate critical systems over time.

Build the infrastructure, keep the leverage

Africa’s digital transition presents a sovereignty choice that is easy to miss. The continent can pass increasingly sophisticated data and digital laws while simultaneously embedding external dependencies into the infrastructure those laws are supposed to govern. That is not an argument against DPI, cloud computing, foreign investment, or international technology partnerships; it is an argument for negotiating them differently.

The next generation of African DPI should be judged not only by whether it is interoperable, scalable, affordable, and secure, but by whether African institutions can understand it, audit it, govern it, and ultimately change it without losing control of essential public services.

The central question is therefore not simply where Africa’s data sits. It is whether Africa retains enough control over the systems that make that data useful, valuable, and governable. The decisions made during the current DPI build-out will determine the answer for years to come.

References
  1. African Union. (2022). AU Data Policy Framework.
  2. African Union Commission. AfCFTA Legal Texts and Policy Documents; Status of AfCFTA Ratification (tralac Trade Law Centre).
  3. Carnegie Endowment for International Peace. (2025). Digital Public Infrastructure: A Practical Approach for Africa.
  4. Development Gateway. (2024). Five Insights on Country-Led Digital Public Infrastructure Systems Across Africa.
  5. Diplo Foundation. What is the Malabo Convention?
  6. LSE Africa Blog. (2026). Africa Should Invest in Digital Public Infrastructure to Aid Regional Integration.
  7. UNDP / 50-in-5 Campaign. (2023–2025). Country commitments and milestone updates (50in5.net).
  8. EJIL:Talk! (2023). The African Union’s Malabo Convention on Cyber Security and Personal Data Protection Enters Into Force.
Data Governance Africa  ·  Policy Brief

Leave a Reply

Your email address will not be published. Required fields are marked *