By CIPESA Writer |

As digital platforms become central to how Africans communicate, access information, conduct business, and participate in public life, the question of who holds these companies accountable has become increasingly urgent.

Technology companies exercise considerable influence over personal data, online visibility, advertising markets, content moderation, and, increasingly, artificial intelligence systems. Yet CIPESA’s work on platform governance shows that having laws and regulations does not always translate into effective oversight of multinational technology companies.

These concerns were at the centre of the Big Tech Accountability Summit on July 30, 2026, where CIPESA’s Policy and Advocacy Officer, Patricia Ainembabazi, spoke on the panel “How Civil Society and Public Interest Litigation Drive Big Tech Data Protection Accountability in Africa.”

The discussions focused on the role civil society can play in triggering enforcement, the barriers to holding multinational companies accountable across borders, and the institutional reforms and policies needed to strengthen accountability. A key point from the discussion was that adopting data protection laws and establishing regulators does not automatically guarantee enforcement.

Across Africa, many regulators operate with limited financial resources, insufficient specialised personnel, fragmented mandates, and varying levels of institutional independence. They are nevertheless expected to oversee companies with substantial financial, technical, and legal capacity. Much of the evidence required to establish violations, including information about algorithms, data flows, and internal risk assessments, also remains under the control of the companies themselves.

This imbalance means that civil society can play an important role. As Patricia Ainembabazi noted, civil society organisations document harms, aggregate the experiences of affected users, undertake legal and technical research, file regulatory complaints, support strategic litigation, and sustain public scrutiny.

Similar concerns regarding tech accountability had been raised earlier on July 7, 2026, during the Humanising Big Tech Accountability webinar, where panelists argued that holding platforms accountable requires concerted efforts and a multistakeholder approach, including through storytelling and narrative building.

Uganda’s data protection case against Google LLC illustrates the importance of citizen-led accountability. The complaint was brought by four Ugandan data subjects, while CIPESA subsequently documented and amplified its wider significance. CIPESA highlighted how the case transformed an abstract privacy right into a concrete enforcement action against one of the world’s largest technology companies. The case also demonstrated the importance of testing the application of national data protection obligations to multinational companies operating across borders.

From western Africa, Nigeria offers another important example. A joint investigation by the Federal Competition and Consumer Protection Commission and the Nigeria Data Protection Commission resulted in a USD 220 million penalty against Meta and WhatsApp, which was subsequently upheld by the Competition and Consumer Protection Tribunal. The case demonstrates that African regulators can build credible enforcement actions against multinational platforms. It also raises the broader question of whether such penalties ultimately lead to lasting compliance and changes in corporate behaviour.

CIPESA’s recent analysis, Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa further show that countries are experimenting with different approaches to regulating platform power. South Africa’s Media and Digital Platforms Market Inquiry examined the influence of dominant platforms on local journalism and secured commitments from several major companies. Uganda’s prolonged restriction on Facebook presents a contrasting experience, where the social and economic costs were borne by users and businesses without clearly producing greater accountability from the platform.

These examples show that the ability of individual African countries to influence global technology companies depends not only on having laws but also on regulatory capacity, market size, and political leverage.

The challenge extends beyond data protection. CIPESA has documented how weaknesses in platform governance affect freedom of expression, access to information, civic participation, and gender equality. Inadequate local language content moderation, technology-facilitated gender-based violence (TFGBV), and rapidly spreading disinformation demonstrate how failures in platform accountability translate directly into harms for African users. Effective platform governance, therefore, needs to address not only content moderation but also pay attention to data governance, competition, algorithmic transparency, market concentration, and access to effective remedies.

For civil society and regulators, one of the major challenges is regulatory fragmentation. A technology company may collect data in one country, process or store it in another, and make key decisions elsewhere. Different national laws, procedures, and institutional capacities can allow companies to challenge jurisdiction or respond selectively across markets. Regulators and civil society organisations may also lack the resources to undertake sophisticated technical audits or sustain lengthy litigation.

As such, CIPESA has called for a shift beyond isolated national enforcement towards the domestication of the African Union-backed cross-border enforcement mechanism, bringing together data protection, competition, consumer protection, and communications regulators.

While regional approaches begin to emerge, the COMESA Competition Commission’s investigation into Meta across its member states illustrates the potential for collective oversight of platform power. CIPESA’s research similarly argues that no African country can effectively address systemic platform power in isolation and calls for stronger institutions, deeper regulatory cooperation, rights-respecting regulation, and greater transparency from technology companies.

Ultimately, civil society must be integral to this accountability architecture, not merely consulted after decisions have been taken, but as a source of complaints, research, community evidence, and independent oversight. Stronger Big Tech accountability in Africa will also depend on regulators that have the resources and independence to act, accessible remedies for affected users, coordinated regional enforcement, and sustained public interest advocacy.

During the Humanising Tech Accountability webinar, CIPESA emphasised the need for civil society actors to proactively engage in research and advocacy that centers and amplifies the impact of unchecked big tech companies’ practices on people’s lives. It is only when people understand the impact of practices and manifestations such as TFGBV or the spread of disinformation on their fundamental human rights, such as freedom of expression, access to information, civic participation, and gender equality, that they will aggressively demand platform reforms and accountability.

Through our research, policy engagement, and advocacy on data governance, privacy, platform governance, and digital rights, CIPESA continues to contribute to building an African digital ecosystem in which technological power is matched by meaningful accountability.