Aug 2026· East African Journal of Law and Ethics· 0 citations
TL;DR
The study concludes that the legal and institutional frameworks governing cross-border data transfers in Tanzania are not yet effective in regulating digital platforms and recommends legislative and regulatory reforms, institutional strengthening, and policy and practice.
Abstract
In the contemporary global economy, data has emerged as the “new oil,” serving as the primary fuel for digital innovation, e-commerce, and social connectivity. Digital platforms ranging from social media giants and cloud service providers to local fintech startups rely on the seamless movement of information across national borders to function efficiently. This is well known as cross-border data transfer, which allows for decentralised storage, global service delivery, and advanced data analytics. However, the borderless nature of the digital world presents a notable challenge to national sovereignty and the fundamental right to privacy, as personal information often moves from jurisdictions with high levels of protection to those with weak or non-existent protections. In Tanzania, the digital landscape has expanded rapidly, necessitating a robust legal response to protect citizens from data misuse. Through doctrinal research design complimented by benchmarks (best practices) from Kenya and the European Union, the study revealed that, the legal frameworks on cross-border data transfers in Tanzania is progressive on paper, but incomplete in practice, there is also institutional capacity and enforcement gaps, furthermore, Meta does not list Tanzania as having a local data center or a designated representative under the Personal Data Protection Act. The experience from Kenya shows that the Office of the Data Protection Commissioner has moved faster in operationalising the Data Protection Act. Furthermore, experience from the European Union establishes a clear hierarchy for transfers. The study concludes that the legal and institutional frameworks governing cross-border data transfers in Tanzania are not yet effective in regulating digital platforms. Hence, the study recommends legislative and regulatory reforms, institutional strengthening, and policy and practice.
The rapid expansion of the digital economy has transformed international trade by enabling the seamless movement of data across national borders. Cross-border data transfers have become essential for global commerce, cloud computing, financial services, e-commerce, digital platforms, artificial intelligence, and multinational business operations. However, the unrestricted flow of personal and commercial data has generated significant legal challenges concerning privacy protection, cybersecurity, national sovereignty, intellectual property, data localization, and regulatory compliance. Different jurisdictions have adopted varying legal approaches to governing international data transfers, creating complex compliance obligations for businesses operating across multiple legal systems. International legal instruments and regional regulations, including the General Data Protection Regulation (GDPR) of the European Union, the OECD Privacy Guidelines, the Asia-Pacific Economic Cooperation (APEC) Privacy Framework, and digital trade provisions under the World Trade Organization (WTO) and modern free trade agreements, seek to balance the free flow of data with the protection of individual rights and national security interests. This paper critically examines the legal issues surrounding cross-border data transfers and international digital trade by analyzing international regulatory frameworks, comparative legal approaches, and emerging challenges associated with artificial intelligence, cloud computing, digital taxation, and data governance. It further evaluates the effectiveness of existing legal mechanisms in promoting secure and lawful international data flows while proposing policy reforms aimed at harmonizing global data protection standards, strengthening international cooperation, facilitating digital trade, and safeguarding privacy and cybersecurity in the evolving digital economy.
Research Author· Global Journal of Computing...· 0 citations
Modern social and economic relations depend on data as the basis of global trade, digital services, and the operations of MNEs. However, the rapid expansion of cross-border data flows has intensified concerns regarding privacy, security, and regulatory oversight, particularly as data increasingly diffuses across multiple jurisdictions. Countries have in turn pursued divergent regulatory solutions, such as data localization policies and transfer limits, leading to a great deal of fragmentation in data governance globally. The paper will discuss differences in regulatory practices in major jurisdictions and discuss the implications of such differences on the operations of MNEs. Based on the institutional logics theory, it describes how divergent policy frameworks are created by existing national priorities, including privacy security, economic liberalization, and national security. The research uses a qualitative document review of policy documents, regulatory tools, and a subset of case-based evidence to determine essential trends and effects. The findings show that, fragmentation of regulations increases compliance costs, operational inefficiencies, and uncertainty of the law to MNEs. In reaction, some adaptive strategies are taken by the firms, such as localized data management and compliance systems, and policymakers are willing to have more international coordination. The paper adds to the body of writing on international business and data governance on the importance of additional interoperable regulatory frameworks that would facilitate the balance between data mobility and trust and protection.
Amos Omolo· International Journal of Law...· 0 citations
In the globalized financial sector, fintech companies routinely collect and transfer data across
international borders. However, these activities face significant legal challenges, particularly
regarding data privacy and security. A key issue is the fragmentation of regulatory frameworks
worldwide. For example, U.S. regulations—including the Patriot Act, Consumer Financial
Protection Act (CFPA), the Gramm-Leach-Bliley Act (GLBA), the Bank Secrecy Act (BSA) with
Anti-Money Laundering (AML) requirements, and the California Consumer Privacy Act
(CCPA)—contrast significantly with international standards like the European Union's
General Data Protection Regulation (GDPR). Additionally, operational challenges such as
cybersecurity risks, cross-jurisdictional licensing, compliance issues, and technological
incompatibilities further hinder data sharing. Specific U.S. regulations around data
localization and international data flows create unique obstacles for fintech firms. This paper
also explores how technological advancements, such as blockchain, are fueling the demand for
secure, efficient, and seamless cross-border data exchange in the fintech sector. To address
these issues, the paper proposes several solutions, including global regulatory harmonization,
the adoption of advanced technologies to bolster data protection, and the establishment of
robust compliance frameworks for AML and Know Your Customer (KYC) processes.
R. B. Akinloye· IIARD INTERNATIONAL JOURNAL...· 0 citations
Ghana’s Data Protection Act, 2012 (Act 843) establishes foundational principles governing
lawful and secure processing of personal data but provides limited guidance on cross-border
data transfers, a regulatory gap that has become increasingly consequential in the context of
the African Continental Free Trade Area (AfCFTA). As digital trade, artificial intelligence
(AI), and cross-border service delivery expand across Africa, uncertainty regarding
international data transfers threatens privacy protection, regulatory compliance, and
economic integration. This paper examines how Ghana can reform its data protection regime
to enable secure cross-border data flows while safeguarding constitutional privacy rights and
national interests. Using doctrinal and comparative legal analysis, the study draws on two
contrasting yet complementary models: the ECOWAS Supplementary Act on Personal Data
Protection (2010), which prioritises regional harmonisation and mutual recognition, and
China’s Personal Information Protection Law (PIPL, 2021), which adopts a sovereignty
oriented and risk-tiered approach to outbound data transfers. The paper argues that Ghana
should adopt a hybrid regulatory model incorporating presumptive adequacy for regional
partners, standard contractual safeguards for international data transfers, and tiered security
assessments for high-risk data exports. Such reforms would align Ghana’s data protection
framework with AfCFTA digital trade obligations while strengthening the protection of
personal data and promoting Africa’s digital economy. This paper thus contributes to Africandigital governance scholarship and advances a scalable framework for reconciling free data
flows with privacy, security, and sustainable digital development.
Joseph Kwaku Asamoah· JOURNAL OF BUSINESS AND AFRI...· 0 citations
The rapid expansion of digital technologies, cloud computing, artificial intelligence, social media, and cross-border data flows has transformed personal data into one of the most valuable resources in the global digital economy. While technological innovation has enhanced communication, commerce, governance, healthcare, and financial services, it has simultaneously increased concerns regarding privacy, surveillance, cybersecurity, identity theft, and unauthorized processing of personal information. Consequently, governments worldwide have introduced comprehensive legal frameworks to regulate the collection, processing, storage, transfer, and protection of personal data. This study presents a comparative analysis of data protection laws in India, the European Union (EU), and the United States (US), examining their legal foundations, regulatory principles, institutional mechanisms, enforcement structures, and challenges. The analysis focuses on India's Digital Personal Data Protection Act, 2023, the European Union's General Data Protection Regulation (GDPR), and the sector-specific privacy framework adopted in the United States. It evaluates key principles such as lawful processing, consent, transparency, accountability, data minimization, purpose limitation, data subject rights, cross-border data transfers, enforcement mechanisms, and penalties for non-compliance. The study further examines emerging challenges arising from artificial intelligence, big data analytics, cloud computing, cybersecurity threats, and international data governance. It concludes that while each jurisdiction reflects different constitutional traditions and regulatory priorities, strengthening international cooperation, harmonized privacy standards, robust institutional oversight, and technology-neutral legislation is essential for ensuring effective protection of personal data, promoting digital trust, and supporting sustainable digital transformation.
R. Author· Global Journal of Computing...· 0 citations
It is concluded that effective digital transformation in Sri Lanka necessitates a multi-pronged approach encompassing legal reform, strategic investment in ICT capacity, strengthened institutional cooperation, and the ethical deployment of emerging technologies such as artificial intelligence.
V. Papakaran· Sri Lanka Journal of Develop...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.