What the document is
A privacy policy is a public statement of what personal data your business collects, how you use it, who you share it with, how long you keep it, and how a user can get their data, correct it, or ask you to delete it. It sits on your website, usually linked from the footer and from any signup or checkout flow, and it is the one legal document nearly every visitor to your site can actually find and read.
The name changes depending on which law you are sitting under. Under the EU's GDPR and under Nigeria's, Kenya's and South Africa's laws, which are all modelled closely on GDPR, you will see the terms "privacy policy," "privacy notice," and "data protection notice" used almost interchangeably, and none of the three data protection authorities in those countries insist on one label over another. Egypt's Personal Data Protection Law leans on the term "privacy notice" in its executive regulations, following the same convention. What matters is not the label but whether the content covers the required elements, so don't let a founder second-guess themselves over which word is on the page.
A real one, for a founder-stage company, is not a wall of boilerplate copied from a template site. It should say, in plain terms:
- What you collect. Name, email, phone number, payment details, device and usage data, location if you use it, and anything collected through cookies or analytics tools (PostHog, Google Analytics, Meta Pixel, whatever you actually run).
- Why you collect it. Account creation, payment processing, customer support, product analytics, marketing. Each purpose should map to something you actually do, not a generic "to improve our services."
- Who you share it with. Named categories at minimum: your payment processor (Paystack, Flutterwave, Stripe), your cloud host (AWS, GCP), your email tool (SendGrid, Mailgun), your analytics vendor. If you sell or share data with advertisers, say so explicitly.
- Where it's processed and stored. If your servers are outside the country your users are in, cross-border transfer is a specific clause under NDPR, POPIA, Kenya's DPA and Egypt's PDPL, not an afterthought.
- How long you keep it and how you dispose of it.
- User rights and how to exercise them. Access, correction, deletion, objection, and a real contact, an email address that gets a human response, not a contact form that vanishes.
- A named contact. Under NDPR and Kenya's DPA this is usually your Data Protection Officer or the person acting as one; under POPIA it's your Information Officer.
If your policy doesn't specify these things for your actual product, it isn't doing its job, no matter how long it is.
What an investor is actually checking for
By the time you're in a data room, nobody at the fund is reading your privacy policy to see if it exists. The checkbox already came back "yes" from an automated scan or an associate's five-minute pass. What actually happens next is a diligence lawyer, either in-house counsel at the fund or an external firm engaged for the round, opens the document and reads it against three things: your actual product, your actual data flows, and the law you claim to be operating under. Here is what fails.
Mismatch between the policy and the product. If your privacy policy says you don't sell or share data with third parties, but your product runs a Meta Pixel and a Google Ads conversion tag that ships user data to advertisers, that is a direct contradiction a lawyer finds in ten minutes with browser dev tools open next to your policy. This is the single most common failure mode, and it is worse than having no policy at all, because it converts a gap into a misrepresentation. A CFO at an acquirer runs the same check during an acquisition, because inheriting a company with a false public statement about data handling is inheriting regulatory exposure the day the deal closes.
Vague sharing language that can't be audited. "We may share your data with our partners and service providers" with no defined list is a red flag precisely because it cannot be checked against anything. A lawyer wants named categories, ideally named vendors, because that is what lets them map your actual third-party risk. A generic clause like this reads as either lazy drafting or an attempt to leave room to do something undisclosed later, and diligence counsel treats both the same way: as a flag that needs a follow-up question, which slows the process and burns goodwill during a round that's already time-pressured.
No lawful basis stated. NDPR, POPIA, Kenya's DPA and Egypt's PDPL all require you to state a lawful basis for processing, typically consent, contract necessity, or legitimate interest. A policy that skips this entirely tells a lawyer the document was templated from a jurisdiction that doesn't require it, usually a US-style CCPA template, which is itself evidence the founder hasn't localised their legal stack.
No retention period. "We keep your data as long as necessary" is not a retention period, it is the absence of one. Under these laws you're required to actually define it, even if the definition is tied to an event, like "for the duration of your account plus 90 days."
Cross-border transfer silence. If your infrastructure sits on AWS in a region outside your users' country, which is true for most African startups running on US or EU cloud regions, and your privacy policy says nothing about international transfers, that's a specific gap under all four regimes covered below, and it's one of the first things a lawyer checks because it's cheap to check and commonly missed.
No registration where one is required. Under Nigeria's NDPA and Kenya's DPA, companies that meet certain thresholds must register as a data controller or processor with the regulator. A diligence lawyer at Series A will ask whether you've registered, separately from asking whether you have a policy, because the two are different obligations and founders regularly do one without the other.
The pattern across all of these: an investor's lawyer is not grading your intentions, they're checking whether the document is an accurate, specific, checkable description of what your systems actually do. A short, accurate policy beats a long, generic one every time.
What it costs to get done properly, by African jurisdiction
Published flat fees for privacy policy drafting specifically are rare. Most African law firms price data protection compliance as a package (policy plus registration plus internal data mapping) and quote after a scoping call, so the ranges below are compiled from registration fee schedules, which are published, and from what compliance-package pricing signals about drafting cost as a component. Where we could not verify a specific drafting fee, we say so.
| Country | Primary law | Regulator | Registration fee (if applicable) | Typical drafting cost |
|---|---|---|---|---|
| Nigeria | Nigeria Data Protection Act (NDPA) 2023, successor to NDPR | Nigeria Data Protection Commission (NDPC) | Data Controller/Processor of Major Importance (DCPMI) registration fee is not fixed publicly; NDPC states it varies by fee schedule and should be confirmed on the registration portal at filing. Data Protection Compliance Organisation (DPCO) licence is reported at around ₦2,000,000, though this should be verified directly with NDPC. | Not publicly published as a standalone flat fee. Nigerian firms typically bundle policy drafting into an NDPA compliance package; expect this to be quoted after scoping, not off a rate card. |
| Kenya | Data Protection Act, 2019 | Office of the Data Protection Commissioner (ODPC) | Registration under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021: micro/small entities (1 to 50 staff, turnover up to KES 5 million) pay KES 4,000 to register and KES 2,000 to renew; medium entities pay KES 16,000 / KES 9,000; large entities pay KES 40,000 / KES 25,000. | Not published as a flat fee by firms surveyed; registration itself is cheap, so the cost driver for most startups is legal drafting time, not the government fee. |
| South Africa | Protection of Personal Information Act (POPIA) | Information Regulator | Registering an Information Officer is free and can be done online via the Regulator's e-services portal in under 30 minutes. | Not published as a standalone fee by the firms surveyed. Compliance-tracking software (not legal drafting) starts around R99/month as a reference point for the low end of the market. |
| Egypt | Personal Data Protection Law No. 151 of 2020 (PDPL), with executive regulations issued under it | Personal Data Protection Centre (PDPC) | Licensing is tiered by data volume under the executive regulations: entities holding records for up to 100,000 people are exempt from the licence fee; 101,000 to 200,000 records costs roughly EGP 200 (about $4); fees scale up from there, capping around EGP 2,000,000 (about $41,000) over three years for datasets above 5 million records. | Not published as a standalone drafting fee by the firms surveyed. |
| Ghana | Data Protection Act, 2012 (Act 843) | Data Protection Commission (DPC) | Registration is mandatory and renews every two years; the Commission ran a fee amnesty in 2020 letting defaulters pay only the current year, but a current standard fee schedule was not found published in the sources checked. Confirm directly with the DPC. | Not published as a standalone fee by the firms surveyed. |
Two honest caveats. First, government registration fees and legal drafting fees are two different line items, and most articles online conflate them; we've kept them separate above because that's the actual cost structure you'll face. Second, where we wrote "not published," that's a real gap in what's publicly available, not a shortcut on our part: African law firms overwhelmingly price data protection work as scoped engagements rather than posted rate cards, so the only way to get a real number is to ask two or three firms for a quote and compare.
Self-serve template generators (Termly, TermsFeed, iubenda, and similar tools) can produce a GDPR/CCPA-flavoured baseline policy quickly and cheaply, several offer free tiers. None of them are built around NDPA, POPIA, Kenya's DPA or Egypt's PDPL specifically, so treat their output as a first draft to hand to a local lawyer for localisation, not a finished document. The gap between "generated" and "correct for your jurisdiction" is exactly the gap a diligence lawyer is trained to find.
Where to get it
Government sources, read these first. The NDPC's guidance notice on registration and the NDPA compliance guide are published directly by Nigeria's regulator: NDPC Guidance Notice on Registration of Data Controllers and Data Processors and the NDPC website. Kenya's ODPC publishes sector-specific guidance notes that clarify what a compliant privacy notice needs to cover for your sector: ODPC Guidance Notes. South Africa's Information Regulator runs Information Officer registration directly and free: inforegulator.org.za and the registration portal guide. Ghana's Data Protection Commission: dataprotection.org.gh.
Firms publishing real African data protection guidance you can act on, not just marketing pages: Michalsons in South Africa maintains a detailed, regularly updated public guide on the Information Officer role under POPIA and PAIA at michalsons.com. TechHive Advisory covers Egypt's PDPL executive regulations in plain terms at techhiveadvisory.africa. TEMPLARS Law's Ghana compliance brief is a useful primer on the DPA 2012 obligations: TEMPLARS Ghana Data Protection Compliance PDF. DLA Piper's country-by-country Data Protection Laws of the World tool is the fastest way to cross-check registration status across all five countries in one place: dlapiperdataprotection.com.
Generators, for a first draft only. Termly's free privacy policy generator, TermsFeed's generator, and iubenda will all get you a structurally complete draft in minutes. Use one of these to move fast, then get a lawyer licensed in your operating jurisdiction to localise it against NDPA, POPIA, Kenya's DPA or Egypt's PDPL specifically. None of these tools claim African-law compliance out of the box, and you shouldn't claim it on their behalf either.
Do not adapt a Delaware SAFE or Series Seed template's privacy language, or any US-market open-source privacy policy template, without a local lawyer's review. The risk here isn't copyright, most of the widely circulated startup legal templates (Y Combinator's SAFE, the Series Seed documents) are published openly for that specific instrument, and using them for a privacy policy specifically is unusual since they aren't built for that purpose. The real risk is jurisdictional: a privacy policy built around CCPA or GDPR concepts will reference rights, timelines and lawful bases that don't map cleanly onto NDPA, POPIA, Kenya's DPA or Egypt's PDPL. It will look complete to you and to a first-time reader, and it will look exactly like what it is, an unadapted foreign template, to the diligence lawyer who opens it during your Series A or the CFO's counsel during an acquisition. That gap doesn't cost you anything at signing. It costs you at the exact moment you can least afford a delay: in the data room, with a term sheet on the table and a clock running.
Sources
- https://ndpc.gov.ng/wp-content/uploads/2025/07/Updated-Guidance-Notice-on-Registtration-2024.pdf
- https://ndpc.gov.ng/
- https://globaladvisoryexperts.com/ndpc-data-controller-registration/
- https://www.odpc.go.ke/
- https://koassociates.co.ke/insight/3-registration-of-data-controllers-and-processors-with-the-odpc/
- https://inforegulator.org.za/
- https://inforegulator.bizportal.gov.za/Registration/Guide.pdf
- https://www.clearcomply.co.za/blog/popia-information-officer-registration-south-africa
- https://dataprotection.org.gh/
- https://www.templars-law.com/app/uploads/2023/05/Data-Protection-Compliance-in-Ghana_final.pdf
- https://www.dlapiperdataprotection.com/index.html?t=registration&c=GH
- https://www.techhiveadvisory.africa/insights/review-of-egypts-executive-regulation-for-the-personal-data-protection-law
- https://www.michalsons.com/focus-areas/privacy-and-data-protection/information-officer-popi-paia
- https://www.dlapiperdataprotection.com/
- https://termly.io/products/privacy-policy-generator/
- https://www.termsfeed.com/privacy-policy-generator/
- https://www.iubenda.com/en/terms-and-conditions-generator/