CDP Sénégal: Rejet Demande Arma Care Pour Données Santé
Summary
- Senegal's CDP reviewed 195 dossiers from April to June, issuing 153 declaration receipts and 39 processing authorizations for diverse digital services.
- The CDP rejected the Arma Care website's authorization request due to unclear data subject categories, undefined retention periods, potential unauthorized third-party access, and lack of consent for international data transfers.
- Approved projects included Orange Money Mastercard, Innovatech's Sama Kopar AI platform, and the Emprise4 medical research project on HIV in children.
- The Commission received eight complaints concerning data breaches, identity theft, harassment, and other personal data violations, some leading to referrals to cybersecurity authorities.
- The rejection of Arma Care highlights the CDP's strict enforcement of data protection requirements, especially for sensitive health data and international transfers, even amidst digital innovation.
CDP's Regulatory Oversight and Emerging Digital Landscape
The CDP's refusal stemmed from several critical deficiencies identified in the proposed system, serving as a clear signal that digital innovation does not supersede stringent data protection requirements.
The Commission de protection des Données Personnelles (CDP) in Senegal has released its quarterly report, Avis trimestriel N°02-2026, covering activities from April to June, highlighting a significant increase in the diversity and complexity of personal data processing requests. During this period, the regulatory body reviewed a total of 195 dossiers across two plenary sessions, ultimately issuing 153 declaration receipts and 39 authorizations for data processing operations. This surge reflects the rapid evolution of digital services in the country, encompassing areas such as mobile applications, digital financial services, artificial intelligence, medical research, geolocation technologies, and video surveillance systems.
Among the notable approvals, the CDP granted authorization for several innovative digital financial services. These included Orange Money's offering of virtual and physical Mastercard prepaid bank cards, as well as a system developed by Mixx by Yas that uses SMS for predicting creditworthiness. Additionally, Innovatech's "Sama Kopar" platform, which leverages artificial intelligence to provide personalized financial analysis, received approval. These cases underscore the CDP's engagement with cutting-edge technologies that utilize personal data for profiling, analysis, and decision-making processes concerning individuals.
Rejection of Arma Care Highlights Data Protection Imperatives
Despite numerous approvals, a significant decision during the quarter involved the rejection of an authorization request for the Arma Care website, a project by Actuarial AI Consulting. This platform aimed to digitalize the management of medical care, claims, and billing. The CDP's refusal stemmed from several critical deficiencies identified in the proposed system, serving as a clear signal that digital innovation does not supersede stringent data protection requirements.
The regulatory body specifically cited the absence of a sufficiently clear identification of the categories of individuals whose data would be processed. Furthermore, the project failed to define an explicit data retention period, raising concerns about the indefinite storage of sensitive information. Another major issue was the potential for unauthorized third-party access to the data, compromising its security and confidentiality. Crucially, the CDP also noted the lack of a mechanism for obtaining prior consent before transferring data to a third country, a fundamental requirement for international data flows involving personal information. This rejection of the Arma Care application underscores the CDP's commitment to enforcing robust data protection standards, particularly for sensitive health data.
Protecting Sensitive Data and Addressing Complaints
The medical sector, in particular, has garnered significant attention from the CDP due to the highly sensitive nature of health-related information. During the reporting period, the Commission authorized projects like Emprise4, led by the CRCF, which focuses on HIV in children and adolescents. Such initiatives, while vital, necessitate enhanced safeguards for data collection, retention, access, and sharing to protect vulnerable individuals. The CDP also reviewed projects incorporating geolocation and video surveillance, including those that involved the cross-border transfer of data, indicating a broad scope of regulatory oversight.
Beyond authorization requests, the CDP actively addressed eight complaints filed during the quarter. These complaints covered a range of personal data infringements, including data breaches, identity theft, harassment, defamation, and unsolicited commercial prospecting. In cases where cybercrime was suspected, the CDP collaborated with law enforcement, transmitting relevant dossiers to the Special Cybersecurity Division (DSC) and informing the Public Prosecutor. The Commission also took direct action by engaging with digital platforms, such as Meta, concerning reports of fake accounts, demonstrating its proactive approach to safeguarding personal data in the evolving digital landscape.
Practical Implications
Lawyers and compliance officers in Senegal must ensure clients developing innovative digital services, especially those involving health data or international transfers, have robust data protection frameworks, clear consent mechanisms, and defined data retention policies to avoid CDP rejection, as exemplified by the Arma Care case.
Source
Source: Original reporting via SenePlus
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Wansom is AI and can make mistakes.
