Tesi etd-08172026-141102 |
Link copiato negli appunti
Tipo di tesi
Tesi di laurea magistrale
Autore
MATINOU, SAMUEL FRANK
URN
etd-08172026-141102
Titolo
Sovereignty Without Servers: Digital Markets and the AfCFTA
Dipartimento
GIURISPRUDENZA
Corso di studi
DIRITTO DELL'INNOVAZIONE PER L'IMPRESA E LE ISTITUZIONI
Relatori
.
relatore Prof. Favaro, Tamara
Parole chiave
- AfCFTA Digital Trade Protocol
- Cloud procurement
- Cross-border data transfers
- Data localisation
- Digital sovereignty
- Sovereign contract
Data inizio appello
14/09/2026
Consultabilità
Completa
Riassunto (Inglese)
African public services, financial systems and cross-border payment networks run on infrastructure owned by a small number of foreign corporations. African states have answered that concentration with data localisation laws requiring sensitive data to be held on servers within their territory. Those laws are largely unenforceable: the infrastructure does not exist at the necessary scale and cannot be built at hyperscale within any plausible legislative timeframe. A gap has opened between where African law assumes control lies and where digital infrastructure is actually governed.
This thesis argues that the gap can be closed by contract instead of by territory and advances the sovereign contract as the instrument that does so. It denotes a procurement agreement, bilateral memorandum or regional framework under which a foreign vendor accepts the regulatory jurisdiction of the procuring state over the data it hosts, through enforceable residency commitments backed by audit rights, customer-managed encryption keys, host-state governing law, and warranties against compliance with third-country demands. Where those terms hold, foreign infrastructure functions as a national or regional public asset whatever the location of its servers.
The method is doctrinal and comparative. It reads the AfCFTA Digital Trade Protocol and its Annex on Cross-Border Data Transfers against four national frameworks and reads each framework against the contractual and policy instruments that implement it: Kenya, whose Cloud Policy and its June 2026 Implementation Guidelines set out a state-issued contract drafting checklist for government cloud agreements; Ghana and Rwanda, whose 2025 central bank memorandum on fintech licence passporting is analysed from the announced framework because the instrument is unpublished; South Africa, whose adequacy model under the Protection of Personal Information Act makes regulatory equivalence rather than physical presence the operative condition; and Nigeria, which has the statutory competence but has not built the instrument, and so marks the distance between legal authority and contractual practice. A decolonial reading, drawn from Mbembe, Tamale and Fanon, is used to test whether the model redistributes control or merely reorganises dependence.
Four constraints qualify the argument: bargaining asymmetry, limited enforcement capacity, the risk that contractual accommodation entrenches dependence, and the small number of states able to negotiate competently. The second is the most serious, since a protection no institution can exercise is indistinguishable from none. Kenya illustrates the difficulty precisely: its Guidelines mandate that no foreign access occur without due legal process, but they never say whose process, leaving the extraterritorial disclosure problem reached and unresolved.
The proposal is that the AfCFTA adopt a continental model sovereign contract: a standard set of embassy clauses, named by analogy with the data embassy, under which data hosted abroad remains subject to the jurisdiction of the state whose data it is. Available to any State Party and required of any vendor seeking access to African government procurement, it would supply what the Protocol and its Annex lack, which is not authority but an operational layer of templates, an intra-African adequacy mechanism, and a disclosure regime.
This thesis argues that the gap can be closed by contract instead of by territory and advances the sovereign contract as the instrument that does so. It denotes a procurement agreement, bilateral memorandum or regional framework under which a foreign vendor accepts the regulatory jurisdiction of the procuring state over the data it hosts, through enforceable residency commitments backed by audit rights, customer-managed encryption keys, host-state governing law, and warranties against compliance with third-country demands. Where those terms hold, foreign infrastructure functions as a national or regional public asset whatever the location of its servers.
The method is doctrinal and comparative. It reads the AfCFTA Digital Trade Protocol and its Annex on Cross-Border Data Transfers against four national frameworks and reads each framework against the contractual and policy instruments that implement it: Kenya, whose Cloud Policy and its June 2026 Implementation Guidelines set out a state-issued contract drafting checklist for government cloud agreements; Ghana and Rwanda, whose 2025 central bank memorandum on fintech licence passporting is analysed from the announced framework because the instrument is unpublished; South Africa, whose adequacy model under the Protection of Personal Information Act makes regulatory equivalence rather than physical presence the operative condition; and Nigeria, which has the statutory competence but has not built the instrument, and so marks the distance between legal authority and contractual practice. A decolonial reading, drawn from Mbembe, Tamale and Fanon, is used to test whether the model redistributes control or merely reorganises dependence.
Four constraints qualify the argument: bargaining asymmetry, limited enforcement capacity, the risk that contractual accommodation entrenches dependence, and the small number of states able to negotiate competently. The second is the most serious, since a protection no institution can exercise is indistinguishable from none. Kenya illustrates the difficulty precisely: its Guidelines mandate that no foreign access occur without due legal process, but they never say whose process, leaving the extraterritorial disclosure problem reached and unresolved.
The proposal is that the AfCFTA adopt a continental model sovereign contract: a standard set of embassy clauses, named by analogy with the data embassy, under which data hosted abroad remains subject to the jurisdiction of the state whose data it is. Available to any State Party and required of any vendor seeking access to African government procurement, it would supply what the Protocol and its Annex lack, which is not authority but an operational layer of templates, an intra-African adequacy mechanism, and a disclosure regime.
Riassunto (Italiano)
File
| Nome file | Dimensione |
|---|---|
| Sovereig....docx.pdf | 1.36 Mb |
Contatta l’autore |
|