Skip to content
TchadHub

National data governance strategy: what this changes for you

On 7 October 2026, the Ministry of Telecommunications, the Digital Economy and Digitalisation brought together in N’Djamena the administration, the private sector, universities, civil society, and technical and financial partners to examine the draft national data governance strategy, with a view to its adoption. This will be the very first of its kind in Chad. Its ambition: to move from fragmented data management to an organised, secure and interoperable national system that strengthens the country's digital sovereignty.

What does this strategy contain, what does the law already say, and what can you do right now? Here is the essential information, followed by practical advice according to your level: beginner, intermediate or advanced.

The essentials

  • The draft strategy was examined during a technical validation workshop on 7 October 2026; it is subsequently due to be adopted.

  • It is based on seven pillars, including security and personal data protection, with a roadmap extending to 2030 and beyond.

  • Law No. 007/PR/2015 already protects your personal data: individuals and organisations alike have rights and obligations as of today.

What the strategy outlines

Work began in May 2026, during a workshop organised with technical support from the United Nations Economic Commission for Africa (ECA). The draft examined on 7 October is structured around seven pillars:

  1. institutional governance;

  2. the legal and regulatory framework;

  3. data management, data quality and interoperability;

  4. infrastructure;

  5. data sharing and accessibility;

  6. data security and personal data protection;

  7. skills, data culture, the data economy and innovation.

Several sectors are considered priorities for its implementation: the single digital window, health, education, mining and oil, agriculture, livestock farming and fishing, as well as telecommunications and digital services. The African Union Commission, AUDA-NEPAD and the ECA are supporting the process. For Mactar Seck, of the ECA, data governance “is not merely a technical issue, but also represents a societal project”.

A few days earlier, on 30 September and 1 October, a meeting organised in N’Djamena by Paradigm Initiative and ACSIS-Chad brought together institutions and civil society around personal data protection and cybersecurity. The shared observation: the legislation exists; the challenge is enforcing it. The recommendations arising from these discussions are set to inform work on the future Digital Code.

What is data governance?

Governing data means deciding who collects it, who can access it, how it is protected, how long it is kept and how it is shared. For the State, the stake is very tangible: avoiding asking a citizen for the same document ten times, having reliable statistics to plan schools and health centres, and protecting sensitive information.

For a business, an NGO or a public authority, the logic is the same on its own scale: knowing what data it holds, where it is located, who is responsible for it and how it is protected.

What the law already says

The strategy does not start from scratch. Law No. 007/PR/2015 of 10 February 2015 governs the protection of personal data in Chad, under the supervision of ANSICE, the National Agency for Computer Security and Electronic Certification. In particular, it recognises your right to be informed about the use of your data, to access it, to have it corrected or erased, and to object to its processing on legitimate grounds.

Organisations, for their part, must collect data for a legitimate purpose, keep it accurate and protect it against any alteration or unauthorised access. Certain types of processing must be declared, while others require prior authorisation, such as those concerning biometric data, and the transfer of data to countries that do not offer adequate protection is regulated. Non-compliance exposes organisations to administrative and criminal penalties. For a specific case, please contact ANSICE or a legal professional.

What you can do right now

Beginner level: protect your personal data

  • Do not publish your official documents (identity card, passport, diplomas, bank statements) on social media or in WhatsApp groups: a simple photo is enough to steal an identity.

  • Annotate the copies you send, for example: 'Copy sent to [recipient], on [date], for [reason]'. An annotated copy is much harder to reuse.

  • Ask how your information will be used when it is requested from you: it is your right.

  • Use a different password for each important account (email, Mobile Money, social media), and enable two-factor authentication.

  • Lock your phone (code or fingerprint) and regularly back up your photos and documents.

Intermediate level: businesses, NGOs and government bodies

  • Take stock: what personal data do you hold (clients, beneficiaries, employees), where is it located (paper registers, spreadsheets, phones, messaging apps, software) and who has access to it?

  • Collect only what is necessary: every piece of data kept is data that must be protected.

  • Appoint a lead person, even on a part-time basis, responsible for keeping this inventory up to date and responding to requests from data subjects.

  • Restrict access: staff should only see what they need to, and access must be revoked as soon as an employee leaves.

  • Back up using the 3-2-1 rule: three copies, on two different media types, with one kept off-site. Check from time to time that restoration works.

  • Set retention periods and delete what is no longer needed.

  • Protect the most vulnerable: health data, data concerning minors, refugees or displaced persons. In reports and shared tables, anonymise this data.

Advanced level: IT and data teams

  • Classify your data (public, internal, confidential, sensitive) and assign rules to each level: encryption, access logging, retention period.

  • Document them in a catalogue: definitions, sources, owners, quality level. This is the foundation of any interoperability.

  • Prepare for interoperability: open formats, documented APIs, common identifiers and reference data. This is what will enable easy exchange with other systems, including those of the government.

  • Measure quality (completeness, accuracy, duplicates, freshness) and correct errors at the source rather than at the end of the chain.

  • Map hosting: local servers, cloud, host countries, subcontractors. Check the rules that apply to transfers outside the country.

  • Monitor the adoption of the strategy and its implementing texts: they will specify the rules for data sharing.

Key takeaways

The future national strategy outlines a roadmap up to 2030 and beyond; the 2015 law, meanwhile, already applies. There is no need to wait to get started: knowing what data you hold, protecting it and keeping only what is useful is already the essence of data governance.

To audit your data or make it more reliable, discover our Consulting & Digital Transformation and Data & Artificial Intelligence services.

Sources: Tchadinfos, technical validation of the strategy (7 October 2026); Tchadinfos, data protection at the heart of discussions (1 October 2026); Le Pays, launch of works (May 2026).

← All articles