
This article examines data sovereignty as a major legal and governance challenge for many countries in the Global South, with a particular focus on Nigeria and Africa. It argues that the current model of data extraction by externally created Artificial intelligence systems often offered under the disguise of free access to technology reflects the model of surveillance capitalism and creates a new form of digital colonialism. The article identifies gaps in existing legal frameworks, it highlights that individual privacy rights are not specifically designed to protect collective digital sovereignty. It concludes by proposing legal and governance reforms grounded in Nigerian and Africa’s institutional capacity, to reduce the gap between individual privacy protection and collective digital sovereignty.
INTRODUCTION
Data is the new oil.1 A valuable resource that powers technology, promotes economic growth, and trains the artificial intelligence systems that increasingly shape how we live. For many countries especially in Africa, this metaphor mirrors a tragic familiarity. A similar pattern of historical extraction that gave rise to colonialism is now resurfacing but in a new form; this time through the collection of data by big data corporations, while being owned and controlled by them. This is a new form of digital colonialism.
The article bases its argument in two major stages. First, it uses the idea of data colonialism developed by Couldry and Mejias2. They explained that taking social data is a way to control people. Birhane3proves that Western AI often repeats the power structures of the past. It looks at how data sovereignty is a challenge for Nigeria and the rest of Africa. Second, the article established that it is also a legal problem. It proves that the NDPA and GDPR do not fully address the gap. Although they were made to safeguard individual privacy rights, but they were not designed to protect a country’s collective control over its data and digital future. It uses this legal gap to justify the reforms proposed in the final sections of the article.
THE TROJAN HORSE OF FREE ACCESS
Big data corporations often offer free AI tools to African schools and businesses. In exchange, they ask for local data to train their systems. This looks like a fair deal, on both sides, but the long term cost may be much higher. This is where the metaphor of the Trojan horse was derived from. Where free access conceals a much hidden agenda, which is the extraction of raw data without giving the extracted countries an equivalent control, ownership, or even
long term commercial benefit. Van der Spuy4 approached the relationship between data subjects and data platforms in the Global South. He contested that it mirrors the kind of relationship colonized territories and colonial extractors displayed.
For countries in the Global South, the pattern is awfully familiar. A trajectory of exploitation. The result is that we will end up paying for it twice. The first is by our data, and the other is with our money while having no control of it.5 This creates a cycle where we depend on systems we did not design. This is algorithmic dependency.6 It happens when a country relies on AI that is trained on its own data but governed by foreign rules. This makes it hard for African nations to build their own digital tools.
DATA AS THE NEW MINERAL: IS HISTORY REPEATING ITSELF?
The analogy of data as the new mineral is structurally accurate. In the colonial era, raw materials were extracted from Africa, processed in European factories, and then sold back as finished products.7 The environmental and economic costs were borne by the locals while the profits went overseas. This data economy follows the same structural logic just that it’s faster and at a greater scale.
Africa represents 18% of the world’s population but hosts less than 1% of global data centre capacity.8 This majority of data generated on the continent from financial transactions to health records, to agricultural patterns is processed and analysed outside Africa. This once more promotes dependence. Africans risk becoming consumers of intelligence that was derived from their own data.
THE AI DIVIDE AS A LEGAL PROBLEM
The disparity in data infrastructure created an AI divide. Not merely a gap in who has access to these AI tools but a gap in the capacity to build, govern, and benefit from AI systems. Countries on the wrong side of this divide are structurally positioned as mere suppliers of raw data which they exercise no governance control. Ayana and others9 found that African states are almost entirely absent from the institutions that set global AI norms.
As the Information Technology for Development10 study on data colonialism and digital sovereignty in the Global South pointed out, data extraction will increase dependence between regions and keeps control of digital systems and knowledge in the hands of a few powerful countries. This is already happening today.
THE GAP IN OUR LAWS
Section 37 of our Constitution11 protects the privacy of citizens. The Nigeria Data Protection Act and the General Data Protection Regulation.12 All these gives individuals rights over their personal data in the European Union. However, there is a gap in these laws. They focus on the rights of one person at a time. They do not protect the digital future of the whole country.
There is also a technical problem with these laws. The law says you have a right to erase your data.13 But once your data is used to train an AI model, it is almost impossible to remove. Once the data is gone from the database but not completely gone from the system. Individual rights cannot fix these big structural problems.
AFRICA IS LEADING THE WAY
Africa is not sitting idle, watching the AI revolution. The solution to Algorithmic Dependency is already being built by African innovators. Many local innovators are solving problems in their own communities. Among others, a company called Bluechip Technologies bought YarnGPT. A Nigerian AI platform that understands Nigerian local languages. This proves that Africa does not need to be a passive consumer of foreign AI. They ensure that the value created from African data stays in Africa and serves African priorities.
RECOMMENDATIONS
- Digital Infrastructure as a National Asset: Governments should treat data centers as a major investment, similar to roads or electricity. They could also back it up with stronger policies to encourage public and private sector investments
- Digital sovereignty cannot be achieved by one African country alone, so regional cooperation is advised to strengthen Africa’s bargaining power. By working with international regulators, and participate more actively in shaping global AI governance. The goal is not digital isolation, but a stronger digital ecosystem where African countries participate as co-creators rather than only as consumers of foreign technology.
- Privacy-Enhancing Technologies: Regulatory bodies like the NDPC should encourage the use of PETs (like Federated Learning) for sensitive national datasets, allowing AI training without data leaving the country.14
CONCLUSION
Data sovereignty for the Global South cannot be attained just by abiding by the data protection law alone. The individual rights architecture of the GDPR and the NDPA cannot address the collective, structural problem of digital sovereignty erosion. We need a strong legal and political environment to keep our value at home.
Africa is not poor but poorly optimized. We have the skill and the vision to shape our own digital world. The local innovations we see today prove that we can lead. Now we need the political and legal backing to protect our work. Once the Global South nations are able to recognize data as a national investment capable of improving their economic power and influence that requires investment, then we can reclaim our digital sovereignty. What we want is to be able to protect and shape our own digital future.







