Repository navigation
feat(examples): add East Africa policy packs (Uganda DPPA, Tanzania PDPA, Ethiopia PDP) - #3110
Conversation
…DPA, Ethiopia PDP) Extends the African regulatory policy pack with three new jurisdictions: - Uganda Data Protection and Privacy Act 2019 (UG) NIRA national ID blocking, biometric deny, PDPO breach notification, financial data escalation, special category data (s.4, s.13, s.19, s.22, s.25) - Tanzania Personal Data Protection Act 2022 (TZ) NIDA 20-digit national ID blocking, PDPC breach notification, consent enforcement, biometric deny (s.8, s.13, s.17, s.25, s.28) - Ethiopia Computer Crime Proclamation 958/2016 + draft PDPP (ET) Fayda/MOSIP ID blocking, unauthorised access detection, ECA breach notification, cross-border controls (pack tagged draft) Also updates: - rego/jurisdiction-router.rego: UG, TZ, ET added to jurisdiction_policies and policy_queries - README.md: coverage table, architecture diagram, and test count (306 → 384) Jurisdiction coverage: NG, KE, ZA → NG, KE, ZA, UG, TZ, ET Total OPA tests: 306 → 384
…2024 Ethiopia's Personal Data Protection Proclamation was enacted July 24, 2024 as Proclamation No. 1321/2024 — corrects the earlier draft reference. - Art. 9: sensitive data categories (health, biometric, genetic, ethnic, religious) - Art. 18-20: cross-border transfer (adequacy, safeguards, derogations) - Art. 22: data sovereignty (critical data must remain in-country) - Art. 43: 72-hour breach notification to ECA - Art. 46/52: records of processing and accountability - Proclamation 958/2016: retained for unauthorised access controls
🤖 AI Agent: security-scanner — View details
No security issues found. |
🤖 AI Agent: code-reviewer — View details
TL;DR: 0 blockers, 1 warning. Comprehensive and well-structured addition of East African policy packs, but one area for improvement.
Action items: None. Warnings:
|
🤖 AI Agent: test-generator — `examples/policies/african-regulatory/rego/ethiopia-pdp.rego`
|
🤖 AI Agent: breaking-change-detector — View details
No breaking changes detected. |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
5cca572
into
microsoft:main
Description
Follow-up to #3077 (merged). Adds three East African data protection policy packs to
examples/policies/african-regulatory/, extending the jurisdiction router to cover Uganda, Tanzania, and Ethiopia. Each pack ships both YAML and OPA Rego formats with full test coverage.Extends the African regulatory policy pack with three new jurisdictions:
Also updates:
rego/jurisdiction-router.rego: UG, TZ, ET added tojurisdiction_policiesandpolicy_queriesREADME.md: coverage table, architecture diagram, and test count (306 → 384)Jurisdiction coverage: NG, KE, ZA → NG, KE, ZA, UG, TZ, ET
Total OPA tests: 306 → 384
Type of Change
Package(s) Affected
None of the above — changes are confined to
examples/policies/african-regulatory/(YAML policy files, Rego reference implementations, jurisdiction router, README).Checklist
Attribution & Prior Art
Prior art / related projects:
Policy files are maintained in kingztech2019/agt-policies-nigeria (MIT), the source repository for this policy pack. OPA Rego patterns follow the same conventions established in #3077.
AI Assistance
Claude Code was used to assist with Rego rule authoring and test generation. All policy rules were reviewed against the cited regulatory sources — including verification that Ethiopia's Personal Data Protection Proclamation No. 1321/2024 was enacted and gazetted on July 24, 2024. All 384 OPA tests were run and verified locally before submission.
IP, Patents, and Licensing
Related Issues
Extends #3077 — African regulatory policy pack (NDPA, CBN, POPIA, Kenya DPA)