Skip to content

feat(examples): add East Africa policy packs (Uganda DPPA, Tanzania PDPA, Ethiopia PDP) - #3110

Merged
Imran Siddique (imran-siddique) merged 2 commits into
microsoft:mainfrom
kingztech2019:feat/east-africa-policy-packs
Jun 18, 2026
Merged

Imran Siddique (imran-siddique) merged 2 commits into
microsoft:mainfrom
kingztech2019:feat/east-africa-policy-packs

Conversation

@kingztech2019

@kingztech2019 Oluwajuwon Omotayo (kingztech2019) commented Jun 18, 2026 •

Copy link
Copy Markdown
Contributor

Description

Follow-up to #3077 (merged). Adds three East African data protection policy packs to examples/policies/african-regulatory/, extending the jurisdiction router to cover Uganda, Tanzania, and Ethiopia. Each pack ships both YAML and OPA Rego formats with full test coverage.

Extends the African regulatory policy pack with three new jurisdictions:

  • Uganda Data Protection and Privacy Act 2019 (UG) — NIRA national ID blocking, biometric deny, PDPO breach notification, financial data escalation, special category data (s.4, s.13, s.19, s.22, s.25)
  • Tanzania Personal Data Protection Act 2022 (TZ) — NIDA 20-digit national ID blocking, PDPC breach notification, consent enforcement, biometric deny (s.8, s.13, s.17, s.25, s.28)
  • Ethiopia Personal Data Protection Proclamation No. 1321/2024 (ET) — enacted July 24, 2024. Fayda/MOSIP ID blocking (Art. 2), sensitive data controls (Art. 9), cross-border transfer adequacy checks (Art. 18–20), data sovereignty (Art. 22), 72-hour ECA breach notification (Art. 43), accountability audit trail (Art. 46/52). Computer Crime Proclamation 958/2016 retained for unauthorised access detection.

Also updates:

  • rego/jurisdiction-router.rego: UG, TZ, ET added to jurisdiction_policies and policy_queries
  • README.md: coverage table, architecture diagram, and test count (306 → 384)

Jurisdiction coverage: NG, KE, ZA → NG, KE, ZA, UG, TZ, ET
Total OPA tests: 306 → 384

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Maintenance (dependency updates, CI/CD, refactoring)
  • Security fix

Package(s) Affected

  • agent-os-kernel
  • agent-mesh
  • agent-runtime
  • agent-sre
  • agent-governance
  • docs / root

None of the above — changes are confined to examples/policies/african-regulatory/ (YAML policy files, Rego reference implementations, jurisdiction router, README).

Checklist

  • My code follows the project style guidelines (ruff check)
  • I have added tests that prove my fix/feature works
  • All new and existing tests pass (pytest)
  • I have updated documentation as needed
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation
  • If this PR implements functionality similar to an existing open-source project, I have listed it below

Prior art / related projects:
Policy files are maintained in kingztech2019/agt-policies-nigeria (MIT), the source repository for this policy pack. OPA Rego patterns follow the same conventions established in #3077.

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

Claude Code was used to assist with Rego rule authoring and test generation. All policy rules were reviewed against the cited regulatory sources — including verification that Ethiopia's Personal Data Protection Proclamation No. 1321/2024 was enacted and gazetted on July 24, 2024. All 384 OPA tests were run and verified locally before submission.

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

Related Issues

Extends #3077 — African regulatory policy pack (NDPA, CBN, POPIA, Kenya DPA)

…DPA, Ethiopia PDP)

Extends the African regulatory policy pack with three new jurisdictions:

- Uganda Data Protection and Privacy Act 2019 (UG)
  NIRA national ID blocking, biometric deny, PDPO breach notification,
  financial data escalation, special category data (s.4, s.13, s.19, s.22, s.25)

- Tanzania Personal Data Protection Act 2022 (TZ)
  NIDA 20-digit national ID blocking, PDPC breach notification,
  consent enforcement, biometric deny (s.8, s.13, s.17, s.25, s.28)

- Ethiopia Computer Crime Proclamation 958/2016 + draft PDPP (ET)
  Fayda/MOSIP ID blocking, unauthorised access detection,
  ECA breach notification, cross-border controls (pack tagged draft)

Also updates:
- rego/jurisdiction-router.rego: UG, TZ, ET added to jurisdiction_policies
  and policy_queries
- README.md: coverage table, architecture diagram, and test count (306 → 384)

Jurisdiction coverage: NG, KE, ZA → NG, KE, ZA, UG, TZ, ET
Total OPA tests: 306 → 384
…2024

Ethiopia's Personal Data Protection Proclamation was enacted July 24, 2024
as Proclamation No. 1321/2024 — corrects the earlier draft reference.

- Art. 9: sensitive data categories (health, biometric, genetic, ethnic, religious)
- Art. 18-20: cross-border transfer (adequacy, safeguards, derogations)
- Art. 22: data sovereignty (critical data must remain in-country)
- Art. 43: 72-hour breach notification to ECA
- Art. 46/52: records of processing and accountability
- Proclamation 958/2016: retained for unauthorised access controls
@github-actions

Copy link
Copy Markdown
🤖 AI Agent: security-scanner — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

No security issues found.

@github-actions github-actions Bot added the size/XL Extra large PR (500+ lines) label Jun 18, 2026
@github-actions

Copy link
Copy Markdown
🤖 AI Agent: code-reviewer — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

TL;DR: 0 blockers, 1 warning. Comprehensive and well-structured addition of East African policy packs, but one area for improvement.

# Sev Issue Where
1 Warn Ethiopia PDP YAML policy lacks explicit test coverage verification. examples/policies/african-regulatory/

Action items: None.

Warnings:

  1. Ethiopia PDP YAML policy should explicitly confirm test coverage for all rules in the PR description or documentation. Fine as follow-up PRs.

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: test-generator — `examples/policies/african-regulatory/rego/ethiopia-pdp.rego`

AI-generated review output. Treat it as untrusted analysis and verify before acting.

examples/policies/african-regulatory/rego/ethiopia-pdp.rego

  • test_ethiopia_breach_suppression -- Test for scenarios where breach notifications are suppressed or delayed.
  • test_ethiopia_sensitive_data_detection -- Validate detection of sensitive personal data categories (e.g., health, biometric, ethnic data).
  • test_ethiopia_cross_border_transfer -- Ensure cross-border data transfer conditions are enforced (adequacy, consent, necessity).
  • test_ethiopia_unauthorized_access -- Test detection and prevention of unauthorized access attempts.
  • test_ethiopia_audit_trail -- Verify logging of personal data access and modification actions for accountability.

examples/policies/african-regulatory/ethiopia-pdp.yaml

  • test_breach_notification -- Ensure breach notifications are not suppressed or delayed.
  • test_sensitive_data_rules -- Validate rules for handling sensitive personal data categories.
  • test_cross_border_transfer_rules -- Test enforcement of cross-border data transfer restrictions.
  • test_unauthorized_access_rules -- Ensure unauthorized access attempts are blocked.
  • test_audit_logging -- Confirm audit logging for personal data access and modifications.

examples/policies/african-regulatory/rego/jurisdiction-router.rego

  • test_jurisdiction_routing -- Verify correct routing of policies for Uganda, Tanzania, and Ethiopia.
  • test_invalid_jurisdiction -- Ensure invalid jurisdictions are handled appropriately.

examples/policies/african-regulatory/README.md

  • test_documentation_accuracy -- Verify that the documentation matches the implemented policies and test counts.

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: breaking-change-detector — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

No breaking changes detected.

@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/XL Extra large PR (500+ lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants