# Discovering a pattern of privacy literacy in rural Sub Saharan Africa

Frederik J. Van Deventer

## Context

With the rise of digitization and the data it produces, the question of ownership of data becomes a contested issue for agents such as Indigenous people, consumers and countries ([Hummel et al. 2021](#ref-hummel2021data)). If the ownership is not clear and personal data cannot always be obtained ([Herrmann and Lindemann 2016](#ref-herrmannObtainingPersonalData2016)) it should be clear we should not only look to data governance or ownership but also to defending this data in the light of privacy norms. However, digital privacy in much of Africa is subject to local and regional legislation ([Prinsloo and Kaliisa 2022](#ref-prinslooDataPrivacyAfrican2022)), but its main challenge lies in enforcement of this legislation ([Abdulrauf 2021](#ref-Abdulrauf04052021)). We should therefore not only rely on legislation, but also work towards higher privacy literacy ([Koltay 2016](#ref-koltay2016data)).

Digital privacy is not a binary or singular thing, and giving our personal information to gain access to a platform or a service can be useful. However people largely underestimate the small bits of information we give to big tech and how the sum of that can still offer a persona or Gestalt ([Puaschunder 2018](#ref-puaschunder2018dignity)) with useful insights.

## Problem

Understanding what happens with your data is difficult and ambigiuous in any context ([Bartsch and Dienlin 2016](#ref-bartschControlYourFacebook2016)). Regulation and enforcement often falls behind. And some regulation interventions simply fail, like the “cookie wall”-solution ([Leenes and Kosta 2015](#ref-leenes2015taming)). When companies like Meta profit from tracking users online ([Wernerfelt et al. 2025](#ref-wernerfeltEstimatingValueOffsite2025)) and

## Research questions

### Main question

How can people in the Majority World benefit from being “connected” without sacrificing their privacy?

What is permissable in bridging the digital divide? To what extent is big tech allowed to

**(Possibly this can be more specified towards a Case Study in rural South Africa, or Botswana?)**

### Sub-questions

-   What initiatives stand out in ameliorating the digital divide?
-   In what way are people aware of the predicament of sharing personal information?
-   What is the benefit of participating in the digital “online world”?
-   What legislation is in place to ensure digital privacy at a national and regional level?
-   What conflicts between legislation and ethics arise concerning privacy?
-   What are main differences when dealing with privacy in Europe and SSA?

## Conceptual Framework

Nissenbaum ([2004](#ref-nissenbaum2004privacy)) proposes the idea of “Contextual Integrity” for privacy. Which instead of focusing on specifics of data outlines “information flows”, of which the norms are subject to the context in which that data flows. With this notion of Contextual Integrity, we can easily establish the divulging of the same type of personal information can be completely permissable in one context and inappropriate in the other. For example sharing my postal address to purchase a product is permissable, whereas sharing my postal address with my students so they can hand in their papers personally, feels like crossing a boundary.

The concept of “Contextual Integrity” has been used in a number of studies to deal with personal information flows.

## Research methodology

At the moment I’m reading Hancké ([2023](#ref-hanckeIntelligentResearchDesign2023)) and sorting through the vast bibliography of Sovacool, Axsen, and Sorrell ([2018](#ref-sovacoolPromotingNoveltyRigor2018)) to help sort out the methodology part.

My initial instinct is to do a survey, but I would like to do something a bit different. But not sure how to go about this.

Some other ideas:

Ideas on how to accomplish this:

-   A/B Testing – do survey’s on 2 groups
    -   one group has received a seminar or dissemination of the information about privacy the other has not
-   Do a deeper but not necessarily wider analysis. So perhaps look for a few groups of participants in rural Botswana and a few groups in urban Botswana. Or try to localize it further by looking at interactions wihtin townships.
-   Data acquisition might be a problem..

## Significance

A study by Prinsloo and Kaliisa ([2022](#ref-prinslooDataPrivacyAfrican2022)) has been held to asses specific sub-topics such as student data privacy researching regulatory frameworks on the African content. The angle here to assess Higher Education Institutes (HEI’s) is helpful as it is a very concrete example and produces very clear results. However HEI’s are also quite an exclusive segment of society that cannot be used to draw broader conclusions. Another study uses a survey in an impressive array of countries but has quite a low sample size, primarily in the generation we call millenials, which might be the most digital and privacy literate ([Agbozo, Alhassan, and Spassov 2018](#ref-agbozo2018personal)).

This study should be different from both previous efforts by both its scope and localization.

## Bibliography

Abdulrauf, Lukman Adebisi. 2021. “Giving ‘Teeth’ to the African Union Towards Advancing Compliance with Data Privacy Norms.” *Information & Communications Technology Law* 30 (2): 87–107. <https://doi.org/10.1080/13600834.2021.1849953>.

Agbozo, Ebenezer, Daniel Alhassan, and Kamen Spassov. 2018. “Personal Data and Privacy Barriers to e-Government Adoption, Implementation and Development in Sub-Saharan Africa.” In *International Conference on Electronic Governance and Open Society: Challenges in Eurasia*, 82–91. Springer.

Bartsch, Miriam, and Tobias Dienlin. 2016. “Control Your Facebook: An Analysis of Online Privacy Literacy.” *Computers in Human Behavior* 56 (March): 147–54. <https://doi.org/10.1016/j.chb.2015.11.022>.

Hancké, Bob. 2023. *Intelligent Research Design: A Guide for Beginning Researchers in the Social Sciences*. Oxford Scholarship Online. Oxford: Oxford University Press. <https://doi.org/10.1093/oso/9780199570782.001.0001>.

Herrmann, Dominik, and Jens Lindemann. 2016. “Obtaining Personal Data and Asking for Erasure: Do App Vendors and Website Owners Honour Your Privacy Rights?” arXiv. <https://doi.org/10.48550/arXiv.1602.01804>.

Hummel, Patrik, Matthias Braun, Max Tretter, and Peter Dabrock. 2021. “Data Sovereignty: A Review.” *Big Data & Society* 8 (1): 2053951720982012.

Koltay, Tibor. 2016. “Data Governance, Data Literacy and the Management of Data Quality.” *IFLA Journal* 42 (4): 303–12.

Leenes, Ronald, and Eleni Kosta. 2015. “Taming the Cookie Monster with Dutch Law–a Tale of Regulatory Failure.” *Computer Law & Security Review* 31 (3): 317–35.

Nissenbaum, Helen. 2004. “Privacy as Contextual Integrity” 79: 119.

Prinsloo, Paul, and Rogers Kaliisa. 2022. “Data Privacy on the African Continent: Opportunities, Challenges and Implications for Learning Analytics.” *British Journal of Educational Technology* 53 (4): 894–913. <https://doi.org/10.1111/bjet.13226>.

Puaschunder, Julia M. 2018. “Dignity and Utility of Privacy and Information Sharing in the Digital Big Data Age.” *International Journal of Commerce and Management Research* 5 (4): 62–70.

Sovacool, Benjamin K., Jonn Axsen, and Steve Sorrell. 2018. “Promoting Novelty, Rigor, and Style in Energy Social Science: Towards Codes of Practice for Appropriate Methods and Research Design.” *Energy Research & Social Science*, Special Issue on the Problems of Methods in Climate and Energy Research, 45 (November): 12–42. <https://doi.org/10.1016/j.erss.2018.07.007>.

Wernerfelt, Nils, Anna Tuchman, Bradley T. Shapiro, and Robert Moakler. 2025. “Estimating the Value of Offsite Tracking Data to Advertisers: Evidence from Meta.” *Marketing Science* 44 (2): 268–86. <https://doi.org/10.1287/mksc.2023.0274>.