Code for Africa

Kenya · codeforafrica.org · 9 vendors

Code for Africa (CfA) is a pan-African non-profit organization that builds digital democracy solutions and empowers citizens with actionable information. It operates as a network of civic technology and data journalism labs, focusing on strengthening civic engagement, public governance, and accountability, and countering misinformation.

Resilience scores

Technology vendors

Services catalogue

8 services in catalogue across 3 categories; runs on 9 sub-vendors.

Insights

Last updated 2026-07-29 · revision 2

9 direct vendors, 150 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Code for Africa exhibits a high degree of migration readiness, primarily driven by its modern and cloud-friendly internal tech stack. The existing use of Amazon Web Services (AWS), Heroku, and Docker indicates a strong foundation in cloud adoption and containerization, which are key enablers for efficient migration to cloud-native architectures. The tech stack, including Python, Django, Node.js, React, and PostgreSQL, consists of widely supported and flexible technologies. The organization's emphasis on 'Open Source Development' as a key technology suggests a reduced reliance on proprietary solutions, which generally simplifies migration efforts. Despite these strengths, several factors introduce uncertainty and potential challenges for migration. The 'Vendor lock-in risk' is unknown, and while there is geographic diversity among vendors (5 countries for 11 services), the specific nature of these services and contracts could pose migration hurdles. Crucially, 'Data residency requirements' are not specified, which could significantly impact migration strategies and choices of cloud regions. Information on the 'Regulatory environment' is also missing, which could introduce compliance complexities during a migration. Lastly, the absence of data on financial stability (revenue, growth history) makes it difficult to assess the company's capacity to fund a potentially significant migration project. While technically well-positioned, these non-technical unknowns prevent a top-tier readiness score.

Compliance

9 in-scope frameworks identified; showing 3.

South Africa POPIA — Assessment Required

POPIA is fully in force in South Africa (since July 1, 2021) and applies to any responsible party that processes personal information of South African data subjects or processes personal information in South Africa. Code for Africa has significant operations in South Africa (including its Africa Check fact-checking initiative and data journalism labs), making POPIA directly applicable. Risk is High because: (1) CfA has confirmed South African operations, (2) POPIA imposes strict obligations including Information Officer registration with the Information Regulator, (3) non-compliance penalties include fines up to ZAR 10 million and/or imprisonment, (4) the Information Regulator of South Africa has been actively enforcing POPIA since 2022, (5) CfA processes personal data of South African journalists, civil society actors, and platform users.

Evidence: https://www.inforegulator.org.za/, https://www.justice.gov.za/inforeg/docs/InfoRegSA-POPIA-act4of2013.pdf, https://codeforafrica.org

Nigeria Data Protection Act 2023 — Assessment Required

Nigeria enacted the Nigeria Data Protection Act 2023 (NDPA), replacing the 2019 NDPR, establishing the Nigeria Data Protection Commission (NDPC) as the supervisory authority. Code for Africa has significant operations in Nigeria (including Dataphyte, civic tech labs, and data journalism initiatives). Risk is High because: (1) CfA has confirmed Nigerian operations, (2) the NDPA applies to data controllers and processors established in Nigeria or processing personal data of Nigeria-based data subjects, (3) the NDPC has been actively issuing compliance directives and enforcement notices, (4) penalties include fines up to 2% of annual gross revenue or NGN 10 million (whichever is higher), (5) CfA processes personal data of Nigerian journalists, civil society actors, and platform users.

Evidence: https://ndpc.gov.ng/, https://codeforafrica.org

ISO 27001 (source) — Assessment Required

ISO 27001 certification is not legally mandated but is a globally recognized best practice for information security management. Code for Africa manages sensitive civic data, investigative journalism sources, election monitoring data, and financial accountability information across multiple African countries. The sensitivity of this data — particularly source protection for journalists and election integrity data — creates meaningful information security risk. The risk is Medium because: (1) a breach of journalist source data or election data could have serious human rights and democratic implications, (2) institutional donors and international partners increasingly expect ISO 27001 or equivalent security frameworks, (3) the organization operates across multiple high-risk political environments where data security is critical. The absence of ISO 27001 certification represents a reputational and operational risk.

Evidence: https://codeforafrica.org, https://www.iso.org/standard/27001

Financials

Three-year financials

Financial Resilience Score: 6/10

Code for Africa (CfA) is a non-profit civic-tech and data journalism network rather than a commercial enterprise, so traditional financial resilience metrics (EBIT, equity, revenue growth) do not fully apply. Its resilience derives primarily from a diversified donor base that includes major philanthropies (Gates Foundation, Omidyar Network, Hewlett, Ford, Luminate, Open Society) and public-sector funders (US State Department, National Endowment for Democracy), as well as platform-linked grants from Google News Initiative and Meta Journalism Project. Historical reporting suggests annual operating budgets in the USD 5–10M range, though these figures are not verified from primary audited sources in this session. CfA's multi-country footprint across ~20 African countries and multiple long-running program lines (PesaCheck, iLAB, sensors.AFRICA, CivicSignal, WanaData) provide operational flexibility and multi-year grant contracts. However, like all grant-dependent NGOs, CfA is exposed to donor cycles, shifts in foreign aid policy (particularly US assistance), FX volatility between USD/EUR grants and local-currency expenses, and the difficulty of building unrestricted reserves when most grants are project-restricted. Transparency is limited: audited financials are not readily accessible on the main website, reducing external ability to assess reserve adequacy. A moderate score of 6 reflects strong reputational capital and donor diversification balanced against inherent NGO grant-dependency risk.

Key strengths: Diversified donor base including Gates Foundation, Omidyar, Hewlett, Ford, Google, Meta, US State Department, NED, Luminate, Open Society, Multi-country footprint across ~20 African countries with regional hubs, Multiple long-running program lines providing multi-year grant contracts, Strong reputational capital as Africa's largest civic-tech/data journalism network, Historical operating budget estimated at USD 5–10M annually

Risk factors: High dependence on grant funding and donor cycles, Exposure to shifts in US and European foreign aid budgets, FX risk between USD/EUR grants and local-currency (KES, ZAR, NGN, UGX) expenses, Restricted vs unrestricted funding mix limits reserve-building, Political and regulatory risk in press-freedom-restricted jurisdictions, Limited public transparency on audited financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report