Antares Genomics

Thought Leadership of 108000 Africa Genomes Project

Genomics, Law & African Sovereignty

A thought-leadership series on the legal, ethical and governance questions shaping the future of genomic medicine in Africa.

01

Article 1

When Is Genomic Data Truly Anonymous?

By Eshara Chotoo

One of the most important questions in genomic data law is deceptively simple: when does data stop being “personal information”?

South Africa’s courts are increasingly being asked to grapple with the meaning of identifiability under POPIA — including whether information that does not contain a person’s name can nevertheless relate to an identifiable person.

The underlying legal disputes may not concern genomics directly. But the principle matters enormously for genomics.

Genomic information is fundamentally different from most ordinary datasets. Removing a name, identity number or contact detail does not necessarily render genomic information anonymous. A genome may still be capable of being associated with an individual when combined with family information, phenotype, geography, clinical records or other datasets.

That distinction between pseudonymisation and true anonymisation will become increasingly important as African genomic programmes scale.

From contractual language to legal frameworks

From a contractual perspective, this means we need to move beyond simplistic wording such as:

  • “the data has been de-identified and therefore no longer constitutes personal information.”

A stronger legal framework distinguishes clearly between:

  • identifiable data;
  • pseudonymised data; and
  • genuinely de-identified data.

Each category carries different legal and practical risks.

Genomic-data sovereignty beyond privacy classification

But there is an even more important point. Genomic-data sovereignty should not depend entirely on whether a court ultimately classifies a particular dataset as personal information under privacy legislation.

Contracts can — and arguably should — independently regulate issues such as:

  • re-identification;
  • linkage with external datasets;
  • cross-border transfer;
  • onward sharing;
  • permitted uses;
  • retention and deletion;
  • AI and model training;
  • commercialisation; and
  • derivatives generated from the data.

For African genomic projects, this matters because the scientific and economic value of a dataset does not disappear simply because a participant’s name has been removed.

Why this matters to the 108,000 Africa Genomes Project

This is not merely an academic question for Antares. Through the 108,000 Africa Genomes Project, we are confronting these questions in practice as we work toward building a large-scale African genomic resource with participation across the continent.

One of the principles shaping the Project is that privacy, scientific utility and African data sovereignty cannot be treated as separate conversations.

Genomic research requires collaboration. Precision medicine requires access to high-quality data. Scientific discovery requires scale. But none of those objectives necessarily requires Africa to relinquish agency over the genomic resources generated from African populations.

As genomic datasets increase in scale and value, the legal frameworks surrounding them have to evolve just as rapidly. The question is therefore becoming bigger than privacy.

It is increasingly about control, permitted use, accountability and sovereignty over genomic information itself.

Africa should not simply participate in that conversation. Africa should help define it.

References & Further Reading

  1. Protection of Personal Information Act 4 of 2013 (POPIA), Republic of South Africa
  2. Information Regulator South Africa — regulatory guidance and enforcement activity
  3. Regulations relating to the Processing of Data Subjects’ Health Information by Certain Responsible Parties, 2026, Government Gazette No. 54268, 6 March 2026
  4. South African Government Gazette No. 54268, 6 March 2026

Note: The discussion in this article regarding genomic identifiability reflects the application of existing privacy-law principles to genomic information. Genomic data presents distinctive re-identification risks because it may remain identifying or become identifiable when combined with other datasets.

02

Article 2

POPIA Compliance Is Becoming an Operational Obligation

By Eshara Chotoo

A sentence I increasingly dislike seeing in technology and healthcare contracts is: “The parties will comply with POPIA.” It sounds reassuring. Legally, however, it may be nowhere near enough.

Recent regulatory developments in South Africa demonstrate an increasingly important shift in the way privacy compliance should be understood.

Compliance is not simply about inserting the right clause into an agreement. It is about being able to demonstrate that appropriate governance, systems and safeguards actually exist.

For organisations dealing with health and genomic data, that distinction is critical.

What a genomic-data agreement should answer

A genomic-data agreement should increasingly answer practical questions such as:

  • Who can access the data?
  • Where is it processed?
  • Where are backups located?
  • Who holds encryption keys?
  • Can a processor appoint a subprocessor?
  • Can data leave South Africa?
  • What happens to temporary computational files?
  • Who investigates a security incident?
  • How quickly must the responsible party be informed?
  • Can the organisation demonstrate that deletion actually occurred?

And perhaps most importantly: Can the data controller audit any of this?

From generic clauses to governance architecture

For genomic programmes, we need to move beyond generic “data protection” clauses and toward detailed data-governance architecture.

That may include provisions addressing:

  • technical and organisational security measures;
  • cross-border transfer mechanisms;
  • subprocessor approval;
  • access logs and audit rights;
  • incident reporting;
  • risk assessments;
  • deletion certification;
  • onward-transfer restrictions;
  • permitted-use controls; and
  • retention of derived data.

The implications become even more significant where African genomic data is analysed through foreign laboratories, cloud platforms, AI systems or software providers.

In those relationships, the question should not simply be: “Is the recipient POPIA compliant?” The stronger question is: “What exactly is the recipient permitted to do with the data, and can we prove that those limits are being respected?”

Designing governance for scale

These questions are particularly relevant to the 108,000 Africa Genomes Project, where responsible governance has to be considered at scale from the outset.

A pan-African genomic initiative may involve multiple countries, laboratories, clinicians, researchers, technology platforms and institutional collaborators. That complexity makes one principle especially important: governance cannot be added at the end as a compliance exercise.

It has to form part of the architecture of the programme itself.

The challenge is not simply protecting information from a breach. It is ensuring clarity around:

  • who controls genomic data;
  • who may access it;
  • for what purpose;
  • for how long;
  • in which jurisdiction;
  • under whose authority; and
  • subject to which continuing obligations.

For me, this is becoming one of the defining legal questions of precision medicine in Africa: How do we enable scientific collaboration at scale while preserving accountability, patient rights and meaningful African control over African genomic resources?

That is where contract drafting moves beyond legal documentation and becomes part of the governance infrastructure itself.

In genomics, contractual precision is increasingly becoming part of data security.

References & Further Reading

  1. Information Regulator South Africa — Media Briefing, 31 August 2026
  2. Information Regulator South Africa — 2026 Media Statements
  3. Protection of Personal Information Act 4 of 2013 — Section 19
  4. Protection of Personal Information Act 4 of 2013 — Section 21
  5. Protection of Personal Information Act 4 of 2013 — Section 72
  6. Regulations relating to the Processing of Data Subjects’ Health Information by Certain Responsible Parties, 2026, Government Gazette No. 54268, 6 March 2026

Note: The contractual recommendations in this article — including audit rights, subprocessor controls, deletion certification, incident obligations and data-governance schedules — are legal-design recommendations derived from these regulatory duties and the particular risk profile of genomic information.

03

Article 3

Africa May Be Shaping a New Model of Genomic Sovereignty

By Eshara Chotoo

There is an important global debate unfolding around genetic information that Africa should be watching very carefully.

International discussions around pathogen access, genomic information and benefit sharing have increasingly raised a fundamental question: Does data need to leave the jurisdiction in which it was generated in order for global science to benefit from it?

Increasingly, the answer may be no.

Federated access without transfer

Federated approaches can allow data to remain under national or regional control while authorised researchers are able to interrogate, analyse or work with it under agreed governance rules.

That idea may have profound implications beyond pathogen surveillance.

For decades, one model of international scientific collaboration has often looked something like this:

  • collect → export → analyse → publish → commercialise.

African countries have too often participated heavily at the beginning of that chain while capturing comparatively little of the downstream scientific, institutional or economic value.

A different architecture is possible. One based on:

  • local custody + controlled access + traceability + equitable benefit.

A legal principle: access is not ownership

That introduces an important legal principle: Access should not automatically mean transfer.

A researcher may be permitted to analyse data without acquiring ownership of it. A technology company may be permitted to run an algorithm without receiving an unrestricted copy of the underlying dataset. A pharmaceutical company may be permitted to investigate an approved research question without acquiring a general right to reuse that information indefinitely for unrelated commercial purposes.

And critically, obligations should be capable of travelling with the data and its authorised derivatives. Restrictions imposed at the first point of access should not disappear simply because information moves to:

  • subcontractors;
  • cloud providers;
  • research collaborators;
  • AI systems;
  • affiliates; or
  • downstream commercial partners.

Access to genomic data should also be separated conceptually from the right to:

  • patent discoveries;
  • train proprietary models;
  • develop commercial products;
  • create new datasets;
  • sublicence information; or
  • monetise downstream applications.

Those are separate rights. And separate rights may require separate authorisation, governance and benefit-sharing.

The relevance to the 108,000 Africa Genomes Project

This thinking resonates strongly with the principles underpinning the 108,000 Africa Genomes Project.

The ambition is not simply to generate a large African genomic dataset. It is to help demonstrate that Africa can participate in genomic discovery at meaningful scale while ensuring that African populations, institutions and health systems remain meaningful participants in the scientific and economic value created from African genomic resources.

That requires a different conversation about sovereignty. A different conversation about access. A different conversation about scientific collaboration. And a more sophisticated conversation about benefit.

The purpose of African genomic sovereignty should not be to isolate African data from international science. Quite the opposite. The objective should be to create frameworks that allow African genomic resources to contribute meaningfully to global discovery without requiring Africa to relinquish control, participation or benefit in return for access to the scientific ecosystem.

This is particularly important because genomic data is not merely an input into scientific research. At sufficient scale, it can become the foundation for:

  • new diagnostic insights;
  • population-specific reference resources;
  • drug discovery;
  • precision-medicine tools;
  • algorithms;
  • clinical decision systems; and
  • future biotechnology.

The legal frameworks governing access therefore influence where scientific value ultimately accumulates.

The question Africa should help lead

The global debate may increasingly move away from asking: “Can African data participate in global science?” Of course it can.

The more important question is: “Can Africa participate in global science without surrendering agency over the assets from which that science derives?”

That is where law, technology, ethics, scientific collaboration and sovereignty increasingly intersect. And it is a conversation Africa should help lead.

References & Further Reading

  1. WHO Pandemic Agreement
  2. WHO — Member States Advance Negotiations on Pathogen Access and Benefit-Sharing, 18 September 2026
  3. WHO — Eighth Meeting of the Intergovernmental Working Group on the WHO Pandemic Agreement, 14–18 September 2026
  4. Africa Group — Initial Submission on the Pathogen Access and Benefit-Sharing Instrument, August 2025
  5. WHO — Draft PABS Annex Text, A79/8
  6. WHO — Member States Continue Negotiations on the PABS Annex, 20 July 2026

Note: The WHO PABS negotiations concern pathogens with pandemic potential, not human germline genomic datasets. Their relevance to the 108,000 Africa Genomes Project is therefore conceptual and policy-based: they demonstrate the growing international importance of sovereignty, controlled access, traceability, contractual governance and equitable benefit-sharing in relation to genetic resources and sequence information.