Skip to content

Launch checklist

What you need before opening a digital service in Senegal: company, hosting, OTP, payment, personal data, backups and monitoring.

Tick every line before opening your service to the public. Regulatory facts come from the hub's Procedures sheets, checked on 28 September 2026 on the authorities' websites.

This list does not replace legal advice. Each linked procedure cites its texts and its authority.

1. The company

  • Legal form chosen (OHADA legal forms).
  • Registration at the APIX Business Creation Office: RCCM and NINEA. Time announced by APIX: 48 hours (procedure).
  • Declaration of existence to the DGID within 20 days. VAT at the standard rate of 18% (procedure).
  • Trademark protected with OAPI, if the name matters (procedure).
  • Startup Act label, if you are eligible (procedure).

2. Personal data

  • Processing declared to the CDP before it starts: purposes, data, retention period, security.
  • Receipt received. Only the receipt allows processing to start. Legal time: one month for a declaration, two for an authorisation (procedure).
  • Authorisation requested for biometric, genetic or criminal data, or for linking files.

3. Hosting

  • Host chosen. Compare the offers in the directory's Hosting category.
  • Data storage location known and consistent with your CDP declaration.
  • HTTPS everywhere, certificates renewed automatically.
  • Secrets (API keys, webhook secrets) outside the source code.

4. OTP and SMS

  • Numbers validated and stored in E.164 format (recipe).
  • SMS provider chosen (directory SMS category).
  • Short code, USSD code or VAS declaration requested from ARTP if your service uses them (procedure).
  • Sending limit per number and per IP address, against abuse and unexpected costs.

5. Payment

  • Flow tested end to end in the provider's test environment.
  • Provider chosen: Wave, Orange Money, PayTech or another in the Payment category.
  • E-money framework checked: without BCEAO approval, your service partners with an approved issuer (procedure).
  • Signed webhooks verified, idempotent processing, daily reconciliation.

6. Backups

  • Automatic database backup, at least daily.
  • A copy outside the main provider.
  • Restore actually tested, with its duration written down.
  • Backup retention aligned with your CDP declaration.

7. Monitoring

  • Alert when the service stops responding.
  • Error log reviewed, without personal data in clear text.
  • Failed payment webhooks tracked.
  • Third-party API quotas tracked. The hub's API returns the RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset headers.
  • A known on-call person, and a way to reach them.

What next?