This paper examines the development, structure, and enforcement of data protection frameworks across Southern Africa and selected island jurisdictions, namely South Africa, Botswana, Namibia, Zimbabwe, Zambia, Eswatini, Lesotho, Malawi, Mozambique, Seychelles, Mauritius and Madagascar. It analyzes how each jurisdiction regulates personal data, defines core concepts, protects data subject rights, imposes obligations on controllers and processors, and manages enforcement and cross-border data flows. The paper delineates trends of alignment with global data protection standards, while also highlighting notable discrepancies in institutional capacity, regulatory scope, and enforcement sophistication. It argues that while statutory adoption has accelerated across the region, effective protection depends less on legislative form and more on regulatory authority, enforcement practice, and political commitment. The paper contributes to comparative African data protection scholarship by offering a structured, jurisdiction-by-jurisdiction assessment within a single analytical framework.