Law / Burundi

Loi n° 1/10, Articles 3, 4(3) and 14: security-of-service duty and diligence penalty for network operators and service providers

Loi n° 1/10 du 16 mars 2022 portant prevention et repression de la cybercriminalite au Burundi, Arts. 3, 4(3), 14

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 16 March 2022.

A sector security regimes rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This binds you only if you are an opérateur des réseaux (network operator) or fournisseur des services under Burundian law, defined at Art. 2(11) as any natural or legal person providing one or more services to users of a telecommunication system.
  • Guarantee the security of the services you offer, and put in place the technical processes and means needed to fight cyber fraud.
  • Maintain an operational management center for your critical infrastructure on Burundian national territory.
  • Exercise the diligence and competence necessary to prevent the disclosure of computer data you hold on behalf of a third party, or face a fine of 10,000,000 to 30,000,000 Burundian francs (BIF) under Article 14.
  • Article 4 also states three further common obligations this row does not flag as a security duty: retain connection and traffic data for at least ten years, install mechanisms to monitor your own network's data traffic, and, if you operate a cybercafé, install a video-surveillance system; these read as data-retention, surveillance-capability, and physical-security mandates rather than a duty over your systems' or services' own security posture.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 14's fine is imposed as an infraction under Chapitre III (offenses against the confidentiality, integrity and availability of data and systems); unlike most neighboring articles in the same chapter, it carries no additional servitude pénale (prison term).

Penalty structure

Article 14 sets a fine of ten to thirty million Burundian francs (BIF) for a service provider or network operator that fails to exercise the diligence and competence necessary to prevent disclosure of computer data made available to a third party; no additional imprisonment attaches to this article.

Rule
Fixed only
As of
19 September 2026
Minimum
10,000,000
Currency
BIF
Fixed cap
30,000,000

Who enforces it

Enforcement body

No cybersecurity or telecommunications regulator is named in the Act as holding supervisory or enforcement authority over these provisions. Chapitre VII's criminal-procedure articles (Arts. 65-68) route investigation through 'l'autorité compétente' and the Officier du Ministère Public, and Article 14 is prosecuted as an ordinary criminal offense through the courts rather than through a dedicated regulator.

Settledness

No implementing decree or ARCT regulation elaborating Article 3's or Article 4's technical requirements was located in the sources reviewed here.

As of
19 September 2026
Open questions
  • Has any decree or ARCT regulation specified the technical processes and means Article 3 requires a network operator or service provider to put in place to guarantee service security and fight cyber fraud?
  • Does Article 14's fine attach only to the disclosure-diligence duty stated there, or does an unlocated implementing text also set a penalty for the retention, traffic-monitoring, or cybercafé video-surveillance duties Article 4 states separately?

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 requires every opérateur des réseaux (network operator) and fournisseur des services (service provider) to guarantee the security of the services it offers and to put in place the technical processes and means needed to fight cyber fraud. Article 2(11) defines a fournisseur des services as any natural or legal person providing one or more services to users of a telecommunication system.

Article 4 additionally requires the same bound parties to maintain an operational management center for their critical infrastructure on Burundian national territory. Article 4 also requires retaining connection and traffic data for a minimum of ten years. It requires installing mechanisms to monitor the operator's own network traffic data.

It requires installing a video-surveillance system in cybercafés. These three obligations read as data-retention, surveillance-capability, and physical-security duties rather than a security-posture requirement for a system or service, so this row flags only the Article 3 and Article 4(3) duties as its activity.

Article 14 imposes a fine of ten to thirty million Burundian francs on a service provider or network operator that fails to exercise the diligence and competence necessary to prevent the disclosure of computer data made available to a third party. No additional imprisonment attaches to Article 14, unlike most neighboring articles in the same chapter.

When LexLint raises it

  • provides_telecom_services

Read the law

Loi n° 1/10 du 16 mars 2022, official text as hosted by ARCT (arct.gov.bi)
the PDF has no text layer and was read by Surya OCR under a leased GPU rather than by plain PDF text extraction

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app