Law / Central African Republic

Loi n° 24.001 portant protection des données à caractère personnel, données sensibles et mineurs

Loi n° 24.001, Chapitre Ier Section 2 et Chapitre II (données sensibles et mineurs)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A sensitive categories rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Get a data subject's explicit consent, and apply extra security and organisational safeguards, before processing a sensitive category of data such as racial origin, biometric or genetic data, health data, or political, religious, or trade union information.
  • Get authorisation from a holder of parental responsibility before processing a minor's personal data, including for a direct offer of information society services to a child.
  • Do not process sensitive data at all unless a listed derogation applies: the person's express consent unless a law bars it, safeguarding a life, a non profit body's own member processing for its religious, philosophical, political, or trade union purpose, establishing or defending a legal claim, health care or public interest health research, data the person made public, a law authorizing a public interest purpose, or a labor law right or obligation.
  • Restrict processing of data about a person's offences, convictions, or safety measures to courts and public authorities acting within their legal powers, and to legal auxiliaries strictly for the duties assigned to them by law.
  • When a processing activity involves sensitive data or a particularly vulnerable person's data, put additional organizational and technical safeguards in place and give that person heightened information before you process it.

What it reaches

Obligation class

Prohibition, Consent, Biometric

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Loi n° 24.001 defines sensitive data as personal data relating to religious, philosophical, or political opinions or activities, sexual life or orientation or racial life, health, including genetic or biometric data, social measures, prosecutions, and criminal or administrative sanctions. A minor's data may be processed only where consent for it is given or authorized by a holder of parental responsibility over the child, including for a direct offer of information society services to children.

Where a processing activity engages sensitive data or the data of a particularly vulnerable person, including a minor, the controller must take every additional appropriate organizational and technical measure to protect the person concerned, and consent must in every case be explicit and require an affirmative act.

Processing sensitive data is otherwise prohibited because of the risk of discrimination or of harming a person's freedoms, covering data revealing racial origin, biometric and genetic data, political opinions, religious or other convictions, trade union membership, and health or sexual life.

By derogation, sensitive data may be processed with appropriate safeguards where the person concerned has given express consent unless a law says otherwise, where processing is necessary to safeguard the life of the person concerned or a third party who cannot consent, where it is carried out by a non profit religious, philosophical, political, or trade union body about its own members without third party disclosure, where it is necessary to establish, exercise, or defend a legal claim, where it serves preventive medicine, diagnosis, care, or health service management by a health professional, where the data were made public by the person concerned, where a law authorizes it for a public interest purpose, or where a labor law right or obligation requires it.

Data about a person's offences, convictions, and safety measures may be processed only by courts and public authorities acting within their legal powers, and by legal auxiliaries strictly for the duties the law assigns them.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice
  • serves_minors
  • handles_health_records

Read the law

Text of Loi n° 24.001 portant protection des données à caractère personnel
archived copy of the Autorité de Régulation des Communications Électroniques et de la Poste (ARCEP) publication

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDF

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app