Law /
Central African Republic
Loi n° 24.001 portant protection des données à caractère personnel, collecte de données publiquement accessibles et transfert transfrontalier
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A personal data rule binding public and private bodies.
As of 22 September 2026.
What it requires
- Before relying on data a person has made freely accessible as your lawful basis for collecting it, confirm your use fits the context in which the person made it accessible; freely accessible data supports the legitimate-interest basis but is not an exemption from the Act's other duties.
- Before transferring personal data you collected in the Central African Republic, or personal data about a person there, to another country, confirm the destination offers a similar level of protection or rely on one of the Act's specific derogations.
- Give the data protection agency prior notice before transferring personal data to a State outside the CEMAC or CEEAC, and rely on the agency's authorization, supported by appropriate contractual guarantees, where the destination lacks equivalent protection.
- Get the data subject's explicit consent, or rely on one of the Act's other listed derogations, before collecting or processing a sensitive category of data such as biometric, genetic, health, political, religious, or criminal-record data, whatever the source.
What it reaches
Obligation class
Consent, Transfer, Biometric
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Loi n° 24.001 reaches personal data wherever a controller finds it, including data a person has made publicly accessible online. A data subject who has made their own personal data freely accessible supports a controller's reliance on the legitimate-interest lawful basis for processing it, provided the use fits the context in which the person made the data accessible, but the Act does not state that publicly accessible data falls outside its scope or its other duties.
A controller may transfer personal data, wherever it was collected, to a foreign State only where that State's own legislation ensures a level of protection similar to the one this Act assures, or under one of the Act's listed derogations, the data subject's informed and unambiguous consent, a contract's necessity, an important public interest or legal claim, a vital interest, or a public register.
A transfer to a State outside the CEMAC or CEEAC needs the controller to give the data protection agency prior notice before the transfer, and absent an equivalent level of protection there the agency may still authorize it where the controller offers sufficient contractual guarantees.
Sensitive categories of personal data, including biometric, genetic, health, political, religious, and criminal-record data, may be processed only on the data subject's explicit consent or one of the Act's other listed derogations, whatever the source from which a controller obtained them.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometrics
Read the law
Text of Loi n° 24.001 portant protection des données à caractère personnel
archived copy of the Autorité de Régulation des Communications Électroniques et de la Poste (ARCEP) publication
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDFEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.