Law /
Central African Republic
Loi n° 24.001 portant protection des données à caractère personnel, flux transfrontalier
Loi n° 24.001, Chapitre III (flux transfrontalier)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A cross border transfer rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Before transferring personal data outside the Central African Republic, confirm the destination offers a similar level of protection, or rely on one of the Act's specific derogations.
- Assess the destination's level of protection against the nature of the data, the purpose and duration of the processing, the countries of origin and destination, and the legal, professional, and security rules it applies, before any transfer.
- Do not let a recipient in a foreign State transfer the data onward to another State without your agreement as the original controller.
- Give the agency prior notice before transferring personal data to a State outside the CEMAC or CEEAC, and rely on the agency's authorization, supported by appropriate contractual clauses, where the destination lacks equivalent protection.
What it reaches
Obligation class
Transfer, Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A controller may transfer personal data to a foreign State only where that State's legislation ensures a level of protection similar to the one this Act assures, assessed against the nature of the data, the purpose and duration of the processing, the countries of origin and destination, and the rules the third country applies.
Absent a similarly protective destination, a transfer may still go ahead where the person concerned, informed of the gap, has unambiguously consented, where it is necessary to perform a contract with or for the person or pre-contractual measures at their request, where a law requires it to safeguard an important public interest or a legal claim, where it safeguards the person's vital interest, or where it comes from a public register open to a person with a legitimate interest.
A recipient may not transfer the data onward to another State without the original controller's agreement. For a transfer to a State outside the CEMAC or CEEAC that does not assure an identical level of protection, the agency may still authorize it where the controller offers sufficient guarantees for privacy and fundamental rights, including through appropriate contractual clauses, and that authorization may be renewed on request.
A transfer to another country outside the CEMAC or CEEAC needs a sufficient level of protection there too, the controller must give the agency prior notice before any such transfer, and absent adequate protection the transfer may still proceed on the person's unambiguous consent, a contract's necessity, an important public interest or legal claim, or a public register.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotships_mobile_app
Read the law
Text of Loi n° 24.001 portant protection des données à caractère personnel
archived copy of the Autorité de Régulation des Communications Électroniques et de la Poste (ARCEP) publication
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDFEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.