Law / Central African Republic
Loi n° 24.001 portant protection des données à caractère personnel
Loi n° 24.001 portant protection des données à caractère personnel (janvier 2024)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A comprehensive regime rule binding public and private bodies.
As of 7 September 2026.
What it requires
- Get a lawful basis, such as consent, a contract necessity, a legal obligation, or a legitimate interest, before collecting or processing someone's personal data.
- Get a data subject's explicit consent, and apply extra security and organisational safeguards, before processing a sensitive category of data such as racial origin, biometric or genetic data, health data, or political, religious, or trade-union information.
- Get authorisation from a holder of parental responsibility before processing a minor's personal data, including for a direct offer of information-society services to a child.
- Get a person's prior consent before contacting them with direct marketing by phone, fax, SMS, email, instant message, or social network, and let them unsubscribe or change their preferences at any time.
- On request, give a person access to their data and to information about how any automated decision producing legal effects for them was reached, so they can understand and contest it.
- Designate a data-protection officer to keep the processing register, review new processing before it starts, and handle data-subject requests.
- Before transferring personal data outside the Central African Republic, confirm the destination offers a similar level of protection, or rely on one of the Act's specific derogations.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Chapitre VIII, Section 2 sets several tiers: six months to five years' imprisonment and a fine of FCFA 100,000 to 5,000,000 for obstructing the data-protection agency; six months to two years and FCFA 100,000 to 2,000,000 for negligent processing without required formalities or for unlawful retention; two to five years and FCFA 1,000,000 to 10,000,000 for fraudulent collection, misusing a file's declared purpose, processing despite a valid objection, or a disclosure harming a person's standing or privacy; doubled on repeat conduct.
Penalty structure
Administrative pecuniary sanction the data-protection agency may impose for a breach of the Act (Chapitre VIII, Section 1), doubled on repeat conduct; separate fixed criminal fines and imprisonment apply under Section 2 for specific offences (see criminal_exposure_note).
- Rule
- Turnover pct only
- As of
- 7 September 2026
- Turnover percentage cap
- 5
Who enforces it
Enforcement body
Agence en charge de la protection des données à caractère personnel (interim oversight resting with the Ministry pending the agency's formal constitution)
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Security, Governance, Reporting, Biometric
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Loi n° 24.001 applies to processing of personal data carried out by an establishment in the Central African Republic or by a processor there, whatever the technology, and to processing that produces effects in the country even where the controller is located abroad, subject to carve-outs for purely personal or domestic use and for the temporary, intermediate technical copies an access provider makes to route traffic.
The Act sets fair-processing, purpose-limitation, accuracy, proportionality, security, and retention principles, requires a lawful basis such as consent, contract necessity, a legal obligation, a legitimate interest, or a vital or public-interest ground before personal data is processed, and bars processing sensitive categories, defined to include racial origin, biometric and genetic data, health data, and political, religious, or trade-union information, except on narrow derogations such as the data subject's express consent or a public-interest research purpose.
A minor's data may be processed only with the authorisation of a holder of parental responsibility. Direct marketing by phone, fax, SMS, email, instant message, or social network requires the recipient's prior consent, and the recipient must be able to unsubscribe or change their preferences at any time.
A person may access their own data, object to its use for prospecting without justification, and obtain, when a decision producing legal effects for them rests on automated processing, information letting them understand and contest that mechanism. Every controller must designate a data-protection officer who keeps the processing register, reviews new processing before it starts, liaises with the supervisory agency, and handles data-subject requests.
A transfer of personal data outside the country needs either an adequacy-level destination or one of the Act's specific derogations (informed consent, contract necessity, an important public interest, a legal claim, or a public register), with a lighter regime for transfers to another CEMAC or CEEAC member state and prior notice to the agency for transfers elsewhere.
Breach of the Act draws an administrative sanction (warning, order to stop processing, pecuniary sanction capped at 5 percent of the controller's turnover, or withdrawal of an authorisation, doubled on repeat conduct) from the data-protection agency, and separate criminal penalties, ranging from six months to five years' imprisonment and a fine of FCFA 100,000 to FCFA 10,000,000 depending on the offence, doubled on repeat conduct, for conduct including obstructing the agency, negligent processing without required formalities, fraudulent collection, misusing a file's declared purpose, processing despite a valid objection, unlawful retention, or a disclosure that harms a person's standing or privacy.
No source confirms whether the dedicated supervisory agency has been formally constituted. The law states that it takes effect from its date of promulgation, but no legible day for that promulgation appears in the archived text.
When LexLint raises it
crawls_webtrains_modelshigh_risk_decisionsautomated_outreachprocesses_biometrics
Read the law
Text of Loi n° 24.001 portant protection des données à caractère personnel
archived copy of the Autorité de Régulation des Communications Électroniques et de la Poste (ARCEP) publication