Law / Djibouti

Digital Code, Book VII: National Health Data System Security Incident Reporting

Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Septième, Art. 747

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 18 September 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Report a serious information-system security incident to the cybersecurity authority without delay, if you access data in Djibouti's national health data system as a health professional, health establishment, health-insurance financing body, or other body accessing that system.
  • Expect a significant security incident to be separately and immediately transmitted by the national authority in charge of information systems to the State's competent authorities.
  • No numeric reporting clock is stated for this duty; a decree defining which incidents count as significant, and how they are handled, was not located in this review.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 747 states no penalty for a failure to report.

Who enforces it

Enforcement body

Autorité de la cybersécurité (the cybersecurity authority, which receives the report); the autorité nationale en charge des systèmes d'information (which transmits a significant incident to the State's competent authorities).

What it reaches

Obligation class

Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 747 requires any person accessing data in Djibouti's national health data system, a category that reaches citizens, health-system users, health professionals, health establishments and their representative organisations, health-insurance financing bodies, State services and public health institutions under the surrounding Chapter, to report a serious information-system security incident to the cybersecurity authority without delay.

An incident the national authority in charge of information systems judges significant is separately and immediately transmitted to the State's competent authorities. A decree, proposed by the minister in charge of the digital economy after the cybersecurity authority's opinion, is to define which categories of security incident count as significant and how they are handled; that decree was not located in this review. The article states no numeric reporting clock, only that notice is given without delay.

When LexLint raises it

  • handles_health_records

Read the law

Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Septième, reproduced by the Journal Officiel de la République de Djibouti

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app