Law / Djibouti

Digital Code, Book II: Electronic Communications Network and Service Security

Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Deuxième, Art. 169

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 18 September 2025.

A sector security regimes rule binding private bodies.

As of 19 September 2026.

What it requires

  • Take all appropriate measures to ensure the integrity of your network and the continuity of the services you supply, if you operate a public electronic communications network or provide a public electronic communications service in Djibouti.
  • Take all technical and organizational measures necessary to secure your network and services at a level adapted to the existing risk, and comply with the technical security prescriptions the national cybersecurity authority issues.
  • Give the cybersecurity authority confidential access, on request, to the arrangements you have made to secure your network, and submit your network to a security and integrity inspection the authority conducts or commissions, at your own expense.
  • Where a particular risk of a security breach exists, inform your users of the risk without delay, of any available remedy, and of its cost.
  • As soon as you become aware of a security breach or integrity loss with a significant impact on your network's or service's operation, notify the cybersecurity authority and the telecoms regulator by registered letter with acknowledgement of receipt. No numeric clock is stated for this notice, unlike the 24-hour clock this jurisdiction's Digital Code sets for a trust service provider or the 72-hour clock it sets for a personal-data breach.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 169 itself states no penalty. Non-compliance is enforced through the telecoms regulator's general administrative sanctions power for the sector, an administrative financial penalty rather than a criminal charge.

Who enforces it

Enforcement body

Autorité nationale en charge de la cybersécurité (the national cybersecurity authority, which issues the technical security prescriptions and receives breach notice) and the Autorité de régulation multisectorielle de Djibouti (the telecoms regulator, which may impose an administrative financial penalty after a formal notice goes unheeded: up to 4 percent of consolidated turnover for a licence or authorization holder, and between 1,300,000 and 25,000,000 Djiboutian francs for a declarant, an agrément holder, or an alternative-infrastructure operator, doubled on repeat non-compliance, under the regulator's general Book II sanctions power).

Settledness

As of
19 September 2026
Open questions
Does the 'as soon as it becomes aware' standard for notifying the cybersecurity authority of a security breach carry any construed numeric deadline, or does it remain an unconstrued reasonableness standard?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 169 requires an operator of a public electronic communications network or a provider of a public electronic communications service to take all appropriate measures to ensure the integrity of its networks and the continuity of the services it supplies, and to take all technical and organisational measures necessary to secure its network and services at a level adapted to the existing risk.

The operator must comply with the technical security prescriptions the national cybersecurity authority issues, must give that authority confidential access to its network-security arrangements on request, and must submit to a security and integrity inspection the authority conducts or commissions, at the operator's expense.

Where there is a particular risk of a breach of its network's security, the operator must inform users of the risk without delay, together with any available remedy and its cost.

As soon as it becomes aware of a security breach or integrity loss with a significant impact on the operation of its networks or services, the operator must notify both the cybersecurity authority and the telecoms regulator by registered letter with acknowledgement of receipt, and must separately notify the cybersecurity authority where the breach results or may result from a cyberattack; the article states no numeric reporting clock for this notice, only that it follows as soon as the operator has knowledge of the breach.

When LexLint raises it

  • provides_telecom_services

Read the law

Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Deuxième, reproduced by the Journal Officiel de la République de Djibouti

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app