Digital Code, Book I: Personal Data Protection and CNDP
Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Premier (Arts. 2 à 156)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 12 months, effective 18 September 2025.
A comprehensive regime rule binding public and private bodies.
As of 7 September 2026.
What it requires
- Obtain a lawful basis, most often the data subject's express, unambiguous, free, specific and informed consent, before processing their personal data.
- Do not process sensitive personal data (racial or ethnic origin, political or philosophical opinions, religious opinions or beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, or health data) without the data subject's express consent or another statutory ground.
- Do not base a decision that produces legal effects on a person, or significantly affects them, solely on automated processing of their personal data, including profiling, unless a statutory or consent-based exception applies with human-intervention, expression and contestation safeguards.
- File a prior declaration with, or obtain the prior authorization of, the Commission Nationale de Protection des Données à Caractère Personnel before processing personal data, depending on the processing's risk category.
- Notify the Commission of a personal-data breach within 72 hours of becoming aware of it, and notify the affected individual without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
- Do not transfer personal data to a country or international organization outside Djibouti unless it offers an adequate level of protection or another authorized safeguard applies.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Chapter 6 of Book I (Articles 141 to 154) criminalises non-compliance with prior formalities, unauthorized processing of the national identification number, processing sensitive or offence-related data outside the statutory grounds, fraudulent collection, misuse of purpose, unauthorized transfer, disregarding an objection, failing to secure or notify a breach, retaining data beyond its legal duration, and unauthorized disclosure. Most of these draw 5 to 10 years' imprisonment and a fine of 7,000,000 to 35,000,000 Djiboutian francs; unauthorized processing of the national identification number draws 5 years and a fixed 4,000,000 francs; and a negligent (rather than intentional) unauthorized disclosure draws 5 years and a fixed 7,000,000 francs.
Penalty structure
Article 135's Commission-imposed administrative sanction: up to 70,000,000 Djiboutian francs or, for an enterprise, 5% of its worldwide annual turnover excluding tax for the last closed financial year, whichever is higher, plus a daily penalty payment of up to 35,000,000 francs for continued non-compliance with a formal notice. This is distinct from Chapter 6's criminal fines (7,000,000 to 35,000,000 francs typically, as low as 4,000,000 francs for the national-identification-number offence), which accompany imprisonment and are recorded in criminal_exposure_note.
- Rule
- Higher of
- As of
- 7 September 2026
- Currency
- DJF
- Fixed cap
- 70,000,000
- Turnover percentage cap
- 5
Who enforces it
Enforcement body
Commission Nationale de Protection des Données à Caractère Personnel (CNDP)
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Licensing, Breach notice, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 3 applies the book to automated and manual processing of personal data carried out by the State, a local authority, a public or private legal person, or a natural person. Article 4 extends it extraterritorially to a controller or processor not established in Djibouti that offers goods or services to, or monitors the behaviour of, persons in Djibouti.
Article 5 exempts only purely domestic or personal processing not intended for onward communication, and temporary technical copies made for network transmission. Article 54 sets the lawfulness, fairness, transparency, purpose-limitation and minimisation principles, and Article 57 requires an express, unambiguous, free, specific and informed consent wherever consent is the ground relied on.
Article 59 lets a minor consent alone to an information-society service's processing of their personal data only from age 16, and requires parental consent below that age, which the controller must make reasonable efforts to verify given the technology available.
Article 62 prohibits processing racial or ethnic origin, political or philosophical opinions, religious opinions or beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, or health data, subject to ten enumerated exceptions including express consent, data the person has manifestly made public, and vital-interest or public-health grounds.
Article 65 bars a decision producing legal effects on a person, or significantly affecting them, from resting solely on automated processing of their personal data, including profiling, unless the decision is authorised by law with appropriate safeguards, or rests on explicit consent or contract performance together with the right to human intervention, to express a point of view, and to contest the decision.
Articles 14 and 15 require the controller to notify the CNDP of a personal-data breach without undue delay and at latest within 72 hours of becoming aware of it, and to notify the affected individual without undue delay where the breach is likely to result in a high risk to their rights and freedoms, unless the data was rendered unintelligible, the risk has been neutralised, or notification would require disproportionate effort.
Articles 66 to 73 subject processing to a prior declaration, a simplified declaration, or the CNDP's prior authorisation depending on its risk category. Articles 99 to 102 bar transferring personal data to a country or international organisation outside Djibouti unless the CNDP has found its level of protection adequate, or the controller relies on an alternative safeguard the CNDP authorises.
Article 104 establishes the CNDP as an independent administrative authority, and Article 135 arms it to impose an administrative sanction of up to 70,000,000 Djiboutian francs or, for an enterprise, 5% of worldwide annual turnover excluding tax for the last closed financial year, whichever is higher, plus a daily penalty payment of up to 35,000,000 Djiboutian francs for continued non-compliance with a formal notice.
Chapter 6 (Articles 140 to 156) separately criminalises non-compliance with the prior-formalities regime, unauthorised processing of the national identification number, processing sensitive or offence-related data outside the statutory grounds, fraudulent collection, misuse of purpose, unauthorised transfer, disregarding an objection, failing to secure or notify a breach, retaining data beyond its legal duration, and unauthorised disclosure, most of these punishable by 5 to 10 years' imprisonment and a fine of 7,000,000 to 35,000,000 Djiboutian francs, with narrower tiers for the national-identification-number offence (5 years and 4,000,000 francs) and for a negligent unauthorised disclosure (5 years and a fixed 7,000,000 francs).
When LexLint raises it
crawls_webtrains_modelshigh_risk_decisionsprocesses_biometrics