Law / Gabon

Law No. 025/2023, personal-data breach notification

Loi n°025/2023, articles 142 à 147 (violation de données à caractère personnel)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 15 July 2023.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the APDPVP without delay of a personal-data breach, describing its nature, the categories and approximate number of data subjects and records concerned where possible, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed to address it; the law sets no numeric deadline for this notice.
  • Accompany a notification to the APDPVP with supporting evidence of the breach.
  • As a processor, notify the controller without delay of a personal-data breach as soon as you become aware of it.
  • Where a breach is likely to create a high risk to a person's rights and freedoms, inform the affected person as soon as possible, in clear and simple terms, giving at least the same information given to the APDPVP.
  • Skip that communication to the person only where you had already applied protective measures rendering the affected data unintelligible, where later measures mean the high risk is no longer likely to materialize, or where it would take disproportionate effort, in which case make a public communication of equal effect instead; expect the APDPVP to be able to compel direct communication anyway after weighing the breach's gravity.
  • Keep an up-to-date register of every personal-data breach, its circumstances, its impact and the remedial measures taken, and make it available to the APDPVP.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 142 requires the controller, on a personal-data breach, to inform the APDPVP without delay, giving the breach's nature, the categories and approximate number of data subjects and records concerned where possible, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed to remedy it; article 143 requires supporting evidence of the breach to accompany that notice.

The law states no numeric deadline for this notice: it runs 'sans délai', without delay, rather than within a stated number of hours or days. Article 144 requires a processor to notify the controller of any breach without delay as soon as it becomes aware of it.

Article 145 requires the controller, where a breach is likely to create a high risk to a person's rights and freedoms, to inform that person as soon as possible, and article 146 requires the communication to describe the breach in clear and simple terms and to carry at least the information article 142 lists for the Authority.

Article 147 excuses that communication to the person only where the controller had already applied protective measures rendering the affected data unintelligible, where later measures mean the high risk is no longer likely to materialize, or where it would take disproportionate effort, in which case a public communication of equal effect substitutes for it; the APDPVP can still compel direct communication after weighing the breach's gravity.

Article 147 also requires every controller to keep an up-to-date register of personal-data breaches, their circumstances, their impact and the remedial measures taken, available to the APDPVP.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • operates_essential_service

Read the law

Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à…
Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à caractère personnel, Journal Officiel de la République Gabonaise

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2025. Publisher's page: https://journal-officiel.ga/20085-025-2023-/

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app