Law / Gabon

Sécurité des systèmes d'information (dispositions communes)

Loi N° 027/2023 du 11 juillet 2023, Titre III, Chapitre III, Section 2, arts. 28-35

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 15 July 2023.

A security baseline statutes rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This binds any operator of an information system with effects in Gabon, a term Law No. 027/2023 defines without a sector or size gate as an organised set of resources that collects, groups, classifies, processes or disseminates information, and separately binds any person whose activity is to offer users access to an information system.
  • Take all technical and administrative measures necessary to guarantee the security of the services you offer, including a standardised system to identify, evaluate, treat and continuously manage the risks affecting your information systems' security.
  • Deploy technical mechanisms addressing threats to your systems' continuous availability, integrity, authentication, resistance to repudiation by third-party users, data confidentiality and physical security, and have those mechanisms cleared for conformity with the competent administrative authority's cybersecurity policy.
  • If your activity is to offer users access to an information system, inform them of the danger of using an unsecured system, the need for a parental-control device, the particular risks of a security breach, and the existence of a technical means to restrict access to certain services, and offer them at least one such means.
  • Retain your systems' connection and traffic data for ten years, and submit your networks and information systems to a mandatory, periodic security audit on terms a regulation sets.
  • Comply within six months of the law's entry into force; Article 98 does not itself state what sanction follows a late or missing compliance with this duty.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 98 gives every person concerned by the law six months from its entry into force to comply, under pain of a sanction the law does not itself specify as criminal, administrative or civil for this duty.

Who enforces it

Enforcement body

The competent administrative authority for the digital domain (autorité administrative compétente), an office the law defines only generically and does not itself name; Article 28 requires that authority's conformity clearance for the operator's security mechanisms against its own cybersecurity policy.

Settledness

As of
18 September 2026
Open questions
What specific administrative, civil or criminal sanction attaches to a failure of the Article 28 to 35 duty, given Article 98 threatens an unspecified sanction after a six-month grace period but names no fine, scale or procedure for this duty?

What it reaches

Obligation class

Security, Governance, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Articles 28 to 35 of Law No. 027/2023 require any operator of an information system, a term the law defines without any sector or size gate as an organised set of resources that collects, groups, classifies, processes or disseminates information, to take all technical and administrative measures necessary to guarantee the security of the services it offers.

Each operator must adopt standardised systems to identify, evaluate, treat and continuously manage the risks affecting its information systems' security, and must deploy technical mechanisms addressing threats to the systems' continuous availability, integrity, authentication, resistance to repudiation by third-party users, data confidentiality and physical security, with those mechanisms subject to a conformity clearance from the competent administrative authority on its cybersecurity policy.

A person whose activity is to offer users access to an information system must inform them of the danger of using an unsecured system, the need for a parental-control device, the particular risks of a security breach, and the existence of a technical means to restrict access to certain services, and must offer at least one such means. An operator of an information system must retain its connection and traffic data for ten years.

Its networks and information systems are also subject to a mandatory, periodic security audit on terms a regulation sets. Article 98 gives every person concerned by the law six months from its entry into force to comply, under pain of sanctions the article does not itself specify.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official gazette text, Journal Officiel de la République Gabonaise N°218 BIS, 15 July 2023
read through an Internet Archive mirror because the live journal-officiel.ga page returned no usable text on a direct request

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://journal-officiel.ga/20087-027-2023-/

Back to the example  ·  Lint your app