Law / Comoros

Law on the Protection of Personal Data

Loi n° 14-029/AU portant protection des données à caractère personnel deliberated and adopted by the Assemblée de l'Union des Comores in plenary session on 26 June 2014

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A comprehensive regime rule binding public and private bodies.

As of 7 September 2026.

What it requires

  • Have a lawful basis, generally the data subject's express consent, before collecting or processing their personal data.
  • Do not collect or process data revealing political, philosophical, or religious opinions, trade-union membership, health, or sexual-life data without the data subject's express consent.
  • Obtain the Commission Nationale de l'Informatique et des Libertés's prior authorization before processing biometric data used to verify a person's identity.
  • Declare automated personal-data processing to the Commission before implementing it, unless a specific exemption applies.
  • Give the data subject access to the personal data collected about them.
  • Do not transfer personal data to a foreign state unless that state ensures a sufficient level of protection for privacy and fundamental rights and freedoms.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Article 65 punishes every offense article 64 lists (obstructing the Commission, processing without required formalities, unauthorized processing of sensitive or national-identification data, fraudulent collection, unauthorized disclosure harming a person's privacy, among others) with five to ten years' imprisonment and a fine of 10,000,000 to 35,000,000 Comorian francs, or either penalty alone; attempt and complicity draw the same penalties.

Penalty structure

Article 65's fine applies to every article 64 offense, alternatively or cumulatively with five to ten years' imprisonment; the law does not scale the fine to turnover or to a per-violation count.

Rule
Fixed only
As of
7 September 2026
Minimum
10,000,000
Currency
KMF
Fixed cap
35,000,000

Who enforces it

Enforcement body

Commission Nationale de l'Informatique et des Libertés (CNIL)

What it reaches

Obligation class

Consent, Data subject rights, Transfer, Security, Biometric

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The law governs any automated or manual processing of personal data and creates the Commission Nationale de l'Informatique et des Libertés (CNIL) as an independent regulator with its own legal personality.

It bars processing data revealing political, philosophical or religious opinion, trade-union membership, health, or sexual life without the data subject's express consent, subjects biometric identity-verification processing and national-population-scale processing to the Commission's prior authorization, and requires most other automated processing to be declared to the Commission before it begins.

A controller must give the data subject access to their data, and may transfer personal data abroad only to a state assuring a sufficient level of protection for privacy and fundamental rights.

Ministers, public authorities, and public or private enterprise directors alike may not obstruct the Commission's action, which can impose a warning, a pecuniary sanction, an injunction to stop processing, withdrawal of an authorization, or a data lock, in addition to the criminal penalties article 65 attaches to the offenses article 64 lists.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics

Read the law

Text of Loi n° 14-029/AU reproduced by ANADEN (Agence Nationale de Développement du Numérique), the Comorian digital-development agency

Back to the example  ·  Lint your app