Law / Madagascar

Law No. 2014-038, CMIL, sanctions and offences

Loi n° 2014-038, arts. 4, 28-42, 50, 55-60, 61-73 (commission, contrôle, sanctions et pénalités)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 9 January 2015.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Comply with any warning, injunction to stop processing, withdrawal of authorization, or monetary sanction the CMIL orders after an adversarial procedure, and with any urgent interruption or data-locking order it issues for up to three months.
  • Give CMIL inspectors on a control mission access to your premises between six in the morning and seven at night, unrestricted access to your files, processing, and equipment, and copies of any information they request.
  • Expect a monetary sanction proportioned to the seriousness of the breach and the advantage drawn from it, capped at five percent of your pre-tax turnover for the last closed financial year, doubling on a repeat offense.
  • Expect criminal prosecution on top of any administrative sanction: unlawfully collecting personal data or disclosing it in a way that harms someone's reputation or privacy carries two to five years' imprisonment and a fine of 1,000,000 to 10,000,000 Ariary, and the other offenses in articles 61 to 70 carry six months to five years' imprisonment and a fine of 200,000 to 8,000,000 Ariary depending on the offense.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Articles 61 to 71 criminalize specific breaches of the Act, each punished by six months' to five years' imprisonment together with a fine ranging from 200,000 to 10,000,000 Ariary depending on the offense; unlawfully collecting personal data by fraudulent or unfair means (art. 65) and disclosing data in a way that harms a person's reputation or privacy (art. 71) each carry two to five years' imprisonment and a fine of 1,000,000 to 10,000,000 Ariary.

Penalty structure

Article 59 caps the monetary sanction the CMIL may impose under article 55 at five percent of the pre-tax turnover of the last closed financial year, with no fixed monetary ceiling stated for it, doubling on a repeat offense under article 55's final paragraph. Criminal penalties are separate and fixed: articles 61 to 71 punish specific unlawful acts with six months' to five years' imprisonment and a fine of 200,000 to 10,000,000 Ariary depending on the offense, topping out at 10,000,000 Ariary for unlawful collection (art. 65) and privacy-harming disclosure (art. 71).

Rule
Turnover pct only
As of
19 September 2026
Turnover percentage cap
5

Who enforces it

Enforcement body

Commission Malagasy de l'Informatique et des Libertés (CMIL)

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 4 subjects compliance with the law's principles to the oversight of an independent Authority named the Commission Malagasy de l'Informatique et des Libertés (CMIL). Article 28 creates that Commission, charges it with seeing that processing operations comply with the law, and gives it regulatory and sanctioning power.

Articles 29 to 42 set the Commission's structure and operation: its members are appointed by decree in the Council of Ministers for a four-year term renewable once, are bound to professional secrecy and take an oath before the Supreme Court, enjoy immunity for opinions and acts within their mandate, receive no instruction from any authority, publish an annual activity report to the President, the Prime Minister, Parliament, and the Minister of Justice, face incompatibilities with government membership or a conflicting management role, and must recuse themselves from a matter touching an organization they were tied to in the past thirty-six months.

The Commission informs people and controllers of their rights and obligations, receives processing declarations and gives the opinions or authorizations the law requires, controls how processing is created and carried out, publishes simplified norms and exemptions, makes recommendations, sets model rules for information-system security, and receives complaints, and its administrative decisions are open to appeal before the Conseil d'Etat.

Article 50 lets Commission members and agents on a control mission, authorized by a mission order the president signs, access professional premises between six in the morning and seven at night, access files, processing, and equipment without restriction, take copies of any information, and collect statements, subject to a written record given to the controller and, where the premises' occupant objects, the authorization of the competent tribunal's president.

Article 55 lets the Commission, after an adversarial procedure, sanction a controller who breaches one or more provisions of the law with a warning, an injunction to stop processing or withdrawal of an authorization granted, or a monetary sanction, and lets it order urgent interruption or the locking of data for up to three months where a rights violation is occurring, with every sanction recorded in a register and a repeat offense doubling a monetary sanction.

Article 59 caps a monetary sanction at five percent of the pre-tax turnover of the last closed financial year, proportioned to the seriousness of the breach and the advantage drawn from it. Article 60 lets the Commission publish its sanction decisions, anonymizing a natural person's identity where it chooses, at the sanctioned person's expense.

Articles 61 to 71 criminalize specific breaches of the law, each punished by six months' to five years' imprisonment together with a fine ranging from 200,000 to 10,000,000 Ariary depending on the offense; unlawfully collecting personal data by fraudulent or unfair means (art. 65) and disclosing data in a way that harms a person's reputation or privacy (art. 71) each carry two to five years' imprisonment and a fine of 1,000,000 to 10,000,000 Ariary.

Article 72 lets a court order the erasure of the data involved in the offense, which Commission members and agents are empowered to verify.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • is_listed_company

Read the law

Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)
not an official government-published copy

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app