Law No. 2014-038, protection of personal data
Loi n° 2014-038 sur la protection des données à caractère personnel
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 9 January 2015.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not base a judicial decision assessing a person's conduct on automated profiling at all, and do not base an administrative or private decision assessing a person's conduct solely on automated profiling.
- Collect and process personal data fairly and lawfully, for determined and legitimate purposes, and keep it no longer than those purposes require.
- Have the data subject's consent, or another of the five lawful grounds in article 17, before processing personal data.
- Do not process sensitive data, including biometric, genetic, health, or sex-life data, unless a listed exception applies, such as the data subject's express consent.
- Take security precautions appropriate to the data and the risk, to prevent unauthorized access, alteration, loss, or disclosure.
- Before transferring personal data to a foreign state, confirm that state offers similar protection, or obtain CMIL authorization or rely on one of the law's listed exceptional grounds.
- Honour a data subject's request to access, rectify, or object to the processing of their personal data.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Articles 61 to 71 criminalize specific breaches of the Act, each punished by six months' to five years' imprisonment together with a fine ranging from 200,000 to 10,000,000 Ariary depending on the offense; unlawfully collecting personal data by fraudulent or unfair means (art. 65) and disclosing data in a way that harms a person's reputation or privacy (art. 71) each carry two to five years' imprisonment and a fine of 1,000,000 to 10,000,000 Ariary.
Penalty structure
Highest tier among articles 61 to 71 (arts. 65 and 71: unlawful collection and privacy-harming disclosure). Lesser breaches, such as processing without the CMIL's required prior formalities (art. 62) or failing to secure data (art. 64), carry a lower fine of 200,000 to 2,000,000 Ariary with the same imprisonment range; the applicable tier depends on which duty was breached.
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- MGA
- Fixed cap
- 10,000,000
Who enforces it
Enforcement body
Commission Malagasy de l'Informatique et des Libertés (CMIL)
What it reaches
Obligation class
Consent, Biometric, Data subject rights, Transfer, Retention, Security, Disclosure, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 3 bars a judicial decision assessing human conduct from resting on automated profiling at all, and bars an administrative or private decision assessing human conduct from resting solely on automated profiling. Article 5 applies the law to any automated or manual processing of personal data carried out in whole or in part on Malagasy territory, excluding only purely personal or household activity and journalistic, literary, or artistic activity.
Article 14 requires that personal data be collected and processed fairly and lawfully for determined, explicit, and legitimate purposes, kept adequate and not excessive, kept accurate, and kept no longer than the purpose requires. Article 15 requires the controller to take precautions appropriate to the data's nature and the risks involved to preserve security against accidental or unlawful destruction, accidental loss, alteration, disclosure, or unauthorized access.
Article 17 requires the data subject's consent or one of five alternative lawful grounds: a legal obligation, safeguarding the data subject's life, a public-service mission, performance of a contract, or the controller's or recipient's legitimate interest, subject to the data subject's own rights and interests.
Article 18 prohibits processing sensitive data, defined to include racial origin, biometric data, genetic data, political opinions, religious or other convictions, trade union membership, and health or sex-life data, subject to listed derogations including the data subject's express consent.
Article 20 bars transferring personal data to a foreign state unless that state offers a similar level of protection, though the CMIL may authorize a transfer where the controller offers sufficient guarantees, and the law lists further exceptional grounds including the data subject's informed consent to the transfer. Articles 22, 23, and 25 give a data subject the right to object on legitimate grounds, the right to access their own data, and the right to have it rectified.
Articles 28 and 29 create the Commission Malagasy de l'Informatique et des Libertés (CMIL) as the independent authority enforcing the law, with regulatory and sanctioning power.
When LexLint raises it
processes_biometricshigh_risk_decisions
Read the law
Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)
not an official government-published copy