Loi n° 2022-59, transfert transfrontalier des données
Loi n° 2022-59, arts. 62-63 (transfert des données vers un autre État)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A cross border transfer rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Before transferring personal data to another State, confirm that State ensures a sufficient level of protection for privacy and fundamental rights and freedoms, weighing its data-protection laws and regulations, the existence of a protection authority, applicable international conventions, or HAPDP-approved safeguards.
- Before any transfer, implement technical and organisational security measures, including encryption and measures for availability, confidentiality, integrity and system resilience, and obtain the HAPDP's authorisation for the transfer.
- Expect the HAPDP to be able to withdraw its transfer authorisation at any time if exceptional circumstances arise in the destination country.
- Where the destination State does not ensure adequate protection, transfer personal data only on the data subject's specific, free, informed and unambiguous consent after telling them the risks, or under another listed ground such as a vital or public interest, a law or treaty applied after the HAPDP's opinion, or a HAPDP-approved contract or binding corporate rules.
What it reaches
Obligation class
Transfer, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 62 bars transferring personal data to another State unless that State ensures a sufficient level of protection for privacy and fundamental rights and freedoms, assessed by its data-protection laws, regulations and the existence of a protection authority, or by the international conventions it has joined or safeguards the HAPDP has approved, and requires the controller to first implement technical and organisational security measures, including encryption, availability, confidentiality, integrity and system resilience, and to obtain the HAPDP's authorisation before the transfer.
The HAPDP may withdraw that authorisation at any time if exceptional circumstances arise in the destination country.
Article 63 permits a transfer to a State that does not ensure adequate protection only where the data subject gave specific, free, informed and unambiguous consent after being told the risks of the missing safeguards, the transfer safeguards a vital or public interest, a law or regulation authorises it after the HAPDP's opinion, a bilateral or multilateral agreement Niger has joined applies, a HAPDP-approved contract or binding corporate rules guarantee adequate protection, or the transfer serves a legal claim or a contract in the data subject's interest.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.