Loi n° 2022-59, protection des données à caractère personnel
Loi n° 2022-59 protection des données à caractère personnel, du 16 décembre 2022, telle que modifiée par la Loi n° 2023-31 du 4 juillet 2023 et les Ordonnances n° 2024-16 du 26 avril 2024 et n° 2024-29 du 24 juin 2024
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Obtain the data subject's express prior consent before processing their personal data, unless a specific legal exception applies.
- Collect personal data only for determined, explicit and legitimate purposes, and do not keep it longer than necessary for those purposes.
- Give the data subject clear information about who is processing their data and why, before processing begins.
- Obtain the HAPDP's prior authorisation before processing biometric data, and treat racial, ethnic, health, genetic, political, religious, trade-union and sex-life data as sensitive, processing it only on a ground this law lists.
- Notify the HAPDP without delay of any personal-data breach, and notify the affected person as well when the breach is likely to create a high risk to their rights.
- Let a person access, rectify, object to, limit, delete and port their personal data on request.
- Before transferring personal data outside Niger, confirm the destination country provides adequate protection, or rely on the data subject's specific consent or another listed exception.
- Appoint a data-protection correspondent (a public-sector controller appoints a focal point instead) and notify the appointment to the HAPDP.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Chapter XIV criminalises specific violations of the Act (illicit processing of sensitive data, purpose diversion, unauthorised disclosure, fraudulent collection, security failures, obstructing a data subject's rights, unlawful retention, direct marketing without consent, and obstructing the HAPDP), each punishable by imprisonment and a fine, with the heaviest bracket at three months to five years' imprisonment and 5,000,000 to 50,000,000 CFA francs (arts. 95, 99-101, 103-104).
Penalty structure
Ceiling recurring across most Chapter XIV offences (arts. 95, 99-101, 103-104): three months to five years' imprisonment and a fine of 5,000,000 to 50,000,000 CFA francs. Other named offences carry lower brackets, from three months to three years' imprisonment and 500,000 to 10,000,000 CFA francs (arts. 96-98) up to two years' imprisonment and 1,000,000 to 20,000,000 CFA francs (art. 102).
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- XOF
- Fixed cap
- 50,000,000
Who enforces it
Enforcement body
Haute Autorité de Protection des Données à caractère Personnel (HAPDP)
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Breach notice, Biometric, Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 3 binds any collection, processing, transmission, storage or use of personal data by a public or private legal person or a natural person, and article 4 extends the Act to a controller or processor established in Niger and to one established abroad that uses processing means located on Niger's territory.
Article 37 conditions lawful processing on the data subject's express prior consent, subject to exceptions for a legal obligation, a public-interest mission, a contract, or safeguarding the data subject's own interest or fundamental rights.
Article 42 prohibits processing data revealing racial, ethnic or regional origin, filiation, political opinions, religious or philosophical beliefs, trade-union membership, sex life, health, morals, genetic or biometric data, social measures, or criminal or administrative sanctions, subject to listed exceptions, and article 49 requires the HAPDP's prior authorisation before any processing of biometric data.
Article 62 bars transferring personal data to a State that does not ensure a sufficient level of protection of privacy and fundamental rights and freedoms, and requires the controller to first implement technical and organisational security measures, including encryption, before any transfer; article 63 permits a transfer to a State lacking adequate protection only on the data subject's specific, free, informed and unambiguous consent or another listed derogation.
Article 79 requires a private-sector controller to designate a data-protection correspondent within its organisation and notify the appointment to the HAPDP, while a public-sector controller designates a focal point instead. Article 83 requires a controller to notify the HAPDP of a personal-data breach without delay on becoming aware of it, and to notify the affected person as well when the breach is likely to create a high risk to their rights and freedoms.
Chapter XIV punishes a list of specific offences, including illicit processing of sensitive data, unauthorised disclosure, purpose diversion, fraudulent collection, direct marketing without consent, and obstructing the exercise of a data subject's rights, each with imprisonment of three months to five years and a fine reaching, depending on the offence, from 500,000 to 50,000,000 CFA francs, and article 110 gives a data subject a judicial remedy independent of a complaint to the HAPDP.
When LexLint raises it
processes_biometricsautomated_outreachcrawls_webtrains_models