Law / Somalia

Data Protection Act No. 005 of 2023

Data Protection Act, Law No. 005 of 2023 (Federal Republic of Somalia)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Obtain a lawful basis, such as the data subject's consent, a contract, or a legal obligation, before processing personal data, and do not process further for an incompatible purpose.
  • Treat biometric data, race, clan or ethnic origin, religious belief, health status, marital status or sex life, and political opinion as sensitive personal data carrying heightened care.
  • Obtain consent from a parent or legal representative before processing a child's personal data, unless the child is sixteen or older and consenting to receive an online service at their own request.
  • Give a data subject the right to confirm, access, correct, and delete their personal data, to withdraw consent, to object to certain processing, and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  • Notify the Data Protection Authority of a personal data breach within seventy-two hours of becoming aware of it, and notify each affected data subject without undue delay where the breach poses a high risk.
  • Before transferring personal data outside Somalia, confirm the recipient country, organisation, or contractual mechanism affords an adequate level of protection, or rely on a specific ground such as the data subject's informed consent.
  • Register with the Authority and designate a data protection officer if the organisation qualifies as a data controller of major importance.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Failing to comply with an order the Authority makes under article 37 is an offence carrying a fine of up to USD 1,000,000, or its Somali currency equivalent, and imprisonment of up to two years (art. 38(1)).

Penalty structure

Administrative penalty the Authority may order against a data controller for a violation of the Act (art. 37(1)(f)); failing to comply with such an order is a separate offence under article 38 carrying the same fine plus up to two years' imprisonment.

Rule
Fixed only
As of
5 September 2026
Currency
USD
Fixed cap
1,000,000

Who enforces it

Enforcement body

Data Protection Authority

What it reaches

Obligation class

Consent, Biometric, Data subject rights, Breach notice, Transfer, Security, DPIA, Governance, Licensing

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

In January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41 elaborating the Act's provisions. Article 14 permits processing only on a lawful basis such as the data subject's consent, a contract, a legal obligation, an official function, or the data subject having intentionally made the data public, and article 15 requires purpose limitation, data minimisation, and accuracy.

Article 16 conditions a child's consent on a parent or legal representative, unless the child is sixteen or older and consenting to receive an online service at their own request, a threshold the Authority may lower to thirteen by regulation.

Articles 20 through 23 give a data subject the right to confirm, access, correct, and delete their personal data, to withdraw consent, to object to certain processing, and not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects.

Article 25 requires notifying the Authority of a personal data breach within seventy-two hours of becoming aware of it, and notifying each affected data subject without undue delay where the breach poses a high risk. Articles 30 and 31 condition a cross-border transfer on the recipient affording an adequate level of protection under a multi-factor test, or on a specific ground such as the data subject's informed consent.

Articles 32 through 34 require a data controller of major importance to register with the Authority and designate a data protection officer.

Article 37 lets the Authority order a remedy, compensation, or an administrative penalty of up to USD 1,000,000 or its Somali currency equivalent for a violation, article 38 makes failing to comply with such an order a separate offence carrying the same fine and up to two years' imprisonment, and article 40 lets an injured data subject recover damages through civil proceedings.

When LexLint raises it

  • processes_biometrics
  • automated_outreach
  • high_risk_decisions
  • crawls_web

Read the law

Text of the Data Protection Act
Law No. 005 of 2023, reproduced by DataGuidance (OneTrust), a commercial data-privacy compliance provider, rather than an official government publication the Data Protection Authority's own website names the Act but its listed download link for the Act's text is unavailable

Back to the example  ·  Lint your app