Loi n°007/PR/2015, sanctions administratives et pénales et recours
Loi n°007/PR/2015 du 10 février 2015, arts. 80-94
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 10 February 2015.
An enforcement supervision rule binding public and private bodies.
As of 7 September 2026.
What it requires
- Comply with an ANSICE warning or formal notice to cease a failure within the period ANSICE sets, on pain of a regulatory penalty and, for the underlying violation, criminal prosecution.
- Meet the collection, purpose-limitation, sensitive-category, information, access-response, notification, declaration, and cross-border transfer conditions the law sets, each of which carries its own criminal exposure on breach.
- Do not obstruct ANSICE, its members, or the experts it requires in exercising their verification powers.
- Compensate a person harmed by unlawful processing or any act inconsistent with the law, unless the harmful act is proven not attributable to the controller.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Article 82 punishes an ANSICE member, staff member, or expert's breach of confidentiality, and article 83 punishes a controller, representative, employee, or agent's failure to meet the confidentiality and security obligations of articles 59-61, each with three months to one year's imprisonment and a fine of 1,000,000 to 10,000,000 CFA francs, or one of those two penalties alone. Article 84 imposes the same three-months-to-one-year, 1,000,000-to-10,000,000-CFA-franc range on a controller, representative, employee, or agent who violates the collection and purpose-limitation conditions (arts. 8-12), the sensitive-category conditions (arts. 16-24), the information duty (art. 35), the notification formalities (art. 65), or the cross-border transfer conditions (arts. 29/31), who mishandles an access request (art. 38) or an article 70 declaration, or who obstructs ANSICE, and the same range reaches anyone who coerces a person over their article 38 rights. Article 89 separately punishes breaching a court's article 88 prohibition on managing personal-data processing, or a repeat offence under that article, with six months to two years' imprisonment and a fine of 1,000,000 to 5,000,000 CFA francs, or one of those two penalties alone; the digit for the prison-term minimum is transcribed here as printed by the OCR pass over a scanned parenthetical figure and is corrected against the Arabic-language parallel text on the same page, which reads six months.
Penalty structure
The dominant tier (arts. 82-84) is a fine of 1,000,000 to 10,000,000 CFA francs (XAF), with imprisonment of three months to one year as an alternative or cumulative penalty, covering confidentiality and security breaches (arts. 59-61), collection and sensitive-category violations (arts. 8-12, 16-24), information and access-request failures (arts. 35, 38), declaration and cross-border transfer violations (arts. 65, 70, 29/31), and obstruction of ANSICE. A separate, lower-cap tier (art. 89) fines 1,000,000 to 5,000,000 CFA francs, with imprisonment of six months to two years, for breaching a court-ordered prohibition on managing processing (art. 88) or a repeat offence.
- Rule
- Fixed only
- As of
- 7 September 2026
- Currency
- XAF
- Fixed cap
- 10,000,000
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 80 lets ANSICE warn a controller who fails to meet the law's obligations, order the failure stopped within a set period, and impose a penalty in line with the failure found, its amount fixed by regulation.
Article 81 lets ANSICE, in urgent cases where a treatment or use of personal data violates rights and freedoms, order after adversarial procedure the interruption of a processing operation or the blocking of the data concerned for up to three months, or a temporary or definitive prohibition of a processing operation contrary to the law.
Article 82 punishes an ANSICE member, staff member, or expert who breaches the confidentiality obligation the ANSICE-establishment law binds them to, with three months to one year's imprisonment and a fine of one to ten million CFA francs, or one of those penalties alone; article 83 imposes the same range on a controller, representative, employee, or agent who fails to meet the confidentiality and security obligations of articles 59, 60, and 61.
Article 84 imposes the same range on a controller, representative, employee, or agent who processes data in violation of the collection and purpose-limitation conditions of articles 8 through 12, the sensitive-category conditions of articles 16 through 24, the information duty of article 35, or the notification formalities of article 65, who fails to respond to an access request under article 38 within one month or knowingly gives inaccurate or incomplete information, who gives incomplete or inaccurate information in an article 70 declaration, who transfers personal data outside the CEMAC or CEEAC blocs in violation of article 29 without satisfying an article 31 ground, or who obstructs ANSICE's verification powers; the same article punishes anyone who uses coercion, violence, threats, gifts, or promises to force a person to disclose information obtained through their article 38 rights or to consent to processing of their data.
Article 88 lets a convicting court bar the offender from managing personal-data processing, personally or through another, for up to two years, and article 89 punishes any breach of that bar, or any repeat offence under article 88, with six months to two years' imprisonment and a fine of one to five million CFA francs, or one of those penalties alone. Article 90 makes the controller or their representative in Chad civilly liable for fines their employee or agent is ordered to pay.
Article 93 gives anyone harmed by unlawful processing or any act inconsistent with the law the right to obtain reparation from the controller, and article 94 lets the controller be exonerated, in whole or part, by proving the harmful act is not attributable to them.
When LexLint raises it
crawls_webtrains_models
Read the law
Loi n°007/PR/2015 du 10 février 2015, official text archived from the telecommunications and digital-economy regulator ARCEP's website
the archived copy is a scanned image PDF with no text layer, transcribed here by optical character recognition, confidence medium