What this law does
Loi n° 24.001 applies to processing of personal data carried out by an establishment in the Central African Republic or by a processor there, whatever the technology, and to processing that produces effects in the country even where the controller is located abroad, subject to carve-outs for purely personal or domestic use and for the temporary, intermediate technical copies an access provider makes to route traffic.
The Act sets fair-processing, purpose-limitation, accuracy, proportionality, security, and retention principles, requires a lawful basis such as consent, contract necessity, a legal obligation, a legitimate interest, or a vital or public-interest ground before personal data is processed, and bars processing sensitive categories, defined to include racial origin, biometric and genetic data, health data, and political, religious, or trade-union information, except on narrow derogations such as the data subject's express consent or a public-interest research purpose.
A minor's data may be processed only with the authorisation of a holder of parental responsibility. Direct marketing by phone, fax, SMS, email, instant message, or social network requires the recipient's prior consent, and the recipient must be able to unsubscribe or change their preferences at any time.
A person may access their own data, object to its use for prospecting without justification, and obtain, when a decision producing legal effects for them rests on automated processing, information letting them understand and contest that mechanism. Every controller must designate a data-protection officer who keeps the processing register, reviews new processing before it starts, liaises with the supervisory agency, and handles data-subject requests.
A transfer of personal data outside the country needs either an adequacy-level destination or one of the Act's specific derogations (informed consent, contract necessity, an important public interest, a legal claim, or a public register), with a lighter regime for transfers to another CEMAC or CEEAC member state and prior notice to the agency for transfers elsewhere.
Breach of the Act draws an administrative sanction (warning, order to stop processing, pecuniary sanction capped at 5 percent of the controller's turnover, or withdrawal of an authorisation, doubled on repeat conduct) from the data-protection agency, and separate criminal penalties, ranging from six months to five years' imprisonment and a fine of FCFA 100,000 to FCFA 10,000,000 depending on the offence, doubled on repeat conduct, for conduct including obstructing the agency, negligent processing without required formalities, fraudulent collection, misusing a file's declared purpose, processing despite a valid objection, unlawful retention, or a disclosure that harms a person's standing or privacy.
No source confirms whether the dedicated supervisory agency has been formally constituted. The law states that it takes effect from its date of promulgation, but no legible day for that promulgation appears in the archived text.
What it requires