Comprehensive regime
Loi n° 2013-015, protection des données à caractère personnel
Loi n° 2013-015 du 21 mai 2013 portant protection des données à caractère personnel en République du Mali, telle que modifiéeofficial Journal Officiel de la République du Mali, No. 26 of 28 June 2013, published by the Secrétariat Général du Gouvernement
In force since 28 June 2013. Binds public and private bodies.
What this law does
Article 1 requires the Malian State to protect the personal data of every natural or legal, public or private person, and article 2 prohibits basing a decision producing legal effects for someone solely on an automated processing intended to profile them or assess aspects of their personality.
Article 5 subjects to the Act any processing of personal data by the State, territorial authorities, incorporated bodies, and private natural or legal persons, and any processing implemented by a controller established or not on Malian territory, excluding only means used solely for transit.
Article 6 excludes just two categories from the Act's scope: processing by a natural person for exclusively personal or domestic activities not intended for systematic communication to third parties or dissemination, and temporary technical copies made for network transmission.
Article 7 requires personal data to be collected and processed fairly and lawfully, for determined, explicit, and legitimate purposes, and article 8 requires the controller to take every precaution useful to preserve data security, including preventing deformation, damage, or unauthorized third-party access.
Article 9 prohibits processing sensitive data (data relating to religious, philosophical, political, or union opinions or activities, sexual life or racial origin, health, or social measures, prosecutions, or criminal or administrative sanctions) unless the Autorité de Protection des Données à Caractère Personnel has approved a derogation meeting one of three conditions: necessity to safeguard the life of the data subject or a third party where consent cannot be given, implementation by a non-profit religious, philosophical, political, or union body solely to manage its own members, or necessity to establish, exercise, or defend a legal right.
Article 11 conditions transfer of personal data to a foreign country on the Autorité recognizing that the destination State ensures a sufficient level of protection, or on the Autorité deciding that the transfer and the recipient's processing guarantee a sufficient level of protection, including through contractual clauses or internal rules.
Articles 12 through 19 give a person the right to obtain a free copy of data concerning them, to have inaccurate, incomplete, or unlawfully processed data rectified, completed, updated, blocked, or deleted, to be informed at collection of the controller's identity, the purpose of processing, the categories of data, and their rights, and to object, for legitimate reasons, to a processing of their data or to its communication to third parties for prospecting purposes.
Articles 20 through 52 establish the Autorité as an independent administrative authority empowered to set data-processing norms, authorize interconnections and transfers, receive complaints, inspect processing operations, and impose administrative sanctions, and article 57 requires a controller to declare to the Autorité the processing operations it intends to carry out for a given purpose.
What it requires