Comprehensive regime
Loi n° 2022-59, protection des données à caractère personnel
Loi n° 2022-59 protection des données à caractère personnel, du 16 décembre 2022, telle que modifiée par la Loi n° 2023-31 du 4 juillet 2023 et les Ordonnances n° 2024-16 du 26 avril 2024 et n° 2024-29 du 24 juin 2024Consolidated text of Loi n° 2022-59 as amended, published by the Haute Autorité de Protection des Données à caractère Personnel (HAPDP)
In force. Binds public and private bodies.
What this law does
Article 3 binds any collection, processing, transmission, storage or use of personal data by a public or private legal person or a natural person, and article 4 extends the Act to a controller or processor established in Niger and to one established abroad that uses processing means located on Niger's territory.
Article 37 conditions lawful processing on the data subject's express prior consent, subject to exceptions for a legal obligation, a public-interest mission, a contract, or safeguarding the data subject's own interest or fundamental rights.
Article 42 prohibits processing data revealing racial, ethnic or regional origin, filiation, political opinions, religious or philosophical beliefs, trade-union membership, sex life, health, morals, genetic or biometric data, social measures, or criminal or administrative sanctions, subject to listed exceptions, and article 49 requires the HAPDP's prior authorisation before any processing of biometric data.
Article 62 bars transferring personal data to a State that does not ensure a sufficient level of protection of privacy and fundamental rights and freedoms, and requires the controller to first implement technical and organisational security measures, including encryption, before any transfer; article 63 permits a transfer to a State lacking adequate protection only on the data subject's specific, free, informed and unambiguous consent or another listed derogation.
Article 79 requires a private-sector controller to designate a data-protection correspondent within its organisation and notify the appointment to the HAPDP, while a public-sector controller designates a focal point instead. Article 83 requires a controller to notify the HAPDP of a personal-data breach without delay on becoming aware of it, and to notify the affected person as well when the breach is likely to create a high risk to their rights and freedoms.
Chapter XIV punishes a list of specific offences, including illicit processing of sensitive data, unauthorised disclosure, purpose diversion, fraudulent collection, direct marketing without consent, and obstructing the exercise of a data subject's rights, each with imprisonment of three months to five years and a fine reaching, depending on the offence, from 500,000 to 50,000,000 CFA francs, and article 110 gives a data subject a judicial remedy independent of a complaint to the HAPDP.
What it requires