Law / Chad

Chad

8 of 15 named instruments researched to a stage, across three of the six areas of law we track: 8 in force. As of 7 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (333 words)

Chad's comprehensive personal-data statute is Loi n°007/PR/2015 du 10 février 2015 portant protection des données à caractère personnel, promulgated in N'Djamena on 10 February 2015 and enforced by ANSICE (Agence Nationale de Sécurité Informatique et de Certification Electronique), the independent administrative authority the law itself designates as its supervisor.

Processing rests on the data subject's consent or one of a limited set of statutory grounds (a legal obligation, a public-interest mission, a contract, or the data subject's vital interest), and separately must be collected for determined, explicit, and legitimate purposes, kept accurate, kept confidential and secure, and retained no longer than the purpose requires.

Biometric data and other sensitive categories, racial or ethnic origin, political opinion, religious or philosophical belief, trade-union membership, sex, health, and sexual life, are prohibited from processing unless the data subject gives explicit written consent or a specific statutory exception applies.

A data subject has rights to information at collection, access to their own data free of charge, objection to processing for legitimate reasons, and rectification or erasure of inaccurate or unlawfully held data.

Transferring personal data outside the CEMAC or CEEAC blocs requires the destination country to offer a sufficient level of protection, prior notification to ANSICE before any such transfer, and, for a destination that does not meet that standard, either a data subject's consent, another statutory ground, or ANSICE's own authorization on the strength of contractual safeguards; this reaches the strict end of the transfer-restriction scale rather than the unrestricted end a prior record carried, corrected here against the primary text.

A controller or subcontractor must notify both ANSICE and the affected data subject without delay of any security breach affecting personal data. Violating most of these duties is a criminal offence carrying imprisonment and a fine, and any person harmed by unlawful processing has a civil right to obtain reparation from the controller.

Chad's separate cybersecurity, electronic-transactions, and ANSICE-establishment statutes are catalogued under this jurisdiction's scraping-topic filing; only the personal-data protection statute is described here.

Breach notification

Loi n°007/PR/2015, obligation de notification des violations de données à l'ANSICE

Loi n°007/PR/2015 du 10 février 2015, art. 61Loi n°007/PR/2015 du 10 février 2015, official text archived from the telecommunications and digital-economy regulator ARCEP's website

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 4, 2020. Publisher's page: https://arcep.td/sites/default/files/Loi-N%C2%B007-PR-2015.pdf

In force since 10 February 2015. Binds public and private bodies.

What this law does

Article 61 requires the controller, or its subcontractor, to notify both ANSICE and the affected data subject, without delay, of any security breach affecting that person's personal data.

This duty sits alongside article 59's confidentiality obligation and article 60's list of required technical and organizational security measures against alteration, damage, or unauthorized third-party access, and a controller or subcontractor who fails to meet the article 59 through 61 obligations is separately subject to criminal penalty.

What it requires

Comprehensive regime

Loi n°007/PR/2015, principes directeurs du traitement des données (consentement, licéité, finalité, conservation)

Loi n°007/PR/2015 du 10 février 2015, arts. 1-15Loi n°007/PR/2015 du 10 février 2015, official text archived from the telecommunications and digital-economy regulator ARCEP's website

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 4, 2020. Publisher's page: https://arcep.td/sites/default/files/Loi-N%C2%B007-PR-2015.pdf

In force since 10 February 2015. Binds public and private bodies.

What this law does

Article 1 sets the law's object as protecting private and professional life against the collection, processing, transmission, storage, and use of personal data, subject to public-order protection, and article 2 applies it to any such operation by a natural person, the State, local authorities, or a public or private legal person.

Article 7 makes processing lawful when the data subject consents, or, absent consent, when it is indispensable to a legal obligation, a public-interest or public-authority mission, a contract to which the data subject is party, or safeguarding the data subject's vital interest or fundamental rights.

Articles 8 through 10 require that collection and processing be lawful, fair, and non-fraudulent, and that data be collected for determined, explicit, and legitimate purposes and not processed incompatibly with them, and be adequate and not excessive for those purposes. Articles 11 through 15 require that data be retained no longer than the purpose requires, kept accurate, and that the controller inform the data subject and keep the data confidential and secure.

What it requires

Cross border transfer

Loi n°007/PR/2015, transfert des données vers un pays non membre de la CEEAC/CEMAC

Loi n°007/PR/2015 du 10 février 2015, arts. 29-32Loi n°007/PR/2015 du 10 février 2015, official text archived from the telecommunications and digital-economy regulator ARCEP's website

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 4, 2020. Publisher's page: https://arcep.td/sites/default/files/Loi-N%C2%B007-PR-2015.pdf

In force since 10 February 2015. Binds public and private bodies.

What this law does

Article 29 bars a controller from transferring personal data to a country outside the CEMAC and CEEAC blocs unless that State ensures a sufficient level of protection for privacy and fundamental rights and freedoms with respect to the processing the data will or may undergo. Article 30 requires the controller to inform ANSICE before any transfer to such a third country, regardless of that country's adequacy.

Article 31 lets a transfer to a non-adequate country proceed by derogation where the data subject has unambiguously consented, the transfer is necessary to a contract with the data subject or its pre-contractual steps, the transfer is necessary to a contract in the data subject's interest between the controller and a third party, the transfer is necessary or legally required to safeguard an important public interest or to establish, exercise, or defend a legal claim, the transfer safeguards the data subject's vital interest, or the transfer comes from a public register open to public consultation under legislative or regulatory provision.

Article 32 lets ANSICE authorize a transfer or set of transfers to a non-adequate country where the controller offers sufficient guarantees for privacy and fundamental rights and freedoms, including through appropriate contractual clauses.

What it requires

Data subject rights

Loi n°007/PR/2015, droits de la personne concernée (information, accès, opposition, rectification)

Loi n°007/PR/2015 du 10 février 2015, arts. 35-50Loi n°007/PR/2015 du 10 février 2015, official text archived from the telecommunications and digital-economy regulator ARCEP's website

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 4, 2020. Publisher's page: https://arcep.td/sites/default/files/Loi-N%C2%B007-PR-2015.pdf

In force since 10 February 2015. Binds public and private bodies.

What this law does

Article 35 requires a controller collecting personal data directly from the data subject to provide, at collection, its own identity, the processing purposes, the categories of data, the recipients, the retention period, the existence of access and rectification rights, and any prospect of transfer to a third country; article 36 extends this duty to data not collected directly from the data subject, timed to registration or first communication to a third party.

Article 38 lets any natural person demand, free of charge, confirmation of whether their data is processed, communication of that data and its origin, information on the processing's purposes, legal basis, categories, and recipients, and information on any transfer to a third country, plus a copy of the data at no more than reproduction cost; the controller may refuse a manifestly abusive request, bearing the burden of proving abuse.

Article 45 gives any natural person the right to object, on legitimate grounds, to processing of their personal data, and specifically to object, free of charge, before their data is first communicated to a third party or used for prospecting on a third party's behalf, except where the processing meets a legal obligation.

Article 46 lets any natural person demand, free of charge, that the controller rectify, complete, update, block, or erase personal data concerning them that is inaccurate, incomplete, equivocal, outdated, or unlawfully collected, used, communicated, or retained, within one month of a written request, on pain of a complaint to ANSICE.

Article 48 has a minor's rights exercised by the parent holding parental authority or the minor's guardian, with the minor associated to the exercise of those rights according to age and maturity.

What it requires

Enforcement supervision

Loi n°007/PR/2015, sanctions administratives et pénales et recours

Loi n°007/PR/2015 du 10 février 2015, arts. 80-94Loi n°007/PR/2015 du 10 février 2015, official text archived from the telecommunications and digital-economy regulator ARCEP's website

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 4, 2020. Publisher's page: https://arcep.td/sites/default/files/Loi-N%C2%B007-PR-2015.pdf

In force since 10 February 2015. Binds public and private bodies.

What this law does

Article 80 lets ANSICE warn a controller who fails to meet the law's obligations, order the failure stopped within a set period, and impose a penalty in line with the failure found, its amount fixed by regulation.

Article 81 lets ANSICE, in urgent cases where a treatment or use of personal data violates rights and freedoms, order after adversarial procedure the interruption of a processing operation or the blocking of the data concerned for up to three months, or a temporary or definitive prohibition of a processing operation contrary to the law.

Article 82 punishes an ANSICE member, staff member, or expert who breaches the confidentiality obligation the ANSICE-establishment law binds them to, with three months to one year's imprisonment and a fine of one to ten million CFA francs, or one of those penalties alone; article 83 imposes the same range on a controller, representative, employee, or agent who fails to meet the confidentiality and security obligations of articles 59, 60, and 61.

Article 84 imposes the same range on a controller, representative, employee, or agent who processes data in violation of the collection and purpose-limitation conditions of articles 8 through 12, the sensitive-category conditions of articles 16 through 24, the information duty of article 35, or the notification formalities of article 65, who fails to respond to an access request under article 38 within one month or knowingly gives inaccurate or incomplete information, who gives incomplete or inaccurate information in an article 70 declaration, who transfers personal data outside the CEMAC or CEEAC blocs in violation of article 29 without satisfying an article 31 ground, or who obstructs ANSICE's verification powers; the same article punishes anyone who uses coercion, violence, threats, gifts, or promises to force a person to disclose information obtained through their article 38 rights or to consent to processing of their data.

Article 88 lets a convicting court bar the offender from managing personal-data processing, personally or through another, for up to two years, and article 89 punishes any breach of that bar, or any repeat offence under article 88, with six months to two years' imprisonment and a fine of one to five million CFA francs, or one of those penalties alone. Article 90 makes the controller or their representative in Chad civilly liable for fines their employee or agent is ordered to pay.

Article 93 gives anyone harmed by unlawful processing or any act inconsistent with the law the right to obtain reparation from the controller, and article 94 lets the controller be exonerated, in whole or part, by proving the harmful act is not attributable to them.

What it requires

Sensitive categories

Loi n°007/PR/2015, traitement des catégories particulières de données (données sensibles et biométriques)

Loi n°007/PR/2015 du 10 février 2015, arts. 16-25Loi n°007/PR/2015 du 10 février 2015, official text archived from the telecommunications and digital-economy regulator ARCEP's website

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 4, 2020. Publisher's page: https://arcep.td/sites/default/files/Loi-N%C2%B007-PR-2015.pdf

In force since 10 February 2015. Binds public and private bodies.

What this law does

Article 16 prohibits processing biometric data and personal data revealing racial or ethnic origin, filiation, political opinion, religious or philosophical belief, trade-union membership, sex, health, or sexual life, unless the data subject gives explicit written consent (withdrawable at any time, at no cost), or the processing falls within a listed exception: a labour-law obligation, protecting the data subject's or another's vital interest, a human-rights association's activity authorized by ANSICE, a social-security purpose, establishing or defending a legal claim, data the data subject has manifestly made public, historical, statistical, or scientific research on conditions ANSICE sets, public-statistics law, preventive medicine or health-service administration under a health professional's supervision, or another important public-interest ground a law permits.

Article 17 confines this processing to written consent or a health professional's responsibility, binding that professional and their staff to confidentiality.

Article 18 separately prohibits processing genetic data and personal data revealing health-related secrets, subject to a similarly structured list of exceptions, and article 20 requires that any such processing use a unique patient identifier distinct from other identification numbers, interconnectable with another identifying number only with ANSICE's express authorization.

Article 24 confines processing a minor's personal data to the representation rules the law sets for the exercise of a minor's own rights.

What it requires

Scraping law1 instrument, 1 in force

Research summary (191 words)

Chad has no scraping-specific statute, so general law governs each dimension separately.

The Code Pénal (Loi n°001/PR/2017), which codifies the offences originally created by Loi n°009/PR/2015 on cybersecurity and cybercrime, criminalises fraudulent access to or interference with a computer system, but its offences turn on accessing a system frauduleusement, so a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of that requirement, and no reported case has tested the point.

No Chadian court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located. Loi n°005/PR/2003 on copyright confers no sui generis database right, and Chad has not enacted a text-and-data-mining exception; the Law's only relevant carve-outs are the news-of-the-day and facts exclusion and the press-review exception described under the aggregation topic, neither aimed at training-data collection.

No statute or case law establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, or assigns legal weight to a robots.txt directive or an AI-training-specific rule. Chad's comprehensive personal-data statute, Loi n°007/PR/2015, has no primary text available to check its reach over scraped public personal data, so that reach is not described here.

Computer misuse

Code Pénal, unauthorised access to and interference with a computer system

Loi n°001/PR/2017 du 8 mai 2017 portant Code Pénal Livre 6, Chapitre 2 (De la cybercriminalité), Section 1, Sous-sections 1-2 (art. 429-431), codifying Loi n°009/PR/2015 du 10 février 2015 relative à la cybersécurité et à la lutte contre la cybercriminalitéText of the Code Pénal (Loi n°001/PR/2017) reproduced by droit-afrique.com, an unofficial commercial mirror

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived January 24, 2022. Publisher's page: https://www.droit-afrique.com/uploads/Tchad-Code-penal-2017.pdf

In force. Binds public and private bodies.

What this law does

Article 429 punishes any person who accesses or attempts to access, fraudulently, all or part of a computer system, and the same person who fraudulently procures or attempts to procure, for themselves or another, any advantage by entering a computer system. Article 430 punishes fraudulently remaining or attempting to remain in all or part of a computer system, and hindering, falsifying, or attempting to hinder or falsify the operation of a computer system.

Article 431 punishes fraudulently introducing or attempting to introduce data into a computer system. Each offence carries imprisonment of one to five years and a fine of 1,000,000 to 10,000,000 CFA francs, or one of those two penalties only. Because each offence's trigger is fraudulent access, entry, or introduction, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of these provisions. This chapter codifies the offences originally created by Loi n°009/PR/2015 on cybersecurity and cybercrime.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (182 words)

Chad has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically.

The relevant instrument is Loi n°005/PR/2003 du 2 mai 2003 sur la protection du droit d'auteur, des droits voisins et des expressions du folklore, which excludes the news of the day and mere facts from copyright protection outright (art. 9), so a bare fact or news item is never protectable regardless of who first reported it.

The same Law lets a person, once a work is lawfully disclosed and its author and source are clearly credited, compile press reviews and reproduce or broadcast current political, social, economic, or religious news articles, even in full, for current-events informational purposes (art. 34(3)); nothing limits that exception to short extracts, and no Chadian court decision applying it to a systematic news aggregator, as opposed to a traditional press review, was located.

The Law predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Loi n°005/PR/2003 sur la protection du droit d'auteur, press review and current-events exception (art. 34) and news-of-the-day exclusion (art. 9)

Loi n°005/PR/2003 du 2 mai 2003 portant protection du droit d'auteur, des droits voisins et des expressions du folklore, art. 9 and art. 34Official bilingual text of Loi n°005/PR/2003, WIPO Lex

In force. Binds public and private bodies.

What this law does

Article 9 excludes official legislative, administrative, or judicial texts and their official translations, the news of the day, and mere facts and data from copyright protection outright: a bare fact, or the news of the day as such, is never a protected work under Chadian law, whichever outlet reports it first.

Article 34(3) separately lets any person, once a work has been lawfully disclosed, and provided the author's name and source are clearly credited, make short critical, polemical, pedagogical, scientific, or informative analyses and quotations, compile press reviews, and reproduce or broadcast, even in full, current political, social, economic, or religious news articles and public speeches delivered before political, administrative, judicial, or academic assemblies, and sermons, lectures, and addresses, for current-events informational purposes.

The text does not cap the exception at a headline-length or short-extract threshold and does not confine it to the press industry.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.