Law / Central African Republic

Loi n° 24.001 portant protection des données à caractère personnel

Loi n° 24.001 portant protection des données à caractère personnel Chapitres Ier, II, V, VII et IX (dispositions générales, principes, interconnexion des fichiers, délégué à la protection des données et dispositions finales)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Have a lawful basis, such as a contract's performance, a legal obligation, a legitimate interest that does not override the data subject's rights, the data subject's freely given and revocable consent, a vital interest, or a public interest mission, before processing someone's personal data.
  • Apply the Act's core principles to every processing activity: lawfulness, fairness, transparency, security, purpose limitation, accuracy, proportionality, and a retention period no longer than the purpose requires.
  • Take precautions appropriate to the data's nature and the risks involved to keep personal data secure, including protection against accidental or unlawful destruction, loss, alteration, or unauthorized access.
  • Only retain personal data for archival, historical, statistical, or scientific purposes beyond its ordinary retention period under the safeguards a law defines for that purpose.
  • Process personal data as a subcontractor only on the controller's instruction, offer sufficient guarantees to implement security and confidentiality measures, and put those obligations in the contract with the controller.
  • If you provide electronic signature certification services, collect the personal data needed for issuing and keeping the certificates directly from the person concerned, and use it only for that purpose absent the person's express consent otherwise.
  • Get the agency's prior authorization before interconnecting personal data files held for different purposes or by different controllers, stating in the request the nature of the data, the interconnection's purpose, and its duration.
  • Designate a data protection officer to keep the processing register, review new processing before it starts, consult the agency in case of doubt, and handle data subject requests; only a person residing in the Central African Republic with the necessary qualifications may hold the role, and the agency must be told before the officer is removed.

What it reaches

Obligation class

Consent, Governance, Security, Retention, Contract terms

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Loi n° 24.001 applies to processing carried out by an establishment of a controller or a processor in the Central African Republic, and to processing that produces effects in the country even where the controller is abroad, subject to carve outs for a purely personal or domestic use and for the temporary, intermediate technical copies an access provider makes to route traffic.

Every activity of processing personal data must respect the principles of lawfulness, fairness, transparency, security, purpose limitation, accuracy, proportionality, and retention limitation.

Personal data may be processed only where it is necessary for the performance of a contract, compliance with a legal obligation, a legitimate interest that does not override the data subject's rights, the data subject's freely given and revocable explicit consent, the safeguarding of someone's vital interests, or the performance of a public interest mission, and a person who has made their own data freely accessible supports a controller's reliance on the legitimate interest ground.

Data processed for archival, historical, statistical, or scientific purposes may be kept and used under safeguards a law defines for that purpose even after the Act's ordinary retention limit would otherwise apply. A controller must take precautions appropriate to the data's nature and the risks involved to keep personal data secure, including protection against accidental or unlawful destruction, loss, alteration, or unauthorized access.

Processing may be subcontracted only on the controller's instruction, the processor must offer sufficient guarantees to implement security and confidentiality measures, and the contract between them must specify the processor's security and confidentiality obligations.

A provider of electronic signature certification services must collect the personal data it needs to issue and keep the certificates directly from the person concerned, and use it only for that purpose, absent the person's express consent otherwise.

Interconnecting personal data files held by different public service bodies with different public interests, or held by private parties for different purposes, needs the agency's prior authorization, stating the nature of the data, the purpose the interconnection serves, and its duration.

Every controller must designate a data protection officer responsible for compliance with the Act's obligations, who keeps the register of processing operations, issues an opinion on every new processing operation before it starts, and consults the agency in case of doubt, and designating one exempts the controller from the ordinary prior declaration formalities except where the processing needs the agency's authorization.

Only a person residing in the Central African Republic with the necessary knowledge and qualifications may be designated data protection officer, whether an employee or an outside person, and the officer may be removed only for serious cause and after the agency has been told.

Chapitre Ier defines a violation of personal data as any destruction, loss, alteration, or unauthorized disclosure of personal data, transmitted, stored, or otherwise processed, that is accidental or unlawful, but no provision of the Act requires that violation to be notified to the agency or to the person concerned. The Act states that it takes effect from its date of promulgation, but the archived text does not show a legible date for that promulgation.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • ships_mobile_app

Read the law

Text of Loi n° 24.001 portant protection des données à caractère personnel
archived copy of the Autorité de Régulation des Communications Électroniques et de la Poste (ARCEP) publication

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDF

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app