Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023
Loi n°001/2011 du 25 septembre 2011 relative à la protection des données à caractère personnel telle que modifiée et complétée par la loi n°025/2023 du 9 juillet 2023, Journal Officiel n°218 bis du 15 juillet 2023, articles 1 à 6, 70 à 73, 78 à 90, 111 à 141, 164 à 167, 175 à 187 et 215 à 221
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 15 July 2023.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Collect and process personal data fairly and lawfully, only for determined, explicit and legitimate purposes, and keep it accurate, adequate and no longer than those purposes need.
- Have a lawful basis for processing, such as the data subject's consent, a legal obligation, a public-service mission, contract performance, or a legitimate interest that does not override the data subject's own rights and freedoms.
- Where you rely on consent, be able to demonstrate it was given and present the request clearly and separately from other terms; never treat acceptance of general terms of use or a pre-checked box as consent, and in an electronic transaction take it through an unambiguous act such as a checkbox.
- Let the data subject withdraw consent at any time without affecting the lawfulness of processing already carried out, and tell them of that right before they consent.
- Declare an automated personal-data processing activity to the APDPVP before carrying it out and wait for the Authority's receipt before starting, unless a simplified or exempt category applies; processing touching a more sensitive category instead needs the APDPVP's prior authorization or a ministerial or Council-of-Ministers decree.
- Keep processing confidential, bind everyone who processes the data under your authority to a signed written undertaking, and impose the same security and confidentiality guarantees on any processor by contract.
- Implement technical and organizational security measures adapted to the risk, including pseudonymization and encryption, and regularly test, assess and evaluate their effectiveness.
- Keep a written or electronic register of your processing activities, and require the same of any processor, naming the controller, purposes, data categories, recipients, transfers and retention periods, and produce it to the APDPVP on request; an organization of fewer than ten employees is exempt unless the processing is not occasional, carries a risk to rights and freedoms, or touches sensitive or criminal-offence data.
- Designate a data protection officer, notify the APDPVP of the designation, and give the officer the office, resources and independence to advise you, monitor compliance, and liaise with the APDPVP, where you are a public authority, carry out large-scale systematic monitoring, or process sensitive or criminal-offence data at scale.
- Before deploying an artificial-intelligence system, a facial-recognition or other biometric-identification system, a drone or other connected object, an electronic-signature or digital-identity service, or a national or sectoral identifier system that processes personal data, file the declaration or notice the applicable norme or decree requires with the APDPVP.
- Comply with the law from the date of its publication.
What it reaches
Obligation class
Consent, Licensing, Security, Retention, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Loi n°025/2023 wholly modifies and completes loi n°001/2011, setting Gabon's general rules for the collection, processing and transfer of personal data by any public or private controller (articles 2 to 4), subject to the household-activity and transit-copy exclusions of article 5.
Processing must be fair and lawful, collected for determined and legitimate purposes, and kept accurate and no longer than those purposes need (article 70), on a lawful basis such as consent, a legal obligation, a public-service mission, contract performance, or a legitimate interest that does not override the data subject's own rights (article 71); where consent is relied on it must be demonstrable, presented clearly and separately from other terms, and, for an electronic transaction, taken by an unambiguous act rather than a pre-checked box or the general terms of sale (articles 72 to 73).
An automated processing activity is declared to the APDPVP before it starts, unless it falls under a simplified or exempt category, while processing touching the categories articles 74 and 81 to 83 list instead needs the APDPVP's prior authorization or a ministerial or Council-of-Ministers decree (articles 78 to 90); the Authority keeps a public, open-format register of every declared or authorized processing activity (article 88).
Processing is confidential, everyone who handles the data under the controller's authority signs a written confidentiality undertaking, and a processor owes the controller the same security and confidentiality guarantees by contract (articles 111 to 112).
The controller and processor must implement risk-adapted technical and organizational security measures, including pseudonymization and encryption, and regularly test their effectiveness (article 113), preserve the data's continuity and keep it no longer than its purpose needs (article 118), and keep a written or electronic register of processing activities naming the controller, purposes, data categories, recipients, transfers and retention periods, produced to the APDPVP on request; an organization of fewer than ten employees is exempt from that register unless the processing carries a risk to rights and freedoms, is not occasional, or touches sensitive or criminal-offence data (articles 119 to 123).
A controller or processor designates a data protection officer, notified to the APDPVP, where it is a public authority or body, carries out large-scale systematic monitoring, or processes sensitive or criminal-offence data at scale, and gives that officer the office, resources and independence the law describes (articles 124 to 141).
Processing carried out solely for literary or artistic expression, or for the professional practice of journalism observing that profession's ethical rules, falls outside the law, provided a press or broadcast body designates its own data-protection correspondent in place of the ordinary declaration (articles 164 to 167).
A further chapter conditions the deployment of an artificial-intelligence system, a digital-identity or biometric-identification service such as facial recognition, a drone or other connected object, an electronic-signature service, or a national or sectoral identifier system, on filing the declaration or notice a norme or decree sets for it with the APDPVP (articles 175 to 187).
Every controller must conform from the law's publication (article 219), and the Authority funds itself through a statutory levy on controllers and processors and issues its own code of conduct by sector (articles 216 to 221).
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_biometricsdistributes_software_product
Read the law
Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à…
Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à caractère personnel, Journal Officiel de la République Gabonaise
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2025. Publisher's page: https://journal-officiel.ga/20085-025-2023-/Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.