Law / Comoros

Law on the Protection of Personal Data

Loi n° 14-029/AU portant protection des données à caractère personnel deliberated and adopted by the Assemblée de l'Union des Comores in plenary session on 26 June 2014, arts. 1-5, 41-42, 43(a) and (e)-(g), 44-46, 49-53 and 66-68 (comprehensive regime, formalities and obligations)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Collect and process personal data lawfully and fairly, only for determined and legitimate purposes, keep it accurate and up to date, and do not retain it beyond the period necessary for those purposes.
  • Declare personal data processing to the Commission before implementing it, or enter it in a register kept by a designated person, unless it is exempt as general accounting, payroll, supplier management, or a non profit association's membership processing.
  • Obtain the Commission's prior authorization before processing a national identification number or a national census, processing concerning state security, defense or public safety or the investigation and prosecution of offenses, interconnecting files serving different purposes, or processing that could exclude a person from a right, a benefit or a contract.
  • State in your declaration the controller's identity and address, the processing's purposes, the data collected and its retention period, who may access it, any transfer abroad, and the security measures you have taken.
  • Collect personal data for an electronic certification service directly from the data subject, and use it only for the purpose it was collected for, unless the data subject expressly consents otherwise.
  • Take precautions appropriate to the nature of the data and the risks the processing presents to preserve its security, including against distortion, damage, or access by unauthorized third parties.
  • Confine a sub processor to your instructions under a written contract addressing security and confidentiality, without relieving yourself of the duty to see those measures respected.
  • Notify the Commission without delay of any change to the information in your declaration and of the discontinuation of the processing.

What it reaches

Obligation class

Consent, Governance, Security, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 1 applies the law to any automated processing of personal data held in a digitized or manual file, and article 5 requires data to be collected and processed lawfully and fairly, for determined and legitimate purposes, kept accurate and up to date, and not retained beyond the period the purpose requires.

Article 41 requires processing carried out by a public or private body to be declared to the Commission before it is implemented, or entered in a register kept by a person the controller designates, and article 42 exempts general accounting, payroll, supplier management, and a non profit association's membership processing from that duty.

Articles 43(a) and 43(e) to (g) require the Commission's prior authorization for processing bearing a national identification number or a national census, processing concerning state security, defense or public safety or the investigation and prosecution of offenses, an interconnection of files serving different purposes, and processing that could exclude a person from a right, a benefit or a contract, and article 44 gives the Commission two months to decide on such a request, with silence counting as approval outside the article 17 state security procedure.

Articles 45 and 46 fix what a declaration must state, including the controller's identity, the processing's purposes, the data and its retention period, who may access it, and the security measures taken. Article 49 requires an electronic certification provider to collect personal data directly from the data subject and to use it only for the purpose for which it was collected, unless the data subject expressly consents otherwise.

Article 50 requires the controller to take precautions appropriate to the data and to the risks the processing presents, and article 51 confines a sub processor to the controller's instructions under a contract addressing security and confidentiality.

Article 52 requires the controller to notify the Commission without delay of any change to the declared processing or of its discontinuation, and article 53 allows retention beyond the article 5 period only for historical, statistical or scientific purposes, with the data subject's express consent, or with the Commission's authorization.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions

Read the law

Text of Loi n° 14-029/AU reproduced by ANADEN (Agence Nationale de Développement du Numérique), the Comorian digital-development agency

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app