Law No. 2014-038, protection of personal data
Loi n° 2014-038 sur la protection des données à caractère personnel arts. 1-2, 5-17, 21, 43-49, 51-54 (dispositions générales, champ d'application, principes fondamentaux, formalités préalables et délégué à la protection des données)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 9 January 2015.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Collect and process personal data fairly, lawfully, and only for determined, explicit, and legitimate purposes, and do not use it later for another purpose without the data subject's consent or a purpose the law itself provides.
- Keep personal data adequate, relevant, accurate, and no longer than those purposes require, unless it is kept for archival, historical, statistical, or scientific purposes under the safeguards the law or the CMIL sets.
- Have the data subject's consent, or another of the five lawful grounds in article 17, before processing personal data.
- Take security precautions appropriate to the data and the risk, to prevent unauthorized access, alteration, loss, or disclosure.
- Process data on a subcontractor's behalf only on the controller's instructions, and use only a subcontractor that offers sufficient guarantees to implement the required security measures.
- As a provider of electronic certification services, collect the personal data needed for a signature certificate directly from the data subject, unless the data subject expressly consents otherwise.
- Declare a processing operation to the CMIL before implementing it, or obtain its prior authorization first where the processing presents a particular risk to rights and freedoms or to privacy.
- Designate a data protection officer to keep the processing register current, advise on new processing before it starts, take in data subjects' requests and complaints, and escalate an uncorrected breach to the CMIL.
What it reaches
Obligation class
Consent, Retention, Security, Governance, Licensing
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 states that the law protects the rights of persons regarding the processing of personal data, and article 2 requires that information technology serve every person and respect human dignity, human rights, privacy, and individual or public freedoms, recognizing a right to the protection of personal data for everyone.
Article 5 applies the law to any automated or non-automated processing of personal data contained in or intended to be included in files, carried out in whole or in part on Malagasy territory, excluding only purely personal activity and processing for the sole purposes of journalism or literary or artistic expression. Article 6 reaches a controller established on Malagasy territory and a controller established elsewhere who uses means of processing located there, other than for mere transit.
Articles 7 to 13 define personal data, processing, a controller, a subcontractor acting on the controller's instructions, a recipient, the data subject, and consent as a free, specific, and informed manifestation of will.
Article 14 requires personal data to be collected and processed fairly, lawfully, and without fraud for determined, explicit, and legitimate purposes, barring later use for another purpose without the data subject's consent or a purpose the law itself sets, and requires it to be adequate, relevant, accurate, and kept no longer than those purposes need, subject to an exception for archival, historical, statistical, or scientific retention under safeguards the law or the CMIL defines.
Article 15 requires the controller to take precautions appropriate to the data's nature and the risks involved to preserve its security, protecting processing and data against accidental or unlawful destruction, accidental loss, alteration, disclosure, or unauthorized access. Article 16 lets processing be subcontracted only on the controller's instructions and only to a subcontractor offering sufficient guarantees to implement the required security measures.
Article 17 requires the data subject's consent or one of five alternative lawful grounds: a legal obligation, safeguarding the data subject's life, a public-service mission, performance of a contract, or the controller's or recipient's legitimate interest, subject to the data subject's own rights and interests.
Article 21 requires a provider of electronic-certification services to collect the personal data needed to issue and store signature certificates directly from the data subject, unless the data subject expressly consents otherwise. Article 43 makes declaring a processing operation to the CMIL a precondition of implementing it, with the operation then entered in a register the controller's data protection officer keeps.
Articles 44 to 46 set the corresponding formalities: public-sector processing needs a regulatory act adopted after the CMIL's reasoned favorable opinion, private-sector processing needs a prior declaration for which a receipt issues without delay, and processing presenting a particular risk to rights and freedoms or to privacy needs the CMIL's prior authorization.
Articles 47 to 49 let the CMIL publish simplified-declaration or exemption norms for the most common categories of processing, require it to rule on a declaration or authorization request within two months, renewable once, with silence read as a refusal, and fix what a declaration or request must contain, including the controller's identity, the processing's purposes, any interconnection with other processing, the data categories and their retention period, the recipients, the security measures, and any subcontractor used.
Article 51 requires every controller to designate a data protection officer who keeps the processing register current, is consulted before any new processing begins, advises the CMIL when in doubt, receives requests and complaints from data subjects, tells the controller of any breach found before referring it to the CMIL if the controller does not fix it, and produces an annual activity report.
Article 52 exempts a controller who has designated a data protection officer from the ordinary declaration formalities, except where the processing needs the CMIL's authorization, and articles 53 and 54 require the officer to be independent, free of conflicting duties, bound to confidentiality, and removable only for serious cause after the CMIL is told.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)
not an official government-published copy
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.