Law / Niger

Loi n° 2022-59, protection des données à caractère personnel

Loi n° 2022-59 protection des données à caractère personnel, du 16 décembre 2022, telle que modifiée par la Loi n° 2023-31 du 4 juillet 2023 et les Ordonnances n° 2024-16 du 26 avril 2024 et n° 2024-29 du 24 juin 2024, arts. 2-5, 29-41, 64-67 et 77-86 (objet, champ d'application, formalités, principes directeurs et outils de conformité)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the data subject's express prior consent before processing their personal data, unless the processing is necessary for a legal obligation, a public-interest or official mission, performance of a contract, or safeguarding the data subject's own vital interests or fundamental rights.
  • Collect personal data only for determined, explicit and legitimate purposes, and do not process it later in a way incompatible with those purposes or keep it longer than the purposes require.
  • Keep personal data adequate, relevant and accurate, update it where necessary, and correct or erase it once you find it inaccurate or incomplete.
  • Collect, record, process, store and transmit personal data lawfully, fairly and without fraud.
  • Keep personal data confidential and implement technical and organizational measures against unauthorized access, loss or damage, including pseudonymization, encryption, and data protection by design and by default.
  • Complete a prior declaration, authorisation request or advisory request with the HAPDP before implementing a processing operation, and obtain its prior authorisation for genetic, medical, biometric, interconnected, unique-identifier or sensitive-category processing.
  • Keep a register of processing operations recording the collection, modification, consultation, disclosure, transfers, interconnection and deletion of personal data, and make it available to the HAPDP on request.
  • Carry out a privacy impact assessment before implementing a sensitive or high-risk processing operation the HAPDP requires one for.
  • Appoint a data-protection correspondent within your organization and notify the appointment to the HAPDP; a public-sector controller appoints a focal point instead.
  • Where two or more controllers jointly determine the purposes and means of processing, define transparently each one's role toward data subjects, who may exercise their rights against each of them.
  • Choose a processor that offers sufficient security and confidentiality guarantees, govern its processing under a written confidentiality contract, and hold it to the same obligations that bind you.

What it reaches

Obligation class

Consent, Governance, Security, Retention, DPIA, Licensing

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 binds every collection, processing, transmission, storage or use of personal data by a public or private legal person or a natural person, and article 4 extends the Act to a controller or processor established in Niger, one using processing means located on Niger's territory, and one targeting Nigerien citizens or offering goods or services to persons established in Niger.

Article 5 excludes only a purely personal or domestic use that is not disseminated to third parties, temporary technical copies made for network transmission, and journalistic, literary or artistic processing carried out under professional ethical rules.

Article 29 makes prior formality with the HAPDP, whether a simple declaration, an authorisation request or an advisory request, a precondition of processing, and article 31 lists the categories, including genetic, medical, biometric, interconnected, unique-identifier and sensitive-category processing, that need the HAPDP's prior authorisation rather than a bare declaration.

Article 37 makes the data subject's express prior consent the legitimacy test for processing, departing from it only where the controller is duly authorised and the processing is necessary for a legal obligation, a public-interest or official mission, performance of a contract, or safeguarding the data subject's own vital interests or fundamental rights.

Article 38 requires personal data to be collected for determined, explicit and legitimate purposes and kept no longer than those purposes require, article 39 requires it to be adequate, relevant, accurate and kept up to date, and article 40 requires collection, recording, processing, storage and transmission to proceed lawfully, fairly and without fraud.

Article 41 and article 82 require the controller and any processor it engages to keep personal data confidential and to implement technical and organisational measures, including pseudonymisation, encryption and data protection by design and by default, against unauthorised access, loss or damage.

Article 64 requires a register of processing operations made available to the HAPDP on request, and article 67 lets the HAPDP demand a privacy impact assessment before authorising a sensitive or high-risk processing operation.

Article 79 requires a private-sector controller to designate a data-protection correspondent and notify the appointment to the HAPDP, while a public-sector controller designates a focal point instead, and article 86 requires a processor to offer sufficient security guarantees, to operate under a written confidentiality contract, and to answer to the same obligations as the controller.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Loi n 2022-59 du 16 decembre 2022, version consolidee, Haute Autorite de Protection des Donnees a Caractere Personnel

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app