Law / Senegal

Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel (Personal Data Protection Act)

Loi n° 2008-12 du 25 janvier 2008 sur la Protection des Données à Caractère Personnel arts. 1-4, 17-24, 33-39, 45-46, 52-57, 70-74 (principes généraux, formalités préalables et obligations du responsable)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 January 2008.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Have a lawful basis, ordinarily the person's consent, before collecting, processing, transmitting, storing, or using their personal data.
  • Take precautions appropriate to the nature of the data, including restricting access to authorized staff and keeping security copies.
  • Declare your processing to the CDP before you start it, using its published form, and do not implement the processing until you receive the CDP's certificate of receipt.
  • Choose a sub-processor offering sufficient guarantees, bind them by a written contract limited to your instructions, and keep processing confidential and restricted to authorized staff.
  • Get the CDP's authorization before combining personal data files across purposes or processing a national identification number or other general-purpose identifier.
  • Do not keep personal data longer than its purpose requires, unless you keep it only for historical, statistical, or scientific treatment.

What it reaches

Obligation class

Consent, Governance, Security, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 2 subjects to the Act any collection, processing, transmission, storage or use of personal data by a natural person, the State, local authorities, or a public or private legal person, and article 3 exempts only a person's exclusive personal or domestic processing and transient technical transmission copies.

Article 33 makes a data subject's consent the general basis for lawful processing, with derogations for a legal obligation, a public interest or official mission, performance of a contract, or safeguarding the data subject's vital interests. Articles 34 through 37 require collection and processing to be lawful, fair and non fraudulent, limited to determined and legitimate purposes, kept accurate and updated, and carried out under a duty of transparency toward the data subject.

Article 38 requires processing to be confidential and secured under article 71, and article 39 requires a controller using a sub processor to choose one offering sufficient guarantees and to bind it by a written contract limited to the controller's own instructions.

Outside the exemptions article 17 lists, article 18 requires a controller to declare its processing to the CDP and wait for the CDP's certificate of receipt before implementing it, and articles 22 through 24 set what a declaration or authorization request must state and the two month period the CDP has to decide it.

Article 20 requires the CDP's prior authorization before processing genetic data or health related research data, data on criminal offences or convictions, an interconnection of files, a national identification number or other general purpose identifier, biometric data, or a public interest historical, statistical or scientific treatment, and articles 53 through 57 set the interconnection authorization procedure.

Article 45 admits processing for journalism, research or artistic or literary expression carried out under the professional rules of those activities, and article 46 leaves the press laws and the Penal Code's own right of reply and privacy protections in place.

Article 71 requires precautions appropriate to the nature of the data, article 72 bars keeping data longer than its purpose needs except for historical, statistical or scientific treatment, article 73 restricts an electronic certification provider to collecting data directly from the person concerned and using it only to issue and keep the certificate, and article 74 requires a controller to keep data usable whatever technical medium stores it.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach

Read the law

Loi n° 2008-12 du 25 janvier 2008, official French text reproduced on the WIPO Lex legislation record for Senegal

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app