Data Protection Act No. 005 of 2023
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Establish a lawful basis before processing personal data, such as the data subject's consent, the performance of a contract, a legal obligation, or the data subject having intentionally made the data public, and process it fairly and transparently.
- Collect personal data for a specified, explicit and legitimate purpose, keep it to the minimum necessary for that purpose, keep it accurate, and retain it no longer than the purpose requires.
- Where you rely on consent, be able to prove the data subject gave it.
- Keep a record of every data processor handling personal data you control, and take reasonable measures to ensure each one processes in a way that keeps you compliant.
- Implement appropriate technical and organisational measures to secure personal data, taking into account the amount and sensitivity of the data and the harm its loss or misuse would cause.
- As a data controller of major importance, carry out a data protection impact assessment before processing likely to result in a high risk to a data subject, and submit the assessment report to the Authority before you start.
- As a data controller of major importance, register with the Authority within six months of qualifying, and designate a data protection officer.
What it reaches
Obligation class
Consent, Disclosure, Security, DPIA, Governance, Licensing
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 4 applies the Act to a data controller domiciled, resident or operating in the Federal Republic of Somalia, to processing that occurs in Somalia, and to processing that monitors the behaviour of, or targets goods or services to, a data subject in Somalia, and article 5 exempts purely personal, recreational or household processing and specified functions of competent authorities.
Article 14 permits processing only on a listed lawful basis, such as the data subject's consent, the performance of a contract, a legal obligation or the data subject having intentionally made the data public, and requires fair and transparent processing. Article 15 requires purpose specification, data minimisation, limited retention and accuracy, and article 17 puts the burden of proving consent on the data controller.
Article 19 requires a data controller to keep a record of its data processors and to take reasonable measures to ensure they process in a way that keeps the controller compliant.
Article 24 requires appropriate technical and organisational measures to secure personal data, article 29 requires a data controller of major importance to carry out a data protection impact assessment before high-risk processing and to submit the report to the Authority, and articles 32 to 34 require such a controller to register with the Authority within six months of qualifying and to designate a data protection officer.
The Act comes into force on adoption by the Federal Parliament, promulgation by the President and publication in the Official Bulletin, and no publication date has been located, so the day it took effect is not stated here. The Act is operative: in January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Text of the Data Protection Act, Law No. 005 of 2023, reproduced by DataGuidance
the Data Protection Authority names the Act and its own copy of the text is not available
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.