Comprehensive regime
Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel
Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel arts. 1-11, 13, 23-41 (dispositions générales, principes fondamentaux, obligations du responsable et formalités préalables)Loi n°001-2021/AN, official text as published by the Assemblée nationale du Burkina Faso on its own storage domain
In force since 30 March 2021. Binds public and private bodies.
What this law does
Article 1 states the act's purpose as protecting a natural person's fundamental rights and freedoms in the processing of their personal data. Articles 2 and 3 apply it to automated and non-automated processing alike, including electronic communications data, and bind a controller established in Burkina Faso or one processing from Burkina Faso's territory without being established there.
Article 4 excludes only purely personal or domestic activity, temporary technical transit copies, and journalism carried out under professional ethical rules, leaving publicly available personal data within scope. Articles 6 and 7 require collection, recording, processing, storage and transmission to be lawful, fair and non-fraudulent.
Article 8 limits processing to the determined, explicit and legitimate purposes the data were collected for, and Article 9 requires collected data to be accurate and, where necessary, updated. Article 10 requires the controller to implement appropriate technical and organizational measures to preserve the security and confidentiality of the data, including protection against accidental or unlawful destruction, loss, alteration, disclosure or unauthorized access.
Article 11 requires a controller that uses a processor to choose one offering sufficient guarantees of protection and to sign an agreement fixing the authorized processing operations and the data's fate at the end of the contract.
Article 13 requires the controller's prior consent for processing, subject to exceptions covering manifestly public data, a vital interest, medical care, a court proceeding, a public interest ground, contractual necessity, a legal obligation, a public authority's mission, and a non-profit organization's activities limited to its own members.
Articles 23 to 25 hold every person handling the data to the controller's or processor's authority and instructions, and bound retention to the processing's purpose subject to an archival, historical, statistical or research exception the CIL approves.
Articles 26 to 33 set the prior-formality regime of a normal declaration, a simplified declaration, a request for the CIL's opinion, or its authorization depending on the category of processing, and let a controller optionally designate a data protection officer.
Articles 30 and 31 require a legislative or regulatory act taken after the CIL's opinion before a public body processes data for state security, criminal justice, the census, or payroll and tax administration, and a CIL authorization before interconnecting personal data files or processing a national identification number. Article 41 bounds any interconnection to a legitimate legal or statutory objective that does not discriminate against or reduce the rights of the people concerned.
Articles 36 and 37 require the CIL's authorization, given after the Health Research Ethics Committee's concurring opinion, before processing personal data for health research, anonymization of the data before transmission wherever the research's purpose allows it, and national hosting of any health data that still permits identification.
What it requires