Law / Burundi

Burundi

5 of 6 named instruments researched to a stage, across four of the six areas of law we track: 5 in force. As of 19 September 2026.

When they take effect5 of 5 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 2 instruments (2 in force) 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (225 words)

Burundi's comprehensive personal-data statute is Law No. 1/03 of March 10, 2026 on the Protection of Personal Data, adopted unanimously by the National Assembly on 15 January 2026 and promulgated on 10 March 2026.

Burundi's telecommunications regulator, the Agence de Régulation et de Contrôle des Télécommunications (ARCT), publishes the law and confirms its title and promulgation date; the enacted text itself is not publicly available through a reachable channel, so public-data coverage, a publicly-available exemption, biometric sensitivity, and the cross-border transfer standard are not established.

A contemporaneous secondary account of the bill describes it as organized into eight chapters covering, among other things, the rights of persons regarding the processing of their personal data, the obligations of data controllers, the protection and oversight body the law creates, and the rules applicable to data processors, and states that the bill's sanctions for violations would apply without prejudice to the Penal Code or to Burundi's separate cybercriminality statute.

Before this law, Burundi's data landscape rested on Decree No. 100/085 of July 25, 2018, establishing a national framework for data collection, dissemination, access, archiving, and security, and on the Electronic Communications Code (2024), which strengthened communications confidentiality and established computer incident response centers (CERTs).

Law No. 1/10 of March 16, 2022 on cybercriminality separately defines personal data and sanctions online privacy violations such as identity theft and disinformation.

Comprehensive regime

Law No. 1/03 of March 10, 2026 on the Protection of Personal Data

Loi n°1/03 du 10 mars 2026 portant protection des données à caractère personnelRegulator's own listing of the law's title and promulgation date (Agence de Régulation et de Contrôle des Télécommunications, ARCT)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 12, 2026. Publisher's page: https://arct.gov.bi/2026/03/18/loi-n1-03-du-10-mars-2026-portant-protection-des-donnees-a-caractere-personnel/

In force 6 months, effective 10 March 2026. Binds public and private bodies.

What this law does

Burundi's comprehensive personal-data statute, adopted unanimously by the National Assembly on 15 January 2026 and promulgated by the President of the Republic on 10 March 2026. The regulator that publishes it, ARCT, confirms only the law's title and promulgation date.

A contemporaneous account of the bill as submitted for the Assembly's analysis that day describes it as organized into eight chapters covering, among other things, the rights of persons regarding the processing of their personal data, the obligations of data controllers, the protection and oversight body the law creates, and the rules applicable to data processors.

The same account states that the bill's sanctions for violations would apply without prejudice to the Penal Code or to Burundi's separate cybercriminality statute; whether the promulgated text retains this structure is unconfirmed.

What it requires

Scraping law2 instruments, 2 in force

Research summary (296 words)

Open-web crawling of public pages carries no dedicated Burundian statute.

Burundi's applicable computer-misuse authority is its dedicated cybercrime statute, Law No. 1/10 of March 16, 2022 on the Prevention and Repression of Cybercriminality; the regulator that publishes it, the Agence de Régulation et de Contrôle des Télécommunications (ARCT), confirms the law's title and promulgation date; the statute's text is not publicly available through a reachable channel, so its specific provisions, and how authorization is read for a public, unauthenticated page, are not established.

No statute or case law addressing terms-of-service enforceability (browsewrap versus clickwrap), or whether login or acceptance of terms changes the legal picture, was located.

Copyright protects a database as a compilation rather than through a separate sui generis database right: Law No. 1/021 of December 30, 2005 on the Protection of Copyright and Related Rights excludes reproducing all or major parts of a database in digital format even from its otherwise-permitted private-copy exception (Article 26(1)(a)), meaning a database is a protected work whose substantial reproduction the rights holder can otherwise prevent.

The same Law excludes official texts, daily news, and mere facts and data from copyright protection altogether (Article 7), and its enumerated exceptions are quotation, press-review, and current-events reporting (Article 26) rather than a general fair-use or text-and-data-mining carve-out; nothing in the Law addresses AI training specifically, and it predates that concept.

Personal-data reach over scraped public personal data is governed by Law No. 1/03 of March 10, 2026 on the Protection of Personal Data; its enacted text is likewise not publicly available, so whether it carves out publicly available personal data is not established. No specific unfair-competition or misappropriation doctrine addressed to scraping, and no case law or regulatory statement giving robots.txt legal weight or addressing AI-training-specific access rules, was located.

Computer misuse

Law No. 1/10 of March 16, 2022 on the Prevention and Repression of Cybercriminality in Burundi

Loi n°1/10 du 16 mars 2022 portant prévention et répression de la cybercriminalité au BurundiRegulator's own listing of the law's title and promulgation date (Agence de Régulation et de Contrôle des Télécommunications, ARCT)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 12, 2026. Publisher's page: https://arct.gov.bi/2023/08/10/loi-n1-10-du-16-mars-2022-portant-prevention-et-repression-de-la-cybercriminalite-au-burundi/

In force since 16 March 2022. Binds public and private bodies.

What this law does

Burundi's dedicated cybercrime statute, promulgated 16 March 2022 by the President of the Republic, portant prévention et répression de la cybercriminalité au Burundi (on the prevention and repression of cybercriminality in Burundi). The Agence de Régulation et de Contrôle des Télécommunications (ARCT), Burundi's telecommunications regulator, publishes the law on its own site and confirms its title and promulgation date.

The statute's own text has not been located online, so its specific offenses, the authorization test it applies to computer-system access, and its penalty structure remain unconfirmed.

What it requires

Database right

Law No. 1/021 of December 30, 2005 on the Protection of Copyright and Related Rights, database and facts exclusions

Loi n° 1/021, Database and Facts Exclusion (Arts. 7 et 26.1), portant protection du droit d'auteur et des droits voisins, 30 décembre 2005Law No. 1/021 of December 30

In force since 30 December 2005. Binds public and private bodies.

What this law does

Burundi's copyright statute treats a database as a protected compilation rather than through a separate sui generis database right. Article 26(1)(a)'s private-copy exception expressly excludes reproducing all or major parts of a database in digital format, meaning a database is a protected work whose substantial reproduction the rights holder can otherwise prevent; there is no separate sui generis database right of the EU kind.

Article 7 excludes official texts, daily news, and mere facts and data from copyright protection outright.

Article 26 also lets a person quote a lawfully published work, including newspaper articles and periodicals in the form of press summaries, and reproduce a current-events news article or broadcast subject to source attribution, unless publication was accompanied by an express reservation against such use; none of these exceptions is framed as a text-and-data-mining carve-out, and nothing in the Law addresses AI training specifically.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (848 words)

Burundi's only enacted cyber-specific statute is Loi n° 1/10 du 16 mars 2022 portant prevention et repression de la cybercriminalite au Burundi, an act combining private-sector operator duties with a long chapter of computer-misuse and content offenses.

It was read here in full across all eight chapters: the copy ARCT (Agence de Regulation et de Controle des Telecommunications, Burundi's telecom and ICT regulator) hosts on its own site is a scanned PDF with no text layer (a Droit-Afrique scan, per the file's own embedded metadata), so an ordinary attempt to read it returns no text; the same bytes were then read with Surya OCR under a leased GPU, since an inline OCR pass is not run automatically when a citation is retrieved.

Chapitre II (Des obligations) binds every operateur des reseaux (network operator) and fournisseur des services (service provider, defined by Article 2(11) as any natural or legal person providing one or more services to users of a telecommunication system) to a general duty to guarantee the security of the services it offers and to fight cyber fraud with technical processes and means (Article 3), and to four further common obligations under Article 4, one of which, maintaining an operational management center for critical infrastructure on national territory, is a genuine security-posture duty; the other three (a ten-year connection- and traffic-data retention duty, installing network traffic-monitoring mechanisms, and video surveillance in cybercafes) are data-retention, surveillance-capability, and physical-security mandates rather than a duty over a system's or service's own security, and are named here rather than flagged as this topic's activity.

Article 14 backs the confidentiality half of that duty with a fine of ten to thirty million Burundian francs (BIF) on a provider or operator that fails to exercise the diligence and competence necessary to prevent disclosure of computer data held for a third party; Articles 3, 4(3) and 14 together are filed here as this jurisdiction's one instrument.

Article 6 requires a service provider that learns its own computer, system or network is being used to commit any offense under the Act, not only an intrusion into its own systems, to report the incident immediately to the criminal-investigation services and preserve evidence, and Article 7 requires one that learns of illegal content or activity to block access to it, suspend or end the client's service, and cooperate with investigators; both bind the provider to cooperate with law enforcement rather than to maintain a security posture, so they are described here rather than filed as a vulnerability-and-incident-reporting duty.

Article 15 punishes a provider or operator that itself furnishes unauthorized access to, transmits, publishes or uses another's computer data or program, which reads as a provider-committed confidentiality offense rather than a security-posture duty, and belongs with the scraping topic's computer_misuse family alongside the Act's much longer run of intruder-facing offenses (Articles 16 through 63: illegal access, system interference, data interference, computer fraud, identity theft, and content offenses), all bound to whoever (quiconque) commits them rather than to an operator or manufacturer.

Article 69 repeals every prior provision contrary to this Act, which on its face supersedes the Penal Code's own computer-offense articles (Arts. 467-470) that this research's dossier named, though that Code's current text was not independently re-read here to confirm. No product-security or connected-device market-placement duty, and no general reasonable-security or information-security-programme statute reaching a business with no sector gate, was located.

Loi n° 1/03 du 10 mars 2026 portant protection des donnees a caractere personnel is Burundi's comprehensive personal-data statute; any security-of-processing or breach-notification clause it carries is this jurisdiction's privacy-topic row and is not restated here.

A targeted check for the text of Loi n° 1/19 du 17 juin 2021 (the Investment Code amendment this research's dossier named) did not locate a full text reachable through ARCT's site or the presidence.gov.bi 'Lois Promulguees' index within this research's tools and budget, so a security-linked incentive clause in it is not confirmed absent.

A check of whether the Banque de la Republique du Burundi (BRB) has issued a cybersecurity or IT-risk directive for a licensed bank or mobile-money operator did not locate one: the BRB's own site is a JavaScript-rendered Drupal site whose 'Reglementation' menu names a 'Secteur Bancaire' and a 'Systemes de Paiement' subsection, but their document URLs return 404 on every path guessed and were not reachable within the tools and search budget used here, so their absence is a gap in what could be checked rather than a finding that no such directive exists.

Whether ARCT has issued a network-security regulation for a licensed telecommunications operator beyond Loi n° 1/10 itself is likewise not confirmed: ARCT's own 'Reglementations' menu lists further categories (Lignes directrices, Ordonnances, Decisions, Circulaires) whose individual contents were not audited here.

Whether Burundi has ratified the African Union Convention on Cyber Security and Personal Data Protection (the Malabo Convention) is not confirmed either: the Convention's own treaty page on au.int was read in full, across both the compliant and the browser-rendered tiers, and names no country on the page reached, so its ratification list evidently lives in a document not reached here.

Sector security regimes

Loi n° 1/10, Articles 3, 4(3) and 14: security-of-service duty and diligence penalty for network operators and service providers

Loi n° 1/10 du 16 mars 2022 portant prevention et repression de la cybercriminalite au Burundi, Arts. 3, 4(3), 14Loi n° 1/10 du 16 mars 2022, official text as hosted by ARCT (arct.gov.bi)

In force since 16 March 2022. Binds public and private bodies.

What this law does

Article 3 requires every opérateur des réseaux (network operator) and fournisseur des services (service provider) to guarantee the security of the services it offers and to put in place the technical processes and means needed to fight cyber fraud. Article 2(11) defines a fournisseur des services as any natural or legal person providing one or more services to users of a telecommunication system.

Article 4 additionally requires the same bound parties to maintain an operational management center for their critical infrastructure on Burundian national territory. Article 4 also requires retaining connection and traffic data for a minimum of ten years. It requires installing mechanisms to monitor the operator's own network traffic data.

It requires installing a video-surveillance system in cybercafés. These three obligations read as data-retention, surveillance-capability, and physical-security duties rather than a security-posture requirement for a system or service, so this row flags only the Article 3 and Article 4(3) duties as its activity.

Article 14 imposes a fine of ten to thirty million Burundian francs on a service provider or network operator that fails to exercise the diligence and competence necessary to prevent the disclosure of computer data made available to a third party. No additional imprisonment attaches to Article 14, unlike most neighboring articles in the same chapter.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (248 words)

Burundi has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is Law No. 1/021 of December 30, 2005 on the Protection of Copyright and Related Rights, which excludes daily news published, broadcast or communicated in public, and mere facts and data, from copyright protection outright (Article 7).

The same Law lets a person, once a work has been lawfully published and the source and author's name are credited, quote a work including newspaper articles and periodicals in the form of press summaries, so long as the quotation is compatible with fair practice and does not exceed the extent justified by its purpose (Article 26(1)(b)), and separately lets a current economic, political or religious news article, or a broadcast of the same character, be reproduced in the press or communicated to the public so long as the source is clearly indicated, unless the article or broadcast was itself accompanied by an express condition prohibiting such use (Article 26(2)).

Nothing limits either exception to a headline-length or short-extract threshold, and no reported Burundian court decision applying either to a systematic news aggregator, as opposed to a traditional press review, was located. The Law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Law No. 1/021 of December 30, 2005 on the Protection of Copyright and Related Rights, news and press-review exceptions (Article 26(2)) and facts exclusion (Article 7)

Loi n° 1/021 Press Review and Current-Events Exception (Art. 26.2), portant protection du droit d'auteur et des droits voisins, 30 décembre 2005Law No. 1/021 of December 30

In force since 30 December 2005. Binds public and private bodies.

What this law does

Article 7 excludes acts, legal decisions and administrative decisions and their official translations, daily news published, broadcast or communicated in public, and mere facts and data, from copyright protection outright: a bare fact, or the news of the day as such, is never a protected work under Burundian law, whichever outlet reports it first.

Article 26(1)(b) separately lets any person, once a work has been lawfully published, quote from it in another work, including quotations from newspaper articles and periodicals in the form of press summaries, provided the quotation is compatible with fair practice, does not exceed the extent justified by its purpose, and the source and the author's name are mentioned.

Article 26(2) lets a current economic, political or religious news article published in a newspaper or periodical, or a broadcast of the same character, be reproduced in the press or communicated to the public, subject to the source being clearly indicated, unless the article as published, or the work as broadcast, was itself accompanied by an express condition prohibiting such use, meaning the publisher can reserve the reproduction right in advance.

Neither exception is capped at a headline-length or short-extract threshold and neither is confined to the press industry; whether either reaches a systematic aggregator's reproduction of headlines and snippets, as opposed to a traditional press review or a broadcaster's current-events report, has not been tested in a reported Burundian decision.

Burundi has no separate press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no recognized hot-news or misappropriation doctrine distinct from ordinary copyright and unfair-competition law, and no located case law on hyperlinking or framed display.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.