Burundi's only enacted cyber-specific statute is Loi n° 1/10 du 16 mars 2022 portant prevention et repression de la cybercriminalite au Burundi, an act combining private-sector operator duties with a long chapter of computer-misuse and content offenses.
It was read here in full across all eight chapters: the copy ARCT (Agence de Regulation et de Controle des Telecommunications, Burundi's telecom and ICT regulator) hosts on its own site is a scanned PDF with no text layer (a Droit-Afrique scan, per the file's own embedded metadata), so an ordinary attempt to read it returns no text; the same bytes were then read with Surya OCR under a leased GPU, since an inline OCR pass is not run automatically when a citation is retrieved.
Chapitre II (Des obligations) binds every operateur des reseaux (network operator) and fournisseur des services (service provider, defined by Article 2(11) as any natural or legal person providing one or more services to users of a telecommunication system) to a general duty to guarantee the security of the services it offers and to fight cyber fraud with technical processes and means (Article 3), and to four further common obligations under Article 4, one of which, maintaining an operational management center for critical infrastructure on national territory, is a genuine security-posture duty; the other three (a ten-year connection- and traffic-data retention duty, installing network traffic-monitoring mechanisms, and video surveillance in cybercafes) are data-retention, surveillance-capability, and physical-security mandates rather than a duty over a system's or service's own security, and are named here rather than flagged as this topic's activity.
Article 14 backs the confidentiality half of that duty with a fine of ten to thirty million Burundian francs (BIF) on a provider or operator that fails to exercise the diligence and competence necessary to prevent disclosure of computer data held for a third party; Articles 3, 4(3) and 14 together are filed here as this jurisdiction's one instrument.
Article 6 requires a service provider that learns its own computer, system or network is being used to commit any offense under the Act, not only an intrusion into its own systems, to report the incident immediately to the criminal-investigation services and preserve evidence, and Article 7 requires one that learns of illegal content or activity to block access to it, suspend or end the client's service, and cooperate with investigators; both bind the provider to cooperate with law enforcement rather than to maintain a security posture, so they are described here rather than filed as a vulnerability-and-incident-reporting duty.
Article 15 punishes a provider or operator that itself furnishes unauthorized access to, transmits, publishes or uses another's computer data or program, which reads as a provider-committed confidentiality offense rather than a security-posture duty, and belongs with the scraping topic's computer_misuse family alongside the Act's much longer run of intruder-facing offenses (Articles 16 through 63: illegal access, system interference, data interference, computer fraud, identity theft, and content offenses), all bound to whoever (quiconque) commits them rather than to an operator or manufacturer.
Article 69 repeals every prior provision contrary to this Act, which on its face supersedes the Penal Code's own computer-offense articles (Arts. 467-470) that this research's dossier named, though that Code's current text was not independently re-read here to confirm. No product-security or connected-device market-placement duty, and no general reasonable-security or information-security-programme statute reaching a business with no sector gate, was located.
Loi n° 1/03 du 10 mars 2026 portant protection des donnees a caractere personnel is Burundi's comprehensive personal-data statute; any security-of-processing or breach-notification clause it carries is this jurisdiction's privacy-topic row and is not restated here.
A targeted check for the text of Loi n° 1/19 du 17 juin 2021 (the Investment Code amendment this research's dossier named) did not locate a full text reachable through ARCT's site or the presidence.gov.bi 'Lois Promulguees' index within this research's tools and budget, so a security-linked incentive clause in it is not confirmed absent.
A check of whether the Banque de la Republique du Burundi (BRB) has issued a cybersecurity or IT-risk directive for a licensed bank or mobile-money operator did not locate one: the BRB's own site is a JavaScript-rendered Drupal site whose 'Reglementation' menu names a 'Secteur Bancaire' and a 'Systemes de Paiement' subsection, but their document URLs return 404 on every path guessed and were not reachable within the tools and search budget used here, so their absence is a gap in what could be checked rather than a finding that no such directive exists.
Whether ARCT has issued a network-security regulation for a licensed telecommunications operator beyond Loi n° 1/10 itself is likewise not confirmed: ARCT's own 'Reglementations' menu lists further categories (Lignes directrices, Ordonnances, Decisions, Circulaires) whose individual contents were not audited here.
Whether Burundi has ratified the African Union Convention on Cyber Security and Personal Data Protection (the Malabo Convention) is not confirmed either: the Convention's own treaty page on au.int was read in full, across both the compliant and the browser-rendered tiers, and names no country on the page reached, so its ratification list evidently lives in a document not reached here.