Law / Central African Republic

Central African Republic

11 of 13 named instruments researched to a stage, across five of the six areas of law we track: 11 in force. As of 22 September 2026.

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law 3
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (116 words)

The Central African Republic has no statute on AI-transparency, output-labelling, high-risk-system conformity, training-data provenance, or algorithmic governance; the only located instrument that plausibly reaches AI-generated content is article 111 of the Code Pénal Centrafricain (Loi n° 10.001 du 6 janvier 2010), a criminal ban on pornographic acts involving children that defines pornography by reference to a representation in a work rather than to a real victim, so it is recorded here as an outright-prohibition instrument rather than as an absence.

The African Union's Continental Artificial Intelligence Strategy, adopted July 2024, binds only member-state governments to develop national AI policy and is not recorded as an instrument; no Central African national implementation of it has been located.

AI prohibited practices

Code Pénal Centrafricain, article 111 (pornographie impliquant des enfants)

Code Pénal Centrafricain, Loi n° 10.001 du 6 janvier 2010, art. 111Text of Loi n° 10.001 du 6 janvier 2010 portant Code pénal centrafricain, WIPO Lex legislation record

In force. Binds public and private bodies.

What this law does

Article 111 opens by defining pornography as a complaisant representation of subjects in a literary, artistic, or cinematographic work that offends against good morals, and then makes it an offence for anyone to be guilty of pornographic acts with respect to children, punishable by two to five years' imprisonment and a fine, doubled on repeat conduct.

Because the article defines the underlying concept of pornography by reference to a representation in a work rather than by reference to conduct against a real child, its wording does not on its face exclude a virtual, drawn, or computer-generated depiction of a child from the offence, so a service generating that kind of synthetic content plausibly falls within the ban; no Central African appellate decision construing the point has been located, so this is a reading of the text rather than a settled interpretation.

The Code has no separate provision addressing AI-generated content, algorithmic transparency, or synthetic-media labelling.

What it requires

Privacy law5 instruments, 5 in force

Research summary (217 words)

The Central African Republic's personal data regime is Loi n° 24.001 portant protection des données à caractère personnel, adopted in January 2024, applying to processing carried out in the country or producing effects there. It sets a comprehensive baseline of principles, lawful bases, subcontracting rules, a file interconnection authorization requirement, and a mandatory data protection officer.

It imposes heightened rules on sensitive categories of data, including biometric, genetic, health, political, religious, and criminal record data, and on a minor's data. It gives a data subject rights of objection, access, rectification, erasure, and information about an automated decision, plus a marketing opt out. It restricts cross border transfer, with a lighter regime for CEMAC and CEEAC member states.

It backs the whole regime with administrative sanctions capped at 5 percent of a controller's turnover, alongside separate criminal fines and imprisonment for specific offences. The Act defines what counts as a violation of personal data but does not state a duty to notify a breach to the agency or to a data subject. The Act states that it takes effect from its date of promulgation, but the archived text does not show a legible date for that promulgation.

The Act does not state whether a private plaintiff may bring a civil claim independent of the agency's own enforcement powers.

Comprehensive regime

Loi n° 24.001 portant protection des données à caractère personnel

Loi n° 24.001 portant protection des données à caractère personnel Chapitres Ier, II, V, VII et IX (dispositions générales, principes, interconnexion des fichiers, délégué à la protection des données et dispositions finales)Text of Loi n° 24.001 portant protection des données à caractère personnel

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDF

In force. Binds public and private bodies.

What this law does

Loi n° 24.001 applies to processing carried out by an establishment of a controller or a processor in the Central African Republic, and to processing that produces effects in the country even where the controller is abroad, subject to carve outs for a purely personal or domestic use and for the temporary, intermediate technical copies an access provider makes to route traffic.

Every activity of processing personal data must respect the principles of lawfulness, fairness, transparency, security, purpose limitation, accuracy, proportionality, and retention limitation.

Personal data may be processed only where it is necessary for the performance of a contract, compliance with a legal obligation, a legitimate interest that does not override the data subject's rights, the data subject's freely given and revocable explicit consent, the safeguarding of someone's vital interests, or the performance of a public interest mission, and a person who has made their own data freely accessible supports a controller's reliance on the legitimate interest ground.

Data processed for archival, historical, statistical, or scientific purposes may be kept and used under safeguards a law defines for that purpose even after the Act's ordinary retention limit would otherwise apply. A controller must take precautions appropriate to the data's nature and the risks involved to keep personal data secure, including protection against accidental or unlawful destruction, loss, alteration, or unauthorized access.

Processing may be subcontracted only on the controller's instruction, the processor must offer sufficient guarantees to implement security and confidentiality measures, and the contract between them must specify the processor's security and confidentiality obligations.

A provider of electronic signature certification services must collect the personal data it needs to issue and keep the certificates directly from the person concerned, and use it only for that purpose, absent the person's express consent otherwise.

Interconnecting personal data files held by different public service bodies with different public interests, or held by private parties for different purposes, needs the agency's prior authorization, stating the nature of the data, the purpose the interconnection serves, and its duration.

Every controller must designate a data protection officer responsible for compliance with the Act's obligations, who keeps the register of processing operations, issues an opinion on every new processing operation before it starts, and consults the agency in case of doubt, and designating one exempts the controller from the ordinary prior declaration formalities except where the processing needs the agency's authorization.

Only a person residing in the Central African Republic with the necessary knowledge and qualifications may be designated data protection officer, whether an employee or an outside person, and the officer may be removed only for serious cause and after the agency has been told.

Chapitre Ier defines a violation of personal data as any destruction, loss, alteration, or unauthorized disclosure of personal data, transmitted, stored, or otherwise processed, that is accidental or unlawful, but no provision of the Act requires that violation to be notified to the agency or to the person concerned. The Act states that it takes effect from its date of promulgation, but the archived text does not show a legible date for that promulgation.

What it requires

Cross border transfer

Loi n° 24.001 portant protection des données à caractère personnel, flux transfrontalier

Loi n° 24.001, Chapitre III (flux transfrontalier)Text of Loi n° 24.001 portant protection des données à caractère personnel

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDF

In force. Binds public and private bodies.

What this law does

A controller may transfer personal data to a foreign State only where that State's legislation ensures a level of protection similar to the one this Act assures, assessed against the nature of the data, the purpose and duration of the processing, the countries of origin and destination, and the rules the third country applies.

Absent a similarly protective destination, a transfer may still go ahead where the person concerned, informed of the gap, has unambiguously consented, where it is necessary to perform a contract with or for the person or pre-contractual measures at their request, where a law requires it to safeguard an important public interest or a legal claim, where it safeguards the person's vital interest, or where it comes from a public register open to a person with a legitimate interest.

A recipient may not transfer the data onward to another State without the original controller's agreement. For a transfer to a State outside the CEMAC or CEEAC that does not assure an identical level of protection, the agency may still authorize it where the controller offers sufficient guarantees for privacy and fundamental rights, including through appropriate contractual clauses, and that authorization may be renewed on request.

A transfer to another country outside the CEMAC or CEEAC needs a sufficient level of protection there too, the controller must give the agency prior notice before any such transfer, and absent adequate protection the transfer may still proceed on the person's unambiguous consent, a contract's necessity, an important public interest or legal claim, or a public register.

What it requires

Data subject rights

Loi n° 24.001 portant protection des données à caractère personnel, droits liés au traitement

Loi n° 24.001, Chapitre II et Chapitre VI (droits liés au traitement, prospection directe)Text of Loi n° 24.001 portant protection des données à caractère personnel

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDF

In force. Binds public and private bodies.

What this law does

Anyone with a legitimate reason has the right to object, at any time and free of charge, to the processing of personal data concerning them, and the agency assesses whether a contested reason is legitimate.

A person may obtain, on request, information about the purposes of the processing, the categories of data processed, and the recipients or categories of recipients the data are communicated to, along with the information letting them understand and contest the mechanism of an automated decision that produces legal effects for them.

The person exercises the right of access free of charge, on the spot or remotely, without delay, and receives a copy of their data on request, and where the access concerns health data the controller may communicate it through the physician the person designates. A controller may refuse a manifestly abusive request, repeated or systematic, from the same person, but bears the burden of proving the request was abusive if the refusal is disputed.

On a substantiated request, a person may require a controller to rectify, complete, update, block, or erase personal data concerning them that is inaccurate, incomplete, ambiguous, outdated, or unlawfully collected, used, communicated, or retained, and where the controller had disclosed the data to a third party it must notify that party of the change without delay.

Where a processing activity concerns State security, defense, or public safety, the rights of access and rectification are exercised indirectly, without the data subject's consent, through a request the agency routes to the controller.

Direct marketing by phone, fax, SMS, email, instant message, or social network needs the recipient's prior consent, the recipient must be able to unsubscribe or change their preferences at any time, and where the marketing targets a business or a person acting professionally the controller must still give notice and an unsubscribe option in every communication, as simple and effective as signing up was.

What it requires

Enforcement supervision

Loi n° 24.001 portant protection des données à caractère personnel, sanctions et agence

Loi n° 24.001, Chapitre VIII et Chapitre IX (sanctions et agence)Text of Loi n° 24.001 portant protection des données à caractère personnel

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDF

In force. Binds public and private bodies.

What this law does

The agency may impose against a controller, for a breach of one or more provisions of the Act, a warning, an order to stop the processing, a pecuniary sanction, or the withdrawal of a granted authorization or certification.

In an emergency, where a processing activity or the exploitation of data violates the rights and freedoms the Act's opening articles protect, the agency may order the interruption of the processing for up to three months, or lock certain data for up to three months where the processing serves only State security, national defense, or public safety purposes.

A pecuniary sanction is doubled on repeat conduct, and where the breach is grave and immediate the agency may ask the competent court, by way of an emergency referral, to order any security measure the rights and freedoms require. A sanction is decided on the basis of a report, gives the controller a chance to make written and oral observations and be represented, and results in a reasoned, published decision the controller may appeal to the administrative courts, at the sanctioned party's cost.

The pecuniary sanction cannot exceed 5 percent of the controller's turnover, excluding tax, for the last closed financial year, and is recovered like a debt owed the State.

Separate criminal penalties apply, from six months to five years' imprisonment and a fine of 100,000 to 10,000,000 FCFA depending on the offence, for obstructing the agency's missions, for negligently processing personal data without observing the Act's required prior formalities, for retaining data beyond the duration declared to the agency outside an historical, statistical, or scientific exception, for collecting data by a fraudulent, unfair, or unlawful means, for misusing a file's declared purpose, for continuing to process despite a person's well founded objection or rectification request, or for an unauthorized disclosure that harms a person's standing or the privacy of their life.

A court may order the erasure of data involved in an offence, and the agency's members and agents are empowered to establish that the erasure took place. The Ministry in charge of the digital economy has twelve months from the Act's promulgation to establish the dedicated agency, and performs the agency's functions itself in the meantime.

What it requires

Sensitive categories

Loi n° 24.001 portant protection des données à caractère personnel, données sensibles et mineurs

Loi n° 24.001, Chapitre Ier Section 2 et Chapitre II (données sensibles et mineurs)Text of Loi n° 24.001 portant protection des données à caractère personnel

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDF

In force. Binds public and private bodies.

What this law does

Loi n° 24.001 defines sensitive data as personal data relating to religious, philosophical, or political opinions or activities, sexual life or orientation or racial life, health, including genetic or biometric data, social measures, prosecutions, and criminal or administrative sanctions. A minor's data may be processed only where consent for it is given or authorized by a holder of parental responsibility over the child, including for a direct offer of information society services to children.

Where a processing activity engages sensitive data or the data of a particularly vulnerable person, including a minor, the controller must take every additional appropriate organizational and technical measure to protect the person concerned, and consent must in every case be explicit and require an affirmative act.

Processing sensitive data is otherwise prohibited because of the risk of discrimination or of harming a person's freedoms, covering data revealing racial origin, biometric and genetic data, political opinions, religious or other convictions, trade union membership, and health or sexual life.

By derogation, sensitive data may be processed with appropriate safeguards where the person concerned has given express consent unless a law says otherwise, where processing is necessary to safeguard the life of the person concerned or a third party who cannot consent, where it is carried out by a non profit religious, philosophical, political, or trade union body about its own members without third party disclosure, where it is necessary to establish, exercise, or defend a legal claim, where it serves preventive medicine, diagnosis, care, or health service management by a health professional, where the data were made public by the person concerned, where a law authorizes it for a public interest purpose, or where a labor law right or obligation requires it.

Data about a person's offences, convictions, and safety measures may be processed only by courts and public authorities acting within their legal powers, and by legal auxiliaries strictly for the duties the law assigns them.

What it requires

Scraping law1 instrument, 1 in force

Research summary (348 words)

The Central African Republic has no statute located that specifically addresses unauthorized computer access, terms-of-service enforceability, a text-and-data-mining exception, a sui generis database right, unfair competition targeting data collection, or the legal weight of robots.txt. Article 164 of the Code Pénal Centrafricain (Loi n° 10.001 du 6 janvier 2010) lists computer or electronic piracy among the acts treated as theft, but the surrounding text confines that item to a fraudulent alteration of an electricity, water, gas, or telephone distribution installation aimed at reducing or inflating a user's charges, so the provision does not on its face create a general unauthorized-access or computer-trespass offense reaching an ordinary public web page.

Loi n° 24.002 du 21 février 2024 relative à la cybersécurité et à la lutte contre la cybercriminalité names the fight against cybercrime in its title and creates the Agence Nationale de la Cybersécurité, documented in this jurisdiction's security-topic instruments; whether that Act also carries a computer-misuse or unauthorized-access offense of its own has not been confirmed here.

Loi n° 18.002 du 17 janvier 2018 régissant les communications électroniques and Loi n° 22.002 régissant les transactions électroniques en République Centrafricaine both exist as titles published by the telecommunications regulator ARCEP; neither has been located in a readable primary text, so their content is not described here.

As a member state of the African Intellectual Property Organization (OAPI), the Central African Republic's copyright regime is the regional Bangui Agreement, documented in this jurisdiction's aggregation-topic instrument; its Annex VII creates a press-quotation exception for news reproduction but no distinct text-and-data-mining exception, opt-out mechanism, or sui generis database right.

The Central African Republic's comprehensive personal-data statute, Loi n° 24.001 portant protection des données à caractère personnel, reaches personal data wherever a controller obtains it, including data a person has made publicly accessible: that circumstance supports the controller's reliance on the legitimate-interest lawful basis but is not stated as a carve-out from the Act's other duties, and every cross-border transfer of personal data, whatever its source, needs either a destination with a similar level of protection or one of the Act's listed derogations.

Personal data

Loi n° 24.001 portant protection des données à caractère personnel, collecte de données publiquement accessibles et transfert transfrontalier

Loi n° 24.001, Chapitre II (motifs de licéité, données librement accessibles) et Chapitre III (flux transfrontalier)Text of Loi n° 24.001 portant protection des données à caractère personnel

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived June 22, 2026. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_001_portant_protection_des_donnes_a_caractere_personnel.PDF

In force. Binds public and private bodies.

What this law does

Loi n° 24.001 reaches personal data wherever a controller finds it, including data a person has made publicly accessible online. A data subject who has made their own personal data freely accessible supports a controller's reliance on the legitimate-interest lawful basis for processing it, provided the use fits the context in which the person made the data accessible, but the Act does not state that publicly accessible data falls outside its scope or its other duties.

A controller may transfer personal data, wherever it was collected, to a foreign State only where that State's own legislation ensures a level of protection similar to the one this Act assures, or under one of the Act's listed derogations, the data subject's informed and unambiguous consent, a contract's necessity, an important public interest or legal claim, a vital interest, or a public register.

A transfer to a State outside the CEMAC or CEEAC needs the controller to give the data protection agency prior notice before the transfer, and absent an equivalent level of protection there the agency may still authorize it where the controller offers sufficient contractual guarantees.

Sensitive categories of personal data, including biometric, genetic, health, political, religious, and criminal-record data, may be processed only on the data subject's explicit consent or one of the Act's other listed derogations, whatever the source from which a controller obtained them.

What it requires

Cybersecurity law3 instruments, 3 in force

Research summary (598 words)

Central African Republic's Loi n° 24.002 du 21 février 2024 relative à la cybersécurité et à la lutte contre la cybercriminalité creates the Agence Nationale de la Cybersécurité (ANCy) as the country's cybersecurity authority and Computer Emergency Response Team, and carries three distinct security duties reachable by a private developer or service provider.

Articles 7 to 12 give ANCy the power to designate essential-service operators, whether public or private, whose continuity could be gravely affected by an incident touching an electronic-communications network or information system, to set and enforce the protective measures those operators must implement, to grant them accreditation, and to impose administrative sanctions, including pecuniary ones, for noncompliance, with no fixed penalty amount stated in the text reviewed here.

Articles 14, 15 and 25 place every electronic-communications network and information system, and name network operators, certification authorities and electronic-communications service providers in particular, under a mandatory security audit at least once a year, whose confidential report reaches ANCy for approval and the Ministères chargés de la Sécurité Publique and de l'Economie Numérique for decision; Article 43 makes obstructing that audit a criminal offense of one to five years' imprisonment and a fine of 100,000 to 1,000,000 CFA francs or either penalty alone.

Articles 16, 19, 20, 21 and 23 impose a general, sector-unlimited duty on an electronic-communications network operator and on any information-system operator to take all technical and administrative measures necessary to secure the services offered, to adopt standardized risk-management systems ANCy must approve, to inform users of security risks and of the technical means to address them, and to periodically review and update those security systems under ANCy's oversight, again with no fixed penalty stated for noncompliance.

No provision reviewed here sets a security requirement a software product or connected device must meet before being placed on the Central African market, and none states a numerical deadline by which an operator must report a vulnerability or a security incident to ANCy or to users; ANCy's own CERT/CSIRT function (Article 11) collects technical information about an incident affecting an essential-service operator's infrastructure or a State information system, without a stated reporting clock.

A separate chapter of the same Act (Articles 33 and 77 to 82) requires a cryptology service provider to disclose the technical characteristics and source code of its cryptology means to ANCy, and to obtain ANCy's prior authorization to import, export or provide cryptology services.

This is a cryptography licensing and state-disclosure regime rather than a duty that a product be secure, carries no vulnerability-handling or incident-reporting duty of its own, and fits none of this topic's four registered law families, so it is named here rather than filed as an instrument.

Article 140 of the same Act states that it complements Loi n° 18.002 du 17 janvier 2018 régissant les Communications Electroniques en République Centrafricaine; that earlier Act's own content beyond Article 140's cross-reference is not described here. Loi n° 22.002 régissant les transactions électroniques en République Centrafricaine, published by the same regulator, exists as a title for this topic; its content is not described here either.

Central African Republic's comprehensive data-protection statute, Loi n° 24.001 portant protection des données à caractère personnel, defines a security incident affecting personal data as a violation des données à caractère personnel and carries that Act's own security-of-processing duty; it is documented as this jurisdiction's privacy-topic instrument rather than repeated here.

ANCy's cybersecurity enforcement carries no published enforcement record; the Agency was created by this 2024 Act, and Article 141 lets the two supervising Ministries perform its missions provisionally pending the establishment of its own organs.

Sector security regimes

Cybersecurity Law: Essential-Service Operator Cybersecurity Regime

Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité, Titre II, Chapitre I (art. 7 à 12)Text of Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 10, 2025. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_002_relative_a_la_cyber_securite.pdf

In force since 21 February 2024. Binds public and private bodies.

What this law does

Article 8 creates the Agence Nationale de la Cybersécurité (ANCy), a public, non-commercial establishment with legal personality and financial autonomy, as the national authority over the security of essential infrastructure and of public authorities' information systems.

Article 10 gives ANCy the power to designate essential-service operators, whether public or private, whose continuity could be gravely affected by an incident touching an electronic-communications network or information system; to set the protective measures those operators must implement to secure their essential infrastructure and to control compliance with them; to grant accreditation to a compliant operator; and to impose administrative sanctions, including pecuniary ones, on an operator that fails to meet its cybersecurity obligations, with no fixed amount stated in the text reviewed here.

Article 11 gives ANCy the function of Computer Emergency Response Team (CERT) or Computer Security Incident Response Team (CSIRT) for the Central African Republic and a 24/7 point of contact, under which it coordinates incident prevention and response with national partners and foreign CERTs and collects technical information about an incident affecting an essential-service operator's essential infrastructure or a State information system; the reviewed text states no deadline by which an operator must report an incident to ANCy.

What it requires

Cybersecurity Law: Mandatory Security Audit Regime

Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité Titre II, Chapitre II (art. 14, 15 et 25) et Titre III, Chapitre I (art. 43)Text of Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 10, 2025. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_002_relative_a_la_cyber_securite.pdf

In force since 21 February 2024. Binds public and private bodies.

What this law does

Article 14 places the electronic-communications networks and information systems of network operators, certification authorities and electronic-communications service providers under a mandatory security audit; the audit's conditions and modalities, and the follow-up of its recommendations, are set by implementing regulation.

Article 25 restates the mandatory security-audit regime over electronic-communications networks and information systems generally, requires the audit and a severity-impact assessment to run at least once a year or whenever circumstances require it, and requires the resulting confidential audit report to reach ANCy for approval before it is transmitted to the Ministères chargés de la Sécurité Publique and de l'Economie Numérique for decision; a further implementing regulation sets the conditions for assessing severity-impact levels.

Article 15 binds ANCy's own personnel and the experts it commissions for an audit to professional secrecy, and Article 41 makes an unauthorized disclosure by that personnel or those experts a criminal offense punishable by one to five years' imprisonment and a fine of 1,000,000 to 10,000,000 CFA francs.

Article 43 makes it a criminal offense, punishable by one to five years' imprisonment and a fine of 100,000 to 1,000,000 CFA francs or either penalty alone, to obstruct a security audit by any means, incite resistance to it, or refuse to provide the information or documents it requires.

What it requires

Security baseline statutes

Cybersecurity Law: Network and Information System Security Duty

Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité Titre II, Chapitre III, Sections I et II (art. 16, 19, 20, 21, 23)Text of Loi n° 24.002 relative à la cybersécurité et à la lutte contre la cybercriminalité

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived May 10, 2025. Publisher's page: https://www.arcep.cf/fr/images/documents/reglementation/lois/Loi_24_002_relative_a_la_cyber_securite.pdf

In force since 21 February 2024. Binds public and private bodies.

What this law does

Article 16 requires an electronic-communications network operator or service provider to take all technical and administrative measures necessary to guarantee the security of the services it offers, and to inform users of the danger of using its networks, of the particular security-violation risks involved (distributed denial of service, abnormal rerouting, traffic spikes, unusual traffic and ports, passive and active eavesdropping, intrusions), and of the technical means available to secure their communications.

Article 19 imposes the same all-measures security duty on any information-system operator, and further requires that operator to adopt standardized systems to continually identify, assess, treat and manage the risks to its information systems' security, to put technical mechanisms in place against threats to the systems' permanent availability, integrity, authentication, non-repudiation, data confidentiality and physical security, to submit those mechanisms to ANCy for approval, and to protect its platforms against intrusion with, among other things, an intrusion-detection system.

Article 20 requires a legal person offering access to information systems to inform users of the danger of an unsecured information system, the need for parental-control devices, and the particular risks of the generic virus family, and to offer at least one technical means of restricting access, such as an up-to-date operating system, antivirus and anti-spyware tools, a personal firewall, an intrusion-detection system or automatic updates; where no such means exists, the provider must say so.

Article 21 requires an information-system operator to inform users that using the network to distribute illicit content, or designing deceptive software, spyware or a potentially unwanted program, is prohibited. Article 23 requires an information-system operator to periodically evaluate and revise its security systems and introduce necessary changes as technology evolves, under ANCy's oversight, and lets it cooperate with its own users on that work.

None of the articles reviewed here states a fixed administrative or criminal penalty specific to a network operator's or information-system operator's failure to meet these security duties.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (101 words)

The Central African Republic's domestic copyright statute, Ordonnance n° 85.002 sur le droit d'auteur (1985), has not been read, and its text is not cited here. As an OAPI member state since 1982, the Central African Republic's operative copyright regime is instead the regional Bangui Agreement, whose Annex VII (as revised February 24, 1999, in force since February 28, 2002) applies directly by virtue of membership and carries a press-quotation exception reaching news reproduction.

That regime creates no press-publisher neighbouring right, no mandatory bargaining code, and no hot-news or linking-and-framing rule, and no other Central African source states a text-and-data-mining opt-out.

Snippet reproduction

Bangui Agreement (revised 1999), Annex VII, Free Use for Informatory Purposes

Agreement of February 24, 1999, Revising the Bangui Agreement of March 2, 1977, Annex VII (Literary and Artistic Property), art. 16Text of the Agreement of February 24

In force since 28 February 2002. Binds public and private bodies.

What this law does

The Central African Republic is a member state of the African Intellectual Property Organization (OAPI), and the Bangui Agreement as revised on February 24, 1999 states that it and its annexes apply in their entirety to every State that ratifies or accedes to it, so its Annex VII copyright regime governs literary and artistic property in the Central African Republic directly, without need of separate domestic transposition.

Article 16 of Annex VII permits, without the author's consent and without payment, reproducing in the press, broadcasting, or communicating to the public an economic, political, or religious article already published in a newspaper or periodical, provided the source and author are credited, unless the right of reproduction has been expressly reserved; the same article separately permits reporting on current events and reproducing political speeches and public addresses for informational purposes.

Annex VII creates no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no hot-news or misappropriation doctrine distinct from ordinary copyright, and no machine-readable text-and-data-mining opt-out; it also predates any Central African case law testing whether the press exception reaches a systematic aggregator's reproduction of headlines and snippets, as opposed to a traditional press review.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.