Law / Djibouti

Djibouti

All 13 named instruments researched to a stage, across five of the six areas of law we track: 13 in force. As of 19 September 2026.

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law 4
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (176 words)

Djibouti has no AI-risk-obligations, AI-training-data, AI-governance, or AI-sector-rules statute, and its one AI-specific finding is a prohibition rather than a transparency duty.

The Digital Code (Loi n° 019/AN/23/9ème L portant Code Numérique) defines child pornography, in its Article 1 definitions chapter, to include a computer-generated image, so its Book VI ban on producing, distributing, importing, possessing, or habitually consulting such material reaches an AI-generated depiction of a minor engaged in sexually explicit conduct on the same terms as a photographic one.

Book I's automated-decision-making provision (Article 65) attaches its duty to the processing of personal data rather than to an AI system, so it is recorded under the privacy topic instead of here.

In January 2026, the Ministry Delegate for the Digital Economy and Innovation began work on Djibouti's first national AI strategy, with technical support from the United Nations Economic and Social Commission for Western Asia and UNESCO, as part of the government's Vision Djibouti 2035 digital-transformation programme; as of this review the strategy remains an unadopted policy document rather than a binding legal instrument.

AI prohibited practices

Digital Code, Book VI: Computer-Generated Child Pornography Ban

Loi n° 019/AN/23/9ème L portant Code Numérique, Art. 1 (définitions), Livre Sixième, Arts. 595 à 598Text of Loi n° 019/AN/23/9ème L portant Code Numérique

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 1's definitions chapter defines child pornography as any visual representation of sexually explicit conduct, including a photograph, film, video, or image, whether manufactured or produced by electronic, mechanical, or other means, where a minor is involved in the production, and expressly includes a digital image, a computer image, or a computer-generated image in which a minor is engaged in sexually explicit conduct, as well as a visual representation created, adapted, or modified so that a minor appears to engage in such conduct.

Article 595 punishes anyone who produces, records, offers, makes available, distributes, or transmits, by means of an information system, an image or representation bearing the character of child pornography, with imprisonment of 2 to 7 years and a fine of 14,000,000 to 70,000,000 Djiboutian francs. Article 596 punishes procuring, importing, or exporting such an image or representation with imprisonment of 6 months to 5 years and a fine of 35,000,000 to 350,000,000 francs.

Article 597 punishes possessing such an image or representation, or facilitating a minor's access to pornographic material, with the same penalties as Article 596. Article 598 punishes habitually consulting an online public communication service that makes such an image or representation available, with 10 years' imprisonment and a fine of up to 17,500,000 francs.

Because the Article 1 definition already reaches a computer-generated image without requiring a real child to have been depicted, these offences bind an AI system's output on the same terms as a photograph or video.

What it requires

Privacy law6 instruments, 6 in force

Research summary (169 words)

Djibouti's foundational personal-data-protection statute is Book I of the Digital Code (Loi n° 019/AN/23/9ème L portant Code Numérique), a 155-article regime that conditions processing of personal data on a lawful basis, prohibits processing of sensitive categories including biometric data used to uniquely identify a person absent consent or another statutory ground, bars a decision producing legal effects on a person from resting solely on automated processing of their personal data without human-intervention and contestation safeguards, requires notice of a personal-data breach to the Commission Nationale de Protection des Données à Caractère Personnel (CNDP) within 72 hours, restricts cross-border transfer to countries the CNDP finds adequate, and backs these duties with both a Commission-imposed administrative sanction of up to 70,000,000 Djiboutian francs or 5% of worldwide turnover and a separate criminal-penalty chapter carrying imprisonment and fines.

The Digital Code was adopted by the National Assembly on 30 June 2025, signed by the President of the Republic on 6 July 2025, and published in the Journal Officiel on 18 September 2025.

Breach notification

Digital Code, Book I: personal-data breach notification

Code Numérique, Livre Premier, Arts. 14 et 15 (notification des atteintes à la sécurité)Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Premier, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 14 requires the controller, in the event of a personal-data breach, to notify the Commission without undue delay and, at the latest, within 72 hours of becoming aware of it, and to accompany a notification made outside that window with the reasons for the delay.

Article 14 also requires the processor to notify the controller of a personal-data breach without undue delay after becoming aware of it, and requires the notification to the Commission to describe the nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned, the contact point, the likely consequences, and the measures taken or proposed to address it, supplied in stages without further undue delay where it cannot all be given at once.

Article 14's closing paragraph requires the controller to keep a register of every personal-data breach, its facts, its effects and the remedial measures taken, for the Commission to check compliance on request.

Article 15 requires the controller to tell the affected individual of a breach without undue delay, in clear and simple terms, where the breach is likely to result in a high risk to their rights and freedoms, and excuses that communication only where protective measures such as encryption render the affected data unintelligible, where subsequent measures make the high risk no longer likely, or where it would involve a disproportionate effort and an equally effective public communication is made instead.

The Digital Code, including Book I, was adopted by the National Assembly on 30 June 2025 and signed by the President of the Republic on 6 July 2025. It was published in the Journal Officiel on 18 September 2025, the date these provisions took effect.

What it requires

Comprehensive regime

Digital Code, Book I: Personal Data Protection and CNDP

Loi n° 019/AN/23/9ème L portant Code Numérique Livre Premier, Arts. 2 à 13, 54, 57 et 66 à 73 (objet, champ d'application, obligations du responsable de traitement et formalités préalables)Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Premier, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 2 states that Book I regulates the collection, transmission, storage, use and any other form of processing of personal data. Article 3 applies the book to automated and manual processing of personal data carried out by the State, a local authority, a public or private legal person, or a natural person, and Article 4 extends it to a controller or processor not established in Djibouti that offers goods or services to, or monitors the behaviour of, persons in Djibouti.

Article 5 exempts only purely domestic or personal processing not intended for onward communication, and temporary technical copies made for network transmission.

Article 6 places responsibility for a processing operation on the controller carrying it out under its own authority, Article 7 governs joint controllers, Article 8 governs recourse to a processor, Article 9 governs a sub-processing chain, and Article 10 requires a controller or processor not established in Djibouti to designate a representative there.

Article 11 requires data protection by design and by default, Article 12 requires processing to be carried out confidentially by persons acting under the controller's authority and on its instructions alone, and Article 13 requires the controller and processor to take the measures necessary to secure personal data, having regard to its nature and the risks the processing presents.

Article 54 sets the lawfulness, fairness, transparency, purpose-limitation and minimisation principles, and Article 57 requires an express, unambiguous, free, specific and informed consent wherever consent is the ground relied on.

Article 66 subjects processing to a prior declaration to the Commission unless another provision of this chapter says otherwise, Article 67 lets the Commission set a simplified declaration for the most common categories of processing, Article 68 exempts processing from declaration where the controller has designated a data protection officer, Article 69 subjects the processing it lists to the Commission's prior authorisation, and Article 73 exempts the processing it lists from every one of these prior formalities.

The Digital Code, including Book I, was adopted by the National Assembly on 30 June 2025 and signed by the President of the Republic on 6 July 2025. It was published in the Journal Officiel on 18 September 2025, the date these provisions took effect.

What it requires

Cross border transfer

Digital Code, Book I: cross-border transfer of personal data

Code Numérique, Livre Premier, Arts. 99 à 102 (transferts vers un pays tiers)Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Premier, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 99 bars a controller or processor from transferring personal data to a country or international organisation outside Djibouti unless that country or organisation ensures a level of protection equivalent and sufficient to Book I's own, and applies the same requirement to an onward transfer from the destination country or organisation to a further one.

Article 100 sets the factors the Commission weighs to determine whether that level of protection is equivalent and sufficient, including the rule of law, the respect for fundamental freedoms and rights, and the legislation, general and sectoral, in force in the destination country or organisation.

Article 101 lets the Commission withdraw a country or organisation from its adequacy list, refuse a declared transfer, or order an existing transfer to that destination to stop, once it finds the destination no longer ensures a sufficient level of protection.

Article 102 lets a controller or processor transfer personal data to a non-adequate third country outside the African Union, or to a non-adequate international organisation, only on the conditions it lists, including the data subject's express consent to the specific transfer, contractual necessity between the controller and the data subject or a third party, and a legally compelling public-interest ground.

The Digital Code, including Book I, was adopted by the National Assembly on 30 June 2025 and signed by the President of the Republic on 6 July 2025. It was published in the Journal Officiel on 18 September 2025, the date these provisions took effect.

What it requires

Data subject rights

Digital Code, Book I: automated individual decision-making

Code Numérique, Livre Premier, Art. 65 (décisions individuelles automatisées)Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Premier, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 65 bars a decision producing legal effects on a person, or significantly affecting them, from resting solely on automated processing of their personal data, including profiling, unless the decision is authorised by law with appropriate safeguards, or rests on explicit consent or contract performance together with the right to human intervention, to express a point of view, and to contest the decision.

The controller must also disclose, on request, the logic underlying the automated decision and the significance and expected consequences of that processing for the data subject. The Digital Code, including Book I, was adopted by the National Assembly on 30 June 2025 and signed by the President of the Republic on 6 July 2025. It was published in the Journal Officiel on 18 September 2025, the date these provisions took effect.

What it requires

Enforcement supervision

Digital Code, Book I: the Commission, administrative sanctions and criminal offences

Code Numérique, Livre Premier, Arts. 104, 135 et 140 à 156 (Commission et sanctions)Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Premier, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 104 establishes the Commission Nationale de Protection des Données à Caractère Personnel as an independent administrative authority charged with overseeing compliance with Book I. Article 135 lets the Commission, where a controller does not comply with a formal notice, impose an injunction to bring processing into conformity or to satisfy a data subject's rights request, an injunction to stop processing or a withdrawal of authorisation, the locking of certain data, and an administrative sanction proportioned to the seriousness of the breach and the advantages drawn from it, capped at 70,000,000 Djiboutian francs or, for an enterprise, 5% of its worldwide turnover excluding tax for the last closed financial year, whichever is higher, on top of a daily penalty payment of up to 35,000,000 francs for continued non-compliance.

Chapter 6 (Articles 140 to 156) applies the Penal Code's general rules on attempt, complicity, receiving, and corporate liability to the offences it creates.

Article 141 punishes processing personal data without the prior formalities Chapter 2 of Title 3 requires, and Article 144 punishes processing that includes the national identification number outside an authorised case, each by 5 to 10 years' imprisonment and a fine of 7,000,000 to 35,000,000 Djiboutian francs, except Article 144's offence, which draws 5 years and a fixed fine of 4,000,000 francs.

Article 145 punishes unlawfully keeping sensitive personal data or offence-related data in computerised memory without the data subject's express consent, Article 146 punishes an unlawful health-research processing, Article 147 punishes fraudulent collection, Article 148 punishes misuse of purpose, and Article 149 punishes an unauthorised cross-border transfer, each by 5 to 10 years' imprisonment and a fine of 7,000,000 to 35,000,000 Djiboutian francs (Article 149's fine is a fixed 8,000,000 francs).

Article 150 punishes disregarding a data subject's objection by 6 months to 10 years' imprisonment and a fine of 7,000,000 to 35,000,000 francs, Article 151 punishes processing without the security measures Articles 11 to 13 require by 10 years' imprisonment and a fixed fine of 8,000,000 francs, Article 152 punishes failing to notify a personal-data breach by 5 to 10 years' imprisonment and a fine of 7,000,000 to 35,000,000 francs, and Article 153 punishes retaining personal data beyond its legal retention period by the same range.

Article 154 punishes an unauthorised disclosure of personal data by 5 to 10 years' imprisonment and a fine of 7,000,000 to 35,000,000 francs, falling to a fixed 5 years and 7,000,000 francs where the disclosure was merely negligent, and that prosecution runs only on the victim's own complaint.

Article 155 lets the criminal court order the erasure of the personal data at issue in an offence under this chapter, and Article 156 requires the public prosecutor to keep the Commission's president informed of the prosecutions this chapter's offences give rise to. The Digital Code, including Book I, was adopted by the National Assembly on 30 June 2025 and signed by the President of the Republic on 6 July 2025. It was published in the Journal Officiel on 18 September 2025, the date these provisions took effect.

What it requires

Sensitive categories

Digital Code, Book I: sensitive categories of personal data and the minor's consent

Code Numérique, Livre Premier, Arts. 59 et 62 (consentement du mineur et données sensibles)Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Premier, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 59 lets a minor consent alone to an information-society service's processing of their personal data only from age 16, requires the consent of the person holding parental authority below that age, and requires the controller to make reasonable efforts to verify that consent given the technology available.

Article 62 prohibits processing personal data revealing, directly or indirectly, racial or ethnic origin, political or philosophical opinions, religious opinions or beliefs, or trade-union membership, and prohibits processing genetic data, biometric data processed to uniquely identify a natural person, or data concerning health, subject to exceptions including the data subject's express and explicit consent to one or more specific purposes, data the data subject has manifestly made public, and vital-interest or public-health grounds.

The Code's own definition of biometric data names facial images, fingerprint data, voiceprints, DNA and iris data as qualifying examples of a characteristic that allows or confirms unique identification, so a voiceprint or a faceprint derived from an ordinary recording is not carved out of the Article 62 prohibition. The Digital Code, including Book I, was adopted by the National Assembly on 30 June 2025 and signed by the President of the Republic on 6 July 2025. It was published in the Journal Officiel on 18 September 2025, the date these provisions took effect.

What it requires

Scraping law1 instrument, 1 in force

Research summary (119 words)

Djibouti has no scraping-specific statute. Book VI of the Digital Code (Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Sixième: Cybersécurité) criminalises fraudulently accessing or remaining within an information system and fraudulently introducing data into one, a computer-misuse regime that on a plain reading reaches a scraper only where it defeats an access control or a technical measure rather than one that merely reads a public, unauthenticated page.

No sui generis database right, text-and-data-mining exception, or robots.txt provision was located; the Digital Code's own réutilisation-des-données-publiques chapter (Book VII) addresses public-sector open-data reuse rather than a private database right, and the personal-data protections a scraper collecting personal data would trigger are recorded under the privacy topic rather than restated here.

Computer misuse

Digital Code, Book VI: Fraudulent Access to Information Systems

Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Sixième, Arts. 555 à 559Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Sixième, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 555 punishes anyone who has accessed or attempted to fraudulently access all or part of an information system with a maximum of three years' imprisonment and a maximum fine of 10,000,000 Djiboutian francs, or either penalty alone. Article 556 punishes fraudulently remaining, or attempting to remain, within all or part of a system after having entered it fraudulently, with the same maximum penalties.

Article 557 raises both offences to a maximum of five years' imprisonment and a maximum fine of 25,000,000 francs where the fraudulent access or continued presence results in the deletion or modification of data held in the system. Article 558 separately punishes fraudulently introducing, or attempting to introduce, data into an information system, with a maximum of five years' imprisonment and a maximum fine of 25,000,000 francs or either penalty alone.

Article 559 punishes disrupting, altering or falsifying, or attempting to disrupt, alter or falsify, the operation of an information system on the same terms as Article 558. Each offence is drafted around unauthorised access or interference with a system rather than around the reading of a page that requires no authorisation, so a scraper confined to public, unauthenticated pages is not on the face of these articles caught by them.

What it requires

Cybersecurity law4 instruments, 4 in force

Research summary (503 words)

Djibouti's Digital Code (Loi n° 019/AN/23/9ème L portant Code Numérique), enacted 30 June 2025 and in force since its 18 September 2025 publication in the Journal Officiel, carries a genuine security-topic layer distinct from the intruder offences Book VI's own Chapter 1 already contributes to the scraping topic.

Book II's electronic-communications title binds an operator of a public electronic communications network or service to take the technical and organisational measures necessary to secure its network and services at a level proportionate to risk, to comply with the national cybersecurity authority's technical security prescriptions, and to notify that authority and the telecoms regulator, without a stated numeric clock, of a security breach or integrity loss with a significant impact on its network or service (Article 169).

Book VI's own Titre 3, headed the implementation of non-military and non-economic defence, separately requires the same class of operator to run a qualified detection system for events capable of affecting its information systems' security and to submit those systems to the cybersecurity authority's own security-level verification controls, backed by a 10,000,000 Djiboutian franc fine for failing to maintain a previously established protective device and a 25,000,000 franc fine for obstructing the authority's related powers (Articles 679 to 684).

Book VII's national health-data system title separately requires anyone accessing that system to report a serious information-system security incident to the cybersecurity authority without delay (Article 747), and requires a digital health-data host to hold a conformity certificate the cybersecurity authority issues and can withdraw before providing hosting, infrastructure, platform, administration or backup services for health data (Articles 760 to 763).

Djibouti has no Cyber Resilience Act style manufacturer or connected-device market-placement security regime, and no general reasonable-security statute reaching a business with no sector gate: Book II's own equipment-approval regime (Articles 202 to 206) exists to ensure user and network safety, network protection and interoperability rather than to impose secure-by-design or vulnerability-handling duties on a product's manufacturer.

Book IV separately binds a trust service provider, qualified or not, to take security measures proportionate to risk and to notify the Organe en charge de la certification racine (the root certification body) of a security breach with a significant impact within 24 hours of becoming aware of it (Articles 407 and 408), and Book III conditions supplying, importing or exporting a cryptographic tool on a prior declaration to, or authorisation from, the cybersecurity authority (Articles 345 to 353); neither trust-service-provider status nor a cryptographic-tool supplier is a role this review's activity vocabulary can express, so both are named here in prose rather than filed as coded instruments.

Book VII's own téléservices and national-health-data-system interoperability-and-security référentiels (Articles 709 to 711 and 745 to 746) bind the administration's own systems rather than a private developer, and are not restated here for that reason. Djibouti's breach-notification duty on personal data itself, a 72-hour notice to the Commission Nationale de Protection des Données à Caractère Personnel under Book I Articles 14 and 15, is the privacy topic's own row and is not restated here.

Sector security regimes

Digital Code, Book II: Electronic Communications Network and Service Security

Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Deuxième, Art. 169Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Deuxième, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds private bodies.

What this law does

Article 169 requires an operator of a public electronic communications network or a provider of a public electronic communications service to take all appropriate measures to ensure the integrity of its networks and the continuity of the services it supplies, and to take all technical and organisational measures necessary to secure its network and services at a level adapted to the existing risk.

The operator must comply with the technical security prescriptions the national cybersecurity authority issues, must give that authority confidential access to its network-security arrangements on request, and must submit to a security and integrity inspection the authority conducts or commissions, at the operator's expense.

Where there is a particular risk of a breach of its network's security, the operator must inform users of the risk without delay, together with any available remedy and its cost.

As soon as it becomes aware of a security breach or integrity loss with a significant impact on the operation of its networks or services, the operator must notify both the cybersecurity authority and the telecoms regulator by registered letter with acknowledgement of receipt, and must separately notify the cybersecurity authority where the breach results or may result from a cyberattack; the article states no numeric reporting clock for this notice, only that it follows as soon as the operator has knowledge of the breach.

What it requires

Digital Code, Book VI: Critical Installation Protection and Operator Security Controls

Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Sixième, Titre 3 (Arts. 679 à 684)Text of Loi n° 019/AN/23/9ème L portant Code Numérique

In force since 18 September 2025. Binds private bodies.

What this law does

Book VI's Titre 3, headed the implementation of non-military and non-economic defence, requires an operator (the Code's own definition: any natural or legal person operating a public electronic communications network or providing a public electronic communications service to the public) to implement a qualified system for detecting events capable of affecting its information systems' security, qualified by the national cybersecurity authority together with the service providers that run such systems (Article 679).

The operator must submit its information systems to controls the cybersecurity authority conducts to verify their security level and compliance with security rules, at the operator's own cost (Article 680); omitting to maintain and keep in good condition a protective device previously established under this Chapter draws a fine of up to 10,000,000 Djiboutian francs (Article 681).

A separate Chapter lets a State service the Council of Ministers designates by decree hold equipment, instruments, programs and data capable of carrying out an offence, in order to analyse and respond to a cyberattack, a power on the State rather than a duty on the operator (Article 682), and lets a competent authority the Council of Ministers designates by decree obtain from an electronic communications operator the identity, postal address and electronic address of a user or holder of a vulnerable, threatened or attacked information system, in order to alert them to the vulnerability or compromise (Article 683).

Obstructing the accomplishment of the missions in Articles 682 and 683 draws a fine of up to 25,000,000 Djiboutian francs (Article 684).

What it requires

Digital Code, Book VII: Health-Data Hosting Security Certification

Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Septième, Arts. 760 à 763Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Septième, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 760 requires a host of digital health data to hold a conformity certificate the national cybersecurity authority issues before providing that hosting.

Article 761 names the activities that count as certifiable hosting: making available and operationally maintaining the physical site or the physical or virtual infrastructure hosting a health-data information system, making available and maintaining an application-hosting platform for it, administering and operating an information system containing health data, and backing up health data, a list a decree may extend.

Article 762 leaves the certificate's own issuance conditions to a decree proposed by the ministry in charge of the digital economy. Article 763 lets the cybersecurity authority withdraw the certificate for a breach of the legislative or regulatory provisions governing digital health-data hosting, or of the certificate's own conditions, under conditions a decree sets; that decree was not located in this review, and no separate monetary penalty for hosting without certification was located either.

What it requires

Vulnerability and incident reporting

Digital Code, Book VII: National Health Data System Security Incident Reporting

Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Septième, Art. 747Text of Loi n° 019/AN/23/9ème L portant Code Numérique, Livre Septième, reproduced by the Journal Officiel de la République de Djibouti

In force since 18 September 2025. Binds public and private bodies.

What this law does

Article 747 requires any person accessing data in Djibouti's national health data system, a category that reaches citizens, health-system users, health professionals, health establishments and their representative organisations, health-insurance financing bodies, State services and public health institutions under the surrounding Chapter, to report a serious information-system security incident to the cybersecurity authority without delay.

An incident the national authority in charge of information systems judges significant is separately and immediately transmitted to the State's competent authorities. A decree, proposed by the minister in charge of the digital economy after the cybersecurity authority's opinion, is to define which categories of security incident count as significant and how they are handled; that decree was not located in this review. The article states no numeric reporting clock, only that notice is given without delay.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (300 words)

Djibouti has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of Law No. 154/AN/06 of July 23, 2006 (Loi n° 154/AN/06 du 23 juillet 2006 relative à la protection du droit d'auteur et du droit voisin), which repealed and replaced Law No. 114/AN/96 of September 3, 1996, is the law reaching an aggregator's reproduction of news content.

Article 8(b) places news of the day, or miscellaneous facts having the character of mere items of press information, published, broadcast or communicated to the public, entirely outside the Law's protected subject matter, so a bare news item is never a protected work regardless of who first reported it.

Article 54(b) permits, without the author's consent, including non-substantial quotations from another lawfully published work, including quotations from newspaper articles and periodicals in the form of press summaries, provided the quotations are compatible with fair practice, do not exceed the extent justified by their purpose, and name the source and the author.

Neighbouring rights under Title 2 of the Law protect performers and phonogram producers, and a separate Title extends comparable rights to broadcasting organisations, but the Law creates no right for a news publisher as such. Article 4 protects a database as a compilation where the selection or arrangement of its contents is an intellectual creation, rather than through a separate sui generis right.

No machine-readable text-and-data-mining opt-out mechanism is stated; Article 116 itself acknowledges the gap, reserving "the rapid and contemporary development of intellectual property" in traditional knowledge, genetic resources, folklore, and the Internet for a future decree to supplement the Law, and no such decree addressing online news aggregation has been located.

No reported Djiboutian decision applies the quotation or news-reporting exception to a systematic online news aggregator as opposed to a traditional press review.

Snippet reproduction

Copyright Law, News-Item Exclusion and Press-Summary Quotation Exception

Loi n° 154/AN/06 du 23 juillet 2006 relative à la protection du droit d'auteur et du droit voisin, arts. 4, 8, 54Official English translation of Law No. 154/AN/06 of July 23

In force since 23 July 2006. Binds public and private bodies.

What this law does

Article 8(b) provides that protection shall not apply to news of the day or to miscellaneous facts having the character of mere items of press information, published, broadcast, or communicated to the public, placing bare news reporting entirely outside the Law's subject matter.

Article 54 permits, without the author's consent, several uses of a protected work that has been lawfully published; alínea (b) covers the inclusion of non-substantial quotations from another work, including quotations from newspaper articles and periodicals in the form of press summaries, provided the quotations are compatible with fair practice, their extent does not exceed what the purpose justifies, and the source and the author's name are named in the citing work.

Article 4 extends protection to the authors of anthologies or collections of works, expressions of folklore, or data such as databases that, by reason of the selection or arrangement of their contents, constitute intellectual creations, without creating a separate sui generis database right.

Title 2 (Articles 60 and following) confines neighbouring rights to performers and phonogram producers, and a later Title extends comparable protection to broadcasting organisations, so the Law creates no publisher-side right of the kind the European Union's Digital Single Market Directive Article 15 creates.

Article 116 reserves traditional knowledge, genetic resources, folklore, and the Internet for a future decree to supplement the Law, acknowledging that the Law as enacted does not itself address online use. Article 117 repealed the prior copyright statute, Law No. 114/AN/96 of September 3, 1996.

Article 118 provides that the Law is implemented as a State Law and published in the Official Gazette upon its enactment; WIPO Lex records both promulgation and entry into force on July 23, 2006, the date of enactment itself.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.