Law / Gabon

Gabon

13 of 16 named instruments researched to a stage, across all six areas of law we track: 13 in force. As of 19 September 2026.

When they take effect13 of 13 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 8 instruments (8 in force) 2024: 0 instruments 2025: 0 instruments 2026: 3 instruments (3 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (204 words)

Gabon has not enacted a general AI statute, but ordonnance n°0011/PR/2026 du 26 février 2026 portant réglementation de l'usage des réseaux sociaux via les plateformes numériques en République Gabonaise, published in Journal Officiel n°110 du 8 avril 2026, imposes two binding AI-specific duties on a social network or digital platform editor: it bans outright a defined set of AI-generated deepfakes, and it requires a visible, permanent label on AI-generated or substantially AI-modified content published or shared on the platform, with origin metadata preserved and handed to the Haute Autorité de la Communication on request.

In January 2024 Gabon's Ministry of New Technologies, Information and Communication and the National Technical Committee for AI (CTN-IA) presented a Rapport d'évaluation de l'état de préparation sur l'intelligence artificielle to the Prime Minister, an assessment published through UNESCO's Readiness Assessment Methodology; as of the date below it is a policy assessment rather than a binding legal instrument, and no numbered bill or public draft implementing it is cited here.

Gabon's data protection law, loi n°025/2023, separately restricts a decision based solely on automated processing that evaluates a person's characteristics; that duty attaches to the processing of personal data rather than to the operation of an AI system as such.

AI prohibited practices

Ordonnance n°0011/PR/2026, contenus interdits générés par intelligence artificielle

Ordonnance n°0011/PR/2026, art. 32-33 (contenus IA interdits), du 26 février 2026 portant réglementation de l'usage des réseaux sociauxOrdonnance n°0011/PR/2026 du 26 février 2026 portant réglementation de l'usage des réseaux sociaux via les plateformes numériques en…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://journal-officiel.ga/22404-0011-pr-2026-/

In force 6 months, effective 8 April 2026. Binds public and private bodies.

What this law does

Ordonnance n°0011/PR/2026 bans outright, whatever their place of creation, four categories of AI-generated content circulated on a social network or digital platform in Gabon: a realistic deepfake depicting an identifiable person in a sexual situation without their express consent, a deepfake of a public or private figure attributing false statements or conduct to them capable of causing serious harm to public order, national security, or personal dignity, a representation of a sexual situation involving a minor by any technical method, and an imitation of a Gabonese state institution's visual or audio identity for disinformation.

Content falling into these categories can be referred immediately to the emergency-relief judge, whose territorial competence is both domestic and extraterritorial and who may order a temporary suspension of an account or content, a targeted de-referencing, publication of a correction, or the forced insertion of an origin marking on the AI-generated content.

An identifiable person depicted without consent in AI-generated content published on a social network or platform separately has a right to report it and have the editor or host remove it within twenty-four hours of the report.

What it requires

AI transparency

Ordonnance n°0011/PR/2026, marquage des contenus générés par intelligence artificielle

Ordonnance n°0011/PR/2026, art. 53 (marquage des contenus IA), du 26 février 2026 portant réglementation de l'usage des réseaux sociauxOrdonnance n°0011/PR/2026 du 26 février 2026 portant réglementation de l'usage des réseaux sociaux via les plateformes numériques en…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://journal-officiel.ga/22404-0011-pr-2026-/

In force 6 months, effective 8 April 2026. Binds private bodies.

What this law does

Ordonnance n°0011/PR/2026 requires every social-network or digital-platform editor, within twelve months of the ordinance's publication (by April 2027), to deploy tools that automatically detect AI-generated content published or shared on its service according to technical standards set by other regulations, to affix a visible, clear, and permanent label to any content identified as generated or substantially modified by an AI system, accessible to the user without any further action on their part, and to preserve and hand over to the Haute Autorité de la Communication, within eight days, the origin metadata of AI-generated content that is the subject of a judicial or administrative investigation.

An emergency-relief judge may also order the forced insertion of an origin marking on AI-generated content as a provisional measure.

What it requires

Privacy law6 instruments, 6 in force

Research summary (328 words)

Gabon's personal-data statute is loi n°001/2011 du 25 septembre 2011 relative à la protection des données à caractère personnel, wholly modified and completed by loi n°025/2023 du 9 juillet 2023, promulgated 12 July 2023 and published in the Journal Officiel n°218 bis du 15 juillet 2023, which every controller must comply with from that publication.

Enforcement sits with the Autorité pour la Protection des Données Personnelles et de la Vie Privée (APDPVP), the successor the Council of Ministers gave the former Commission Nationale pour la Protection des Données à Caractère Personnel (CNPDCP) in the same 2023 reform.

Beyond the omnibus regime of lawful basis, consent, registration, security and a data protection officer duty, the act states six further families in its own text: a sensitive-categories chapter banning collection of racial, political, religious, trade-union, biometric, genetic, health and sexual-life data absent a listed exception, paired with a children's-data chapter and a health-research authorization regime; a set of data-subject rights reaching access, rectification, erasure, restriction, portability, objection and a right to oppose an automated decision, backed by a detailed information-notice and cookie-consent regime with a one-month response deadline; a cross-border-transfer regime under which a controller needs the APDPVP's prior authorization for any transfer abroad, not merely a suspension power over an inadequate destination; a breach-notification duty running to the APDPVP and, for a high-risk breach, to the person, with no numeric deadline stated in the act itself; and an enforcement chapter combining escalating administrative sanctions capped at 98,400,000 FCFA for a first breach and up to 300,000,000 FCFA (or 5% of a company's last closed-year turnover, itself capped at 196,000,000 FCFA) on repetition, emergency measures such as an immediate processing ban, and a criminal track referring most offences to the Penal Code and setting its own penalty for obstructing the APDPVP's own action.

Any person may bring a non-jurisdictional and a jurisdictional recourse for a breach of their rights under the law, though only the ordinary courts can award compensation.

Breach notification

Law No. 025/2023, personal-data breach notification

Loi n°025/2023, articles 142 à 147 (violation de données à caractère personnel)Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2025. Publisher's page: https://journal-officiel.ga/20085-025-2023-/

In force since 15 July 2023. Binds public and private bodies.

What this law does

Article 142 requires the controller, on a personal-data breach, to inform the APDPVP without delay, giving the breach's nature, the categories and approximate number of data subjects and records concerned where possible, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed to remedy it; article 143 requires supporting evidence of the breach to accompany that notice.

The law states no numeric deadline for this notice: it runs 'sans délai', without delay, rather than within a stated number of hours or days. Article 144 requires a processor to notify the controller of any breach without delay as soon as it becomes aware of it.

Article 145 requires the controller, where a breach is likely to create a high risk to a person's rights and freedoms, to inform that person as soon as possible, and article 146 requires the communication to describe the breach in clear and simple terms and to carry at least the information article 142 lists for the Authority.

Article 147 excuses that communication to the person only where the controller had already applied protective measures rendering the affected data unintelligible, where later measures mean the high risk is no longer likely to materialize, or where it would take disproportionate effort, in which case a public communication of equal effect substitutes for it; the APDPVP can still compel direct communication after weighing the breach's gravity.

Article 147 also requires every controller to keep an up-to-date register of personal-data breaches, their circumstances, their impact and the remedial measures taken, available to the APDPVP.

What it requires

Comprehensive regime

Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023

Loi n°001/2011 du 25 septembre 2011 relative à la protection des données à caractère personnel telle que modifiée et complétée par la loi n°025/2023 du 9 juillet 2023, Journal Officiel n°218 bis du 15 juillet 2023, articles 1 à 6, 70 à 73, 78 à 90, 111 à 141, 164 à 167, 175 à 187 et 215 à 221Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2025. Publisher's page: https://journal-officiel.ga/20085-025-2023-/

In force since 15 July 2023. Binds public and private bodies.

What this law does

Loi n°025/2023 wholly modifies and completes loi n°001/2011, setting Gabon's general rules for the collection, processing and transfer of personal data by any public or private controller (articles 2 to 4), subject to the household-activity and transit-copy exclusions of article 5.

Processing must be fair and lawful, collected for determined and legitimate purposes, and kept accurate and no longer than those purposes need (article 70), on a lawful basis such as consent, a legal obligation, a public-service mission, contract performance, or a legitimate interest that does not override the data subject's own rights (article 71); where consent is relied on it must be demonstrable, presented clearly and separately from other terms, and, for an electronic transaction, taken by an unambiguous act rather than a pre-checked box or the general terms of sale (articles 72 to 73).

An automated processing activity is declared to the APDPVP before it starts, unless it falls under a simplified or exempt category, while processing touching the categories articles 74 and 81 to 83 list instead needs the APDPVP's prior authorization or a ministerial or Council-of-Ministers decree (articles 78 to 90); the Authority keeps a public, open-format register of every declared or authorized processing activity (article 88).

Processing is confidential, everyone who handles the data under the controller's authority signs a written confidentiality undertaking, and a processor owes the controller the same security and confidentiality guarantees by contract (articles 111 to 112).

The controller and processor must implement risk-adapted technical and organizational security measures, including pseudonymization and encryption, and regularly test their effectiveness (article 113), preserve the data's continuity and keep it no longer than its purpose needs (article 118), and keep a written or electronic register of processing activities naming the controller, purposes, data categories, recipients, transfers and retention periods, produced to the APDPVP on request; an organization of fewer than ten employees is exempt from that register unless the processing carries a risk to rights and freedoms, is not occasional, or touches sensitive or criminal-offence data (articles 119 to 123).

A controller or processor designates a data protection officer, notified to the APDPVP, where it is a public authority or body, carries out large-scale systematic monitoring, or processes sensitive or criminal-offence data at scale, and gives that officer the office, resources and independence the law describes (articles 124 to 141).

Processing carried out solely for literary or artistic expression, or for the professional practice of journalism observing that profession's ethical rules, falls outside the law, provided a press or broadcast body designates its own data-protection correspondent in place of the ordinary declaration (articles 164 to 167).

A further chapter conditions the deployment of an artificial-intelligence system, a digital-identity or biometric-identification service such as facial recognition, a drone or other connected object, an electronic-signature service, or a national or sectoral identifier system, on filing the declaration or notice a norme or decree sets for it with the APDPVP (articles 175 to 187).

Every controller must conform from the law's publication (article 219), and the Authority funds itself through a statutory levy on controllers and processors and issues its own code of conduct by sector (articles 216 to 221).

What it requires

Cross border transfer

Law No. 025/2023, interconnection and cross-border transfer of personal data

Loi n°025/2023, articles 168 à 174 (interconnexion et transfert transfrontalier de données)Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2025. Publisher's page: https://journal-officiel.ga/20085-025-2023-/

In force since 15 July 2023. Binds public and private bodies.

What this law does

Article 171 conditions any transfer of personal data to another State on the APDPVP's prior authorization, which the Authority grants only once it is satisfied the destination State assures a sufficient level of protection, judged by that State's rules, its security measures, and the processing's own purpose, duration, nature, origin and destination; the APDPVP publishes the list of States it has found to offer a sufficient level of protection.

Article 173 lets a controller transfer to a State that does not meet article 171's standard only where the data subject has expressly consented to that specific transfer and it is necessary to safeguard the person's life or the public interest, to establish, exercise or defend a legal claim, to consult a public register, or to perform or negotiate a contract with or for the person's benefit, or otherwise by a decision of the APDPVP or a decree finding the processing offers a sufficient level of protection through means such as contractual clauses or binding internal rules.

Article 174 has the APDPVP issue a receipt barring a transfer once it finds the destination State's protection insufficient, informing officials and the public without delay, and enjoining a controller to suspend or cancel a transfer a pending declaration reveals; it lifts the suspension once it finds the State's protection now sufficient.

Articles 168 to 170 separately condition on the APDPVP's authorization any interconnection of information systems belonging to different public-service bodies pursuing different public interests, or to different private parties pursuing different main purposes, and record every interconnection request and authorization in the public register of processing activities.

What it requires

Data subject rights

Law No. 025/2023, rights of the data subject and transparency obligations

Loi n°025/2023, articles 43 à 69 et 91 à 110 (droits de la personne concernée et obligation de transparence)Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2025. Publisher's page: https://journal-officiel.ga/20085-025-2023-/

In force since 15 July 2023. Binds public and private bodies.

What this law does

Chapter III, section 1 (articles 43 to 69) gives a data subject the right of access to the data a controller holds on them, the right to rectification and to erasure, the right to have processing restricted, the right to receive their data in a portable format, the right to object to processing, and the right, at article 66, to oppose a decision based solely on automated processing, including profiling, that concerns them.

Section 2's transparency paragraph (articles 91 to 110) requires the controller to inform the person, at collection, of the controller's and any data protection officer's identity and contact details, the purpose and legal basis of processing, any legitimate interest relied on, recipients, any transfer abroad, the retention period or the criteria for it, the person's rights including withdrawal of consent, the right to complain to the APDPVP, and the existence and logic of any automated decision-making or profiling concerning them (article 98); where the data were not collected from the person, the same categories of information are owed, plus the data's origin and whether it came from a publicly accessible source, within one month or by the time of first contacting the person or first disclosing the data, whichever comes first (articles 100 to 101).

A controller must act on an access, rectification, erasure, restriction, portability or objection request within one month of receiving it, extendable by two months for complex or numerous requests provided the person is told of the extension and its reasons within the first month; declining to act requires telling the person why within one month and of their right to complain to the APDPVP or go to court (articles 93 to 94).

Information is provided free of charge, except that a manifestly unfounded or excessive request, particularly a repetitive one, lets the controller charge a reasonable fee or refuse, with the burden of showing that on the controller (article 95).

Article 104 requires anyone accessing or storing information on a subscriber's or user's terminal equipment, such as through a cookie, to tell them the purpose and how to object, and to proceed only once they have consented through their connection settings or another device they control, except where the access is strictly necessary to provide an electronic communication service they expressly requested.

What it requires

Enforcement supervision

Law No. 025/2023, recourse, oversight and sanctions

Loi n°025/2023, articles 200 à 214 (recours, contrôle et sanctions)Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2025. Publisher's page: https://journal-officiel.ga/20085-025-2023-/

In force since 15 July 2023. Binds public and private bodies.

What this law does

Article 200 gives any person a non-jurisdictional and a jurisdictional recourse for a breach or violation touching their personal data, but bars the APDPVP itself from awarding compensation, which only the ordinary courts can rule on.

Articles 201 and 202 let the APDPVP's members and sworn, authorized agents, accompanied by judicial police officers with the public prosecutor informed in advance, access a controller's professional premises used for processing, demand documents, and access programs and data for control purposes, with a court order required over the premises holder's opposition.

Sanctions escalate from a warning, to a formal notice to end a breach within a set period, to a financial penalty the Authority can make public (articles 203 to 205): a first breach is capped at 98,400,000 FCFA and, on repetition, at 300,000,000 FCFA or 5% of a company's last closed financial year's turnover up to 196,000,000 FCFA, alongside a provisional suspension of collecting or processing data that becomes definitive after three months.

A controller that already holds a declaration receipt or authorization and breaches the law faces, after formal notice, suspension of that receipt or authorization for up to two months, then its definitive withdrawal, and a fine of 1,000,000 to 100,000,000 FCFA; a controller that never filed at all is a de facto controller facing the same fine alongside a formal notice to regularize (articles 206 to 207).

Article 208 lets the APDPVP order, without the notice-and-cure process, the interruption of a processing operation, the locking of data, or a temporary ban of up to three months, or a definitive ban, wherever it finds a processing operation violates rights and freedoms.

Sanctions and APDPVP decisions are appealable to the Conseil d'Etat (article 210), and any person may sue a controller or processor in the competent courts after first bringing the matter to the APDPVP, including through a nongovernmental organization or association working in data protection that the person mandates to represent them (article 211).

Criminal offences arising from a breach of the law are punished under the Penal Code (article 212), and obstructing the APDPVP's own action, by opposing its members or agents or refusing or concealing documents useful to their mission, carries six months' to a year's imprisonment and a fine of 1,000,000 to 10,000,000 FCFA, doubled on repetition (article 213).

What it requires

Sensitive categories

Law No. 025/2023, sensitive categories of personal data and children's data

Loi n°025/2023, articles 74 à 77, 148 à 163 et 188 à 199 (catégories sensibles de données et protection des mineurs)Loi n°025/2023 du 9 juillet 2023 portant modification de la loi n°001/2011 du 25 septembre 2011 relative à la protection des données à…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2025. Publisher's page: https://journal-officiel.ga/20085-025-2023-/

In force since 15 July 2023. Binds public and private bodies.

What this law does

Article 74 makes processing a child's data lawful on the child's own consent once they turn eighteen, and otherwise only on the express authorization of the holder of parental authority, confirmed by the controller by any means.

Articles 75 and 76 prohibit collecting or processing data revealing racial or ethnic origin, political, philosophical or religious opinions, trade-union membership, biometric or genetic data, or data on health or sex life, unless a listed exception applies: the data subject's own express consent, safeguarding a life the person cannot consent to protect, a non-profit body's processing of its own members' data, data the person made public, establishing or defending a legal claim, preventive medicine, medical diagnosis or care administered by a professional bound by professional secrecy, statistical processing by a competent ministry's statistical service, or health research; the same article separately conditions processing genetic, biometric, or offence and conviction data on the data subject's written, informed, express consent with no risk of discrimination.

Article 77 confines processing of data on offences, convictions and safety measures to public, judicial and public-service bodies acting within their legal remit, and to legal auxiliaries defending the person concerned.

Articles 148 to 151 subject processing personal data for a public-interest research, study or evaluation purpose in the health domain to the APDPVP's authorization, given after the health-research consultative committee opines on the research methodology and the necessity and relevance of the data to it; articles 152 to 163 set the conditions for coding identifying data before transmission by a health professional, publishing results without identifying anyone, and processing health data for evaluating or analyzing care practices and health-system performance.

A dedicated children's-data chapter (articles 188 to 199) treats anyone under eighteen as a child, bars arbitrary or unlawful interference with a child's private life including online, and requires a search engine, website, platform, application or connected or geolocation service to obtain a parent's or guardian's prior consent before collecting a child's personal data; information addressed to a child must be written in terms they can understand, a child's profiling is banned outside an APDPVP-authorized exception for the child's best interest or a public-interest ground, and a contract a child enters through an internet-based service is void on a court challenge where it is prejudicial to them.

An online service aimed at children must build in privacy-protective technical measures such as marking and filtering systems, keep advertising, entertainment and games clearly distinct from content, never incite a child to buy goods or enter an online contract, and never use prizes, rewards or links to non-compliant sites to keep a child engaged.

What it requires

Scraping law2 instruments, 2 in force

Research summary (189 words)

Gabon's computer-misuse authority is loi n°027/2023 du 11 juillet 2023 portant réglementation de la cybersécurité et de la lutte contre la cybercriminalité, which replaced ordonnance n°15/PR/2018 du 23 février 2018 on the same subject and punishes fraudulently accessing or remaining in a computer system whether or not the system is behind a technical protection measure, so a public, unauthenticated page is not carved out by the text.

No statute or reported case addresses terms-of-service enforceability, or whether login or acceptance of terms changes the legal picture; this is unsettled rather than a specific regime.

Copyright protects a compilation only where the choice or arrangement of its contents is itself an original intellectual creation: loi n°1/87 du 29 juillet 1987 instituant la protection du droit d'auteur et des droits voisins protects an anthology or similar collection on that standard and does not name a database specifically, so Gabon has no separate sui generis database right and an unoriginal, purely factual collection of data is not itself protected against reproduction.

No text-and-data-mining exception, and no AI-training-specific rule, is in force, and robots.txt carries no statutory weight one way or the other.

Computer misuse

Loi n°027/2023, infractions et sanctions informatiques

Loi n°027/2023 du 11 juillet 2023 portant réglementation de la cybersécurité et de la lutte contre la cybercriminalité en République… Gabonaise, chapitre Ier (art. 49-61)Loi n°027/2023 du 11 juillet 2023 portant réglementation de la cybersécurité et de la lutte contre la cybercriminalité en République…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://journal-officiel.ga/20087-027-2023-/

In force since 15 July 2023. Binds public and private bodies.

What this law does

Loi n°027/2023 punishes fraudulently accessing all or part of a computer system, including exceeding an authorized access, with up to ten years' imprisonment and a fine of up to 100,000,000 FCFA or one of these penalties; fraudulently remaining in a system or hindering its operation each carry up to five years and up to 50,000,000 FCFA or either penalty; and fraudulently introducing, altering, deleting, or extracting data, or knowingly using data obtained through any of these offences, each carry up to ten years and up to 100,000,000 FCFA or either penalty.

An offence against a State information system or critical infrastructure, or an offence committed in an organized group, is punished more heavily still: up to twenty-five years' criminal detention and a fine of up to 500,000,000 FCFA. A legal person additionally faces dissolution, a temporary or permanent bar on operating, closure of an establishment, or exclusion from public tenders, where it diverted its purpose to commit the offence.

The law replaced ordonnance n°15/PR/2018 du 23 février 2018 on the same subject, and gave every person and entity it reaches six months from its entry into force to come into compliance.

What it requires

Database right

Loi n°1/87, protection des recueils et compilations

Loi n°1/87, art. 5 (recueils et compilations), du 29 juillet 1987 instituant la protection du droit d'auteur et des droits voisinsLoi n°1/87 du 29 juillet 1987 instituant la protection du droit d'auteur et des droits voisins, WIPO Lex

In force since 29 July 1987. Binds public and private bodies.

What this law does

Loi n°1/87 protects a collection of literary or artistic works, such as an encyclopedia or anthology, as an original work only where the choice or arrangement of its contents constitutes an intellectual creation; the text does not name a database specifically, so an unoriginal, purely factual database or compilation of data is not itself protected against reproduction and Gabon has no separate sui generis database right.

Reproducing a protected work without authorization is illicit and is punished under the Penal Code's provisions on literary and artistic property, with no specific fine amount stated in this law itself.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (508 words)

Law No. 027/2023 of 11 July 2023 on the regulation of cybersecurity and the fight against cybercrime is a single statute whose two halves this corpus files on two different topics: its cybersecurity title, Title III (Articles 8 to 47), sets operator-facing security duties and is researched here, while its cybercrime title, Title IV (Articles 48 to 88), criminalises conduct against a system by an intruder and is recorded on this jurisdiction's scraping row.

Gabon has no standalone product-security statute requiring a manufacturer to meet a security standard, provide a support period, or run a vulnerability-disclosure channel before placing a software product or connected device on the market.

The law's only incident-reporting duty runs from a state administration or a dismembered arm of the state to the competent administrative authority (Article 25), a government information-security duty this topic leaves to the wing that already covers a government's own programme obligations, so no private-sector vulnerability or incident-reporting duty exists in the primary text; Article 13 envisions a cooperation framework among critical-infrastructure operators for sharing threat and vulnerability information and for detecting and responding to incidents, but leaves its procedures to an implementing order, so it sets no self-executing reporting duty with its own threshold or clock.

The law also creates two sector-gated cyber-resilience regimes: one for a decree-designated critical-infrastructure or critical-service operator, spanning the sovereign, human, economic and technological domains, with an administration-approved protection plan and a fine tied to the resulting damage for missing its execution deadline (Articles 8 to 18); and one for an electronic-communications network operator or service provider, covering user-risk notices, a ten-year data-retention duty, network monitoring and an on-territory operations centre (Articles 19 to 22).

Because neither regime's bound party maps onto a declared activity this corpus can flag against, both are recorded here in prose rather than raised on a guess.

Articles 28 to 35, by contrast, bind any operator of an information system, defined without a sector or size gate, to a general information-security-programme duty, and a person whose activity is to offer users access to an information system to a set of user-facing security notices; that duty is recorded as this jurisdiction's baseline instrument and flagged inclusively.

No provision of Law No. 027/2023 arms a private plaintiff, and its general compliance clause, Article 98, threatens an unspecified sanction for non-compliance after a six-month grace period rather than naming a fine or scale for the Article 28 duty specifically. Gabon's breach-notification and data-protection statute is Law No. 001/2011 of 25 September 2011, as substantially amended by Law No. 025/2023 of 9 July 2023, already researched as this jurisdiction's privacy row and not restated here.

No confirmation was found of a Banque des États de l'Afrique Centrale cybersecurity or information-technology risk directive binding a licensed financial institution in Gabon; if one exists, it would likely bind by regulated-sector status rather than by a declared activity, the same shape as this topic's DORA and NY DFS Part 500 findings elsewhere in the corpus, and it is left unresearched rather than recorded on a guess.

Security baseline statutes

Sécurité des systèmes d'information (dispositions communes)

Loi N° 027/2023 du 11 juillet 2023, Titre III, Chapitre III, Section 2, arts. 28-35Official gazette text, Journal Officiel de la République Gabonaise N°218 BIS, 15 July 2023

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://journal-officiel.ga/20087-027-2023-/

In force since 15 July 2023. Binds public and private bodies.

What this law does

Articles 28 to 35 of Law No. 027/2023 require any operator of an information system, a term the law defines without any sector or size gate as an organised set of resources that collects, groups, classifies, processes or disseminates information, to take all technical and administrative measures necessary to guarantee the security of the services it offers.

Each operator must adopt standardised systems to identify, evaluate, treat and continuously manage the risks affecting its information systems' security, and must deploy technical mechanisms addressing threats to the systems' continuous availability, integrity, authentication, resistance to repudiation by third-party users, data confidentiality and physical security, with those mechanisms subject to a conformity clearance from the competent administrative authority on its cybersecurity policy.

A person whose activity is to offer users access to an information system must inform them of the danger of using an unsecured system, the need for a parental-control device, the particular risks of a security breach, and the existence of a technical means to restrict access to certain services, and must offer at least one such means. An operator of an information system must retain its connection and traffic data for ten years.

Its networks and information systems are also subject to a mandatory, periodic security audit on terms a regulation sets. Article 98 gives every person concerned by the law six months from its entry into force to comply, under pain of sanctions the article does not itself specify.

What it requires

Age gating law1 instrument, 1 in force

Research summary (202 words)

Gabon fixes the digital age of majority at sixteen: ordonnance n°0011/PR/2026 du 26 février 2026 portant réglementation de l'usage des réseaux sociaux via les plateformes numériques en République Gabonaise, published in Journal Officiel n°110 du 8 avril 2026, prohibits creating an account or profile on any online communication service, social network, or digital platform for a minor under sixteen, and requires an operator to block or suspend posting, sharing, and social-interaction features for an account identified as belonging to a user under sixteen unless a parent's consent is formally registered.

The Haute Autorité de la Communication publishes a technical référentiel setting the minimum requirements a platform's age-verification system must meet, and audits platforms against it; operators had twelve months from the ordinance's publication to deploy an effective age-verification mechanism at registration. Pornographic content is separately barred to a minor under eighteen.

No adult-content age-verification statute, app-store age-verification requirement, or general age-appropriate design code exists outside this ordinance and the children's-data chapter of the personal-data law (loi n°025/2023). The ordinance was taken under Article 99 of the Constitution on the authority of Loi n°042/2025 du 18 décembre 2025, which authorised the President of the Republic to legislate by ordinance during the parliamentary intersession.

Social media and minors

Ordonnance n°0011/PR/2026, protection des mineurs sur les réseaux sociaux

Ordonnance n°0011/PR/2026 art. 14, 16-24 et 53 (protection des mineurs), du 26 février 2026 portant réglementation de l'usage des réseaux sociauxOrdonnance n°0011/PR/2026 du 26 février 2026 portant réglementation de l'usage des réseaux sociaux via les plateformes numériques en…

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://journal-officiel.ga/22404-0011-pr-2026-/

In force 6 months, effective 8 April 2026. Binds private bodies.

What this law does

Ordonnance n°0011/PR/2026 sets Gabon's digital age of majority at sixteen and prohibits creating an account or profile on any online communication service, social network, or digital platform for a minor under that age, with a narrow carve-out for online encyclopedias, educational, cultural, or scientific directories, free and open-source software development and sharing platforms, and pedagogical content consulted at school with a teacher's supervision and the parent's express consent.

The person holding parental authority is liable for what a minor under sixteen does on a social network or platform in their charge, and that person may have data about the minor erased.

Pornographic content is barred to a minor under eighteen, and the Haute Autorité de la Communication publishes and enforces a technical référentiel setting the minimum requirements an age-verification system must meet, entrusting technical audits of those systems to itself or to the Autorité de Régulation des Communications Electroniques et des Postes (ARCEP) or another independent body with proven expertise.

Within twelve months of the ordinance's publication, every social-network or digital-platform editor must deploy an effective technical mechanism to verify a user's age at registration.

The editor must block or suspend posting, sharing, and social-interaction features for an account identified as belonging to a user under sixteen unless parental consent is formally registered, disable by default any feature letting an unidentified person contact a minor's account directly, filter out algorithmic recommendation of AI-generated violent, sexual, or psychologically harmful content to accounts identified as minors, and report quarterly on the number of minor accounts detected, blocked, or removed and the verification methods used.

A user's own false declaration of age does not relieve the platform of this duty of reasonable vigilance. An editor must also acknowledge a cyberbullying report or a report of harmful content involving a minor within twenty-four hours and decide and notify the user within seventy-two hours.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (173 words)

Gabon has no press-publisher neighbouring right and no compelled platform-to-publisher bargaining regime; the general copyright framework of loi n°1/87 du 29 juillet 1987 instituant la protection du droit d'auteur et des droits voisins is the only law reaching an aggregator's reproduction of news content.

Its analysis-and-short-quotation exception permits citing or borrowing from a work already lawfully made accessible to the public where the use conforms to fair practice and is justified by a scientific, critical, polemical, educational, or informational purpose, expressly including a quotation from a newspaper article reproduced as part of a press review; a further exception lets the press reproduce or broadcast, for informational purposes and with the author's name and source given, a current economic, political, or religious news article, unless the right of reproduction has been expressly reserved.

Neither exception is drafted for a systematic or wholesale reproduction of a publisher's output. No reported case or statute addresses hyperlinking or framing specifically, and no text-and-data-mining exception or machine-readable opt-out mechanism is in force; the 1987 law predates that concept.

Snippet reproduction

Loi n°1/87, exception de courte citation et revue de presse

Loi n°1/87, art. 34-36 (citations, revues de presse), du 29 juillet 1987 instituant la protection du droit d'auteur et des droits voisinsLoi n°1/87 du 29 juillet 1987 instituant la protection du droit d'auteur et des droits voisins, WIPO Lex

In force since 29 July 1987. Binds public and private bodies.

What this law does

Loi n°1/87 permits, provided the title of the work and the author's name are given, an analysis or short quotation drawn from a work already lawfully made accessible to the public, conforming to fair practice and justified by a scientific, critical, polemical, educational, or informational purpose, expressly including a quotation from a newspaper article or periodical reproduced as part of a press review, in either the original or a translation.

Separately, provided the author's name and source are given and the right of reproduction has not been expressly reserved, the press may reproduce or broadcast for informational purposes a current economic, political, or religious news article published or broadcast in the original or in translation, or a speech delivered before a deliberative assembly, a public court hearing, or a public political meeting or official ceremony.

Reproducing a protected work outside these exceptions is illicit and, for a work made available to the public without authorization, exposes both the person who let it happen on their premises and whoever materially committed the reproduction to civil liability.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.