Law / Haiti

Haiti

3 of 7 named instruments researched to a stage, across three of the six areas of law we track: 3 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law none researched
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Scraping law1 instrument, 1 in force

Research summary (302 words)

Haiti has no scraping-specific statute, so general law governs each dimension separately, and much of it could not be confirmed against a primary source. No provision was located, in the copyright decree or elsewhere, addressing open-web crawling of public pages as such.

A Code Pénal is reported by press accounts as criminalizing fraudulent access to, or interference with, an automated data-processing system (arts. 587 to 593), and as adopted by decree in 2020 and separately reported as brought into force on 24 June 2025, but no official gazette text was located, a further press account describes implementation preparations still targeting a 1 January 2027 entry into force, and Haiti's older Penal Code, still the version WIPO Lex records as current, carries no computer-specific offence at all, so this Code's current status and content are not established here and no computer-misuse instrument is recorded.

No Haitian case law on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located.

The Décret du 12 octobre 2005 sur le Droit d'Auteur predates the concept of a text-and-data-mining exception and carries none, and its own exceptions to copyright are narrow (reproduction for a judicial or administrative proceeding, and, for neighbouring rights only, reproduction for scientific research, teaching, or short-fragment citation of a performance, phonogram, or broadcast); the Decree confers no sui generis database right, but does protect a compilation, such as an anthology, encyclopedia, or database, as a copyright work where the choice, coordination, or arrangement of its contents is an original intellectual creation.

Haiti has no comprehensive data-protection statute, so no privacy-law carve-out or reach over scraped public personal data was found either way. No Haitian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Database right

Décret du 12 octobre 2005 sur le Droit d'Auteur, protection des recueils et bases de données

Décret du 12 octobre 2005, Droit d'Auteur, recueilsFrench text of the Decree

In force since 9 March 2006. Binds public and private bodies.

What this law does

The Decree recognizes a compilation of works, folklore expressions, or mere facts or data, such as an encyclopedia, anthology, or database, whether reproduced on a machine-exploitable medium or in any other form, as a protected work where the choice, coordination, or arrangement of its contents constitutes an intellectual creation.

This is an ordinary copyright-style originality test applied to compilations rather than a sui generis database right protecting investment in extraction or verification; the Decree confers no separate database right. Bare facts or data collected into a scraped dataset are not protected on their own, and an unoriginal, purely mechanical arrangement of scraped data would fall outside this provision as well.

The same Decree excludes the news of the day and mere facts, ideas, or data from copyright protection outright, and carries no text-and-data-mining exception; its only reproduction exceptions are for a judicial or administrative proceeding, and, limited to neighbouring rights, for scientific research, teaching, or short-fragment citation of a performance, phonogram, or broadcast.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (349 words)

Haiti's clearest private-sector security duty is Banque de la République d'Haïti (BRH) Circulaire 126, Sur les règles en matière de sécurité informatique, which sets the information-security rules binding every institution BRH supervises. Haiti's telecommunications regulator, the Conseil National des Télécommunications (CONATEL), publishes its regulatory texts at conatel.gouv.ht, including a base télécommunications décret signed under Jean-Claude Duvalier's government.

That décret requires telecommunications personnel and anyone who becomes aware of the existence or content of telecommunications correspondence to keep it secret (arts. 8-9), and gives the armed forces and the Secrétairerie d'État de l'Intérieur et de la Défense Nationale priority access to the national telecommunications network during war, civil unrest, or other emergencies (arts. 130-135), but it sets no network- or information-security requirement on a telecommunications operator or internet service provider as such.

CONATEL's own regulatory-texts listing carries a single dated regulatory decision, OE-CNT-DEC-20220001, and that decision sanctions radio-frequency interference with electronic communications rather than addressing information security. CONATEL's homepage carries a navigation stub for a Cyber sécurité project, commented out of the rendered page and linking to no published content, so no CONATEL cybersecurity regulation for licensed operators could be confirmed as published.

A CONATEL décret published 27 August 2025, amending the 14 February 2017 law on the electronic signature, extends CONATEL's authority to supervise electronic-certification infrastructure and, on CONATEL's own description, covers the responsibility of certification authorities, but the décret's own text could not be located, so whether it sets a specific security-posture duty on a certification authority, beyond legal recognition of electronic signatures and certificates, is not established here.

No general, sector-neutral reasonable-security or information-security-programme statute reaching every information-system operator was located.

Haiti's Code Pénal computer-misuse provisions, reported at arts. 587 to 593 and already recorded under the scraping topic as an offense committed against a system rather than an operator-facing security duty, carry an unresolved current-status question among conflicting press accounts and no separate operator-facing security requirement was found inside them.

Haiti has no comprehensive data-protection statute and no confirmed breach-notification duty on this jurisdiction's own privacy-topic record, so no privacy-topic security-of-processing article stands beside these findings.

Sector security regimes

BRH Circulaire 126, Information Security Rules for Financial Institutions

Banque de la République d'Haïti, Circulaire 126, Sur les règles en matière de sécurité informatique, 13 janvier 2022, arts. 1-5Official PDF of Banque de la République d'Haïti Circulaire 126

In force since 1 February 2022. Binds private bodies.

What this law does

Circulaire 126 sets the information-security rules that bind every institution financière the Banque de la République d'Haïti (BRH) supervises, pursuant to Articles 83 and 161 of the 14 May 2012 law on banks and other financial institutions. Every financial institution must have a written information-security policy, updated annually and approved by its board of directors.

Every bank must have an information-security committee that validates and approves the security measures adopted to implement that policy, a function the board of directors performs for other categories of financial institution. Every financial institution must designate an information-security officer independent of the IT department, reporting either to the risk-management function or directly to general management.

Every financial institution must ensure that its security committee is systematically informed of incidents capable of compromising information security, and of the measures taken to address them. Every financial institution must develop, test and maintain a contingency plan based on a risk analysis, to ensure the continuity of its activities in all circumstances.

Every financial institution must have its information system's security audited at least once every three years, with a copy of the audit report attached to its annual internal-control report. A financial institution that fails to have its system audited on that three-year cycle is liable to a penalty of two hundred thousand gourdes, and BRH may itself order and charge for an audit after notice.

A financial institution that fails to remedy a violation BRH identifies is liable to a further penalty of one hundred thousand gourdes per day of continuing infraction, plus an additional late-payment penalty of two thousand five hundred gourdes per day. The circular's provisions took effect 1 February 2022.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (188 words)

Haiti has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically.

The relevant instrument is the Décret du 12 octobre 2005 sur le Droit d'Auteur, which excludes the news of the day (les nouvelles du jour) and mere facts, ideas, or data from copyright protection outright, so a bare fact or news item is never protectable regardless of who first reported it.

The same Decree recognizes a compilation, such as an anthology, encyclopedia, or database, as a protected work where the choice, coordination, or arrangement of its contents is an original intellectual creation.

No general quotation or press-review exception for reproducing headlines or article text was located; the Decree's only citation exception, for short fragments of a performance, phonogram, or broadcast used in reporting a current event, sits in its chapter on neighbouring (performers', producers', and broadcasters') rights and does not reach a written news article.

The Decree predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Décret du 12 octobre 2005 sur le Droit d'Auteur, exclusion de l'actualité et des simples faits

Décret du 12 octobre 2005, Droit d'Auteur, actualitéFrench text of the Decree

In force since 9 March 2006. Binds public and private bodies.

What this law does

The Decree excludes from copyright protection official legislative, administrative, or judicial texts and their official translations, the news of the day, and ideas, procedures, systems, operating methods, concepts, principles, discoveries, or mere facts or data, even where these are stated, described, explained, illustrated, or incorporated in a work.

The same provision recognizes a compilation of works, folklore expressions, or mere facts or data, such as an encyclopedia, anthology, or database, whether reproduced on a machine-exploitable medium or in any other form, as a protected work where the choice, coordination, or arrangement of its contents constitutes an intellectual creation.

The Decree carries no general quotation or press-review exception for reproducing a headline or article text from a protected literary work; its only citation exception, limited to short fragments of a performance, phonogram, or broadcast used to report a current event, sits in the chapter on neighbouring rights and does not reach a written news article. The Decree replaced and repealed the earlier Décret du 9 janvier 1968 on copyright.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.