Law / Comoros

Comoros

9 of 12 named instruments researched to a stage, across five of the six areas of law we track: 9 in force. As of 19 September 2026.

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (213 words)

Comoros has no AI-transparency, output-labeling, or bot-disclosure statute, no AI risk-management or conformity regime, and no dedicated AI strategy document naming a government agency.

The one AI-adjacent duty found binds any person, not only a government body: Chapter 4 of the 2020 Penal Code criminalizes producing, recording, offering, distributing, or publishing an image or a representation of a pornographic or erotic character involving a minor through an information system, a term the same chapter's definitions section uses broadly enough to reach a representation that is not a photograph of a real child, alongside a separate, non-child-specific offense for producing or distributing a counterfeit or manipulated image or video harming a person's dignity through an information system.

A cybersecurity law that might carry further provisions, Loi n°21-012/AU relative à la cybersécurité et à la lutte contre la cybercriminalité (promulgated by Décret n°22-003/PR of 18 January 2022), is unreached: its only located copy on justice.gouv.km is a scanned image PDF that returns no extractable text through the crawler tiers or a web.archive.org snapshot of the same file.

A right against purely automated decision-making that a legacy database entry attributes to Comoros's data-protection law does not appear in the statute's text, and, in any case, would belong under the privacy topic's seam rule rather than here.

AI prohibited practices

Penal Code, pornographic and manipulated image or representation offenses via an information system

Code pénal Loi n° 20-038/AU du 29 décembre 2020, promulguée par Décret n° 21-018/PR du 16 février 2021, Chapitre 4 (De la cybercriminalité), Section 2, arts. 462-465Unofficial mirror of the 2020 Penal Code (Loi n° 20-038/AU) text

In force since 16 February 2021. Binds public and private bodies.

What this law does

Article 462 punishes with one to five years' imprisonment and a fine of 7,000,000 to 10,000,000 Comorian francs whoever produces, records, offers, makes available, disseminates, or publishes, through an information system or a data-storage medium, an image or a representation of a pornographic, erotic, or morally offensive character.

Its second paragraph separately punishes with two to seven years' imprisonment and a fine of 5,000,000 to 7,000,000 Comorian francs whoever produces, records, counterfeits, or distributes a counterfeit image, video image, or representation of that character that harms a person's dignity, through the same means.

Article 463 punishes, with two to five years' imprisonment and a fine of 5,000,000 to 10,000,000 Comorian francs, procuring, importing, or exporting an image or a representation of a child-pornographic, erotic character through an information system, and article 464 punishes intentional possession of the same at one to three years and 2,000 to 4,000,000 Comorian francs.

None of these articles limits the offending material to a photograph of a real person; the chapter's own definitions section (article 449) defines a covered representation broadly, as any representation of facts, information, or concepts in a form amenable to computerized processing, so a computer-generated or otherwise synthetic image or representation of the kind these articles describe falls within the same wording used for a captured one.

What it requires

Privacy law5 instruments, 5 in force

Research summary (320 words)

Comoros's comprehensive personal-data statute is Loi n°14-029/AU portant protection des données à caractère personnel, deliberated and adopted by the Assemblée de l'Union des Comores in plenary session on 26 June 2014; no later law replacing it was found, and it remains the country's operative data-protection regime.

It applies to any automated or manual processing of personal data without an exception for publicly accessible information, bars collecting or processing data revealing political, philosophical, or religious opinions, trade-union membership, health, or sexual life absent the data subject's express consent, and separately subjects biometric processing used to verify a person's identity to the prior authorization of the Commission Nationale de l'Informatique et des Libertés (CNIL), the independent regulator the law creates.

A controller may transfer personal data abroad only where the receiving state ensures a sufficient level of protection for privacy and fundamental rights, and a person whose rights are harmed may seek civil damages before the competent court in addition to the Commission's own administrative sanctions (warning, pecuniary sanction, injunction to stop processing, withdrawal of authorization, or data lock).

A broad list of offenses in article 64, including obstructing the Commission, processing without required formalities, unauthorized processing of sensitive or national-identification data, fraudulent collection, and disclosure harming a person's privacy, all draw the same criminal penalty under article 65: five to ten years' imprisonment and a fine of 10,000,000 to 35,000,000 Comorian francs, or either alone.

No breach-notification duty to the Commission or to affected individuals was found in the text.

A legacy database entry for this jurisdiction (short_code km-loi-n-001-2021-union-comoros-national-assembl) cites the law under Burkina Faso's own citation (Loi n°001-2021/AN, National Assembly, 2021) while pointing at the very same Comorian PDF; the citation text appears to have been contaminated from Burkina Faso's data-protection law, and a second legacy entry (km-loi-n-21-012-au-du-29-juin-2021-relative-la-p) restates the number of a separate 2021 cybersecurity law under a data-protection title. Neither error changes what the primary statute itself states.

Comprehensive regime

Law on the Protection of Personal Data

Loi n° 14-029/AU portant protection des données à caractère personnel deliberated and adopted by the Assemblée de l'Union des Comores in plenary session on 26 June 2014, arts. 1-5, 41-42, 43(a) and (e)-(g), 44-46, 49-53 and 66-68 (comprehensive regime, formalities and obligations)Text of Loi n° 14-029/AU reproduced by ANADEN (Agence Nationale de Développement du Numérique), the Comorian digital-development agency

In force. Binds public and private bodies.

What this law does

Article 1 applies the law to any automated processing of personal data held in a digitized or manual file, and article 5 requires data to be collected and processed lawfully and fairly, for determined and legitimate purposes, kept accurate and up to date, and not retained beyond the period the purpose requires.

Article 41 requires processing carried out by a public or private body to be declared to the Commission before it is implemented, or entered in a register kept by a person the controller designates, and article 42 exempts general accounting, payroll, supplier management, and a non profit association's membership processing from that duty.

Articles 43(a) and 43(e) to (g) require the Commission's prior authorization for processing bearing a national identification number or a national census, processing concerning state security, defense or public safety or the investigation and prosecution of offenses, an interconnection of files serving different purposes, and processing that could exclude a person from a right, a benefit or a contract, and article 44 gives the Commission two months to decide on such a request, with silence counting as approval outside the article 17 state security procedure.

Articles 45 and 46 fix what a declaration must state, including the controller's identity, the processing's purposes, the data and its retention period, who may access it, and the security measures taken. Article 49 requires an electronic certification provider to collect personal data directly from the data subject and to use it only for the purpose for which it was collected, unless the data subject expressly consents otherwise.

Article 50 requires the controller to take precautions appropriate to the data and to the risks the processing presents, and article 51 confines a sub processor to the controller's instructions under a contract addressing security and confidentiality.

Article 52 requires the controller to notify the Commission without delay of any change to the declared processing or of its discontinuation, and article 53 allows retention beyond the article 5 period only for historical, statistical or scientific purposes, with the data subject's express consent, or with the Commission's authorization.

What it requires

Cross border transfer

Law on the Protection of Personal Data, transfer to a foreign state

Loi n° 14-029/AU, arts. 9, 43(h) (cross border transfer)Text of Loi n° 14-029/AU reproduced by ANADEN (Agence Nationale de Développement du Numérique), the Comorian digital-development agency

In force. Binds public and private bodies.

What this law does

Article 9 bars a controller from transferring personal data to a foreign state unless that state ensures a sufficient level of protection for privacy and fundamental rights and freedoms, judged by the protections and security measures in force there and by the nature, origin and destination of the data and the purpose and duration of the processing.

Article 43(h) requires the Commission's prior authorization for a processing operation that provides for personal data to be transferred to another state, including where the transfer is grounded on contractual clauses or internal rules said to guarantee a sufficient level of protection.

What it requires

Data subject rights

Law on the Protection of Personal Data, rights of data subjects

Loi n° 14-029/AU, arts. 10-18, 48 (rights of data subjects)Text of Loi n° 14-029/AU reproduced by ANADEN (Agence Nationale de Développement du Numérique), the Comorian digital-development agency

In force. Binds public and private bodies.

What this law does

Article 10 gives a data subject the right to object, on legitimate grounds, to processing of their personal data, and article 11 gives them a further right, free of charge and without needing to state a reason, to object to their data being used for commercial, charitable or political prospecting.

Article 12 requires a controller collecting data directly from the data subject to disclose its identity, the processing's purpose, whether answering is mandatory, the recipients, and how the rights of objection, access and rectification are exercised.

Article 13 gives a person the right to ask a body running a listed automated processing whether it holds data concerning them, and article 14 gives the holder of that right of access communication of the information in clear language and a copy on payment of a scale fee the Commission sets, subject to a response delay or the disregard of manifestly abusive requests the Commission may grant.

Article 15 lets a data subject demand correction, completion, updating, locking or erasure of data that is inaccurate, incomplete, ambiguous, outdated, or unlawfully collected, used, disclosed or retained, and requires notice to any third party the data was disclosed to.

Article 16 lets a file be completed or corrected, even on the controller's own initiative, on the Commission's favorable opinion, and article 18 lets access to medical information be exercised only through a physician the data subject designates.

Article 48 requires a controller to tell a network communication user, clearly and completely, the purpose of accessing or storing information in their terminal equipment and the means available to object to it, and requires information under article 14 to be given to a data subject the data was not collected from at the latest by the data's first communication to a third party.

What it requires

Enforcement supervision

Law on the Protection of Personal Data, the Commission and sanctions

Loi n° 14-029/AU, arts. 19-40, 47, 54-65 (enforcement, sanctions and offenses)Text of Loi n° 14-029/AU reproduced by ANADEN (Agence Nationale de Développement du Numérique), the Comorian digital-development agency

In force. Binds public and private bodies.

What this law does

Article 19 creates the Commission Nationale de l'Informatique et des Libertés (CNIL) as the body charged with protecting personal data and controlling its processing, and article 20 gives it its own legal personality, administrative and management autonomy, and independence from every administrative and political authority.

Article 21 lists the Commission's missions, including informing and advising controllers and data subjects of their rights and obligations, controlling the creation of processing, receiving and answering complaints, alerting the public prosecutor to violations amounting to criminal offenses, and proposing legislative improvements. Articles 23 to 30 fix the Commission's nine member composition, their nomination, oath, five year renewable term, incompatibilities, and professional secrecy.

Article 39 bars ministers, public authorities, and public or private enterprise directors from obstructing the Commission's action and requires them to take useful measures to facilitate its mission, and article 47 lets Commission members and agents access the premises where processing is carried out, subject to judicial authorization if the controller objects, and requires a report of the visit.

Article 54 lets the Commission issue a warning or a formal notice fixing a deadline of up to eight days to end a violation, and article 55 lets it, where the controller does not comply, impose a pecuniary sanction, an injunction to stop the processing, withdrawal of an authorization, or a data lock, after a contradictory procedure under articles 56 to 59; article 60 lists what counts as a serious violation, including unlawful collection of sensitive, offense related or national identification data and obstructing the Commission's inspection.

Article 63 lets an injured person seek damages before the competent court, and article 65 punishes every offense article 64 lists, including obstructing the Commission, processing without required formalities, and unauthorized disclosure harming a person's privacy, with five to ten years' imprisonment and a fine of 10,000,000 to 35,000,000 Comorian francs, or either penalty alone, extending the same penalties to complicity and attempt.

What it requires

Sensitive categories

Law on the Protection of Personal Data, sensitive personal data

Loi n° 14-029/AU, arts. 6-8, 43(b)-(d) (sensitive personal data)Text of Loi n° 14-029/AU reproduced by ANADEN (Agence Nationale de Développement du Numérique), the Comorian digital-development agency

In force. Binds public and private bodies.

What this law does

Article 6 bars collecting or processing data revealing political, philosophical or religious opinions, trade union membership, or health or sexual life data without the data subject's express consent, though a religious, philosophical, political or trade union body may keep an automated membership register free of that bar, and the Commission may allow a further exception for reasons of public interest.

Article 7 lifts the article 6 bar where the data subject has expressly consented and consent may lawfully remove the bar, where processing safeguards a human life the data subject cannot consent to protect, where a non profit, religious, philosophical or trade union body processes data limited to its own members and regular contacts, where the processing establishes, exercises or defends a right in court, or where the processing serves individual therapeutic or medical follow up or health research.

Article 8 restricts processing of data on offenses, convictions or security measures to courts, public authorities and bodies managing a public service acting within their legal duties, legal auxiliaries for the strict needs of the missions the law entrusts to them, and other legal persons for the strict needs of managing disputes over offenses of which they were the victim.

Articles 43(b) to (d) require the Commission's prior authorization and control before processing biometric data needed to verify a person's identity, data on a person's health or condition, or data on offenses and convictions, because of the particular risk such processing poses to privacy and fundamental rights.

What it requires

Scraping law1 instrument, 1 in force

Research summary (246 words)

Comoros has no dedicated statute or reported case on scraping, terms-of-service enforceability, or a sui generis database right; the only checked source for a database right, the WIPO Lex jurisdiction profile's complete list of Comoros's main intellectual-property laws (trademarks, copyright, industrial designs, patents), names none.

The applicable computer-misuse regime is Chapter 4 (De la cybercriminalité) of the 2020 Penal Code, which criminalizes fraudulently accessing or remaining within an information system for any person, without an authorization test specific to public web pages, so how it would read against unauthenticated crawling of a public page is unsettled rather than tested.

The country's copyright regime, a 1957 French statute retained without a later replacement, carries no text-and-data-mining exception and predates any digital-reproduction concept, and its record is filed under the aggregation topic (see data/law-topics/aggregation/km.json), which the same statute's snippet and press-review exceptions predominantly serve.

The personal-data reach over scraped data belongs to the privacy topic under the seam rule: Loi n°14-029/AU covers any automated processing of personal data, scraping included, and is recorded there rather than duplicated here.

A separate, specialized cybersecurity law, Loi n°21-012/AU relative à la cybersécurité et à la lutte contre la cybercriminalité, promulgated by Décret n°22-003/PR of 18 January 2022, may also bear on unauthorized access, but its only located copy on justice.gouv.km is a scanned image PDF with no extractable text after two crawler tiers and a web.archive.org snapshot of the same file, so its provisions are unreached rather than confirmed or denied.

Computer misuse

Penal Code, unauthorized access to an information system

Code pénal Loi n° 20-038/AU du 29 décembre 2020, promulguée par Décret n° 21-018/PR du 16 février 2021, Chapitre 4 (De la cybercriminalité), Section 2, art. 451Unofficial mirror of the 2020 Penal Code (Loi n° 20-038/AU) text

In force since 16 February 2021. Binds public and private bodies.

What this law does

Article 451 of Chapter 4's Section 2 (Infractions spécifiques aux technologies de l'information et de la communication) punishes with one to two years' imprisonment and a fine of 500,000 to 5,000,000 Comorian francs whoever accesses or attempts to access, fraudulently, all or part of an information system.

Article 452 separately punishes fraudulently remaining or attempting to remain within all or part of a system, and articles 453 through 459 punish fraudulently hindering, corrupting, intercepting, altering, or forging data, or knowingly using fraudulently obtained data, or obtaining an advantage by any of those means.

None of these articles carries a public-page or authorization-test exception, so the chapter reads as a general unauthorized-access regime rather than one written with automated collection of published web content in mind.

What it requires

Age gating law1 instrument, 1 in force

Research summary (158 words)

Comoros has no social-media minor-access statute, no age-appropriate design code, and no app-store or device-level age-verification duty.

The one gating duty found binds private internet-access providers rather than a platform or a device maker: Chapter 4 of the 2020 Penal Code requires a cybercafé operator to identify users before granting internet access, bars a minor under eighteen from a cybercafé unless accompanied by an adult authorized by a parent or guardian, and limits a minor's access there to exclude pornographic, violent, racist, or degrading websites; it separately requires every internet-access provider to inform subscribers of, and offer, a technical means to filter or select the services their subscribers reach.

A general criminal offense of facilitating a minor's access to pornographic material exists in the same chapter, but binds any person rather than imposing a gating or verification duty on a service, so it is not recorded as a separate instrument here. No case law testing either provision exists.

Adult content age verification (AV)

Penal Code, cybercafé and internet-access-provider minor-access restrictions

Code pénal Loi n° 20-038/AU du 29 décembre 2020, promulguée par Décret n° 21-018/PR du 16 février 2021, Chapitre 4 (De la cybercriminalité), Section 5, arts. 479-482Unofficial mirror of the 2020 Penal Code (Loi n° 20-038/AU) text

In force since 16 February 2021. Binds private bodies.

What this law does

Article 479 conditions access to internet service from a cybercafé on prior identification of the user, which the cybercafé operator must carry out under conditions a decree sets.

Article 480 bars a minor under eighteen from accessing a cybercafé unless accompanied by an adult authorized by the minor's parents or guardian, and limits a minor's internet access there to exclude pornographic, violent, racist, or degrading websites and, generally, any website offending human dignity or inciting lawlessness.

The same article requires every person offering online communication-service access to inform subscribers of the existence of technical means to restrict or select the services they reach, and to offer at least one such means.

Article 481 punishes an internet-access provider that does not comply with article 480's obligations with six to twelve months' imprisonment, and article 482 punishes anyone who does not comply with the information-and-filtering-tools obligation with a fine of 1,000,000 to 10,000,000 Comorian francs.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (137 words)

Comoros has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no hot-news misappropriation doctrine, no specific linking or framing rule, and no text-and-data-mining opt-out mechanism; none of the six aggregation law families beyond snippet reproduction has a located instrument or reported case.

The operative copyright statute is a 1957 law on literary and artistic property that WIPO Lex still lists as Comoros's current main copyright law, with no later Comorian copyright act found to replace it.

That statute lets an author's short quotations and analyses, justified by a critical, polemical, pedagogical, scientific, or informational character, and press reviews, reproduce a divulged work without the author's consent, provided the author's name and the source are clearly indicated; it was written decades before automated news aggregation existed and does not address a machine-readable reservation, a hyperlink, or framing.

Snippet reproduction

Law on Literary and Artistic Property, quotation and press-review exception

Loi du 11 mars 1957 sur la propriété littéraire et artistique, art. 41Text of the Law of March 11, 1957, on Literary and Artistic Property reproduced by WIPO Lex under its Comoros jurisdiction profile

In force. Binds public and private bodies.

What this law does

Article 41 lists what an author of a divulged work may not prohibit once it has been made public, including, on condition that the author's name and the source are clearly indicated, analyses and short quotations justified by the critical, polemical, pedagogical, scientific, or informational character of the work into which they are incorporated, and press reviews.

It also permits, for current-events information, the full or partial dissemination by press or broadcasting of public speeches delivered before political, administrative, judicial, or academic assemblies, and public meetings of a political, administrative, judicial, or academic character.

WIPO Lex lists this 1957 statute as Comoros's current main copyright and related-rights law, with no later Comorian act shown as having replaced it; nothing in the text or in WIPO Lex's record addresses a press-publisher neighbouring right, a compelled-bargaining charge, a hot-news doctrine, linking or framing, or a text-and-data-mining reservation.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.