Law / Madagascar

Madagascar

8 of 9 named instruments researched to a stage, across three of the six areas of law we track: 8 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (159 words)

Madagascar's comprehensive personal-data regime is Law No. 2014-038 on the Protection of Personal Data, promulgated 9 January 2015, which requires a lawful basis for processing, bars processing sensitive data such as biometric, genetic, political, religious, trade union, health, or sex-life data absent a listed exception, gives a data subject rights of objection, access, rectification, and notice, sets an adequacy-based standard for transferring personal data abroad, and creates the Commission Malagasy de l'Informatique et des Libertés (CMIL) as the independent supervisory authority with administrative sanction power capped at five percent of turnover and its own criminal offenses.

The law contains no breach-notification duty to the CMIL or to affected individuals. Decree No. 2023-1541 of 6 December 2023 organized the CMIL's functions, and the government-led operationalization effort that followed, tracked by the Presidency's reform unit (PREA) from a first committee meeting on 28 February 2024, indicates the Commission only became functionally active some years after the 2015 law that created it.

Comprehensive regime

Law No. 2014-038, protection of personal data

Loi n° 2014-038 sur la protection des données à caractère personnel arts. 1-2, 5-17, 21, 43-49, 51-54 (dispositions générales, champ d'application, principes fondamentaux, formalités préalables et délégué à la protection des données)Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)

In force since 9 January 2015. Binds public and private bodies.

What this law does

Article 1 states that the law protects the rights of persons regarding the processing of personal data, and article 2 requires that information technology serve every person and respect human dignity, human rights, privacy, and individual or public freedoms, recognizing a right to the protection of personal data for everyone.

Article 5 applies the law to any automated or non-automated processing of personal data contained in or intended to be included in files, carried out in whole or in part on Malagasy territory, excluding only purely personal activity and processing for the sole purposes of journalism or literary or artistic expression. Article 6 reaches a controller established on Malagasy territory and a controller established elsewhere who uses means of processing located there, other than for mere transit.

Articles 7 to 13 define personal data, processing, a controller, a subcontractor acting on the controller's instructions, a recipient, the data subject, and consent as a free, specific, and informed manifestation of will.

Article 14 requires personal data to be collected and processed fairly, lawfully, and without fraud for determined, explicit, and legitimate purposes, barring later use for another purpose without the data subject's consent or a purpose the law itself sets, and requires it to be adequate, relevant, accurate, and kept no longer than those purposes need, subject to an exception for archival, historical, statistical, or scientific retention under safeguards the law or the CMIL defines.

Article 15 requires the controller to take precautions appropriate to the data's nature and the risks involved to preserve its security, protecting processing and data against accidental or unlawful destruction, accidental loss, alteration, disclosure, or unauthorized access. Article 16 lets processing be subcontracted only on the controller's instructions and only to a subcontractor offering sufficient guarantees to implement the required security measures.

Article 17 requires the data subject's consent or one of five alternative lawful grounds: a legal obligation, safeguarding the data subject's life, a public-service mission, performance of a contract, or the controller's or recipient's legitimate interest, subject to the data subject's own rights and interests.

Article 21 requires a provider of electronic-certification services to collect the personal data needed to issue and store signature certificates directly from the data subject, unless the data subject expressly consents otherwise. Article 43 makes declaring a processing operation to the CMIL a precondition of implementing it, with the operation then entered in a register the controller's data protection officer keeps.

Articles 44 to 46 set the corresponding formalities: public-sector processing needs a regulatory act adopted after the CMIL's reasoned favorable opinion, private-sector processing needs a prior declaration for which a receipt issues without delay, and processing presenting a particular risk to rights and freedoms or to privacy needs the CMIL's prior authorization.

Articles 47 to 49 let the CMIL publish simplified-declaration or exemption norms for the most common categories of processing, require it to rule on a declaration or authorization request within two months, renewable once, with silence read as a refusal, and fix what a declaration or request must contain, including the controller's identity, the processing's purposes, any interconnection with other processing, the data categories and their retention period, the recipients, the security measures, and any subcontractor used.

Article 51 requires every controller to designate a data protection officer who keeps the processing register current, is consulted before any new processing begins, advises the CMIL when in doubt, receives requests and complaints from data subjects, tells the controller of any breach found before referring it to the CMIL if the controller does not fix it, and produces an annual activity report.

Article 52 exempts a controller who has designated a data protection officer from the ordinary declaration formalities, except where the processing needs the CMIL's authorization, and articles 53 and 54 require the officer to be independent, free of conflicting duties, bound to confidentiality, and removable only for serious cause after the CMIL is told.

What it requires

Cross border transfer

Law No. 2014-038, cross-border transfer of personal data

Loi n° 2014-038, art. 20 (transfert de données à l'étranger)Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)

In force since 9 January 2015. Binds public and private bodies.

What this law does

Article 20 bars a controller from transferring personal data to a foreign State unless that State's legislation assures a level of protection for people similar to what this law assures, a level assessed against every circumstance of the transfer, including the data's nature, the purpose and duration of the processing, the countries of origin and final destination, and the third country's general or sector rules of law, professional rules, and security measures.

Absent a similar level of protection, the CMIL may still authorize the transfer where the controller offers sufficient guarantees for privacy and fundamental rights and freedoms, which may rest on appropriate contractual clauses or binding internal rules.

By way of exception to those paragraphs, a transfer to a country that does not assure a similar level of protection may still go ahead where the data subject has unambiguously consented to the transfer after being informed there is no similar level of protection, where the transfer is necessary to perform or negotiate a contract with the data subject or a contract in the data subject's interest with a third party, where it is necessary or legally required to safeguard an important public interest or to establish, exercise, or defend a legal right, where it safeguards the data subject's vital interest, or where it comes from a public register open to public consultation under legislative or regulatory provisions and the legal conditions for consulting it are met.

Article 20 also bars a recipient from transferring the data onward to a foreign country again without the agreement of the original controller and of the CMIL.

What it requires

Data subject rights

Law No. 2014-038, rights of data subjects

Loi n° 2014-038, arts. 3, 22-27 (droits des personnes)Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)

In force since 9 January 2015. Binds public and private bodies.

What this law does

Article 3 bars a judicial decision assessing a person's conduct from resting at all on automated data processing meant to profile the person or assess aspects of their personality, and bars an administrative or private decision assessing a person's conduct from resting solely on that kind of automated processing.

Article 22 gives a person with a legitimate reason the right to object at any time and free of charge to processing of personal data concerning them, gives an unqualified right to object to processing for prospecting purposes, and lets the CMIL judge a disputed reason's legitimacy, though the right does not apply where the processing meets a legal obligation or where the act authorizing the processing has expressly excluded it.

Article 23 gives every person the right to know whether they are concerned by a processing operation and, on proof of identity, to obtain the purposes, the categories of data processed, the recipients, the data itself in an intelligible form and its origin, and enough information to understand and contest automated logic behind a decision with legal effects, free of charge and without delay, and, for health data, directly or through a doctor the person designates; these access rights do not apply to processing concerning public security or the detection and prosecution of offenses, which article 26 governs instead.

Article 24 lets the controller refuse a manifestly abusive request, judged by its number or its repetitive or systematic character, with the burden of proving abuse on the controller who received it.

Article 25 gives a person the right to have inaccurate, incomplete, ambiguous, outdated, or unlawfully held, used, disclosed, or retained data rectified, completed, updated, blocked, or erased free of charge, and requires the controller to notify any third party the data were disclosed to of the changes made.

Article 26 substitutes an indirect procedure through a CMIL member drawn from the judiciary for the ordinary access and rectification rights where the processing concerns State security, defense, or public security.

Article 27 requires the controller to make sure the person data are collected from is told the controller's identity, the purpose of the processing, whether supplying the information is mandatory or optional, the data categories, the recipients, the rights of objection, access, and rectification and how to exercise them, and, where relevant, the transfers made and their article 20 safeguards, and requires equivalent clear notice, including the means to object, before storing or reading information on a user's terminal equipment for electronic communications, unless that access serves only to carry the communication or is strictly necessary for a service the user expressly requested; where data were not collected from the person, the same information is due when the data are recorded or, if disclosure to a third party is planned, by the first such disclosure at the latest.

What it requires

Enforcement supervision

Law No. 2014-038, CMIL, sanctions and offences

Loi n° 2014-038, arts. 4, 28-42, 50, 55-60, 61-73 (commission, contrôle, sanctions et pénalités)Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)

In force since 9 January 2015. Binds public and private bodies.

What this law does

Article 4 subjects compliance with the law's principles to the oversight of an independent Authority named the Commission Malagasy de l'Informatique et des Libertés (CMIL). Article 28 creates that Commission, charges it with seeing that processing operations comply with the law, and gives it regulatory and sanctioning power.

Articles 29 to 42 set the Commission's structure and operation: its members are appointed by decree in the Council of Ministers for a four-year term renewable once, are bound to professional secrecy and take an oath before the Supreme Court, enjoy immunity for opinions and acts within their mandate, receive no instruction from any authority, publish an annual activity report to the President, the Prime Minister, Parliament, and the Minister of Justice, face incompatibilities with government membership or a conflicting management role, and must recuse themselves from a matter touching an organization they were tied to in the past thirty-six months.

The Commission informs people and controllers of their rights and obligations, receives processing declarations and gives the opinions or authorizations the law requires, controls how processing is created and carried out, publishes simplified norms and exemptions, makes recommendations, sets model rules for information-system security, and receives complaints, and its administrative decisions are open to appeal before the Conseil d'Etat.

Article 50 lets Commission members and agents on a control mission, authorized by a mission order the president signs, access professional premises between six in the morning and seven at night, access files, processing, and equipment without restriction, take copies of any information, and collect statements, subject to a written record given to the controller and, where the premises' occupant objects, the authorization of the competent tribunal's president.

Article 55 lets the Commission, after an adversarial procedure, sanction a controller who breaches one or more provisions of the law with a warning, an injunction to stop processing or withdrawal of an authorization granted, or a monetary sanction, and lets it order urgent interruption or the locking of data for up to three months where a rights violation is occurring, with every sanction recorded in a register and a repeat offense doubling a monetary sanction.

Article 59 caps a monetary sanction at five percent of the pre-tax turnover of the last closed financial year, proportioned to the seriousness of the breach and the advantage drawn from it. Article 60 lets the Commission publish its sanction decisions, anonymizing a natural person's identity where it chooses, at the sanctioned person's expense.

Articles 61 to 71 criminalize specific breaches of the law, each punished by six months' to five years' imprisonment together with a fine ranging from 200,000 to 10,000,000 Ariary depending on the offense; unlawfully collecting personal data by fraudulent or unfair means (art. 65) and disclosing data in a way that harms a person's reputation or privacy (art. 71) each carry two to five years' imprisonment and a fine of 1,000,000 to 10,000,000 Ariary.

Article 72 lets a court order the erasure of the data involved in the offense, which Commission members and agents are empowered to verify.

What it requires

Sensitive categories

Law No. 2014-038, sensitive personal data

Loi n° 2014-038, arts. 18-19 (données sensibles)Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)

In force since 9 January 2015. Binds public and private bodies.

What this law does

Article 18 bars all processing of sensitive data because of the risk of discrimination and harm to a person's freedoms, and defines sensitive data to include racial origin, biometric data, genetic data, political opinions, religious or other convictions, trade union membership, and data concerning health or sex life.

It then lists the exceptions under which sensitive data may be processed with appropriate safeguards the law or the CMIL defines: the data subject's express consent unless the law bars lifting the prohibition that way, safeguarding the life of the data subject or a third party where the data subject cannot consent, processing by a nonprofit religious, philosophical, political, or trade union body limited to its own members or regular contacts, establishing, exercising, or defending a legal right, preventive medicine, medical diagnosis, care, or health-service management carried out by a health professional or another person bound by professional secrecy, public-interest health research the patient has not opposed, data the data subject has made public, and a public interest the law or the CMIL authorizes under article 46.

Article 19 restricts processing personal data relating to offenses, convictions, and safety measures to courts and public authorities managing a public service acting within their legal powers, and to legal auxiliaries for the strict needs of the missions the law assigns them.

What it requires

Scraping law2 instruments, 2 in force

Research summary (281 words)

Madagascar has no scraping-specific statute, so general law governs each dimension separately, and no reported Malagasy case addresses scraping directly.

The Law on the Fight Against Cybercrime (Law No. 2014-006) criminalizes fraudulent access to or continued presence in an information system, defined as accessing it intentionally without legitimate excuse or justification; unlike Kenya's equivalent, the definition does not expressly require defeating a technical security measure, so whether reading a public, unauthenticated page without a login or other barrier falls inside it is not settled by the text or by any located case.

No Malagasy statute or case addresses the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

Law No. 94-036 on literary and artistic property permits, without the author's authorization, quoting and short-citing a lawfully published work if the source is named, and reproducing a lawfully published economic, political, or religious press article unless the reproduction right has been expressly reserved; it also protects a database, defined as a compilation of data, extracts, or whole works in electronic or other form, but only as to the selection and arrangement of its contents, a compilation-style right rather than a European-style sui generis database right, and the statute predates text-and-data-mining and creates no text and data mining (TDM)-specific exception or opt-out mechanism.

Law No. 2014-038 on the protection of personal data applies to personal data processed on Malagasy territory with no exemption for information that is already publicly accessible, so scraping personal data from a public Malagasy website remains subject to that Act's lawful-basis and cross-border-transfer duties.

No Malagasy statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Law No. 2014-006, fraudulent access to an information system

Loi n° 2014-006 sur la lutte contre la cybercriminalité, art. 3, 4 et 6 (accès et maintien frauduleux)Text of Loi n° 2014-006 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)

In force. Binds public and private bodies.

What this law does

Article 3 defines fraudulent access as intentionally accessing all or part of an information system without a legitimate excuse or justification, or beyond one. Article 4 defines fraudulent continued presence in the same terms, for remaining connected to or continuing to use a system.

Article 6 punishes fraudulent access or continued presence alone with a fine of 100,000 to 10,000,000 Ariary; where the access or continued presence damaged, erased, altered, or suppressed data, or impeded or altered the system's functioning, the penalty rises to six months' to five years' imprisonment together with the same fine range.

Article 3's definition of fraudulent access nowhere requires infringing a security measure or other technical protection, so its trigger, an intentional access without a legitimate excuse or justification, reads broader on its face than a standard limited to defeating one. The National Assembly adopted the law on 19 June 2014; the presidential promulgation date and Journal Officiel publication date are not confirmed in the primary text located.

What it requires

Database right

Law No. 94-036, protection of databases as compilations

Loi n° 94-036, art. 6 et 7 (protection des banques de données)English-and-Malagasy bilingual text of Loi n° 94-036 hosted by the Centre Europe-Tiers Monde (CEJA)

In force since 6 November 1995. Binds public and private bodies.

What this law does

Article 6 extends copyright protection to authors of anthologies or compilations of diverse works or expressions of folklore, and to databases under the terms of article 7, without prejudice to the rights of the authors of the original works included.

Article 7 defines a database as a compilation of data or other information, or of extracts of works, or of entire works, in electronic or other form, and confines protection to the selection and arrangement of the materials rather than to the underlying data or works themselves; where the compilation is of works, the compilation and the constituent works are protected independently, and where it is a compilation of information, only the compilation itself is protected.

This is a copyright-style protection of the compiler's selection and arrangement of materials, not a right created independently of any originality in that selection or arrangement.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (154 words)

Madagascar has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, and no reported case recognizing a hot-news misappropriation doctrine outside copyright; general copyright law under Law No. 94-036 on literary and artistic property governs a news aggregator's reproduction of headlines and article text instead.

Article 44 permits using analyses and short quotations from a lawfully published work without the author's authorization, if the source and the author's name are indicated, and article 46 separately permits reproducing, distributing, broadcasting, or cable-communicating a lawfully published economic, political, or religious press article, unless the right to reproduce or communicate it has been expressly reserved.

Article 115 grants a parallel press-review exception against the related (neighbouring) rights of performers, phonogram producers, and broadcasters. The 1994 statute predates text-and-data-mining and creates no text and data mining (TDM)-specific exception or machine-readable opt-out, and no Malagasy statute or reported case addresses whether hyperlinking or framing a news article is a communication to the public.

Snippet reproduction

Law No. 94-036, quotation and press-article reproduction exceptions

Loi n° 94-036, art. 44 et 46 (exceptions de citation et de reproduction de la presse)English-and-Malagasy bilingual text of Loi n° 94-036 hosted by the Centre Europe-Tiers Monde (CEJA)

In force since 6 November 1995. Binds public and private bodies.

What this law does

Article 44 permits using analyses and short quotations lawfully published in another work, without the author's authorization and without payment, on condition of naming the source and the author.

Article 46(1) separately permits reproducing and distributing by press, or broadcasting or cable-communicating to the public, an economic, political, or religious article published in a newspaper or periodical, or a broadcast work of the same character, in cases where the right to reproduce or so communicate it has not been expressly reserved, again on condition of naming the source and the author where the author's name appears there.

Article 115, in the book on related (neighbouring) rights, separately exempts press reviews from the rights it grants to performers, phonogram producers, and broadcasting organisations. The article 46 reproduction exception can be defeated by the rightsholder's express reservation of the reproduction or communication right.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.