Comprehensive regime
Law No. 2014-038, protection of personal data
Loi n° 2014-038 sur la protection des données à caractère personnel arts. 1-2, 5-17, 21, 43-49, 51-54 (dispositions générales, champ d'application, principes fondamentaux, formalités préalables et délégué à la protection des données)Text of Loi n° 2014-038 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)
In force since 9 January 2015. Binds public and private bodies.
What this law does
Article 1 states that the law protects the rights of persons regarding the processing of personal data, and article 2 requires that information technology serve every person and respect human dignity, human rights, privacy, and individual or public freedoms, recognizing a right to the protection of personal data for everyone.
Article 5 applies the law to any automated or non-automated processing of personal data contained in or intended to be included in files, carried out in whole or in part on Malagasy territory, excluding only purely personal activity and processing for the sole purposes of journalism or literary or artistic expression. Article 6 reaches a controller established on Malagasy territory and a controller established elsewhere who uses means of processing located there, other than for mere transit.
Articles 7 to 13 define personal data, processing, a controller, a subcontractor acting on the controller's instructions, a recipient, the data subject, and consent as a free, specific, and informed manifestation of will.
Article 14 requires personal data to be collected and processed fairly, lawfully, and without fraud for determined, explicit, and legitimate purposes, barring later use for another purpose without the data subject's consent or a purpose the law itself sets, and requires it to be adequate, relevant, accurate, and kept no longer than those purposes need, subject to an exception for archival, historical, statistical, or scientific retention under safeguards the law or the CMIL defines.
Article 15 requires the controller to take precautions appropriate to the data's nature and the risks involved to preserve its security, protecting processing and data against accidental or unlawful destruction, accidental loss, alteration, disclosure, or unauthorized access. Article 16 lets processing be subcontracted only on the controller's instructions and only to a subcontractor offering sufficient guarantees to implement the required security measures.
Article 17 requires the data subject's consent or one of five alternative lawful grounds: a legal obligation, safeguarding the data subject's life, a public-service mission, performance of a contract, or the controller's or recipient's legitimate interest, subject to the data subject's own rights and interests.
Article 21 requires a provider of electronic-certification services to collect the personal data needed to issue and store signature certificates directly from the data subject, unless the data subject expressly consents otherwise. Article 43 makes declaring a processing operation to the CMIL a precondition of implementing it, with the operation then entered in a register the controller's data protection officer keeps.
Articles 44 to 46 set the corresponding formalities: public-sector processing needs a regulatory act adopted after the CMIL's reasoned favorable opinion, private-sector processing needs a prior declaration for which a receipt issues without delay, and processing presenting a particular risk to rights and freedoms or to privacy needs the CMIL's prior authorization.
Articles 47 to 49 let the CMIL publish simplified-declaration or exemption norms for the most common categories of processing, require it to rule on a declaration or authorization request within two months, renewable once, with silence read as a refusal, and fix what a declaration or request must contain, including the controller's identity, the processing's purposes, any interconnection with other processing, the data categories and their retention period, the recipients, the security measures, and any subcontractor used.
Article 51 requires every controller to designate a data protection officer who keeps the processing register current, is consulted before any new processing begins, advises the CMIL when in doubt, receives requests and complaints from data subjects, tells the controller of any breach found before referring it to the CMIL if the controller does not fix it, and produces an annual activity report.
Article 52 exempts a controller who has designated a data protection officer from the ordinary declaration formalities, except where the processing needs the CMIL's authorization, and articles 53 and 54 require the officer to be independent, free of conflicting duties, bound to confidentiality, and removable only for serious cause after the CMIL is told.
What it requires