Comprehensive regime
Loi n° 2013-015, protection des données à caractère personnel
Loi n° 2013-015 du 21 mai 2013 portant protection des données à caractère personnel en République du Mali telle que modifiée, arts. 1, 4-8, 57 (objet, champ d'application, principes et déclaration)official Journal Officiel de la République du Mali, No. 26 of 28 June 2013, published by the Secrétariat Général du Gouvernement
In force since 28 June 2013. Binds public and private bodies.
What this law does
Article 1 has the Malian State assure every natural or legal, public or private person the protection of their personal data, without distinction of race, origin, colour, sex, age, language, religion, wealth, birth, opinion, nationality, or another such ground, and article 4 applies the Act to every processing of personal data carried out wholly or partly on national territory.
Article 5 subjects to the Act any processing by the State, territorial authorities, incorporated public bodies, and private natural or legal persons, any processing a controller carries out whether or not established on Malian territory, excluding only means used solely for transit, and processing concerning public security, national defence, or the investigation and prosecution of criminal offences, subject to this Act's own derogations or to specific provisions of other texts.
Article 6 excludes only two categories from the Act's scope: processing a natural person carries out in the exclusive context of personal or domestic activities, provided the data are not destined for systematic communication to third parties or dissemination, and temporary copies made for the technical activities of transmitting and providing access to a digital network.
Article 7 requires personal data to be collected and processed fairly, lawfully, and without fraud, for determined, explicit, and legitimate purposes, never used for other purposes, kept adequate, proportionate, and relevant to those purposes, accurate and updated where necessary, and kept in a form permitting identification of the persons concerned for no longer than those purposes require.
Article 8 requires the controller to take every precaution useful to preserve data security, including preventing deformation, damage, or unauthorized third-party access, requires a processor to offer sufficient guarantees of security and confidentiality, and states that this requirement does not relieve the controller of its own duty to see that those measures are respected.
Article 57 requires a controller to declare to the Autorité de Protection des Données à Caractère Personnel the processing operations it intends to carry out for a given purpose, and lets the Autorité impose an administrative sanction where that declaration was omitted in bad faith.
What it requires