What this law does
Article 3 binds every collection, processing, transmission, storage or use of personal data by a public or private legal person or a natural person, and article 4 extends the Act to a controller or processor established in Niger, one using processing means located on Niger's territory, and one targeting Nigerien citizens or offering goods or services to persons established in Niger.
Article 5 excludes only a purely personal or domestic use that is not disseminated to third parties, temporary technical copies made for network transmission, and journalistic, literary or artistic processing carried out under professional ethical rules.
Article 29 makes prior formality with the HAPDP, whether a simple declaration, an authorisation request or an advisory request, a precondition of processing, and article 31 lists the categories, including genetic, medical, biometric, interconnected, unique-identifier and sensitive-category processing, that need the HAPDP's prior authorisation rather than a bare declaration.
Article 37 makes the data subject's express prior consent the legitimacy test for processing, departing from it only where the controller is duly authorised and the processing is necessary for a legal obligation, a public-interest or official mission, performance of a contract, or safeguarding the data subject's own vital interests or fundamental rights.
Article 38 requires personal data to be collected for determined, explicit and legitimate purposes and kept no longer than those purposes require, article 39 requires it to be adequate, relevant, accurate and kept up to date, and article 40 requires collection, recording, processing, storage and transmission to proceed lawfully, fairly and without fraud.
Article 41 and article 82 require the controller and any processor it engages to keep personal data confidential and to implement technical and organisational measures, including pseudonymisation, encryption and data protection by design and by default, against unauthorised access, loss or damage.
Article 64 requires a register of processing operations made available to the HAPDP on request, and article 67 lets the HAPDP demand a privacy impact assessment before authorising a sensitive or high-risk processing operation.
Article 79 requires a private-sector controller to designate a data-protection correspondent and notify the appointment to the HAPDP, while a public-sector controller designates a focal point instead, and article 86 requires a processor to offer sufficient security guarantees, to operate under a written confidentiality contract, and to answer to the same obligations as the controller.
What it requires