Law / Somalia

Somalia

7 of 8 named instruments researched to a stage, across two of the six areas of law we track: 7 in force. As of 20 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law none researched
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (155 words)

Somalia's Data Protection Act, Law No. 005 of 2023, establishes the country's first comprehensive personal-data regime, administered by the Data Protection Authority the Act itself creates.

The Act binds a data controller domiciled, resident, or operating in Somalia, any processing occurring within Somalia, and any processing that monitors the behaviour of, or targets goods or services to, a data subject in Somalia, and it does not carve personal data an individual has intentionally made public out of that coverage; that circumstance is instead one of several lawful grounds for processing such data.

Biometric data, together with race, clan or ethnic origin, religious belief, health status, marital status or sex life, and political opinion, is classified as sensitive personal data carrying heightened rules the Authority may prescribe, and a cross-border transfer requires the recipient country, organisation, or contractual mechanism to meet a multi-factor adequacy test or a specific ground such as the data subject's informed consent.

Breach notification

Data Protection Act, 2023, personal data breach notification

Data Protection Act, Law No. 005 of 2023, arts. 25-27 (data breach notifications)Text of the Data Protection Act, Law No. 005 of 2023, reproduced by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 25(1) requires a data controller to notify the Authority of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals within seventy-two hours after having become aware of it.

Article 25(2) and (3) let the controller extend that period for the legitimate needs of law enforcement or as reasonably necessary to determine the scope of the breach, provided it tells the Authority the grounds for the extension, with supporting evidence, inside the same seventy-two hours.

Article 25(4) requires the controller to communicate a breach likely to result in a high risk to a data subject to each affected data subject without undue delay, in plain and clear language, and article 25(5) allows communication through widely used media where direct communication would involve disproportionate effort or expense. Article 26 sets out what a notification and a communication must contain, and article 27 requires a record of breaches.

The Act comes into force on adoption by the Federal Parliament, promulgation by the President and publication in the Official Bulletin, and no publication date has been located, so the day it took effect is not stated here. The Act is operative: in January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41.

What it requires

Comprehensive regime

Data Protection Act No. 005 of 2023

Data Protection Act, Law No. 005 of 2023 (Federal Republic of Somalia), arts. 4-5, 14-15, 17, 19, 24, 29, 32-34Text of the Data Protection Act, Law No. 005 of 2023, reproduced by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 4 applies the Act to a data controller domiciled, resident or operating in the Federal Republic of Somalia, to processing that occurs in Somalia, and to processing that monitors the behaviour of, or targets goods or services to, a data subject in Somalia, and article 5 exempts purely personal, recreational or household processing and specified functions of competent authorities.

Article 14 permits processing only on a listed lawful basis, such as the data subject's consent, the performance of a contract, a legal obligation or the data subject having intentionally made the data public, and requires fair and transparent processing. Article 15 requires purpose specification, data minimisation, limited retention and accuracy, and article 17 puts the burden of proving consent on the data controller.

Article 19 requires a data controller to keep a record of its data processors and to take reasonable measures to ensure they process in a way that keeps the controller compliant.

Article 24 requires appropriate technical and organisational measures to secure personal data, article 29 requires a data controller of major importance to carry out a data protection impact assessment before high-risk processing and to submit the report to the Authority, and articles 32 to 34 require such a controller to register with the Authority within six months of qualifying and to designate a data protection officer.

The Act comes into force on adoption by the Federal Parliament, promulgation by the President and publication in the Official Bulletin, and no publication date has been located, so the day it took effect is not stated here. The Act is operative: in January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41.

What it requires

Cross border transfer

Data Protection Act, 2023, cross-border transfers of personal data

Data Protection Act, Law No. 005 of 2023, arts. 30-31 (cross-border transfers)Text of the Data Protection Act, Law No. 005 of 2023, reproduced by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 30(1) prohibits a data controller from transferring personal data to a country outside the Federal Republic of Somalia or to an international organisation unless the data will be received only where an adequate level of protection applies, the recipient is an international organisation whose policies and measures afford an adequate level of protection, the recipient is subject to a law, binding corporate rules, contractual clauses, code of conduct, certification mechanism or other measure affording an adequate level of protection, or a legal basis in article 31 applies.

Article 30(2) lists the factors adequacy is assessed against. Article 31 permits a transfer without adequate protection where the data subject has given and not withdrawn consent after being informed of the risks, the transfer is necessary for a contract with or in the interest of the data subject, or another listed ground applies.

The Act comes into force on adoption by the Federal Parliament, promulgation by the President and publication in the Official Bulletin, and no publication date has been located, so the day it took effect is not stated here. The Act is operative: in January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41.

What it requires

Data subject rights

Data Protection Act, 2023, information to the data subject and rights of the data subject

Data Protection Act, Law No. 005 of 2023, arts. 18 and 20-23 (information and rights of the data subject)Text of the Data Protection Act, Law No. 005 of 2023, reproduced by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 18 requires a data controller to inform a data subject, before it collects their personal data, of the controller's identity and contact details, the basis and purposes of processing, who the data will be shared with, the data subject's rights and right to complain to the Authority, and a description of any automated decision-making, including profiling, and its likely consequences.

Article 20 gives a data subject the right to obtain, at no expense and without unreasonable delay, confirmation of whether their personal data is being processed and its source, a copy in a commonly used electronic format, correction or deletion of inaccurate, out of date, incomplete or misleading data, and deletion of data the controller is not entitled to retain. Article 21 gives the right to withdraw consent and requires withdrawal to be as easy as giving it.

Article 22 gives the right to object to processing that causes substantial unwarranted damage or distress on the grounds it names. Article 23 gives the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similar significant effects, except where the decision is necessary for a contract, authorised by a written law with safeguards, or authorised by the data subject's consent.

The Act comes into force on adoption by the Federal Parliament, promulgation by the President and publication in the Official Bulletin, and no publication date has been located, so the day it took effect is not stated here. The Act is operative: in January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41.

What it requires

Enforcement supervision

Data Protection Act, 2023, complaints, orders of the Authority and civil remedies

Data Protection Act, Law No. 005 of 2023, arts. 35-40 (complaints, orders and civil remedies)Text of the Data Protection Act, Law No. 005 of 2023, reproduced by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 35 lets a data subject aggrieved by an act or omission that violates the Act lodge a complaint with the Authority, which admits a complaint where the complainant has an interest and the complaint is not frivolous or vexatious. Article 36 lets the Authority investigate on a complaint or of its own accord and compel attendance, documents and information.

Article 37 lets the Authority order a data controller to stop the violating processing, remedy the violation, pay compensation to a data subject who suffered injury, loss or harm, account for profits, or pay an administrative penalty of up to one million United States dollars or its equivalent in Somali currency.

Article 38 makes failing to comply with such an order an offence carrying the same fine and imprisonment for two years, and article 39 allows an application to the Supreme Court within thirty days for judicial review of an order. Article 40 lets a data subject who suffers injury, loss or harm, or a consumer organisation acting for them, recover damages by civil proceedings.

The Act comes into force on adoption by the Federal Parliament, promulgation by the President and publication in the Official Bulletin, and no publication date has been located, so the day it took effect is not stated here. The Act is operative: in January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41.

What it requires

Sensitive categories

Data Protection Act, 2023, sensitive personal data and children's consent

Data Protection Act, Law No. 005 of 2023, arts. 2(15), 14(5) and 16 (sensitive personal data and children)Text of the Data Protection Act, Law No. 005 of 2023, reproduced by DataGuidance

In force. Binds public and private bodies.

What this law does

Article 2(15) defines sensitive personal data as personal data relating to an individual's biometric data, race, clan or ethnic origin, religious beliefs, health status, marital status or sex life, or political opinions or affiliations, together with any further category the Authority prescribes by regulation.

Article 14(5) empowers the Authority to prescribe in regulations the measures that must be applied to the processing of sensitive personal data, having regard to the risk of significant harm, the expectation of confidentiality and the protection afforded to personal data generally, so the heightened measures themselves are set by regulation rather than by the Act.

Article 16 requires consent for a child or an individual otherwise lacking legal capacity to be obtained from a parent or other appropriate legal representative, permits a data controller to rely on the consent of a child aged sixteen or more for information and services supplied by electronic means at that child's own request, lets the Authority extend that to a child aged thirteen or more by regulation, and requires a controller to verify the identity and age of the data subject and the representative.

The Act comes into force on adoption by the Federal Parliament, promulgation by the President and publication in the Official Bulletin, and no publication date has been located, so the day it took effect is not stated here. The Act is operative: in January 2026 the Authority announced that the Council of Ministers had approved regulations issued under article 41.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (409 words)

Somalia enacted a National Cybersecurity Law in 2025 that designates the National Communications Authority as the country's highest government authority for the governance and management of cybersecurity.

Under the Law, the Authority's Cybersecurity Department develops national cybersecurity regulations, standards and guidelines, identifies and designates Critical Information Infrastructure essential to national security, economic stability and public services across the telecommunications, financial services, energy, water, transportation and government digital-systems sectors, and sets the cybersecurity standards a designated infrastructure operator must meet.

The Department maintains a national register of designated infrastructure and conducts inspections and compliance monitoring to ensure a designated operator implements the required cybersecurity measures and meets its incident reporting obligations.

The Somalia Computer Emergency Response Team operates under the Authority as the national cyber incident response centre, receiving and analysing cyber incident reports, issuing alerts and advisories, coordinating a national response, and cooperating with international CERT organisations including OIC-CERT, AfricaCERT and FIRST.

Separately, the Law requires a cybersecurity company or a cybersecurity professional operating in Somalia to hold a National Communications Authority licence or registration.

The Law's own operative text was not located despite direct navigation of the National Communications Authority's site, including its National Communications Law, Regulations, and Strategies and Foresight Reports pages, each of which returned a 404, and the Somalia Computer Emergency Response Team's own Policies and Guidelines page, which returned template navigation with no document linked from it.

What is recorded above rests on the National Communications Authority's own published description of the Law's mandate rather than on the Law's numbered provisions, so the criteria that make an infrastructure Critical Information Infrastructure, the clock and threshold on an incident report, and the Law's penalties for a missed report or an unlicensed cybersecurity service are not stated here.

No product-security requirement was located that a software product or a connected device must meet before or after it reaches the Somali market, and no general reasonable-security or information-security-programme statute reaching a business generally, outside the Critical Information Infrastructure and licensed-service duties above, was located.

Somalia's privacy-topic counterpart is the Data Protection Act, Law No. 005 of 2023, whose own security-of-processing article requires a data controller to take appropriate technical and organisational measures to secure personal data and whose Data Protection Authority requires notice of a personal data breach that exposes personal data, compromises confidentiality or security, or poses a risk to a data subject's rights and freedoms; both duties are catalogued under that Act rather than here.

Sector security regimes

National Cybersecurity Law (2025)

National Cybersecurity Law (2025) (Federal Republic of Somalia); no law number locatedNational Communications Authority, official description of the Cybersecurity Department's mandate under the Law

In force. Binds public and private bodies.

What this law does

The Law designates the National Communications Authority as Somalia's highest cybersecurity governance authority. It directs the Authority to identify and designate Critical Information Infrastructure across the telecommunications, financial services, energy, water, transportation and government digital-systems sectors, and requires a designated operator to meet the cybersecurity standards the Authority sets and to comply with the Authority's incident reporting obligations.

It separately requires a cybersecurity company or a cybersecurity professional operating in Somalia to hold a National Communications Authority licence or registration. The Law's designation criteria, its incident reporting clock and threshold, and its penalty provisions were not located in the primary text, so they are not stated here.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.