§ Dossier · WEST AFRICA · updated 22 July 2026
in force
DP law status
Law No. 001-2021/AN on the Protection of Persons with regard to Personal Data Processing (replaced Law 010-2004)
Yes
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 001-2021/AN of 30 March 2021 on the Protection of Persons with regard to the Processing of Personal Data (replacing Law No. 010-2004/AN) IN FORCE
commenced 2021-03-30 (adoption; promulgated 2021) · Official full text ↗
- Scope
- Processing of personal data in any form by natural persons, legal persons and public entities, including foreign entities processing in Burkina Faso (transit-only excluded); exclusions for national security, journalistic/artistic purposes and temporary copies.
- Key obligations
- Consent-and-legitimacy default with purpose limitation, proportionality, lawfulness/fairness, limited retention, and security/confidentiality duties; Preliminary formalities with the CIL before processing: declaration, opinion or authorisation depending on the processing (simplified declaration where a CIL 'norme simplifiée' applies); Prohibition on processing sensitive data (health, race/ethnicity, opinions, union membership, morals, offences) without consent or legal exception; Annual reporting to the CIL on processing activity
- DPO required
- No: no DPO or equivalent appointment obligation has been identified in the law.
- Registration
- Yes: preliminary formalities with the CIL (declaration, opinion or authorisation depending on processing type); simplified declaration of conformity where processing matches a published simplified norm; plus annual reports.
- Cross-border transfers
- Arts. 42-44 verified: transfers to a foreign country or international organisation only where it ensures a level of protection adequate to Burkina Faso's (art. 42); BEFORE any transfer the controller must obtain CIL authorisation, sign confidentiality and data-reversibility clauses with the counterparty, and implement security measures including encryption (art. 42). Adequacy is assessed on all transfer circumstances, international agreements, and CIL-approved ad hoc or standardised guarantees - which the CIL can withdraw (art. 43). Derogations for non-adequate destinations (art. 44): specific informed consent, contract necessity/pre-contractual measures, vital interest, exceptional-circumstances transfer authorised by Council of Ministers decree on the CIL's binding opinion, overriding legitimate/public interests provided by law, punctual non-massive transfers for important public interest or legal claims, punctual public-register transfers, international judicial assistance, bilateral/multilateral agreements, or express reasoned CIL authorisation of a CIL-homologated contract with protective clauses or internal rules. The CIL's transfer-authorisation competence is in art. 56. Verified against the archived 2021 text 2026-07-11.
- Breach notification
- No general breach-notification duty; art. 21 requires notifying a third party of rectification/cancellation where data was transmitted to it by mistake, unless the CIL grants an exemption.
- Penalties
- Administrative (arts. 63-78): CIL may impose warning, mise en demeure, injunction to cease processing, data blocking, amende forfaitaire and withdrawal of authorisation (art. 63); the amende forfaitaire is 1% of the last financial year's pre-tax turnover for a first offence, 5% on repeat (art. 65); article-specific fines (arts. 67-75) range XOF 1,000,000 to 100,000,000 - e.g. obstruction 5-10M (art. 67), missing prior formalities 5-20M (art. 68), security failures 5-20M and unauthorised communication/access 1-10M (art. 69), purpose diversion and fraudulent collection each 5-100M (arts. 70-71), sensitive-data storage without express consent 10-100M (art. 73), over-retention 5-20M (art. 74); plus confiscation/erasure of media and a processing ban of up to 2 years (art. 76) and publication of the decision at the offender's cost (art. 77). Criminal: breaches are punished under the Penal Code's ICT-offence provisions (art. 79). Section numbers verified against the archived 2021 text 2026-07-11.
- Authority
- Commission de l'Informatique et des Libertés (CIL)
Verified 2026-07-11
Access to information
Law No. 051-2015/CNT on the Right of Access to Public Information and Administrative Documents IN FORCE
The regulator
- Authority
- Commission de l'Informatique et des Libertés (CIL)
- Website
- https://cil.bf ↗
- Established
- 2007
- Operational
- Yes
- Enforcing
- Yes
- Publishes decisions
- No
Enforcement record
Enforcement activity is documented for this jurisdiction, but the authority does not publish its decisions. The tracker records only what can be verified against a public document, so no decision pages exist here; the publication gap itself is measured in Enforcement in the Dark.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Burkina Faso
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.