Research hub / Burundi
§ Dossier · EAST AFRICA · updated 22 July 2026

Burundi

Regulator
Independent supervisory authority provided for by Law 1/03; not yet established
Law
Law No. 1/03 of 10 March 2026 on the Protection of Personal Data ↗
Status
Law in force, enforcement not found
Authority
Independent supervisory authority provided for by Law 1/03; not yet established
in force
DP law status
Law No. 1/03 of 10 March 2026 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Law No. 1/03 of 10 March 2026 on the Protection of Personal Data IN FORCE

commenced 2026-03-10 (adopted unanimously by the National Assembly 15 January 2026; promulgated 10 March 2026) · Official full text ↗

Scope
Applies to all automated or non-automated processing of personal data by natural persons, the State, local authorities and public- or private-law legal persons, and to any controller or processor (established in Burundi or not) using processing means on Burundian territory, transit-only means excluded (art. 2). A 'responsable majeur du traitement' (major controller) - any enterprise of more than 200 employees, any public authority or national public body, or legal persons regularly processing life-safeguarding, judicial, therapeutic-emergency or health-research data (art. 1(12)) - carries the Chapter IV supplementary obligations. Verified from the archived text 2026-07-11.
Key obligations
Multiple data-protection regimes with an independent administrative authority responsible for their implementation; Criminal provisions drafted to sit compatibly with the Penal Code and the cybercrime law; An organ for personal-data protection placed under the supervision of the ministry responsible for the digital economy; Detailed obligations pending article-level extraction (see notes)
DPO required
Yes for major controllers - a responsable majeur must designate a 'delegue a la protection des donnees' (DPD); optional for other controllers; all designations notified to the authority, which keeps a register; corporate groups and same-type local authorities may share one DPD if it can handle the workload (art. 37). The DPD is involved in all DP questions, runs training/advice, alerts on violation risks and is the contact point with the authority (art. 38). Verified from the archived text 2026-07-11.
Registration
Yes for major controllers - registration with the DP authority within six months of acquiring that quality; the authority keeps a register (art. 34). Non-registration after a written warning: activity suspension up to three months, then a definitive ban on collecting and processing personal data (art. 35). Major controllers also keep a processing register incl. security measures (art. 36). Pre-existing State/public-service processing is subject to declaration only (art. 52), with 1-year (public) and 6-month (other) compliance windows (art. 53). Verified from the archived text 2026-07-11.
Cross-border transfers
Arts. 15-16, verified from the text 2026-07-11: transfers to a foreign State or international organisation only where it ensures a SUFFICIENT level of protection of privacy and fundamental rights (art. 15); sufficiency assessed on the destination's legal protections, security measures and the processing's purpose/duration/nature; an ORDINANCE of the Minister for the digital economy establishes the adequacy list; transfers to non-listed countries are allowed where the recipient adopts adequate guarantees APPROVED by the Burundian DP authority (art. 15 in fine). Art. 16 evaluation elements: rule of law and human rights, relevant general/sectoral legislation and its implementation, an effective independent supervisory authority, and international commitments. No consent/contract transfer derogations appear in the law.
Breach notification
Yes, dual-clock (image-verified): breaches posing a RISK to rights and freedoms are notified to the authority as soon as possible and at latest within 48 HOURS of awareness, late notification requiring reasons (art. 45); breaches posing a HIGH risk are also notified to the affected data subjects within a maximum of 96 HOURS in clear and simple terms (art. 46). Distinctive teaching point: the 48h/96h pair differs from the GDPR's 72h/without-undue-delay and from Rwanda's 48h/72h.
Penalties
All quanta image-verified 2026-07-11 (the fines are judicial, in the Chapter VII penal provisions; the authority's own coercive powers are the art. 35 suspension/ban): any violation of personal data - 3 months-1 year servitude penale and/or fine of BIF 50,000-500,000 for a natural person acting deliberately, BIF 1,000,000-20,000,000 for a private legal person, plus up to 6 months' activity suspension for a recidivist major controller (art. 47); unfair/unlawful/opaque collection or purpose-incompatible processing - 6 months-5 years and/or BIF 500,000-10,000,000 (natural persons), BIF 5,000,000-20,000,000 (legal persons, DOUBLED for a major controller) (art. 48); unjustified obstruction of archival/scientific/statistical processing - 3 months-1 year and/or BIF 50,000-500,000, or BIF 5,000,000-10,000,000 for a major controller (art. 49); sensitive-data or selective biometric-identification processing outside art. 10 - fine BIF 500,000-5,000,000 (art. 50). Cybercrime law and Penal Code apply in parallel (art. 51).
Authority
The 'Agence de protection des donnees a caractere personnel', created by art. 42 to supervise the law's application; its missions, composition, organisation and functioning are left to a DECREE (art. 42 al. 3) - not yet issued at last check, so the Agency exists on paper only. Data-subject requests on state-security/defence/public-security files run through the authority (art. 30).

Verified 2026-07-11

The regulator

Authority
Independent supervisory authority provided for by Law 1/03; not yet established
Operational
No
Enforcing
No enforcement activity found
Publishes decisions
No

Enforcement record

No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Burundi

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.