§ Dossier · EAST AFRICA · updated 22 July 2026
in force
DP law status
Law No. 1/03 of 10 March 2026 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 1/03 of 10 March 2026 on the Protection of Personal Data IN FORCE
commenced 2026-03-10 (adopted unanimously by the National Assembly 15 January 2026; promulgated 10 March 2026) · Official full text ↗
- Scope
- Applies to all automated or non-automated processing of personal data by natural persons, the State, local authorities and public- or private-law legal persons, and to any controller or processor (established in Burundi or not) using processing means on Burundian territory, transit-only means excluded (art. 2). A 'responsable majeur du traitement' (major controller) - any enterprise of more than 200 employees, any public authority or national public body, or legal persons regularly processing life-safeguarding, judicial, therapeutic-emergency or health-research data (art. 1(12)) - carries the Chapter IV supplementary obligations. Verified from the archived text 2026-07-11.
- Key obligations
- Multiple data-protection regimes with an independent administrative authority responsible for their implementation; Criminal provisions drafted to sit compatibly with the Penal Code and the cybercrime law; An organ for personal-data protection placed under the supervision of the ministry responsible for the digital economy; Detailed obligations pending article-level extraction (see notes)
- DPO required
- Yes for major controllers - a responsable majeur must designate a 'delegue a la protection des donnees' (DPD); optional for other controllers; all designations notified to the authority, which keeps a register; corporate groups and same-type local authorities may share one DPD if it can handle the workload (art. 37). The DPD is involved in all DP questions, runs training/advice, alerts on violation risks and is the contact point with the authority (art. 38). Verified from the archived text 2026-07-11.
- Registration
- Yes for major controllers - registration with the DP authority within six months of acquiring that quality; the authority keeps a register (art. 34). Non-registration after a written warning: activity suspension up to three months, then a definitive ban on collecting and processing personal data (art. 35). Major controllers also keep a processing register incl. security measures (art. 36). Pre-existing State/public-service processing is subject to declaration only (art. 52), with 1-year (public) and 6-month (other) compliance windows (art. 53). Verified from the archived text 2026-07-11.
- Cross-border transfers
- Arts. 15-16, verified from the text 2026-07-11: transfers to a foreign State or international organisation only where it ensures a SUFFICIENT level of protection of privacy and fundamental rights (art. 15); sufficiency assessed on the destination's legal protections, security measures and the processing's purpose/duration/nature; an ORDINANCE of the Minister for the digital economy establishes the adequacy list; transfers to non-listed countries are allowed where the recipient adopts adequate guarantees APPROVED by the Burundian DP authority (art. 15 in fine). Art. 16 evaluation elements: rule of law and human rights, relevant general/sectoral legislation and its implementation, an effective independent supervisory authority, and international commitments. No consent/contract transfer derogations appear in the law.
- Breach notification
- Yes, dual-clock (image-verified): breaches posing a RISK to rights and freedoms are notified to the authority as soon as possible and at latest within 48 HOURS of awareness, late notification requiring reasons (art. 45); breaches posing a HIGH risk are also notified to the affected data subjects within a maximum of 96 HOURS in clear and simple terms (art. 46). Distinctive teaching point: the 48h/96h pair differs from the GDPR's 72h/without-undue-delay and from Rwanda's 48h/72h.
- Penalties
- All quanta image-verified 2026-07-11 (the fines are judicial, in the Chapter VII penal provisions; the authority's own coercive powers are the art. 35 suspension/ban): any violation of personal data - 3 months-1 year servitude penale and/or fine of BIF 50,000-500,000 for a natural person acting deliberately, BIF 1,000,000-20,000,000 for a private legal person, plus up to 6 months' activity suspension for a recidivist major controller (art. 47); unfair/unlawful/opaque collection or purpose-incompatible processing - 6 months-5 years and/or BIF 500,000-10,000,000 (natural persons), BIF 5,000,000-20,000,000 (legal persons, DOUBLED for a major controller) (art. 48); unjustified obstruction of archival/scientific/statistical processing - 3 months-1 year and/or BIF 50,000-500,000, or BIF 5,000,000-10,000,000 for a major controller (art. 49); sensitive-data or selective biometric-identification processing outside art. 10 - fine BIF 500,000-5,000,000 (art. 50). Cybercrime law and Penal Code apply in parallel (art. 51).
- Authority
- The 'Agence de protection des donnees a caractere personnel', created by art. 42 to supervise the law's application; its missions, composition, organisation and functioning are left to a DECREE (art. 42 al. 3) - not yet issued at last check, so the Agency exists on paper only. Data-subject requests on state-security/defence/public-security files run through the authority (art. 30).
Verified 2026-07-11
The regulator
- Authority
- Independent supervisory authority provided for by Law 1/03; not yet established
- Operational
- No
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Burundi
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.