§ Dossier · CENTRAL AFRICA · updated 22 July 2026
in force
DP law status
Law No. 24.001 of January 2024 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 24.001 of January 2024 on the Protection of Personal Data IN FORCE
commenced 2024-01 (exact promulgation date to confirm against the archived text) · Official full text ↗
- Scope
- Any processing of personal data within CAR or having effects within its territory, including public-security, defence, criminal-justice and judicial processing; exemptions for personal/household use, network-access facilitation and temporary technical storage.
- Key obligations
- Full GDPR-family lawful-basis set (consent, contract, legal obligation, vital interests, public interest, official authority, legitimate interests) with mandatory parental consent for minors; Mandatory resident DPO for data controllers: compliance, processing registers, liaison with the authority; independent and dismissible only on serious grounds; Prior-consent regime for direct marketing by phone, SMS, email, instant messaging or social media, with a simple opt-out required; Processor contracts and security-of-processing duties
- DPO required
- Yes: controllers must appoint a DPO resident in CAR, independent, adequately resourced, maintaining the processing register (an unusually strict residency requirement worth teaching).
- Registration
- The compliance architecture runs through the mandatory DPO's processing register rather than a general filing regime; the supervisory authority the law requires has not been established (12-month deadline missed: the Ministry of Digital Economy oversees in the interim).
- Cross-border transfers
- Chapter III (arts. 21-27, image-verified): transfers to a foreign State only where its legislation ensures protection SIMILAR to this law, assessed on data nature, purpose/duration, origin/destination, general and sectoral law, professional rules and security (art. 21); derogations for non-similar destinations - unambiguous informed consent, contract necessity/pre-contractual measures, contract in the data subject's interest, important public interest or legal claims, vital interest, public-register transfers (art. 21); the RECIPIENT may not onward-transfer to another State without the originating controller's agreement (art. 21 in fine). Section 2 (arts. 23-26): CEMAC/CEEAC member-state transfers conditioned on necessity for the recipient's legitimate missions. The agency may authorise transfers to non-CEMAC/CEEAC states without identical protection where the controller offers sufficient guarantees, which may result from appropriate contractual clauses (art. 27). Verified against the archived scan 2026-07-11.
- Breach notification
- The controller must notify breaches to the (yet-to-be-established) data protection agency; with no authority constituted, the duty currently has no working recipient.
- Penalties
- Administrative (arts. 43-48, image-verified): warning, injunction to cease processing, pecuniary sanction and withdrawal of authorisation/certification, plus urgent 3-month processing interruption or data blocking; sanctions recorded in a register and pecuniary sanctions DOUBLED on recidivism (art. 43); the pecuniary sanction is capped at 5% of pre-tax turnover of the last closed financial year, recovered as a State debt (art. 47); decisions are public and publishable at the offender's cost (art. 48). Criminal (arts. 49-55, image-verified): obstruction of the agency - 6 months-5 years and FCFA 100,000-5,000,000 (art. 49); negligent processing without prior formalities - 6 months-2 years and FCFA 100,000-2,000,000 (art. 50); fraudulent collection and purpose diversion - 2-5 years and FCFA 1,000,000-10,000,000 (art. 51); processing despite justified rectification/opposition - 2-5 years and FCFA 1M-10M (art. 52); over-retention - 6 months-2 years and FCFA 100,000-2,000,000 (art. 53); unauthorised harmful disclosure - 2-5 years and FCFA 1M-10M (art. 54); courts may order erasure (art. 55). All figures re-read from the page images 2026-07-11 (contract v1.11 rule) - all contingent on an authority that does not yet exist (art. 57 gave the Ministry 12 months from promulgation to establish it; the Ministry acts in the interim).
- Authority
- Independent administrative authority provided for by Law 24.001; not established (the January 2025 statutory deadline was missed; the Ministry of Digital Economy, Posts and Telecommunications oversees in the interim)
Verified 2026-07-11
The regulator
- Authority
- DPA provided for by Law 24.001; not established (Jan 2025 deadline missed)
- Operational
- No
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Central African Republic
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.