§ Dossier · CENTRAL AFRICA · updated 22 July 2026
in force
DP law status
Law No. 007/PR/2015 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 007/PR/2015 on the Protection of Personal Data IN FORCE
commenced 2015-02-10 (to confirm against the archived text) · Official full text ↗
- Scope
- Any information relating to a natural person identified or identifiable directly or indirectly (art. 5); the sensitive-data list follows the francophone family, including social measures and administrative charges.
- Key obligations
- Written declaration to ANSICE for ordinary processing; prior authorisation for genetic/biometric data, health research, offence data, interconnection, national ID numbers, and public-interest processing (arts. 51-53); Reasoned-opinion ('avis') regime for state-sector processing decided by regulatory act; Standard processing principles of the ECOWAS/francophone model; Compliance-formalities decree exists alongside the law
- DPO required
- No: DPO appointment is left to the controller's discretion; no statutory provision.
- Registration
- Yes: declaration to ANSICE for all ordinary processing, authorisation for the higher-risk categories, avis for state processing (arts. 51-53).
- Cross-border transfers
- Transfers to non-CEMAC/CEEAC countries only where the destination ensures sufficient protection (art. 29), with prior INFORMATION to ANSICE before any such transfer (art. 30); non-adequate destinations ride the art. 31 derogations (unambiguous consent, contract necessity, contract in the data subject's interest, important public interest/legal claims, vital interest, public register) or ANSICE authorisation on sufficient guarantees, notably contractual clauses (art. 32 - the OCR sidecar drops the 'non' in 'pays non membre'; corrected from the page image). Intra-community transfers are unrestricted. (Verified from the archived scan 2026-07-11, S27.)
- Breach notification
- No mandatory breach-notification protocol under Chadian law.
- Penalties
- ANSICE administrative sanctions: warning, formal notice, penalties for observed shortcomings, processing interruption, data blocking (up to three months), and temporary or permanent processing bans without court order (art. 8 of Law 006/PR/2015; art. 81 of the DP law); criminal sanctions of 1-5 years' imprisonment and fines of XAF 1,000,000 to 10,000,000 (Criminal Code art. 438).
- Authority
- Agence Nationale de Sécurité Informatique et de Certification Électronique (ANSICE)
Verified 2026-07-10
The regulator
- Authority
- Agence Nationale de Sécurité Informatique et de Certification Électronique (ANSICE)
- Website
- https://ansice.td ↗
- Established
- 2015
- Operational
- Yes
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Chad
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.