§ Dossier · EAST AFRICA · updated 22 July 2026
in force
DP law status
Law No. 14-029/AU on the Protection of Personal Data (adopted 26 June 2014; reported 2021 promulgation unverified)
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 14-029/AU on the Protection of Personal Data (adopted 26 June 2014; reported promulgation 29 June 2021 unverified) IN FORCE
commenced adopted 2014-06-26; promulgation date needs_review (secondary sources say 2021-06-29, no decree found) · Official full text ↗
- Scope
- Automated and non-automated processing by controllers and processors established in Comoros, plus extraterritorial reach over foreign entities processing data of individuals in Comoros in connection with offering goods/services or monitoring behaviour; exemptions for personal/domestic and (conditionally) journalistic, artistic or literary processing.
- Key obligations
- GDPR-family principles and lawful bases, privacy notices at collection, and data protection by design and by default; Processor contracts, security measures, and internal records of processing activities; 72-hour breach notification to the authority, with high-risk communication to data subjects; Full GDPR-style rights set incl. portability, restriction and protection from solely automated decisions
- DPO required
- Yes, in defined cases: public authorities, and entities whose core activities involve large-scale regular monitoring or large-scale sensitive-data processing.
- Registration
- No general filing regime: accountability runs through internal records of processing; the National Authority the law establishes has never been constituted, so no formalities operate in practice.
- Cross-border transfers
- CORRECTED from the primary text 2026-07-11 - the regime is the French 1978 model, NOT a GDPR mirror: transfers to a foreign State are allowed only where that State ensures a SUFFICIENT level of protection of privacy and fundamental rights, assessed on the destination's legal protections, security measures, and the processing's purpose/duration/nature (art. 9). Processing involving transfers abroad is on the art. 43 list requiring PRIOR Commission authorisation and control, with contractual clauses or internal rules among the factors establishing sufficient protection (art. 43(h)); intended transfers must appear in the declaration (art. 45(f)). The statute contains NO GDPR-style safeguards catalogue (no named SCCs/BCRs) and NO transfer-specific derogations (no explicit-consent or contract-necessity route). The previous 'fully GDPR-mirrored' description was secondary-source lore.
- Breach notification
- Notify the National Authority for the Protection of Personal Data within 72 hours unless the breach is unlikely to pose a risk; data subjects notified without undue delay where the risk is high.
- Penalties
- Administrative (arts. 54-61): warning and mise en demeure (art. 54); on non-compliance, a pecuniary sanction (not applicable to State processing), injunction to cease processing, withdrawal of authorisation or data blocking (art. 55) - the statute sets NO fine quantum for the pecuniary sanction, only a proportionality rule (gravity of the breach and advantages drawn, art. 59); decisions appealable to the administrative court (art. 58) and publishable (art. 61). Criminal (arts. 64-65): the art. 64 offence catalogue (obstruction, processing without prior formalities, unlawful sensitive-data processing, fraudulent collection, over-retention, harmful disclosure, etc.) is punished with 5-10 years' imprisonment and a fine of 10,000,000-35,000,000 Comorian francs, or either penalty alone; complicity and attempt punished the same; courts may order erasure (art. 65). Quanta verified against the archived 14-029/AU text 2026-07-11; none has ever been applied - the authority was never constituted.
- Authority
- National Authority for the Protection of Personal Data (provided for; not operational)
Verified 2026-07-11
The regulator
- Authority
- National Authority for the Protection of Personal Data (provided for; not operational)
- Operational
- No
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Comoros
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.