§ Dossier · WEST AFRICA · updated 22 July 2026
in force
DP law status
Law No. 2013-015 on the Protection of Personal Data (amended by Law No. 2017-070)
Yes
enforcement activity
as of the last landscape verification
Yes
decisions published
collection under way
The law
Law No. 2013-015 of 21 May 2013 on the Protection of Personal Data (as amended by Law No. 2017-070 of 18 December 2017) IN FORCE
commenced 2013-05-21 · Official full text ↗
- Scope
- Processing of personal data in any form by natural persons, legal persons and public entities, including foreign entities processing in Mali (transit-only excluded); exclusions for purely personal/domestic use and temporary copies.
- Key obligations
- Fair, lawful, non-fraudulent collection for specific and legitimate purposes; proportionality, accuracy, limited retention, and protection against damage or unauthorised access; Declaration/authorisation formalities with the APDP before processing (the APDP examined ~2,000 declaration files in a single 2025 session); Prohibition on processing sensitive data (health, race, sexual life, opinions, union membership, behaviours, judicial data) where it risks discrimination or fundamental rights; Data subject rights: access in intelligible form, objection (incl. to prospecting), rectification, completion, locking and deletion
- DPO required
- No: no DPO appointment obligation has been identified in the law.
- Registration
- Yes: declaration/authorisation formalities with the APDP before processing; the amendment law 2017-070 reorganised the APDP's functioning.
- Cross-border transfers
- Two routes only (art. 11): transfer to a foreign State whose sufficient protection level the APDP has found (based on internal legislation or effectively-applied international commitments), or transfer by APDP decision where the transfer and the recipient's processing guarantee sufficient protection, notably through contractual clauses or internal rules; the APDP's missions include authorising transfers. No consent or necessity derogations exist in the text. (Verified from the archived scan via the OCR sidecar 2026-07-11, S27.)
- Breach notification
- No general breach-notification duty to the APDP or to data subjects under the law.
- Penalties
- APDP administrative sanctions including warnings, formal notices (100+ issued), withdrawal of authorisation and financial sanctions: a documented 2025 example is a XOF 5,000,000 fine on a Bamako clinic for obstructing a video-surveillance verification; criminal provisions also arise under the cybercrime law (Law 2019-056).
- Authority
- Autorité de Protection des Données à Caractère Personnel (APDP)
Verified 2026-07-10
The regulator
- Authority
- Autorité de Protection des Données à Caractère Personnel (APDP)
- Website
- https://apdp.ml ↗
- Established
- 2015
- Operational
- Yes
- Enforcing
- Yes
- Publishes decisions
- Yes
Enforcement record
The authority publishes enforcement outcomes. Published decisions are being collected and verified for the tracker; this dossier will carry them as they pass verification.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Mali
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.