What Is Law No. 24.001 on the Protection of Personal Data?
The Central African Republic has an enacted general data-protection statute: Law No. 24.001 on the Protection of Personal Data. The official Ministry of the Economy, Posts and Telecommunications documentation portal lists and hosts the law as an official text, and the Ministry’s data-protection page describes it as promulgated. The law’s final provision states that it takes effect from promulgation and is to be published in the Journal Officiel. The statute provides information, access, rectification, completion, updating, blocking, erasure, opposition, indirect access for certain State processing, and related representation rights. It also establishes administrative measures, criminal penalties, cross-border-transfer controls, and a route through the controller or DPO, the Agency, administrative courts, or ordinary criminal-justice channels. Currentness and implementation are not fully closed. No official amending statute, repeal, consolidated text, or implementing decree was located, and the exact Journal Officiel issue and promulgation date were not independently located. No operational standalone data-protection authority website, official Agency contact details, or complaint portal was located.
At a glance
- Full name
- Law No. 24.001 on the Protection of Personal Data
- Short code
- Law No. 24.001
- Jurisdiction
- Central African Republic
- Enacted
- 2024
- Last major update
- Current official MENPT materials describe Law No. 24.001 as promulgated; no official amending statute, repeal, consolidated text, or implementing decree was located, and the exact Journal Officiel issue and promulgation date were not independently located
- Regulator
- Agency for the Protection of Personal Data provided for by Law No. 24.001; no operational standalone website or complaint portal located
- Private right of action
- Yes
- Statutory citation
- Law No. 24.001 on the Protection of Personal Data
Scope, who Law No. 24.001 covers
Protected data
Data subject rights
Right to information about the controller and representative, purposes, mandatory or optional data, categories, recipients, and opposition, access, and rectification methods
Right to free access in person or remotely, without delay, including relevant data, origin information, purposes, categories, recipients, and information enabling a person to understand and contest certain automated-processing mechanisms
Right to request a copy of personal data; health data may be provided directly or through a chosen doctor
Right to rectification, completion, updating, blocking, or erasure where data are inaccurate, incomplete, ambiguous, outdated, or unlawfully processed
Right to oppose processing at any time and without charge for a legitimate reason; opposition to direct marketing does not require justification
Right to indirect access and rectification through the Agency for sensitive State-security, defence, or public-security processing
Representation rights for minors and adults with certified physical or mental incapacity under the statutory order of representation
Right to seek referral through the controller’s DPO, investigation by the Agency, and challenge of sanction decisions before the administrative courts
No express right to portability, restriction of processing, withdrawal of consent, or a general right not to be subject to solely automated decisions was located
Notable features
The Central African Republic is an enacted-law case with a broad territorial and rights framework but incomplete implementation evidence. The statute contains detailed cross-border rules, including similar-protection requirements, listed exceptions, onward-transfer restrictions, CEMAC/CEEAC provisions, and Agency authorization mechanisms. It does not provide an express portability, restriction, consent-withdrawal, or general solely automated-decision right.
Enforcement & penalties
Penalties: Administrative measures include warnings, orders to cease processing, monetary sanctions, withdrawal of authorization or certification, emergency interruption of processing or locking of data for up to three months, and publication of decisions and sanctions. The administrative monetary sanction may not exceed 5% of the controller’s turnover excluding tax for the last closed financial year, doubling in cases of recidivism. Criminal penalties include 6 months–5 years’ imprisonment and 100,000–5,000,000 FCFA for obstructing the Agency; 2–5 years and 1,000,000–10,000,000 FCFA for fraudulent, unfair, or unlawful collection, diversion of a file’s original purpose, processing despite a legitimate rectification or opposition request, or unauthorized disclosure harming reputation or private life.
Private right of action: The law provides judicial routes including urgent measures and compensation for serious infringement, while sanction decisions may be challenged before the administrative courts. No fixed deadline located governs submitting a complaint, controller response, Agency investigation, Agency decision, or administrative appeal.
Relevance to data brokers
No Central African data-broker category, broker-specific complaint process, public-record correction or deletion portal, or public-record-specific regulator guidance was located. The law defines a public register and treats transfers originating from a legally established public register as a cross-border exception, but it does not create a dedicated public-record deletion route or exempt public-register data from general correction, blocking, erasure, or opposition provisions.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does the Central African Republic have a data-protection law?+
Yes. Current official MENPT materials identify Law No. 24.001 on the Protection of Personal Data as enacted and promulgated. No official amending statute, consolidated text, implementing decree, or directly located Journal Officiel issue was found, so currentness is supported but not fully closed at that level.
What rights does Law No. 24.001 provide?+
The law provides information, access, copying, rectification, completion, updating, blocking, erasure, opposition, indirect access for certain State processing, and representation rights. No express right to portability, restriction of processing, withdrawal of consent, or a general right not to be subject to solely automated decisions was located.
Can I ask a Central African data broker or public register to delete my information?+
No broker-specific or public-record-specific deletion route was located. The statute’s general route is to contact the relevant controller or DPO and, where appropriate, refer the matter to the Agency or ordinary criminal-justice system.
Official sources & citations
Other international privacy regimes
Law No. 24.001 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
