AI LAW RADAR · Daily Last verified 18 Aug 2026

Jurisdiction dossier

Central African Republic: AI regulation & deadlines

No AI-specific statute in force, and the thinnest automated-decision regime yet recorded in Africa. Loi 24.001 du 25 janvier 2024 portant protection des données à caractère personnel gave the Central African Republic its first dedicated data-protection statute, in force from promulgation under art. 58. It contains no prohibition on automated decisions: nothing in its fifty-eight articles says that a decision producing legal effects may not be taken on the sole foundation of an automated processing, and there is no human-intervention right and no GDPR-style right of objection to automated decisions. The single hook is the third indent of the art. 30 access right, in the Directive 95/46/EC art. 12(a) form: the data subject may obtain the information allowing them to know and to contest the mechanism of the automated processing where a decision is taken on its foundation and produces legal effects in respect of them. It is purely reactive — the art. 35 information duty owed at collection lists purposes, categories, recipients and the rights of objection, access and rectification, but says nothing about automated logic, so a Central African controller need never volunteer that a decision was automated. Art. 6 nevertheless carries the full GDPR art. 4(4) definition of Profilage, down to the prediction of work performance, economic situation, health, preferences, interests, reliability, behaviour, location and movements — and the defined term is then used nowhere else in the Law. Art. 28 subjects the interconnection of files with differing purposes to the agency's prior authorisation and requires that it not entail discrimination. Enforcement is administrative for art. 30, capped at 5% of the prior year's pre-tax turnover; processing in defiance of a legitimate objection under art. 29 carries two to five years' imprisonment and 1,000,000 to 10,000,000 FCFA. Transfers run on a CEMAC and CEEAC perimeter rather than a national adequacy list. Art. 57 gave the Ministry twelve months from promulgation to stand up the supervisory agency, a deadline that expired on 25 January 2025, with the Ministry discharging its missions in the interim. 1 obligation tracked — 1 in force.

Binding — Binding sectoral Flagship law: Loi 24.001 art. 30

No AI-specific statute in force, and the thinnest automated-decision regime yet recorded in Africa. Loi 24.001 du 25 janvier 2024 portant protection des données à caractère personnel gave the Central African Republic its first dedicated data-protection statute, in force from promulgation under art. 58. It contains no prohibition on automated decisions: nothing in its fifty-eight articles says that a decision producing legal effects may not be taken on the sole foundation of an automated processing, and there is no human-intervention right and no GDPR-style right of objection to automated decisions. The single hook is the third indent of the art. 30 access right, in the Directive 95/46/EC art. 12(a) form: the data subject may obtain the information allowing them to know and to contest the mechanism of the automated processing where a decision is taken on its foundation and produces legal effects in respect of them. It is purely reactive — the art. 35 information duty owed at collection lists purposes, categories, recipients and the rights of objection, access and rectification, but says nothing about automated logic, so a Central African controller need never volunteer that a decision was automated. Art. 6 nevertheless carries the full GDPR art. 4(4) definition of Profilage, down to the prediction of work performance, economic situation, health, preferences, interests, reliability, behaviour, location and movements — and the defined term is then used nowhere else in the Law. Art. 28 subjects the interconnection of files with differing purposes to the agency's prior authorisation and requires that it not entail discrimination. Enforcement is administrative for art. 30, capped at 5% of the prior year's pre-tax turnover; processing in defiance of a legitimate objection under art. 29 carries two to five years' imprisonment and 1,000,000 to 10,000,000 FCFA. Transfers run on a CEMAC and CEEAC perimeter rather than a national adequacy list. Art. 57 gave the Ministry twelve months from promulgation to stand up the supervisory agency, a deadline that expired on 25 January 2025, with the Ministry discharging its missions in the interim.

checked 18 Aug 2026 primary source ↗

The Register

1 obligation
Central African Republic Binding

Loi 24.001 art. 30 — the access limb without the bar: the only tracked statute that lets you contest an automated decision but never forbids one

Binds Responsables de traitement, and through the art. 6 definition also sous-traitants, being any natural or legal person, public or private, any other body or association that processes data on the controller's behalf. The art. 4 scope is territorial-plus-effects and unusually explicit about the public sector: the Law applies to processing carried out in the context of the activities of an establishment of a controller or a processor on the territory of the Central African Republic, whether or not the processing takes place in the Central African Republic; to processing that deploys effects in the Central African Republic even where those effects arose abroad or through a controller established abroad; to processing concerning public security, defence, the investigation and prosecution of criminal offences or state security, subject to derogations fixed by other laws in force; to processing not provided for by a special law; and to processing in the context of court proceedings. Art. 4 excludes purely personal or domestic processing by a natural person, and temporary technical copies made for transmission and network access provision. Art. 31 removes the art. 30 right altogether for processing concerning public security and for the collection of information necessary to establish offences and pursue the consequent proceedings, and lets the controller refuse requests that are manifestly abusive by their number or their repetitive or systematic character, with the burden of proof on the controller in case of contestation. For state-security, defence and public-security processing the access and rectification rights are exercised indirectly through the agency rather than against the controller. No ex ante gate attaches to automated decision-making or to profiling: the only prior-authorisation regimes in the Law are art. 28, which subjects the interconnection of files held by legal persons managing a public service with differing public interests, processing operated by the State for users of remote e-administration services, and interconnection of files with differing purposes, to the prior authorisation of the agency — an interconnection must not entail discrimination or prejudice to rights, freedoms and guarantees — and arts. 24 to 27, which govern transfers. Those transfer articles are the first on the tracker to draw the free-flow perimeter around CEMAC and CEEAC rather than around a national adequacy list: a controller may transfer personal data to a state that is not a member of CEMAC or CEEAC only where that state ensures a sufficient level of protection, the agency must be informed before any such transfer, and art. 27 lets the agency authorise a transfer to a non-adequate non-member state where the controller offers sufficient guarantees, which may result from appropriate contractual clauses. Impact tier: all entities.. Article 30 of Loi 24.001 du 25 janvier 2024 portant protection des données à caractère personnel is the Central African Republic's only operative automated-decision provision, and it is an access limb, not a bar. It sits in Chapitre VI, Des droits liés au traitement des données à caractère personnel, which opens at art. 29 with the right of any person showing a legitimate motive to object at any time and free of charge to the processing of their personal data, and a free-standing right to object to the use of their data for prospection without having to justify a motive. Art. 30 then gives every person the right to be informed of the processing of their data, subject to proof of identity, and to obtain from the controller three things: information on the purposes of the processing, the categories of personal data processed and the recipients or categories of recipient to whom the data are communicated; the communication of all the data concerning them together with any available information as to their origin; and — the automated-decision limb — les informations permettant de connaître et de contester le mécanisme du traitement automatisé en cas de décision prise sur le fondement de celui-ci et produisant des effets juridiques à l'égard de l'intéressé, the information allowing the person to know and to contest the mechanism of the automated processing where a decision is taken on the foundation of that processing and produces legal effects in respect of them. That is the Directive 95/46/EC art. 12(a) third-indent form word for word, and it is the whole of it. The right is exercised free of charge, on the spot or remotely, and must be granted without delay, with a copy of the data conforming to the content of the processing delivered on request. What the Central African Republic does not have is the second half of the Directive template. There is no art. 15-style rule anywhere in the Law providing that a decision producing legal effects may not be taken on the sole foundation of an automated processing, no deeming clause for contractual decisions, no human-intervention right, and no GDPR art. 22 right of objection to automated decisions. The word automatisé appears exactly three times in the fifty-eight articles: in the art. 6 definition of Profilage, in the art. 6 definition of Traitement, and in this indent of art. 30. Nothing prohibits an automated decision in the Central African Republic; art. 30 only entitles the person, after the fact and on their own initiative, to be told how the machine worked and to argue with it. The Law is therefore the thinnest automated-decision regime yet recorded in the African block, and the only one where the rule is purely reactive.

Force. Art. 58, the Law's final provision, is explicit and self-executing: la présente Loi qui prend effet à compter de la date de sa promulgation, est enregistrée et publiée au Journal Officiel — the Law takes effect from the date of its promulgation, and publication in the Journal Officiel is a separate, non-suspensive formality. That removes the ambiguity that forced a medium confidence on Morocco, Congo-Brazzaville, Gabon and Cameroon, where the final article was a bare publication clause and the publication-to-force rule had to be assumed. Nothing in the Law defers art. 30. Confidence is nevertheless medium, for a different and narrower reason: the promulgation date is not legible in the copy read. The text was read in the scanned copy published by the Autorité de Régulation des Communications Électroniques et des Postes, the Central African regulator, and its title page carries only LOI N° 24.001 PORTANT PROTECTION DES DONNEES A CARACTERE PERSONNEL with no date, while the date block on the signature page — over the signature of President Faustin-Archange Touadéra — falls inside the stamped and handwritten region of the scan and does not survive text extraction. The date recorded here, 25 January 2024, comes from ARCEP's own regulation index, which cites the instrument as Loi 24.001 du 25 janvier 2024, portant protection des données à caractère personnel and lists it immediately beside Loi 24.002 du 21 février 2024, relative à la cybersécurité et à la lutte contre la cybercriminalité. That is the publishing regulator's own citation of the file it hosts, not a news report, and the 24.001 numbering is consistent with a January 2024 first law of the year; but it is one step removed from the face of the enacted text, so the entry is not marked high. The one dated duty in the Law has already run: art. 57 gives the Ministère en charge de l'Economie Numérique, des Postes et Télécommunications a period of twelve (12) months from promulgation to put in place the agency in charge of personal data protection, which expired on 25 January 2025, and provides that until the agency is in place its missions are discharged by the supervising Ministry. Whether the agency has since been constituted was not verified and does not affect the existence of the art. 30 duty, which runs against controllers directly; it affects only which body answers an indirect-access request under art. 32 and which body opens an administrative sanction file. Art. 58 also provides that a decree in Council of Ministers shall fix, as needed, the modalities of application of the Law; art. 30 is not among the provisions that await one and is operative on its own terms. Supersession: none. The Central African Republic had no dedicated data-protection statute before Loi 24.001 — its adjacent instruments are Loi 18.002 du 17 janvier 2018 régissant les communications électroniques, Loi 22.002 du 11 janvier 2022 régissant les transactions électroniques and the companion Loi 24.002 du 21 février 2024 relative à la cybersécurité, none of which carries an automated-decision rule. Nothing on the tracker is superseded by this row. No AI-specific statute is in force and the Law does not define artificial intelligence; Gabon's Loi 025/2023 remains the only Francophone African data-protection statute that does. Text read article by article across the fifty-eight articles of the ARCEP copy, covering the arts. 1 to 5 object and scope, the art. 6 definitions, the arts. 7 to 21 principles and sensitive-data regime, the arts. 22 to 27 transfer chapter, the art. 28 interconnection chapter, the arts. 29 to 36 rights chapter, the arts. 37 to 46 agency and administrative-sanction chapter, the arts. 47 to 56 penal chapter and the arts. 57 and 58 final provisions.

Stated maximum penalty — No penalty in the Law attaches to art. 30 by name, and the route to it is administrative. The agency's administrative sanctions are pronounced on the basis of a report drawn up by its services or by a member it designates; the report is notified to the controller, who may make written and oral observations and be represented or assisted, and the rapporteur may speak but does not take part in the deliberation. Decisions are reasoned, notified, made public, and may be published in journals the agency designates at the sanctioned person's cost, and they may be appealed to the administrative courts. The ceiling is turnover-based and is the operative maximum for an art. 30 refusal: le montant de la sanction pécuniaire ne peut excéder 5% du chiffre d'affaires hors taxes du dernier exercice clos, recovered as a debt due to the State. Every sanction decision must carry a period within which the object of the dispute is to be modified or suppressed, and the agency may go to the competent court by way of référé to obtain, if need be under a penalty payment, any security measure necessary to safeguard the rights and freedoms mentioned in art. 1. The penal chapter, Section 2 of Chapitre VIII, does not reach the access right, but it does reach the neighbouring art. 29 objection right, which is the closest criminal exposure a Central African controller running automated processing faces: two (2) to five (5) years' imprisonment and a fine of one million (1,000,000) to ten million (10,000,000) FCFA for anyone who processes the personal data of a natural person despite that person's request for rectification or objection, where the request is founded on legitimate grounds. The rest of the chapter, for context on the scale: six (6) months to five (5) years and 100,000 to 5,000,000 FCFA for obstructing the agency's missions; six (6) months to two (2) years and 100,000 to 2,000,000 FCFA for negligently processing without the prior formalities required by law; two (2) to five (5) years and 1,000,000 to 10,000,000 FCFA for collecting personal data by fraudulent, unfair or unlawful means; the same range for diverting a file from its initial purpose, notably on the occasion of recording, classification or transmission; six (6) months to two (2) years and 100,000 to 2,000,000 FCFA for retaining data beyond the period declared to the agency, unless the retention is for historical, statistical or scientific purposes on the conditions provided by law; and two (2) to five (5) years and 1,000,000 to 10,000,000 FCFA for bringing to the knowledge of an unqualified third party, without the data subject's authorisation, data whose disclosure harms the person's standing or the intimacy of their private life. The court may order the erasure of all or part of the data processed in the commission of an offence, and the agency's members and agents are empowered to verify that erasure. The Procureur de la République must inform the agency's Director General of prosecutions under the Law, and the trial court may call the Director General or their representative to file or develop observations at the hearing.

In force · 25 Jan 2024 checked 18 Aug 2026 Loi 24.001 art. 30 ↗ medium confidence

Questions & answers

From the data

When does Loi 24.001 art. 30 take effect in Central African Republic?

Loi 24.001 art. 30 is already in force, with obligations live since January 25, 2024. No AI-specific statute in force, and the thinnest automated-decision regime yet recorded in Africa. Loi 24.001 du 25 janvier 2024 portant protection des données à caractère personnel gave the Central African Republic its first dedicated data-protection statute, in force from promulgation under art. 58. It contains no prohibition on automated decisions: nothing in its fifty-eight articles says that a decision producing legal effects may not be taken on the sole foundation of an automated processing, and there is no human-intervention right and no GDPR-style right of objection to automated decisions. The single hook is the third indent of the art. 30 access right, in the Directive 95/46/EC art. 12(a) form: the data subject may obtain the information allowing them to know and to contest the mechanism of the automated processing where a decision is taken on its foundation and produces legal effects in respect of them. It is purely reactive — the art. 35 information duty owed at collection lists purposes, categories, recipients and the rights of objection, access and rectification, but says nothing about automated logic, so a Central African controller need never volunteer that a decision was automated. Art. 6 nevertheless carries the full GDPR art. 4(4) definition of Profilage, down to the prediction of work performance, economic situation, health, preferences, interests, reliability, behaviour, location and movements — and the defined term is then used nowhere else in the Law. Art. 28 subjects the interconnection of files with differing purposes to the agency's prior authorisation and requires that it not entail discrimination. Enforcement is administrative for art. 30, capped at 5% of the prior year's pre-tax turnover; processing in defiance of a legitimate objection under art. 29 carries two to five years' imprisonment and 1,000,000 to 10,000,000 FCFA. Transfers run on a CEMAC and CEEAC perimeter rather than a national adequacy list. Art. 57 gave the Ministry twelve months from promulgation to stand up the supervisory agency, a deadline that expired on 25 January 2025, with the Ministry discharging its missions in the interim.

Who must comply with AI rules in Central African Republic?

Current obligations bind, among others, Responsables de traitement, and through the art. 6 definition also sous-traitants, being any natural or legal person, public or private, any other body or association that processes data on the controller's behalf. The art. 4 scope is territorial-plus-effects and unusually explicit about the public sector: the Law applies to processing carried out in the context of the activities of an establishment of a controller or a processor on the territory of the Central African Republic, whether or not the processing takes place in the Central African Republic; to processing that deploys effects in the Central African Republic even where those effects arose abroad or through a controller established abroad; to processing concerning public security, defence, the investigation and prosecution of criminal offences or state security, subject to derogations fixed by other laws in force; to processing not provided for by a special law; and to processing in the context of court proceedings. Art. 4 excludes purely personal or domestic processing by a natural person, and temporary technical copies made for transmission and network access provision. Art. 31 removes the art. 30 right altogether for processing concerning public security and for the collection of information necessary to establish offences and pursue the consequent proceedings, and lets the controller refuse requests that are manifestly abusive by their number or their repetitive or systematic character, with the burden of proof on the controller in case of contestation. For state-security, defence and public-security processing the access and rectification rights are exercised indirectly through the agency rather than against the controller. No ex ante gate attaches to automated decision-making or to profiling: the only prior-authorisation regimes in the Law are art. 28, which subjects the interconnection of files held by legal persons managing a public service with differing public interests, processing operated by the State for users of remote e-administration services, and interconnection of files with differing purposes, to the prior authorisation of the agency — an interconnection must not entail discrimination or prejudice to rights, freedoms and guarantees — and arts. 24 to 27, which govern transfers. Those transfer articles are the first on the tracker to draw the free-flow perimeter around CEMAC and CEEAC rather than around a national adequacy list: a controller may transfer personal data to a state that is not a member of CEMAC or CEEAC only where that state ensures a sufficient level of protection, the agency must be informed before any such transfer, and art. 27 lets the agency authorise a transfer to a non-adequate non-member state where the controller offers sufficient guarantees, which may result from appropriate contractual clauses. Impact tier: all entities.. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in Central African Republic?

Stated statutory maxima include: Loi 24.001 art. 30 — No penalty in the Law attaches to art. 30 by name, and the route to it is administrative. The agency's administrative sanctions are pronounced on the basis of a report drawn up by its services or by a member it designates; the report is notified to the controller, who may make written and oral observations and be represented or assisted, and the rapporteur may speak but does not take part in the deliberation. Decisions are reasoned, notified, made public, and may be published in journals the agency designates at the sanctioned person's cost, and they may be appealed to the administrative courts. The ceiling is turnover-based and is the operative maximum for an art. 30 refusal: le montant de la sanction pécuniaire ne peut excéder 5% du chiffre d'affaires hors taxes du dernier exercice clos, recovered as a debt due to the State. Every sanction decision must carry a period within which the object of the dispute is to be modified or suppressed, and the agency may go to the competent court by way of référé to obtain, if need be under a penalty payment, any security measure necessary to safeguard the rights and freedoms mentioned in art. 1. The penal chapter, Section 2 of Chapitre VIII, does not reach the access right, but it does reach the neighbouring art. 29 objection right, which is the closest criminal exposure a Central African controller running automated processing faces: two (2) to five (5) years' imprisonment and a fine of one million (1,000,000) to ten million (10,000,000) FCFA for anyone who processes the personal data of a natural person despite that person's request for rectification or objection, where the request is founded on legitimate grounds. The rest of the chapter, for context on the scale: six (6) months to five (5) years and 100,000 to 5,000,000 FCFA for obstructing the agency's missions; six (6) months to two (2) years and 100,000 to 2,000,000 FCFA for negligently processing without the prior formalities required by law; two (2) to five (5) years and 1,000,000 to 10,000,000 FCFA for collecting personal data by fraudulent, unfair or unlawful means; the same range for diverting a file from its initial purpose, notably on the occasion of recording, classification or transmission; six (6) months to two (2) years and 100,000 to 2,000,000 FCFA for retaining data beyond the period declared to the agency, unless the retention is for historical, statistical or scientific purposes on the conditions provided by law; and two (2) to five (5) years and 1,000,000 to 10,000,000 FCFA for bringing to the knowledge of an unqualified third party, without the data subject's authorisation, data whose disclosure harms the person's standing or the intimacy of their private life. The court may order the erasure of all or part of the data processed in the commission of an offence, and the agency's members and agents are empowered to verify that erasure. The Procureur de la République must inform the agency's Director General of prosecutions under the Law, and the trial court may call the Director General or their representative to file or develop observations at the hearing.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.