AI LAW RADAR · Daily Last verified 23 Sep 2026

Topic dossier

AI transparency & disclosure requirements

When people have to be told they are dealing with AI, and content has to be marked as model-generated — chatbot disclosure, content labelling and training-data transparency. 126 obligations across 75 jurisdictions — 100 in force. Next dated deadline: 1 Oct 2026.

Transparency is the most common thread running through AI law. Three duties recur: telling a person when they are interacting with an AI system, marking content that an AI generated, and — increasingly — disclosing what data a model was trained on. The instruments below each carry one or more of these duties, tracked to their primary sources.

The Register

126 obligations · 75 jurisdictions

Albania 2

Albania Binding

Law 124/2024 art. 20 — GDPR art. 22 transposed, in force since 1 February 2025, penalised at 2 billion lekë or 4% of global turnover

Binds Controllers and processors generally, with no size, sector or turnover threshold and no public/private split, subject only to the law-enforcement carve-out. Art. 20 sits in Part II of the Law, which carries the GDPR; Part III (arts. 47-74) carries the Law Enforcement Directive and applies instead to competent authorities processing for the prevention, investigation, detection or prosecution of criminal offences, the execution of criminal penalties, and the protection against threats to public, defence and national security. The same body processing for an ordinary purpose — its own staff records, for instance — answers to art. 20 and not to art. 53. Hiring sifts, credit scoring, insurance pricing and automated benefit or eligibility decisions are the paradigm cases; a decision with a human materially in the loop falls outside art. 20(1), which reaches only decisions based «vetëm», solely, on automated processing, and the Law supplies no gloss on what degree of human involvement defeats that. Art. 21 permits the rights in arts. 13-20 to be restricted by law subject to the essence, necessity and proportionality test.. Art. 20 of Ligj nr. 124/2024 «Për mbrojtjen e të dhënave personale» is Albania's general automated-decision rule and it follows GDPR art. 22 with one drafting change that matters. Art. 20(1): «Subjekti i të dhënave ka të drejtë të mos jetë subjekt i një vendimi që bazohet vetëm në përpunimin automatik të të dhënave, përfshirë profilizimin, i cili shkakton pasoja ligjore ose pasoja të ngjashme të rënda mbi të.» The trigger is a decision resting solely on automated processing, profiling included, which causes legal effects or similar SERIOUS effects — «të rënda», grave or severe — where GDPR art. 22(1) says «similarly significantly affects him or her». The Albanian threshold is drafted in terms of the gravity of the effect rather than its significance, and the comparison to the legal-effects limb is retained. Art. 20(2) supplies the same three exits as GDPR art. 22(2): the decision is necessary for concluding or performing a contract between the data subject and the controller; it is authorised by a law to which the controller is subject and which itself lays down appropriate measures protecting the data subject's rights, freedoms and legitimate interests; or it rests on the consent of the person to whom the data relate. Art. 20(3) governs sensitive data: processing sensitive data for automated decisions requires the data subject's clearly expressed consent, or a legal provision in accordance with art. 9(2)(e), and in either case appropriate protective measures. Art. 20(4) is the safeguards clause and it is where the human-review right lives: in the cases of paras. 2 and 3 the controller applies appropriate measures to protect the data subject's rights, fundamental freedoms and legitimate interests, including the data subject's right to manual intervention by the controller — «ndërhyrje manuale nga ana e kontrolluesit» — to express their point of view and to contest the decision. Profiling is defined at art. 5(19) as any form of automated processing consisting in the use of data to evaluate certain aspects relating to a natural person, in particular to analyse or predict aspects concerning performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. The transparency side is separate and unconditional: arts. 13 and 14 both require the controller to inform the data subject of the existence and the logic of automated decision-making and profiling under art. 20(1) and (3) and, at least in those cases, of the significance and the envisaged consequences of that processing for the data subject.

In force since 1 February 2025. Art. 101(1): «Ky ligj hyn në fuqi 15 ditë pas botimit në Fletoren Zyrtare.» Publication in Fletorja Zyrtare nr. 9 was on 17 January 2025, so the Law entered into force on 1 February 2025. Art. 101(2) defers a closed list of articles — 29(3), 31, 32, 35, 36, 64, 65 and 67(2), (3) and (5) — to two years after publication, that is 17 January 2027; the deferred list covers the data-protection impact assessment at art. 31, prior consultation at art. 32, codes of conduct at art. 35 and monitoring bodies at art. 36, and it does NOT contain art. 20 or art. 53, both of which have applied since 1 February 2025. Art. 99(1) repealed Law no. 9887 of 10 March 2008 on the protection of personal data, as amended, on the same day, so the 2008 regime is superseded rather than supplemented; art. 99(2) keeps the sub-legal acts made under the 2008 Law alive until replaced, so far as they do not conflict. Art. 98 converts every reference to the 2008 Law in other legislation into a reference to this Law. Art. 100 is unusual and worth reading before relying on this row long term: on the date of Albania's accession to the European Union all provisions of this Law are repealed except those of Parts III and IV, so art. 20 is drafted to fall away in favour of the GDPR itself while art. 53 is drafted to survive. Supersession check, 27 August 2026: a query of the QBZ Alfresco repository for acts of type «ligj» whose text names Law 124/2024 returns the original, the corrigendum reprint and no amending act, and the QBZ act record for the Law carries no amending gazette reference, so art. 20 stands as enacted. Albania has no AI-specific statute in force and no published bill. A draft National AI Strategy 2025-2030 went to public consultation in 2025 and has not been adopted; the Digital Agenda 2022-2026 and a Council of Ministers decision on methodology and technical standards for the use of AI in public administration are policy instruments addressed to state bodies, not obligations on controllers, and formal drafting of an EU AI Act-aligned law is expected only on the accession timetable. Nothing is tracked as an obligation on that basis. The text relied on is the promulgated Law as published by the Qendra e Botimeve Zyrtare in Fletorja Zyrtare nr. 9, dated 17 January 2025, read end to end from the QBZ repository's own PDF at https://qbz.gov.al/alfresco/api/-default-/public/alfresco/versions/1/nodes/921d3810-ab2a-4e45-bdca-bef3a84b2721/content — 327,906 bytes, closing «Miratuar në datën 19.12.2024. Shpallur me dekretin nr. 5, datë 15.1.2025, të Presidentit të Republikës së Shqipërisë, Bajram Begaj.» The ELI cited as the source is the official QBZ permalink for the same act and is the human-facing citation; qbz.gov.al is an Angular single-page application that answers a 4,274-byte shell to every path, so a fetch of the ELI proves nothing — that is the shell, not rot, the same pattern as Serbia's pravno-informacioni-sistem.rs and Senegal's cdp.sn. QBZ also carries a corrected reprint, ligj-2024-12-19-124-korrigjuar.pdf, published 24 June 2025 under the consolidated ELI http://qbz.gov.al/eli/ligj/2024/12/19/124/cons/202506-24; it was downloaded and diffed against the original, and the text of arts. 20 and 53 is byte-identical in both, so the corrigendum does not touch either rule.

Stated maximum penalty — Up to 2,000,000,000 lekë, or in the case of a commercial company up to 4% of total global annual turnover for the preceding financial year, whichever is higher. Art. 94(2)(b) names the breach expressly and puts it in the Law's top band: administrative offences punished at that level include «shkeljet e të drejtave të subjekteve të të dhënave sipas neneve 12-20 të këtij ligji», which carries art. 20 on its face. The lower band at art. 94(1) is up to 1,000,000,000 lekë or 2% of global turnover, whichever is higher, and covers controller and processor duties under Chapter III of Part II. Art. 93(2) sets the GDPR art. 83(2) circumstances the Commissioner must weigh and allows the fine to be accompanied by or replaced with the corrective measures of art. 83(2)(a)-(f); art. 93(3) caps concurrent breaches arising from the same or linked processing operations at the amount set for the gravest of them. Art. 94(4) requires the Commissioner to issue an instruction, based on European Data Protection Board guidelines, on whether and to what extent these sanctions are imposed. Art. 95 gives the controller or processor an appeal against the fining decision. Supervision and enforcement sit with the Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale. Impact tier: all entities.

In force · 1 Feb 2025 checked 10 Sep 2026 Law 124/2024 art. 20 ↗ high confidence
Albania Binding

Law 124/2024 art. 53 — solely automated decisions banned for police, prosecutors and security bodies, plus an exceptionless ban on discriminatory profiling

Binds Competent authorities only, and the Law defines the trigger by purpose rather than by institution. Part III of the Law (arts. 47-74) governs the processing of personal data by competent authorities for public or national security and for the prevention, investigation, detection or prosecution of criminal offences and the execution of criminal penalties, and art. 53 sits inside it. The division from art. 20 is by purpose: the same police force processing its own payroll answers to art. 20. Private controllers are outside art. 53 entirely, with one edge — a private body exercising delegated public powers for one of those purposes is a competent authority for these provisions. Art. 61 separately requires the controller's record of processing to carry information on the use of profiling where profiling is used, which gives the supervisor a documentary route into art. 53. Art. 100(1) repeals the whole Law on the date of Albania's accession to the European Union with the express exception of Parts III and IV, so art. 53 is one of the provisions drafted to survive accession; art. 100(2) keeps those provisions of the rest of the Law that Part III cross-refers to alive for competent-authority processing.. Art. 53 is the law-enforcement counterpart of art. 20 and, following art. 11 of Directive (EU) 2016/680, it is drafted as a prohibition on the authority rather than as a right the individual must invoke. Art. 53(1): «Ndalohet marrja e vendimeve të bazuara vetëm te përpunimi automatik, përfshirë profilizimin, të cilat sjellin pasoja ligjore negative për subjektin e të dhënave ose mund të ndikojnë ndjeshëm te subjekti i të dhënave, me përjashtim të rastit kur parashikohen shprehimisht me ligj, i cili parashikon masa të përshtatshme mbrojtëse për të drejtat e liritë themelore të subjektit të të dhënave dhe të drejtën që t'i sigurohet ndërhyrje manuale nga ana e kontrolluesit.» Three drafting choices matter. The effects limb is narrowed by «negative» — the legal consequences must be adverse — but widened by «mund të ndikojnë», so the prohibition bites on the capacity to affect the person significantly rather than on realised effect. There is no consent exit and no contract exit: the single way out is an express statutory basis that itself prescribes appropriate safeguards, and the floor for those safeguards is named in the article — the right to manual intervention by the controller. And unlike art. 20(4), the person is given no right here to express a view or to contest the decision; the enabling statute must supply whatever more it supplies. Art. 53(2) does two things: such decisions may not rest on sensitive data unless appropriate measures protecting the data subject's rights, fundamental freedoms and legitimate interests are in place, and — as a separate sentence — decisions under para. 1 that result in discrimination against natural persons on the basis of sensitive data are prohibited outright. Art. 53(3) then goes wider than any decision: «Profilizimi që sjell si pasojë diskriminimin e personave për shkak të të dhënave sensitive është i ndaluar.» That is a flat, exceptionless ban on profiling which results in discrimination on sensitive-data grounds — tied to no decision, to no effects threshold and to no «solely automated» qualifier, so it reaches profiling that merely feeds a human decision, and it admits no statutory override. It is the near-exact twin of art. 39(3) of Serbia's Personal Data Law, and the two are the only provisions of their kind in this dataset. Art. 52(2) makes the specific limits of art. 53(2) a condition on any processing of sensitive data by a competent authority.

In force since 1 February 2025 on the same art. 101(1) timetable as art. 20; art. 53 is not in the art. 101(2) list of articles deferred to 17 January 2027. Art. 101(1): «Ky ligj hyn në fuqi 15 ditë pas botimit në Fletoren Zyrtare.» Publication in Fletorja Zyrtare nr. 9 was on 17 January 2025, so the Law entered into force on 1 February 2025. Art. 101(2) defers a closed list of articles — 29(3), 31, 32, 35, 36, 64, 65 and 67(2), (3) and (5) — to two years after publication, that is 17 January 2027; the deferred list covers the data-protection impact assessment at art. 31, prior consultation at art. 32, codes of conduct at art. 35 and monitoring bodies at art. 36, and it does NOT contain art. 20 or art. 53, both of which have applied since 1 February 2025. Art. 99(1) repealed Law no. 9887 of 10 March 2008 on the protection of personal data, as amended, on the same day, so the 2008 regime is superseded rather than supplemented; art. 99(2) keeps the sub-legal acts made under the 2008 Law alive until replaced, so far as they do not conflict. Art. 98 converts every reference to the 2008 Law in other legislation into a reference to this Law. Art. 100 is unusual and worth reading before relying on this row long term: on the date of Albania's accession to the European Union all provisions of this Law are repealed except those of Parts III and IV, so art. 20 is drafted to fall away in favour of the GDPR itself while art. 53 is drafted to survive. Art. 53 is new law rather than a re-enactment: the repealed Law no. 9887/2008 had a single automated-decision provision and no prohibition addressed to law-enforcement bodies, and nothing resembling the art. 53(3) discriminatory-profiling ban. Supersession check, 27 August 2026: no amending act to Law 124/2024 is recorded in the QBZ repository and the corrigendum reprint of 24 June 2025 leaves art. 53 byte-identical. Albania has no AI-specific statute in force and no published bill. A draft National AI Strategy 2025-2030 went to public consultation in 2025 and has not been adopted; the Digital Agenda 2022-2026 and a Council of Ministers decision on methodology and technical standards for the use of AI in public administration are policy instruments addressed to state bodies, not obligations on controllers, and formal drafting of an EU AI Act-aligned law is expected only on the accession timetable. Nothing is tracked as an obligation on that basis. The text relied on is the promulgated Law as published by the Qendra e Botimeve Zyrtare in Fletorja Zyrtare nr. 9, dated 17 January 2025, read end to end from the QBZ repository's own PDF at https://qbz.gov.al/alfresco/api/-default-/public/alfresco/versions/1/nodes/921d3810-ab2a-4e45-bdca-bef3a84b2721/content — 327,906 bytes, closing «Miratuar në datën 19.12.2024. Shpallur me dekretin nr. 5, datë 15.1.2025, të Presidentit të Republikës së Shqipërisë, Bajram Begaj.» The ELI cited as the source is the official QBZ permalink for the same act and is the human-facing citation; qbz.gov.al is an Angular single-page application that answers a 4,274-byte shell to every path, so a fetch of the ELI proves nothing — that is the shell, not rot, the same pattern as Serbia's pravno-informacioni-sistem.rs and Senegal's cdp.sn. QBZ also carries a corrected reprint, ligj-2024-12-19-124-korrigjuar.pdf, published 24 June 2025 under the consolidated ELI http://qbz.gov.al/eli/ligj/2024/12/19/124/cons/202506-24; it was downloaded and diffed against the original, and the text of arts. 20 and 53 is byte-identical in both, so the corrigendum does not touch either rule.

Stated maximum penalty — No fine ceiling is stated for this article, and that gap is on the face of the Law rather than a gap in this research. Art. 92 states generally that breaches of the Law by controllers or processors are punished with administrative sanctions in accordance with the following articles of the chapter, and art. 93(1) then directs the Commissioner to impose sanctions «për shkeljet e këtij ligji, sipas pikave 1, 2 dhe 3, të nenit 94» — that is, according to the enumeration in art. 94. That enumeration is drawn entirely from Part II and from the Commissioner's own orders: art. 94(1) covers arts. 8(6) and 11 and Chapter III of Part II, certification bodies under arts. 37-38 and monitoring bodies under art. 36(3); art. 94(2) covers the principles at arts. 6-9, data-subject rights at arts. 12-20, third-country transfers at arts. 39-42 and the duties at arts. 43-46; art. 94(3) covers non-cooperation with the Commissioner and breach of an order, temporary or definitive processing limitation or suspension of data flows issued under art. 83(2)(b), at up to 2,000,000,000 lekë or 4% of global turnover. None of those items reaches Part III, so a breach of art. 53 attracts no article-specific fine tier; what remains against a competent authority is the Commissioner's corrective powers, the art. 83(2)(b) orders whose breach IS fineable at the top band under art. 94(3), and the individual's remedies under Part V, including the art. 90 right to have the Commissioner review the lawfulness of a competent authority's response and the processing behind it, and the art. 91 preliminary limitation order. The same structural gap exists in Serbia, where art. 95(1)(19) is written around a decision producing legal consequences and does not obviously reach the standalone art. 39(3) profiling ban. Impact tier: public sector.

In force · 1 Feb 2025 checked 10 Sep 2026 Law 124/2024 art. 53 ↗ high confidence

Angola 1

Angola Binding

Lei 22/11 art. 29.º — decisões individuais automatizadas: the only prohibition on the tracker that the data-protection authority can licence

Binds Responsáveis pelo tratamento — controllers — with subcontratados (processors) bound through the art. 23 processor regime. Art. 3(1) makes the scope explicitly tri-sectoral: the Law catches processing carried out by any person or entity of the public, private or cooperative sector. Art. 3(2) sets the territorial reach at four limbs: processing by a controller headquartered in the Republic of Angola; processing in the context of the activities of a controller established in Angola even where that controller is not headquartered in Angolan territory; processing outside Angola where Angolan law applies by virtue of public or private international law; and processing by a controller not established in Angola that resorts, for the processing, to means situated in Angolan territory. Art. 3(3) makes that last limb wide — a controller is deemed to resort to means in Angolan territory where the processing operations are carried out with, or the data are hosted on, means situated in Angola, the mere use of such means for the collection, recording or transit of personal data in the territory being enough. Art. 3(4) then requires any controller caught by the means limb to designate, by communication to the Agência de Protecção de Dados, a representative established in Angola who substitutes for it in all its rights and obligations, without prejudice to the controller's own liability — so a foreign scoring or profiling operator hosting on Angolan infrastructure is both bound by art. 29 and required to stand up a local representative. Art. 4 excludes processing by a natural person in the exercise of exclusively personal or domestic activities, and, without prejudice to special legislation, processing under the legal rules on state secrecy and security and on judicial secrecy, and processing of the personal data of members of the Angolan Armed Forces by military units, establishments and organs. Impact tier: all entities — art. 29 applies to every controller in every sector, with no employee-count, turnover or high-risk-system threshold, and its named evaluation grounds (professional capacity, credit, trustworthiness, conduct) put hiring and credit-scoring deployers squarely in scope.. Article 29.º of Lei n.º 22/11, de 17 de Junho — Lei da Protecção de Dados Pessoais is Angola's automated-decision provision, and it is Portuguese Lei 67/98 lineage rather than the Directive 95/46/EC transposition template that the Francophone African rows carry or the GDPR template that Cameroon carries. Under art. 29(1), qualquer pessoa tem o direito de não ficar sujeita a uma decisão que produza efeitos na sua esfera jurídica ou que a afecte de modo significativo, tomada exclusivamente com base num tratamento automatizado de dados destinado a avaliar determinados aspectos da sua personalidade, designadamente, a sua capacidade profissional, o seu crédito, a confiança de que é merecedora ou o seu comportamento — any person has the right not to be subject to a decision producing effects in their legal sphere or significantly affecting them, taken exclusively on the basis of automated data processing intended to evaluate certain aspects of their personality, namely their professional capacity, their credit, their trustworthiness or their conduct. The trigger is the classical one: solely automated, evaluative, and gated by a legal-effects-or-significant-effect threshold, so it is narrower than Equatorial Guinea's art. 13(b) and narrower than Cameroon's art. 44, neither of which requires a threshold. What makes Angola structurally different is the second route out. Art. 29(2) carries the familiar contract exception — a person may be subject to such a decision where it occurs in the conclusion or performance of a contract and either their request to conclude or perform was satisfied, or adequate measures exist guaranteeing the defence of their legitimate interests, designadamente o seu direito de representação e expressão, namely their right of representation and expression. Art. 29(3) then adds the route that, on the tracker, only one other jurisdiction carries: pode ainda ser permitida a tomada de uma decisão, nos termos do n.º 1 deste artigo, quando a Agência de Protecção de Dados o autorize, definindo medidas de garantia da defesa dos interesses legítimos do titular dos dados — the decision may further be permitted where the Agência de Protecção de Dados authorises it, itself defining the measures that guarantee the defence of the data subject's legitimate interests. Most prohibitions on the tracker admit only exceptions fixed in the statute (consent, contract, or a law laying down safeguards); Angola and Cabo Verde are the two where the supervisory authority can licence an otherwise-forbidden automated decision case by case and write the safeguards for it. The clause is a shared inheritance from art. 13(3) of Portugal's Lei 67/98 rather than an Angolan invention — Cabo Verde carries it as art. 23(3) of the text republished by Lei 121/IX/2021, naming the Comissão Nacional de Proteção de Dados — and São Tomé e Príncipe, from the same lineage, dropped it. The safeguard package is also thinner than the GDPR's. Art. 29(2) gives a right of representation and expression but no right to obtain human intervention in the decision and no right to contest it after the fact, and the Law carries no logic-disclosure duty anywhere: the art. 25 information list runs through purposes, recipients, whether the answer is obligatory, the existence and conditions of access, rectification, updating, elimination and opposition, and the consequences of collection without consent, with no item on the existence of automated decision-making and no item on the logic involved; and the art. 26 access right reaches confirmation, purposes, categories, recipients, the specific data and available information on their origin, but not the logic of any automated processing. So a data subject in Angola may never learn that a machine decided, and if the Agência authorises the decision under art. 29(3) the safeguards they get are whatever that authorisation says. Impact tier: all entities.

Force, and the date is exact. Art. 67.º (Entrada em vigor) provides A presente lei entra em vigor à data da sua publicação — the Law enters into force on the date of its publication — and it was published in the Diário da República, I Série, n.º 114, de 17 de Junho de 2011, at pp. 3185-3202. The instrument was approved by the Assembleia Nacional in Luanda on 24 May 2011 and promulgated by President José Eduardo dos Santos on 8 June 2011; art. 64.º revokes all legislation contrary to it, and art. 63.º gave controllers of pre-existing processing two years from entry into force to notify the Agência de Protecção de Dados. Art. 65.º required the Executive to regulate the Law within 120 days of publication. Supersession: none in force. A revision is live but has not been enacted — the Agência de Protecção de Dados ran a public consultation titled Projecto de Revisão da Lei n.º 22/11, de 17 de Junho - Lei de Protecção de Dados Pessoais on the Government's consultapublica.gov.ao portal from 17 March 2025 to 17 April 2025, and that consultation is recorded as Encerrada (closed). No successor law has appeared in the Diário da República, so Lei 22/11 art. 29 is the operative rule today and the draft is tracked as a watch item, not as a dateset entry; it will only be published as an obligation once the successor is gazetted with an entry-into-force clause. No AI-specific statute is in force in Angola and the Law does not define artificial intelligence — Gabon's Loi 025/2023 remains the only data-protection statute in the African block that does. Text read in full in the official scanned copy of the Diário da República issue published by the Agência de Protecção de Dados itself, the supervisory authority created by the Law, which satisfies Primary Source First on the same basis as the Nigeria, Burkina Faso, Gabon, Chad and Equatorial Guinea copies. The copy is an 18-page image-only scan (RC4-40 encrypted, DCTDecode page streams) with no text layer and was read as page images. Coverage of the read: art. 3 scope and art. 4 exclusions in full; art. 5 definitions; the whole of Secção IV Direitos dos Titulares dos Dados, arts. 25 information, 26 access, 27 opposition, 28 rectification-updating-elimination and 29 automated individual decisions, verbatim; arts. 17-19 and 22-24 on video surveillance, direct marketing, communication of data, processors and interconnection; arts. 44-46 on the Agência; and the whole of Capítulo IV, arts. 47-62 — administrative and judicial protection, civil liability, contraventions and fines, and the criminal section — plus Capítulo V arts. 63-67. Confidence high: the article was read verbatim in the gazette text, the entry-into-force clause is explicit, and the enforcement route was traced through the sanction articles rather than assumed. AIL-300 computation check (2026-08-31): out of scope for the publication-relative sweep. Art. 67.º sets no vacatio at all — «a presente lei entra em vigor à data da sua publicação» — so there is no plazo to compute and no rule of Angolan law on the reckoning of statutory terms can move the date off the publication date of 17 June 2011. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. Angola deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 11 May 2020, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. Art. 14(5) of the Convention states the same bar as art. 29.º and admits no exception of any kind, where art. 29.º admits two. Art. 29.º(2) carries the contract exception, available where the decision occurs in the conclusion or performance of a contract and either the person's request to conclude or perform was satisfied or adequate measures guarantee the defence of their legitimate interests. Art. 29.º(3) carries the rarer one: the decision may also be permitted where the Agência de Protecção de Dados authorises it and defines safeguard measures. A regulator-authorisation route of that kind has no counterpart in the Convention at all — art. 12(2)(h) gives the national authority a sanctioning power, not a dispensing power over art. 14(5). The national statute is carried here as the operative rule, because it is the instrument that has a supervisory authority behind it and a penalty attached to it, and the Convention runs behind it as a stricter parallel rule. This is recorded as a divergence rather than resolved: neither instrument repeals or qualifies the other, Angola has not legislated the Convention into domestic law by a separate instrument, and the domestic reception question — whether art. 14(5) is directly effective in Angola, as arts. 18 and 144 of the Mozambican and Namibian constitutions respectively make it there — has not been separately verified for Angola and is not asserted here. A controller relying on an exception the statute grants therefore stands on solid statutory ground and unresolved treaty ground.

Stated maximum penalty — No fine attaches to art. 29 itself — the enforcement route is indirect, and this is the entry's most consequential finding. Art. 51.º(1) enumerates the contraventions exhaustively by article number: alínea a) sets USD 75,000.00 to USD 150,000.00 for breach of the obligations in arts. 14.º, 15.º, 16.º, 17.º, 20.º, 30.º, 31.º and 32.º, for negligent failure to notify the Agência or notification with false information, and for failing to comply with an Agência order to cease access to open transmission networks; alínea b) sets USD 65,000.00 to USD 130,000.00 for breach of the principles in arts. 6.º to 11.º, for processing without the data subject's consent where no dispensation applies, and for breach of arts. 18.º, 19.º and 21.º to 24.º. Art. 29.º appears in neither list. Art. 51.º(2) trebles the respective limits for legal persons, companies and de facto associations — so the ceiling elsewhere in the Law reaches USD 450,000.00 — and art. 51.º(3) makes negligence and attempt punishable; art. 53.º gives the Agência de Protecção de Dados the power to apply the fines, its homologated deliberation constituting an enforceable title if not challenged in the legal period. What a data subject actually has against an unlawful automated decision is three-fold. First, art. 47.º: without prejudice to the right to complain to the Agência, any person may use administrative or judicial means to secure compliance with the data-protection provisions, and decisions of the Agência are themselves subject to contentious administrative appeal. Second, art. 48.º: anyone who has suffered moral or material harm through the undue use of personal data has the right to demand reparation by judicial route, with the judge grading the injury objectively. Third, and the sharpest, art. 58.º (Desobediência qualificada): whoever, having been notified to that effect, fails to interrupt, cease or block the processing of personal data is punished with imprisonment of up to 3 years or a corresponding fine — so once the Agência orders an art. 29 profiling operation stopped, defying the order is a crime. Art. 61.º allows accessory penalties alongside applied fines, including temporary or definitive prohibition of the processing, blocking, erasure or total or partial destruction of the data, publication of the conviction at the convicted party's expense, and public warning or censure of the controller. Separately, art. 55.º(1)(a) makes it a crime punishable with 3 to 18 months' imprisonment or a corresponding fine to omit the request for authorisation to the Agência de Protecção de Dados — a limb that on its face reaches a controller who takes an art. 29(1) decision on the art. 29(3) footing without ever having sought the Agência's authorisation, though the Law does not spell that application out and it has not been tested.

In force · 17 Jun 2011 checked 13 Sep 2026 Lei 22/11 art. 29.º ↗ high confidence

Australia 1

AU Binding

Australia Automated Decision-Making Transparency (Privacy Act APP 1.7–1.9)

Binds All Australian Privacy Principle (APP) entities using automated decision-making affecting individual rights or interests. All APP entities using personal information in ADM that could significantly affect individual rights must disclose this in their privacy policies.

OAIC published the ADM Transparency Issues Paper May 2026; consultation closed 15 June 2026 (https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making). OAIC states it intends to release the guidance by September 2026, ahead of the 10 December 2026 commencement of the ADM obligation. No new OAIC guidance issued as of 2026-08-11.

Stated maximum penalty — Civil penalties up to AUD $50M (OAIC enforcement)

Applies 10 Dec 2026 checked 22 Sep 2026 Privacy & Other Legislation Amendment Act 2024 (Cth) ↗ high confidence

Azerbaijan 1

Azerbaijan Binding

Law on Personal Data art. 7.3 — an objection right against decisions taken by information technology, whose remedy is re-processing by another method or a full stop

Binds Owners («mülkiyyətçi») and operators («operator»), the Law's two controller-analogues — art. 2.1 defines the owner as the person who owns the information system and determines the purpose and scope of collection and processing, and the operator as the person who carries out collection and processing under a contract with or on the instruction of the owner. Art. 10.2 applies the operator's duties to an owner that performs them itself. The Law's preamble extends it to state and local self-government bodies and to legal and natural persons alike, so public-sector deployers are inside it on the same terms as private ones. There is no size threshold, no sectoral limit and no turnover test anywhere in art. 7. The reach is territorial and system-based rather than targeting-based: the Law regulates collection, processing and protection of personal data and the formation of the personal-data segment of the national information space, and art. 15 requires state registration of personal-data information systems, which is the hook that brings a system within the regime. Art. 3.2 carves out processing outside the Law's scope, and art. 10.5 requires operators to facilitate intelligence, counter-intelligence and operative-search measures and to keep the methods used confidential.. Art. 7.3 of the Law of the Republic of Azerbaijan on Personal Data (No. 998-IIIQ of 11 May 2010) is an automated-decision rule that never uses the word automated, which is why keyword sweeps miss it: the operative term is «informasiya texnologiyaları vasitəsilə» — by means of information technologies. The sentence reads «İnformasiya texnologiyaları vasitəsilə fərdi məlumatların toplanılması və işlənilməsi nəticəsində qəbul olunan qərar subyektin mənafeyini pozduğu halda, qanunvericiliklə müəyyən olunmuş qaydada məcburi xarakter daşıdığı hallar istisna olmaqla, subyektin bu məlumatların göstərilən üsulla toplanılmasına və işlənilməsinə etiraz etmək hüququ vardır» — where a decision taken as a result of the collection and processing of personal data by means of information technologies infringes the subject's interests, the subject has the right to object to the collection and processing of that data by that method, save where the processing is mandatory in the manner established by legislation. The whole of the Law was read end to end in its consolidated text on e-qanun.az, the official corpus of the Ministry of Justice; the words «avtomat» and «profil» appear nowhere in its nineteen articles. Four features set it apart from the GDPR art. 22 family. First, there is no «solely» qualifier and no profiling concept: the trigger is the method of processing, so a decision produced with information technology in the loop and a human signing it off is caught, where GDPR art. 22 and the Kazakh, Uzbek and Russian analogues would let it through. Second, the effects threshold is «subyektin mənafeyini pozduğu halda» — infringes the subject's interests. That is lower and wider than legal effects or similarly significant effects, and like the Turkish art. 11(g) it is adverse-only, so a favourable machine-made decision produces no right. Third, the remedy is not human intervention. Art. 7.3 second sentence obliges the owner or operator, on receiving the objection, either to obtain the subject's consent to process the data «digər üsulla» — by another method — or to stop the processing «təxirə salmadan», without delay. The subject cannot demand that a person re-take the decision, but can force the processing off the information-technology track altogether, which no GDPR-family rule offers. Fourth, the exception architecture is a single item: processing made mandatory by legislation. There is no consent limb and no contract limb, so a controller cannot buy its way out with a consent click. There is no explanation or logic-disclosure limb tied to automation. Art. 7.1.2 gives a general right to demand the legal justification for collection, processing and third-party disclosure and to be told what legal consequences these will have for the subject, and art. 11.2 lists what must be told at collection — identity, purpose and its legal basis, the protection level of the information system, whether that system holds a conformity certificate and has passed state expert examination, the circle of intended users, and the subject's rights under the Law — but neither list carries an automated-decision or logic item. Art. 7.5 adds real procedural friction: the art. 7.1 to 7.3 rights are exercised only by a written paper application presented with an identity document, or by an electronic request bearing an enhanced electronic signature. Art. 7.2 sits alongside it as a general objection right with the same stop-immediately consequence and no requirement to give reasons, so a subject who cannot show that a decision infringed their interests can often reach the same outcome by the more general route.

In force, and art. 7.3 is original 2010 text: the consolidated version on e-qanun.az marks amended provisions with bracketed source-document numbers — art. 8.2 carries [3] and art. 8.6 carries [4] — and art. 7 carries none across all five of its paragraphs, so none of the six amending laws listed in the source-document schedule (20 June 2014, 3 April 2018, 8 July 2022 and later) touched it. The commencement date is derived rather than stated, which is why confidence on the date alone is medium. The Law has no entry-into-force article: art. 19 is the last article and deals with liability, after which the text runs straight to the President's signature of 11 May 2010. It was published in «Azərbaycan» gazette on 6 June 2010, no. 121, and in the Collection of Legislative Acts of 30 June 2010, no. 06, art. 480, which under the ordinary rule puts it in force on publication. The e-qanun record separately carries a registration date of 1 July 2011 in its «registerDate» field and leaves «effectDate» null; that field tracks the state registry entry, not commencement, but the discrepancy is recorded here rather than resolved silently. Nothing turns on it for a reader today — the rule has been binding for well over a decade on either reading. Azerbaijan has no AI-specific statute and no GDPR-style replacement law in force.

Stated maximum penalty — 300 to 500 manat, roughly USD 175 to 295 — the lowest ceiling in the atlas. Art. 19 of the Law itself sets no figure, providing only that those guilty of violating it bear liability in the manner prescribed by the legislation of Azerbaijan. The quantum sits in art. 375 of the Code of Administrative Offences (Law No. 96-VQ of 29 December 2015), «violation of the legislation on personal data». Art. 375.0.2 is the limb that reaches art. 7.3: it penalises an owner or operator for failing to ensure the protection of personal data, for failing to destroy personal data in the cases and within the periods the Law requires, and — the operative words here — «fərdi məlumatların toplanılmasının, işlənilməsinin və ya verilməsinin dayandırılmamasına görə», for failing to stop the collection, processing or transfer of personal data. That is exactly the duty art. 7.3 imposes once an objection is received, so ignoring an objection is a discrete administrative offence rather than a matter for damages alone. Art. 375.0.1 covers collecting or processing in an information system that has not passed the state registration the Law requires. Unusually, art. 375.0 draws no distinction between natural persons, officials and legal persons and applies no turnover multiplier: the band is flat at 300 to 500 manat however large the offender. The separate civil route is art. 7.4 and art. 10.1 of the Law — complaint to the relevant executive authority or to a court, with material and moral damage assessed by the court and paid by the owner.

In force · 6 Jun 2010 checked 20 Sep 2026 Personal Data Law art. 7.3 ↗ medium confidence

Bosnia and Herzegovina 1

Bosnia and Herzegovina Binding

ZZLP arts. 24 and 67 — GDPR art. 22 and LED art. 11 in one state-level act since 4 October 2025, with «participation of a natural person in the decision» in place of human intervention

Binds Art. 24 binds data controllers and processors — natural persons, legal persons and public bodies alike — under DIO DRUGI. Art. 5 applies the Act to wholly automated processing and to non-automated processing of personal data forming or intended to form part of a filing system, and excludes purely personal or household activity. Art. 6 is GDPR art. 3 in substance: establishment, seat, domicile or residence in Bosnia and Herzegovina regardless of where processing happens; and, for controllers or processors without one, processing of data subjects in BiH where the activity is connected to offering goods or services to them or to monitoring their behaviour as it occurs within BiH. Art. 67 binds «nadležni organ» only — the bodies competent for the prevention, investigation and detection of criminal offences, prosecution of offenders or execution of criminal sanctions, including protection against and prevention of threats to public security, and legal persons where a law empowers them to perform those tasks — when processing for those purposes, which art. 5(3) and art. 6(4) route to DIO TREĆI instead of DIO DRUGI. Impact tier: all entities.. Arts. 24 and 67 of the Zakon o zaštiti ličnih podataka («Službeni glasnik BiH» broj 12/25) are Bosnia and Herzegovina's automated-decision rules, and they have applied since 4 October 2025. The Act is a state-level statute adopted under art. IV.4.a) of the Constitution — passed by the House of Representatives at its 16th emergency session on 23 January 2025 and signed on 30 January 2025 — and it carries the GDPR and the Law Enforcement Directive in one instrument, split by Part, on the Albanian rather than the Macedonian or Montenegrin pattern. Art. 24, in DIO DRUGI (processing by a natural person, legal person or public body as controller), is GDPR art. 22: «Nosilac podataka ima pravo da se na njega ne primjenjuje odluka zasnovana isključivo na automatiziranoj obradi, uključujući i profiliranje, koja proizvodi pravni učinak koji se na njega odnosi ili na sličan način značajno na njega utiče.» The same solely-automated trigger, the same legal-effects-or-similarly-significantly-affects threshold, and the same three exits at art. 24(2) — necessary for concluding or performing a contract between the data subject and the controller, permitted by a law applying to the controller that itself lays down suitable safeguards, or based on the data subject's explicit consent. Art. 24(4) bars such decisions from resting on special categories under art. 11(1) unless art. 11(2)(a) or (g) applies, landing exactly where GDPR art. 22(4) does. «Izrada profila» is defined in GDPR terms at art. 4. The one drafting divergence is in the safeguards, and it runs through the whole Act: art. 24(3) requires, for the contract and consent exits, «najmanje prava na učešće fizičkog lica u donošenju odluke, prava izražavanja vlastitog stava i prava na osporavanje odluke» — at least the right to the PARTICIPATION of a natural person IN THE MAKING of the decision, rather than the GDPR's right to obtain human intervention on the part of the controller. The right to express a view and the right to contest are unchanged, but the first limb is drafted as something built into the decision procedure rather than something the data subject asks for afterwards. Art. 67, in DIO TREĆI (processing by a competent authority for criminal-law purposes), is the LED art. 11 counterpart and is a flat prohibition: a competent authority may not take a decision based solely on automated processing, profiling included, that produces negative legal effects for or significantly affects the data subject, unless authorised by a special law laying down safeguards — and the only safeguard the statute names there is, again, «prava na učešće fizičkog lica u donošenju odluke». There is no contract exit and no consent exit on the police side. Art. 67(2) bars reliance on special categories, and art. 67(3) prohibits outright any profiling that leads to discrimination on special-category grounds — untied to any decision or effects threshold and admitting no exception, the twin of Serbia's art. 39(3) and Albania's art. 53(3). Transparency is proactive and triple-anchored: arts. 15, 16 and 17 each require disclosure of «postojanju automatiziranog donošenja odluka, uključujući i izradu profila iz člana 24. st. (1) i (4)» with, in arts. 16 and 17, reasonable information about the criterion used and, in art. 15, the manner of operation, plus in all three the significance and envisaged consequences; art. 37 makes systematic and extensive automated evaluation a mandatory impact-assessment trigger. Supersession is the other half of the story: until 4 October 2025 the rule in force was art. 29 of the 2006 Act («Sl. glasnik BiH» br. 49/06, 76/11, 89/11), a Directive 95/46 art. 15 prohibition of the same shape as Montenegro's art. 15a — no profiling concept, contract-or-law exits only, no consent. Art. 119(1) of the new Act repealed it on the day the new Act became applicable.

Applicable since 4 October 2025. The Act was published in «Službeni glasnik BiH» broj 12/25 on 28 February 2025; art. 120 sets entry into force on the eighth day after publication, i.e. 8 March 2025, and application «nakon isteka 210 dana od dana stupanja na snagu». The Agency's own Central Register notice states the start of application as «dana 04.10.2025», and its transitional notice on the same Act says only «u oktobru tekuće godine»; a strict day-count from 9 March would put the 210th day on 4 October and application from 5 October, and one Bosnian legal publisher reports 5 October. The regulator's stated date is taken as authoritative here, with the one-day divergence recorded rather than smoothed over; nothing in the atlas turns on it. Two follow-on dates are live. Art. 116(1) and (2) require other laws touching personal-data processing, and processing operations already under way, to be aligned within two years of entry into force — 8 March 2027. Art. 117 required all subordinate acts under the Act within 210 days of entry into force. Art. 119 repealed the 2006 Act («Sl. glasnik BiH» br. 49/06, 76/11, 89/11) and its implementing rulebooks on the day application began; the atlas carried no BiH row under the old Act, so this is an addition rather than a supersession edit, but art. 29 of the 2006 Act — the pre-GDPR prohibition it replaced — is recorded in the entry for the comparison it enables. The Act is state-level and applies across both Entities and Brčko District; there is no separate Entity-level automated-decision rule to track.

Stated maximum penalty — 20,000 KM to 40,000,000 KM, or for an undertaking up to 4% of total worldwide annual turnover for the preceding financial year, whichever is higher — art. 113(5)(b) puts breach of the data-subject rights in arts. 14 to 24, art. 24 among them, in the top band. Two things are worth naming. First, the KM figures are not the GDPR's euro ceilings converted at the currency-board peg of 1 EUR = 1.95583 KM but doubled: 40,000,000 KM is about €20.45m against GDPR art. 83(5)'s €20m, and the lower band's 20,000,000 KM at art. 113(4) is about €10.23m against €10m. Second, and unlike the GDPR, the bands have a floor — 20,000 KM, about €10,226, is the minimum for an art. 24 breach, where GDPR art. 83 sets only a ceiling. Against a public body or a competent authority no fine can be imposed at all: art. 113(10) exempts them, leaving only the responsible person at 5,000–70,000 KM (about €2,556–€35,790) and an employee at 500–5,000 KM under art. 113(8), whose list of articles covers arts. 14 to 24 and arts. 67 to 73. So art. 67, the police-side prohibition, carries no institutional fine anywhere in the Act — its enforcement runs through the Agency's art. 103(2) measures, non-compliance with which is itself in the top band. The Agency issues a misdemeanour order or applies to the competent court under the Zakon o prekršajima BiH; limitation is five years from the breach. Under the repealed 2006 Act the equivalent exposure for the same conduct was 5,000–50,000 KM (art. 50(1)(u), breach of art. 29), so the ceiling for a private controller rose roughly eight-hundredfold on 4 October 2025.

In force · 4 Oct 2025 checked 15 Sep 2026 ZZLP arts. 24 and 67 ↗ high confidence

Burkina Faso 1

Burkina Faso Binding

Loi 001-2021/AN art. 15 — a two-limb bar with no exception, backed by art. 19's reasoning and artificial-intelligence disclosure right and by art. 31's prior authorisation for predictive-AI decision support

Binds Responsables du traitement and sous-traitants within the scope of the Law, whose art. 6 states that information and communication technologies are at the service of the human person and must not harm human identity, private life, individual and collective freedoms or human rights generally. Art. 4 excludes temporary copies made for technical transmission and access purposes, which must be erased once their purpose is achieved, and processing for purely literary, artistic or journalistic purposes carried out in accordance with the ethical rules of those professions, the security measures protecting journalistic sources and the moderation rules applicable to discussion forums operated by news publishers. Prior formalities are a standing precondition: art. 30 sets the declaration regime and art. 31 the prior-authorisation regime, which covers offence and conviction data in the private sector, interconnection of files in either sector, national-identification-number processing in either sector, biometric processing in the private sector, public-interest processing including for historical, statistical or scientific purposes, decision-support processing involving an appraisal of human conduct or profiling or resting on predictive artificial-intelligence techniques, and transfers abroad. The first limb of art. 15 binds the courts themselves; the second binds every administrative and private decision-maker, irrespective of size or sector. Art. 78 makes the sanctions in arts. 63 to 75 applicable to all files, automated or not, whose use does not fall exclusively within the exercise of the right to private life. Impact tier: all entities.. Article 15 of Loi n° 001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel is Burkina Faso's operative automated-decision rule, closing Chapitre 1 of Titre II on fundamental principles immediately before the chapter on the rights of the data subject. Its first limb bars any judicial decision involving an appraisal of human conduct from having as its foundation an automated processing of information giving a definition of the profile or the personality of the person concerned and intended to evaluate certain aspects of their personality. Its second bars any administrative or private decision involving an appraisal of human conduct from having as its sole foundation an automated processing of information giving a definition of the profile or the personality of the person concerned. Like Côte d'Ivoire's art. 25 and Mali's art. 2, the Law states no exception whatever — no contract carve-out, no consent exception, no legal-authorisation exception and no opportunity to present observations. Two neighbouring provisions do the work that the exception clause does elsewhere. Article 19 gives every person the right to know and to contest the information and the reasoning used in processing, automated or not, whose results are relied on against them, and adds that where that processing falls within artificial intelligence the criteria and the nature of the personal data founding it must be indicated to the person from the point of collection. Article 31 goes further than any other row on the tracker by putting the technology itself behind a licence: processing that assists administrative or private decision-making, involves an appraisal of human conduct, gives a definition of the profile or the personality of the person concerned, or rests on artificial-intelligence techniques for predictive purposes, may not be implemented without prior authorisation from the Commission de l'informatique et des libertés. That is a permissioning gate on predictive AI, not merely a constraint on the resulting decision. There is no right to obtain human intervention or a fresh non-automated decision, and the art. 16 information list stops at identity, purposes, categories, whether answers are compulsory, recipients, access, rectification, suppression and objection rights, retention period, foreign transfers and the means of giving or withdrawing consent.

Supersession: art. 82 abrogates Loi n° 010-2004/AN du 20 avril 2004 portant protection des données à caractère personnel, the statute this sweep originally targeted, which is therefore no longer operative and is not tracked. Art. 83 is a bare execution clause — "La présente loi sera exécutée comme loi de l'Etat" — and there is no commencement article and no deferral of art. 15. The date recorded is the date printed at the foot of the enacted text, "Ainsi fait et délibéré en séance publique à Ouagadougou, le 30 mars 2021", the Assemblée nationale having deliberated in its sitting of that day. Confidence is medium and the reason is specific to Burkina Faso: laws there are promulgated by presidential decree, and neither the promulgation decree for Loi n° 001-2021/AN nor the date of the Journal officiel carrying it could be established from any official host this run — cil.bf serves a maintenance page on every path, legiburkina.bf, jo.gov.bf and sgg.gov.bf do not resolve, and the CIL's own document tree returns 404 live. Entry into force can therefore only be 30 March 2021 or later. Art. 81 is transitional and not a deferral of art. 15: processing already created and governed by art. 30 is subject only to declaration, the CIL may by special decision apply art. 31 to it subject to a prorogation of not more than one year granted by decree in Council of Ministers on the supervisory authority's opinion, and from the date of entry into force all processing had one year to meet the Law's prescriptions, failing which it is deemed implemented without the corresponding declaration or authorisation. Art. 80 preserves the mandates of CIL members already appointed. Source: the enacted text as published by the CIL itself, retrieved from the Internet Archive capture of 10 July 2025 of the CIL's own document store, the live path having 404'd during the site's maintenance outage; an archived copy of a document served by the official host satisfies Primary Source First on the same basis as ng-ndpa-s37. Coverage symmetry against the fifteen African rows already tracked: art. 15 takes the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting shared with Côte d'Ivoire's art. 25 and Niger's art. 52 — the second limb is tied to an appraisal of human conduct rather than to legal or significant effects — and, like Côte d'Ivoire and Mali, states no exception at all. Its art. 19 is materially identical to the third and fourth paragraphs of Niger's art. 52, including the artificial-intelligence disclosure duty at collection; since Burkina Faso's Law predates Niger's by twenty months, Burkina Faso is the source of that drafting on the tracker and Niger the follower. Two rows therefore carry an express artificial-intelligence clause, not one. Burkina Faso goes one step beyond Niger in art. 31 by making predictive-AI decision-support processing subject to prior authorisation, which is the only ex ante licensing gate on artificial intelligence in any data-protection statute on the tracker. The four-way African lineage picture: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, sn-loi200812-art48, ci-loi2013450-art25, ne-loi202259-art52, bj-code-num-art401, ml-loi2013015-art2 and now bf-loi0012021-art15; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63. Update 2026-08-25: cil.bf, previously reported as serving a maintenance page on every path, now serves a normal operating site; the promulgation decree date for Loi n° 001-2021/AN still could not be located on it, so confidence remains medium.

Stated maximum penalty — Art. 79 is the entire criminal chapter and creates no offence of its own: breaches of the Law are punished by the Penal Code in its provisions dealing with offences in computing matters and by means of information and communication technologies, so no criminal figure is attributed to art. 15 here. Everything operative is administrative and belongs to the CIL. Art. 63 lets the CIL, following the verification and inspection missions under art. 57 and without prejudice to criminal proceedings, impose a warning, a mise en demeure, an injunction to cease the processing carried out, blocking of certain personal data, a flat-rate fine, or withdrawal of the authorisation. Art. 65 fixes the flat-rate fine by reference to turnover rather than to a currency ceiling, which is unique among the Francophone rows: proportionate to the gravity of the failures and the advantages drawn from them, it is one per cent of pre-tax turnover for the last closed financial year on a first failure and five per cent on recidivism, recovered as a debt due to the State. Arts. 67 to 75 then set specific CIL fines: 5,000,000 to 10,000,000 francs CFA for obstructing the CIL's action in three specified ways; 5,000,000 to 20,000,000 francs CFA for processing without the prior formalities prescribed by the Law, which is the provision that reaches a failure to obtain the art. 31 prior authorisation for decision-support or predictive-artificial-intelligence processing; 5,000,000 to 20,000,000 francs CFA for processing without the precautions needed to preserve data security and 1,000,000 to 10,000,000 francs CFA for communicating data to unauthorised third parties or intentionally accessing files without authorisation; 5,000,000 to 100,000,000 francs CFA for purpose diversion; 5,000,000 to 100,000,000 francs CFA for fraudulent, unfair or unlawful collection, and for health-research processing in breach of art. 36; 2,000,000 to 5,000,000 francs CFA for processing despite a legitimately founded objection; 10,000,000 to 100,000,000 francs CFA for keeping sensitive data in computerised memory without express agreement, and for offence, conviction or security-measure data outside the permitted cases; 5,000,000 to 20,000,000 francs CFA for retaining identifiable data beyond the declared or authorised period, except for State processing; and 5,000,000 to 20,000,000 francs CFA for unauthorised divulgation harming honour, consideration or the intimacy of private life, reduced to 2,000,000 to 5,000,000 francs CFA where committed by imprudence or negligence. Art. 15 is named in none of them, so the route to it is the art. 63 general list including the art. 65 turnover-based flat-rate fine. Art. 76 lets the CIL order confiscation of the material media carrying the data or their erasure, even where the media do not belong to the sanctioned person, and, where it sanctions under arts. 67 to 75, ban the controller from managing any processing personally or through an intermediary for up to two years. Art. 77 lets it order publication of the decision or extracts in one or more newspapers at the sanctioned person's expense. Art. 64 requires sanctions to rest on a report by a CIL member designated by the President, notified to the controller, who may file observations and be represented or assisted at a hearing, requires decisions to be reasoned and notified, and makes sanction decisions appealable to the competent administrative court. Art. 66 lets the President of the CIL, or the person whose rights and freedoms are violated, apply in référé for any measure necessary to safeguard those rights, under astreinte, where the infringement of the Chapitre 2 rights is serious and immediate, and preserves compensation for moral or material damage.

In force · 30 Mar 2021 checked 20 Sep 2026 Loi n° 001-2021/AN art. 15 ↗ medium confidence

Burundi 1

Burundi Binding

Loi 1/03 arts. 19-20 — the automated decision a human must retake from scratch, and the first statute here to name AI in an operative duty

Binds Responsables du traitement and sous-traitants. Art. 2 applies the Law to any automated or non-automated processing of personal data by a natural person, the State, local authorities and legal persons of public or private law; to any processing by a controller or processor «établi ou non sur le territoire burundais» that resorts to processing means situated in Burundi, excluding means used only for transit; and to processing concerning public security, defence, the investigation and prosecution of criminal offences or State security, subject to the derogations the Law itself defines and to specific provisions in other legislation. A controller or processor not established in Burundi designates a representative established there unless its processing is occasional, without prejudice to actions that may be brought against it. Art. 3 excludes processing by a natural person in the exclusive framework of personal or domestic activities provided the data are not intended for systematic communication to third parties or dissemination, and temporary technical copies made for automatic, intermediate and transitory storage in transmission and network-access activities. Impact tier: all entities — arts. 19 and 20 turn on the effects of the decision, legal or important effects on the data subject's situation, not on the size or sector of the entity taking it, and art. 17(7)'s artificial-intelligence disclosure item attaches to every collection of personal data from the data subject regardless of effect.. Articles 19 and 20 of Loi n°1/03 du 10 mars 2026 portant protection des données à caractère personnel give Burundi the most demanding automated-decision regime on the tracker, and the Law is also the first tracked data-protection statute to name l'intelligence artificielle in an operative duty rather than in a recital or a definition. Art. 20 is a permission rule, not a right to object: «les prises de décisions automatisées produisant des effets juridiques ou des effets importants sur la situation de la personne concernée, ne sont autorisées que lorsque» they are provided for by a legislative or regulatory act laying down appropriate safeguards, taken with the data subject's consent, or strictly necessary for the conclusion or performance of a contract between the data subject and the controller. Where such a decision is permitted it must be accompanied by an individual motivation — which, the article concedes, may itself be produced by automated processing — and then comes the limb that has no equivalent anywhere else on the tracker: after learning the decision and its motivation, the data subject «a le droit de faire reformuler la décision», is invited by the controller to submit written observations in support of their case, and «une nouvelle décision motivée est prise par un être humain, qui remplace entièrement la première». Not a right to human intervention alongside the machine, as in GDPR art. 22(3), but a right to have the automated decision vacated and retaken by a person. Art. 19 supplies the transparency half twice over. Its first paragraph: where an automated decision produces legal effects or important effects on the data subject's situation, the existence of the automatism must be signalled to them and «la logique sous-jacente du traitement lui être expliquée en termes clairs et simples» — explained in clear and simple terms, a plain-language standard rather than the GDPR's «informations utiles». Its second paragraph reaches the decision-support case that most statutes leave untouched: where the processing merely aids a decision with such effects, the controller «décrit l'apport propre du décideur humain intervenant après l'automatisme, en particulier les méthodes et les critères sur lesquels il fonde son appréciation» — describes what the human decider actually added after the machine, and on what methods and criteria. That is a rubber-stamp rule: it puts the burden on the controller to show the human in the loop did something. Art. 20 closes with a sentence whose drafting is imperfect in the gazetted text — «Les motivations de la décision humaine ne peuvent s'appuyer que sur les résultats du traitement automatisé opaque» — which as printed says the opposite of what its Kirundi column and its context indicate, namely that the human decision's reasons cannot rest on opaque automated output; it is quoted here as gazetted rather than silently corrected. Upstream of all of this, art. 17(7) makes «du traitement des données à l'aide de l'intelligence artificielle pour la prise de décision automatisée» a mandatory item of the information the controller gives the data subject at the moment the data are obtained, and art. 21 carries the same list, plus the source of the data, into indirect collection with a one-month deadline. Impact tier: all entities.

Force, and the date is exact. Art. 55, the final article, provides «La présente loi entre en vigueur le jour de sa promulgation», and the instrument closes «Fait à Gitega, le 10 mars 2026», signed by President Evariste Ndayishimiye and countersigned by the Minister of Justice, Human Rights and Gender, Alfred Ahingejeje, under the seal of the Republic — so entry into force is 10 March 2026 with no vacatio legis. Art. 54 abrogates all earlier contrary provisions. Two forward deadlines follow from art. 53, which requires all processing to answer the Law's prescriptions within, from entry into force, one year for processing carried out on behalf of the State, a public establishment, a local authority or a private legal person charged with a public-service mission — 10 March 2027 — and six months for processing carried out on behalf of anyone else — 10 September 2026. Art. 52 leaves public-sector processing that predates entry into force subject only to a declaration to the data-protection organ. Neither transition suspends arts. 19 and 20 for processing begun after 10 March 2026. Supersession: none; the Law is four months old. Text read in the copy published by the Agence de Régulation et de Contrôle des Télécommunications, the Burundian regulator, on its own gov.bi site, which posted it on 18 March 2026; the file is the signed and sealed original, 32 pages, printed in parallel French and Kirundi columns with the initials of the signatories on every page, and it is image-only (Flate-wrapped DCTDecode page streams, no text layer), so it was read as page images. Coverage of the read: arts. 1-3 object, scope and exclusions; the head of the art. 4 definitions; arts. 11-12 on processors; the whole of the automated-decision material — arts. 17 information at collection, 19 explanation duties, 20 permission rule and human re-decision, 21 indirect collection and 22 opposition — verbatim; art. 46 breach notification; and the whole of Chapitre VII, arts. 47-51, and Chapitre VIII, arts. 52-55. Confidence high on the substance: arts. 19, 20 and 17(7) were read verbatim in the signed original and the entry-into-force clause is explicit and dated on its face. Two points are recorded as read rather than resolved. First, the art. 20 closing sentence quoted in the summary is defective as gazetted and no corrigendum was found. Second, «intelligence artificielle» appears in the operative text of art. 17(7) but is not defined: the art. 4 definitions run in French alphabetical order and no artificial-intelligence entry sits between «fichier de données à caractère personnel» and «personne concernée par un traitement», where one would fall. Institutionally the Law creates a data-protection organ and, per the regulator's own announcement and the parliamentary record of the 15 January 2026 adoption, an agency under the Ministry with responsibility for the digital economy; the standing-up of those bodies was not verified against primary text in this pass and no claim about their present operation is made here. AIL-300 computation check (2026-08-31): out of scope for the publication-relative sweep. Art. 55 sets no vacatio at all — «La présente loi entre en vigueur le jour de sa promulgation» — and the instrument is dated on its face «Fait à Gitega, le 10 mars 2026», so there is no term to compute. The two art. 53 conformity windows (10 September 2026 and 10 March 2027) are month-terms running from entry into force and are not carried as dates on this row.

Stated maximum penalty — Up to 20,000,000 Burundian francs for a private legal person, or six months to five years' imprisonment with a fine of 500,000 to 10,000,000 francs for a natural person, and the route to arts. 19-20 is indirect: the penal chapter, arts. 47-51, names no article of the Law, so the automated-decision provisions are enforced through the general offences rather than through a limb of their own. The one that fits them is art. 48, which punishes whoever, even absent any data breach, has collected or processed data «de manière déloyale, illicite ou non transparente au regard des personnes concernées» for purposes that are undetermined, non-explicit, illegitimate or incompatible with the original purposes — the non-transparency limb is what an undisclosed automated decision or an unexplained logic engages. It carries six months to five years' penal servitude and a fine of 500,000 to 10,000,000 Burundian francs, or one of those penalties alone, where the author is a natural person, and a fine of 5,000,000 to 20,000,000 francs where the offence was committed by a private legal person, that second figure being doubled where the offender is a responsable majeur de traitement. Art. 47 punishes any personal-data breach with three months to one year and a fine of 50,000 to 500,000 francs for an intentional natural person, or 1,000,000 to 20,000,000 francs for a private legal person, and allows a suspension of activities of up to six months on recidivism where the legal person is a responsable majeur de traitement. Art. 50 sets 500,000 to 5,000,000 francs for processing revealing racial or ethnic origin, political, philosophical or religious opinions, trade-union membership or health data, and for biometric processing for the selective identification of a natural person, outside the art. 10 conditions. Art. 49 punishes obstruction of archival, scientific, historical or statistical processing. Art. 51 preserves the penal provisions of other laws, naming the cybercrime law and the Penal Code, so the fines above are floors rather than the whole exposure. Upstream of the criminal route, art. 46 obliges the controller to notify the data subjects themselves, within 96 hours of becoming aware, of a breach of the obligations flowing from processing liable to create a high risk to their rights and freedoms, in clear and simple terms.

In force · 10 Mar 2026 checked 9 Sep 2026 Loi 1/03 arts. 19-20 ↗ high confidence

Benin 1

Benin Binding

Code du numérique art. 401 — a Directive-shaped bar widened to significant effects, with profiling named, mandatory safeguards inside the exception and a full logic-disclosure right

Binds Responsables du traitement within the scope of Livre cinquième, whose art. 379 states that the Livre's provisions establish a legal framework for the protection of private and professional life consequent on the collection, processing, transmission, storage and use of personal data, and that any processing, in whatever form, must respect the fundamental rights and freedoms of natural persons whatever their nationality or residence, while taking account of the prerogatives of the State, the rights of local authorities and the purposes for which undertakings were created. Prior formalities under Chapitre III of Titre II are a standing precondition, and Chapitre IV imposes the controller obligations, including the arts. 415 and 416 information duties that carry the automated-decision disclosure. The Autorité de Protection des Données à caractère Personnel established by Titre III supervises. The first paragraph of art. 401 binds the courts themselves; the second binds any decision-maker whose decision produces legal effects or significantly affects the person, irrespective of size or sector. Impact tier: all entities.. Article 401 of Loi n° 2017-20 du 20 avril 2018 portant code du numérique en République du Bénin, headed "Fondement d'une décision de justice — Aspects de la personnalité d'une personne physique", is Benin's operative automated-decision rule. It sits in Livre cinquième (protection of personal data), Titre II, Chapitre IV, immediately after the direct-marketing prohibition in art. 400. Its first paragraph bars any judicial decision involving an appraisal of the conduct of a natural person from having as its foundation an automated processing — expressly including profiling — of personal data intended to evaluate certain aspects of that person's personality. Its second paragraph bars any decision producing legal effects with regard to a person, or significantly affecting them, from being taken on the sole basis of an automated processing of data intended to evaluate certain aspects of their personality: the significant-effects limb is what separates Benin from Senegal, Morocco and Algeria, whose second limb stops at legal effects. Its third paragraph is the exception, and it is conditional rather than absolute — the prohibition does not apply where the decision is taken in the context of a contract or is founded on a provision laid down by or under the provisions of the Livre, a decree or an ordinance, but that contract or provision must contain appropriate measures safeguarding the legitimate interests of the person concerned, and the person must at least be permitted to put their point of view usefully. Benin is unusual among the Francophone rows in defining profiling: art. 1 defines it as any form of automated processing of personal data consisting in using those data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict elements concerning work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Unlike Senegal, Côte d'Ivoire, Morocco and Algeria, Benin also carries a full logic-disclosure right modelled on the GDPR: arts. 415 and 416 require the controller to inform the data subject, at collection and where data are obtained indirectly, of the existence of automated decision-making including profiling within the meaning of art. 401 and, at least in such cases, of useful information about the underlying logic and about the significance and the envisaged consequences of that processing for the data subject, and the access right repeats the same entitlement, with a copy of the information to be supplied without delay and at the latest within sixty days of the request. Art. 401 processing is also a named data protection impact assessment trigger: a systematic and extensive evaluation of personal aspects based on automated processing including profiling, on the basis of which decisions producing legal effects or similarly significantly affecting a natural person are taken, requires a prior impact assessment. There is no right to obtain human intervention or a fresh non-automated decision; the safeguard the Law names is the opportunity to put one's point of view usefully, and it exists only inside the exception.

The Code carries no commencement article: its final provision abrogates earlier texts, naming among them Loi n° 2009-09 du 24 mai 2009 portant protection des données à caractère personnel en République du Bénin, and ends with a bare execution clause, "La présente loi sera exécutée comme loi de l'État". The date recorded is the date the Law bears, 20 April 2018, which is also the date printed in the running head of every page of the enacted text. Confidence is medium for the same reason as the other Francophone rows: the Beninese general publication-to-force rule was not read against a primary source, and the date of the Journal officiel de la République du Bénin carrying the Code could not be established from an official host this run, so entry into force can only be that date or later. Supersession is settled on the face of the text: Loi n° 2009-09 of 2009 is abrogated and is not tracked. Note the Law's own numbering oddity, which is not an error in this entry — the instrument is numbered 2017-20 but dated 20 April 2018, because it was voted by the Assemblée nationale in 2017 and promulgated in 2018. One drafting defect is recorded for candour: art. 461, which fixes the penalties, refers to "les infractions visées à l'article 445" where the offence list is in fact art. 460, and the same article then refers correctly to "l'article 460" twice in its later paragraphs, so the cross-reference in the first sentence is a slip. Text read in the edition of the Code printed by the Autorité de Protection des Données à caractère Personnel, the supervisory authority established by Titre III of Livre cinquième, which carries the Assemblée nationale imprint; art. 401 and its heading, arts. 415 and 416, the impact-assessment article, the arts. 452 to 459 administrative chapter and the arts. 460 and 461 penal chapter were each read in full. Coverage symmetry against the thirteen African rows already tracked: art. 401 is the hybrid of the Francophone group. Its shape is the Directive 95/46/EC art. 15 shape — a judicial limb, a general limb, an exception — but three features are imported from the GDPR: the significant-effects alternative in the second limb, the express naming of profiling as a defined term, and the logic-disclosure and impact-assessment machinery. That makes Benin the bridge between the two African lineages rather than a member of either. Within the Francophone family the split is now three ways: Senegal, Morocco and Algeria keep the Directive drafting with a legal-effects threshold and a deeming clause; Côte d'Ivoire and Niger take the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting in which any administrative or private decision appraising human conduct is caught; Benin keeps the Directive skeleton and grafts GDPR flesh onto it. Benin's exception is also the strongest-conditioned of the Francophone rows: where Senegal, Morocco and Algeria simply deem contract decisions with an opportunity to present observations outside the bar, and Niger admits consent, contract and legal authorisation outright, Benin requires the contract or the enabling provision itself to contain appropriate measures safeguarding the person's legitimate interests, with the right to put one's point of view usefully as an express minimum. The four-way African lineage picture: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, sn-loi200812-art48, ci-loi2013450-art25, ne-loi202259-art52 and now bj-code-num-art401 as its GDPR-inflected outlier; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — No offence reaches art. 401 directly. Art. 460 enumerates fifteen offences under Livre cinquième — obstructing the Autorité in three specified ways, processing without the prescribed prior formalities, knowingly using data collected by a fraudulent process, processing sensitive, offence-related or national-identification-number data outside the permitted conditions, processing without implementing the prescribed measures, collecting data by fraudulent, unfair or unlawful means, diverting or manipulating data held for registration, classification, transmission or other processing, transferring data to a third State without satisfying the transfer requirements, using violence, threats, gifts or promises to compel a person to hand over information obtained under art. 436 or to consent to processing, processing despite a well-founded rectification request or objection, failing to respect the Livre's provisions on informing data subjects, failing to respect its provisions on access rights, retaining data beyond the declared period outside historical, statistical or scientific purposes, unauthorised divulgation harming the person's consideration or the intimacy of their private life, and participating in an association or agreement formed to commit any of those offences — and the automated-decision bar is not among them. Two of the fifteen do reach the disclosure duties that art. 401 feeds: the failure to respect the Livre's provisions on informing data subjects and the failure to respect its provisions on access rights both catch a controller that withholds the art. 415, 416 and access-right information about the existence of automated decision-making including profiling, the underlying logic, and its significance and envisaged consequences. Art. 461 punishes those offences with imprisonment of six months to ten years and a fine of 10,000,000 to 50,000,000 francs CFA, or one of those penalties only, with complicity and attempt punished identically; where the formalities offence is committed by simple negligence only a fine of 5,000,000 to 50,000,000 francs CFA may be imposed. The court may order erasure of all or part of the data processed, may pronounce complementary penalties including confiscation of the material media carrying the data, excluding computers, and final convictions are published in the Journal officiel de la République du Bénin and on an electronic medium at the convicted person's expense. The route that reaches art. 401 itself is administrative. Art. 452 lets the Autorité issue a warning to a controller that does not respect the obligations arising under the Livre and a formal notice to end the observed failure within a period not exceeding eight days. Art. 453 defines grave failures — unfair collection, communication to an unauthorised third party, unlawful collection of sensitive, offence-related or national-identifier data, collection or use causing serious harm to fundamental rights or to the intimacy of private life, and obstruction of an on-site inspection. Art. 454 lets the Autorité, respecting the adversarial principle, impose a pecuniary sanction (except where the processing is implemented by the State), an injunction to cease the processing, definitive or temporary withdrawal of the authorisation, or blocking of certain data. Art. 455 fixes the amount: proportionate to the gravity of the failures and the advantages drawn from them, not exceeding 50,000,000 francs CFA on a first failure and, on a repeated failure within five years from the date the previous pecuniary sanction became definitive, not exceeding 100,000,000 francs CFA or, for an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of 100,000,000 francs CFA; where the Autorité's pecuniary sanction becomes definitive before the criminal court rules on the same or connected facts, that court may set the sanction off against its fine. Art. 456 lets any sanction be coupled with an injunction to make any useful modification or deletion in the operation of the processing within a period not exceeding eight days; art. 457 requires a report notified to the controller, who has fifteen days to make written or oral observations and may attend or be represented; art. 458 makes sanction decisions appealable to the competent administrative court; and art. 459 lets the Autorité publish the sanctions imposed.

In force · 20 Apr 2018 checked 20 Sep 2026 Code du numérique art. 401 (Loi n° 2017-20) ↗ high confidence

Brazil 3

Brazil Binding

Brazil LGPD Art. 20 — right to review of solely-automated decisions

Binds Processing agents (controllers and operators) under LGPD Art. 3 — processing carried out in Brazil, processing aimed at offering goods or services to, or processing data of, individuals located in Brazil, or data collected in Brazil, regardless of where the agent or the data is based. Impact tier: all entities.. Data subjects may request review of decisions taken solely on the basis of automated processing of personal data that affect their interests, expressly including decisions that define personal, professional, consumer or credit profiles or aspects of personality. On request the controller must give clear and adequate information about the criteria and procedures used for the automated decision, subject to trade and industrial secrecy; where secrecy is invoked the ANPD may audit the processing for discriminatory effects.

Art. 20 as amended by Lei 13.853/2019: the original "por pessoa natural" wording was removed, so this is a right to review, NOT a guaranteed human-review right. The proposed reinstatement (Art. 20 s.3) was vetoed. Commencement traced through Art. 65: Lei 13.853/2019 set Art. 65 II at 24 months after publication (LGPD published DOU 15.8.2018); MP 959/2020 (DOU 29.4.2020, in force on publication) art. 4 pushed Art. 65 II to 3 May 2021; Congress dropped that amendment on conversion, and the conversion law Lei 14.058/2020 (17 Sept 2020, DOU 18.9.2020, in force on publication) contains no amendment to Lei 13.709 — so the postponement fell away and the general articles, including Art. 20, took effect on 18 September 2020. The administrative sanctions regime (Arts. 52-54) commenced separately on 1 August 2021 under Art. 65 I-A, inserted by Lei 14.010/2020. Coverage-symmetry check 2026-08-14: no ANPD normative act specifically regulating AI or automated decision-making — a DOU sweep of "RESOLUÇÃO CD/ANPD" and of ANPD acts mentioning inteligência artificial / decisões automatizadas returned only internal-organisation and international-transfer resolutions (e.g. Res. 32/2026 EU adequacy, Res. 33/2026 staffing). Brazil's AI-specific bill remains proposed — see br-pl2338.

Stated maximum penalty — LGPD Art. 52: warning; simple fine up to 2% of the private-law entity's, group's or conglomerate's Brazilian turnover in its last financial year, excluding taxes, capped in total at R$50,000,000 per infraction; daily fine; publicisation; blocking, deletion, partial or total suspension of processing or of the database (up to 6 months, renewable); partial or total prohibition of processing activities. ANPD enforcement; sanctions applicable since 1 August 2021 (Art. 65 I-A).

In force · 18 Sep 2020 checked 14 Sep 2026 LGPD (Lei 13.709/2018) Art. 20 ↗ high confidence
Brazil Binding

Brazil ECA Digital (Lei 15.211/2025) — algorithmic duties for services used by minors

Binds Suppliers of information-technology products or services (including internet application providers, social networks, app stores, electronic games and child-monitoring products) that are directed at children and adolescents or likely to be accessed by them, offered in Brazilian territory, including foreign companies, which must keep a legal representative in Brazil (Art. 40). Art. 39 modulates the duties in Arts. 6, 17, 18, 19, 20, 27, 28, 29, 31, 32 and 40 by the product's characteristics and functionalities, the provider's degree of interference over content, user numbers and size, and exempts editorially-controlled services and licensed-content providers that meet the four conditions in Art. 39 s.1. Impact tier: all entities, modulated by size and degree of content control.. Providers of information-technology products or services directed at, or likely accessed by, children and adolescents must give parents control over personalised recommendation systems, including the option to switch them off, and must regularly review the artificial-intelligence tools in the service with the participation of specialists and competent bodies against technical criteria that ensure their safety and suitability for use by minors, with non-essential functionalities capable of being disabled. Behavioural profiling of child and adolescent users for advertising is prohibited, as is profiling-based ad targeting and the use of emotional analysis, augmented, extended or virtual reality for that purpose. Where content is removed, the provider must tell the user whether the content was identified by human or automated analysis.

Lei 15.211/2025 ("ECA Digital"), sanctioned 17 September 2025 and published DOU 17.9.2025 extra edition. Art. 41-A originally set entry into force at six months after publication (inserted by MP 1.319/2025); the version now in force, inserted by Lei 15.352/2026, fixes the date expressly: "Esta Lei entra em vigor em 17 de março de 2026." Scope call 2026-08-14: kept in the tracker because the statute imposes express algorithmic-system duties rather than only platform-safety duties — Art. 17 s.4 V (control over personalised recommender systems with an off switch as a default parental-supervision setting), Art. 17 s.4 VIII (regular expert review of AI tools in the service), Art. 30 II (disclosure of whether a removal decision came from human or automated analysis), Art. 22 (ban on profiling for ad targeting and on emotional analysis / AR / XR / VR for that purpose) and Art. 26 (ban on building behavioural profiles of minors from personal, group or collective data, including data obtained in age verification, for advertising). Art. 24 s.3 age-assurance and Art. 27 automated illicit-content detection duties feed the separate transparency-report obligation tracked as br-lei15211-art31-report. Enforcement: Art. 34 gives the autonomous administrative authority for the protection of children's and adolescents' rights in the digital environment supervisory and complementary-rulemaking power; Decreto 12.622/2025 designates the ANPD as that authority and Decreto 12.880/2026 (DOU 18.3.2026 extra edition) is the implementing regulation. Distinct from br-lgpd-art20, which is a data-subject right under the LGPD. AIL-300 computation check (2026-08-31): out of scope for the publication-relative sweep as the law now stands. Art. 41-A's original six-months-from-publication formula was replaced by Lei 15.352/2026 with an express calendar date — «Esta Lei entra em vigor em 17 de março de 2026» — so the in-force text sets no period to compute and LINDB art. 1's counting rule does not engage.

Stated maximum penalty — Art. 35: warning with up to 30 days to take corrective measures; simple fine of up to 10% of the economic group's Brazilian turnover in its last financial year or, absent turnover, R$10 to R$1,000 per registered user, capped in total at R$50,000,000 per infraction; temporary suspension of activities; prohibition of activities. Fines and warnings are applied by the ANPD; suspension and prohibition by the Judiciary (Art. 35 s.5) and enforced if needed by blocking orders to connectivity providers, IXPs and DNS resolvers (Art. 35 s.6). A foreign company's Brazilian branch or establishment is jointly liable for the fine (Art. 35 s.2); fine amounts are indexed annually to the IPCA (Art. 35 s.4).

In force · 17 Mar 2026 checked 14 Sep 2026 Lei 15.211/2025 (ECA Digital) ↗ high confidence
Brazil Binding

Brazil ECA Digital Art. 31 — semi-annual transparency report, first due 17 September 2026

Binds Internet application providers directed at or likely accessed by children and adolescents with more than 1,000,000 registered users in that age band with an internet connection in Brazilian territory. Exempt: providers below that threshold, and editorially-controlled services and licensed-content providers meeting the four conditions in Art. 39 s.1 (Despacho Decisório CD/ANPD 122/2026 item VII). Impact tier: enterprise.. Internet application providers directed at, or likely accessed by, children and adolescents with more than 1,000,000 registered users in that age band connecting from Brazil must publish semi-annual reports in Portuguese on their own website. The report must cover the complaint channels and investigation systems, the number of complaints received, the volume of content and account moderation by type, the measures used to identify child accounts on social networks under Art. 24 s.3 and to identify illicit acts under Art. 27, technical improvements for personal-data protection and privacy and for ascertaining parental consent under LGPD Art. 14 s.1, and the methods used and results of impact assessments and of the identification and management of risks to the safety and health of children and adolescents. Providers must also give academic, scientific, technological, innovation and journalistic institutions free access to the data needed to research the service's impact on minors.

Art. 31 of Lei 15.211/2025 has been in force since 17 March 2026 (Art. 41-A as amended by Lei 15.352/2026), but the statute only says the reports are semi-annual and sets no publication date. Despacho Decisório CD/ANPD 122/2026 (DOU 11.8.2026, Section 1, p. 59) fixes the calendar until specific regulation supervenes: the time runs from entry into force on 17 March 2026; the first report covers 1 January to 30 June 2026, and providers without data for January and February may limit it to 17 March to 30 June 2026; the first report must be published by 17 September 2026 (item III); from the second report the periods follow the civil semesters, published by 1 August for the first semester and by 1 February for the second (item IV). Art. 45 of Decreto 12.880/2026 adds, under Art. 31 II, the number of notifications received by category and proportional data on how they were followed up. Art. 47 of the decree requires the child-safety-and-health impact assessment behind Art. 31 VII, with a plain-language summary made public, and lets an ANPD act set its minimum content and periodicity. The ANPD recommends emailing a copy of each report to monitoramento@anpd.gov.br at publication (item VIII). Tracked separately from br-lei15211-eca-digital because 17 September 2026 is a distinct near-term deadline.

Stated maximum penalty — Art. 35: warning with up to 30 days to correct; simple fine up to 10% of the economic group's Brazilian turnover in its last financial year or, absent turnover, R$10 to R$1,000 per registered user, capped at R$50,000,000 per infraction; temporary suspension of activities; prohibition of activities. ANPD applies the warning and fine (Art. 35 s.5).

Applies 17 Sep 2026 checked 15 Sep 2026 Lei 15.211/2025 Art. 31; Despacho CD/ANPD 122/2026 ↗ high confidence

Canada 1

Canada Binding

Quebec Law 25 — automated decision transparency

Binds Organisations making automated decisions using personal information in Quebec. Right to be informed + disclosure of key factors for automated decisions using personal info (Quebec).

Stated maximum penalty — AMPs up to C$10M / 2% turnover

In force · 22 Sep 2023 checked 15 Sep 2026 Quebec Law 25 (s.12.1) ↗ high confidence

Democratic Republic of the Congo 1

Democratic Republic of the Congo Binding

Code du numérique art. 209 — the logic behind the decision must be disclosed, but no decision is ever forbidden

Binds Responsables de traitement — controllers — and their representatives, with sous-traitants (processors) reached through the same Titre. Art. 184 fixes the scope in four limbs and it is unusually wide: the Titre catches the collection, processing, transmission, storage and use of personal data by l'Etat, la Province, Entités Territoriales Décentralisées et Déconcentrées, legal persons of public or private law and natural persons; processing automated or not of data contained in or intended for a file; «le traitement de données mis en œuvre sur le territoire national ou à l'étranger» — processing implemented on the national territory or abroad, with no establishment, targeting or means limb to narrow it; and processing concerning public security, defence, the investigation and prosecution of criminal offences or State security, subject to derogations laid down by other legislation in force. Art. 185 excludes processing by a natural person in the exclusive framework of personal or domestic activities provided the data are not intended for systematic communication to third parties or for dissemination; temporary copies made in the technical activities of transmission and of providing access to a computer network for automatic, intermediate and transitory storage; and processing by competent authorities for the prevention and detection of criminal offences, investigations and prosecutions or the execution of criminal penalties. Impact tier: all entities — art. 209 attaches to every controller subject to the Titre with no employee-count, turnover, sector or high-risk-system threshold, and because the disclosure duty is triggered by the existence of automated decision-making including profiling rather than by a legal-effects threshold, a scoring or profiling deployer owes it even where the DPIA trigger in art. 245 would not bite.. Article 209 of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique is the Democratic Republic of the Congo's automated-decision provision, and it is the mirror image of Angola's. The DRC's data-protection Titre is GDPR-template — it carries a délégué à la protection des données, a portability right, and a data-protection impact assessment — but it took the transparency half of the GDPR's automated-decision package and left the prohibition behind. Under art. 209, the natural person whose personal data are processed may ask the controller for, among other things, «l'existence d'une prise de décision automatisée, y compris un profilage, et, au moins en pareils cas, des informations utiles concernant la logique sous-jacente, ainsi que l'importance et les conséquences prévues de ce traitement pour la personne concernée» — the existence of automated decision-making, including profiling, and at least in such cases meaningful information about the underlying logic as well as the significance and the envisaged consequences of that processing for the data subject. The same limb is repeated twice more as an up-front duty rather than an on-request one: art. 220 requires the controller or its representative to give it to the data subject at the latest at the moment of collection, whatever the means and medium employed, and art. 235 requires it where the data were not collected from the data subject. Art. 245 then makes «l'évaluation systématique et approfondie d'aspects personnels concernant des personnes physiques, qui est fondée sur un traitement automatisé, y compris le profilage, et sur la base de laquelle sont prises des décisions produisant des effets juridiques à l'égard d'une personne physique ou l'affectant de manière significative de façon similaire» the first named trigger for a mandatory data-protection impact assessment. What is absent is the GDPR art. 22 analogue. Nothing in the Titre gives a right not to be subject to a decision based solely on automated processing, and there is no human-intervention right and no right to contest the decision after the fact. The rights section, Chapitre VI Section 1, runs from art. 209 through the general opposition right in art. 213 — a right exercisable «à tout moment, pour des motifs légitimes» against processing as such, not against automated decisions as a category — and never reaches a prohibition. Nor is profiling gated ex ante: art. 187 lists the processing operations needing prior authorisation from the Autorité de protection des données — genetic and medical data and research on them, offence and conviction data, national identification numbers and other identifiers of the same nature including telephone numbers, biometric data, and public-interest processing — and automated decision-making and profiling are on none of those limbs; art. 186 leaves them in the ordinary prior-declaration regime. So the DRC and Angola between them bracket the two halves of the GDPR provision: Angola forbids the decision and never makes anyone disclose the logic, the DRC compels disclosure of the logic three times over and never forbids the decision. Impact tier: all entities.

Force, and the date is exact. Art. 390, the final article, provides «La présente ordonnance-loi entre en vigueur à la date de sa promulgation» — the Ordonnance-loi enters into force on the date of its promulgation — and the instrument closes «Fait à Kinshasa, le 13 mars 2023», signed by President Félix-Antoine Tshisekedi Tshilombo and countersigned by Prime Minister Jean-Michel Sama Lukonde Kyenge, so entry into force is 13 March 2023 with no vacatio legis and no phased application. Art. 389 abrogates all earlier provisions contrary to the Ordonnance-loi. Art. 388 carries the only transition: digital-service providers operating on titles obtained before the Ordonnance-loi had six months from entry into force — to 13 September 2023 — to bring themselves into conformity; that window is long closed and it did not defer art. 209 for anyone else. Supersession: none. Text read in the certified copy of the Ordonnance-loi issued by the Cabinet of the President of the Republic — the last page carries the stamp «Pour copie certifiée conforme à l'originale, Le 13 mars 2023, Le Cabinet du Président de la République, Guylain NYEMBO MBWIZYA, Directeur de Cabinet» — which is the same 175-page file the Autorité de régulation publishes on are.gouv.cd (the ARE download page states 45.30 MB against the 47,498,251 bytes of the copy read, i.e. the same file). That satisfies Primary Source First on the same footing as the Angola, Chad and Equatorial Guinea copies. Two independent renderings of the same instrument were used and cross-checked against each other: the certified scan, which is image-only (Flate-wrapped DCTDecode page streams, no text layer) and was read as page images; and a born-digital rendering whose text layer covers arts. 186 to 390 contiguously with no missing article heading, which was used for full-text search. Coverage of the read: arts. 184 scope and 185 exclusions verbatim; art. 186 prior declaration and art. 187 prior authorisation in full; arts. 209 and 210 verbatim in the scan, including the logic-disclosure indent of art. 209(2); arts. 212 and 213 verbatim; arts. 219, 220, 235 and 245 in the text layer; the enforcement chain at arts. 255 to 258; and arts. 383 to 390 verbatim in the scan. The negative finding — no art. 22 analogue — rests on both renderings: a normalised full-text search of arts. 186-390 returns no «ne pas faire l'objet d'une décision», no «décision individuelle», and no occurrence of «automatis» outside the seven hooks listed here, and the rights-section pages were additionally read as images to guard against the lossy-text-layer failure mode that parked Cabo Verde. Confidence high: the disclosure limb was read verbatim in a certified government copy, the entry-into-force clause is explicit and dated on its face, and the sanction route was traced through arts. 255-257 rather than assumed. No AI-specific statute is in force in the DRC and the data-protection Titre neither defines nor separately regulates artificial-intelligence systems; its automated-decision hooks are the three disclosure limbs and the DPIA trigger. AIL-300 computation check (2026-08-31): out of scope for the publication-relative sweep. Art. 390 sets no vacatio at all — «La présente ordonnance-loi entre en vigueur à la date de sa promulgation» — and the instrument is dated on its face «Fait à Kinshasa, le 13 mars 2023», so there is no term to compute.

Stated maximum penalty — 8,000,000 to 200,000,000 Congolese francs, but only on the second step — the enforcement chain runs through a mise en demeure and the fine attaches to defying it, not to the underlying breach. Art. 255 lists the manquements under the Titre, among them unfair collection, communication of personal data to an unauthorised third party, collection of sensitive, strategic, offence-related or national-identification-number data without meeting the legal conditions, collection or use of personal data having the consequence of seriously infringing fundamental rights or the intimacy of the data subject's private life, and obstructing an on-site inspection by the services of the Autorité de protection des données. Art. 256 then gives the Autorité a warning against a controller that fails to comply with the obligations flowing from the Titre, and lets it put the controller on formal notice — mise en demeure — to end the established breach within a fixed period «qui ne peut excéder huit jours», not exceeding eight days. Art. 257 is the sanction: where the controller does not comply with the mise en demeure, the Autorité may, respecting the adversarial principle, order (1) payment of eight million to two hundred million Congolese francs where the violation had no serious impact on the State and/or the data subjects; (2) payment of 5% of its annual turnover excluding tax for the closed financial year where the violation led to the death or attempted murder of one or more persons; or (3) an injunction to cease the processing of personal data where the violation endangered national security and safety and/or led to a mass crime or genocide. The turnover limb is drafted to homicide and mass-atrocity outcomes rather than to data-protection gravity, which is unusual and means that in the ordinary case — an undisclosed scoring model — the exposure is the capped 8M-200M CDF band, not a percentage of turnover. Art. 257 also reserves the State's right to bring criminal proceedings against the controller and to claim damages. Art. 258 makes the sanction pronounced by the Autorité appealable. Separately, art. 310 sets the penalties for cybercrime offences as servitude pénale, fine and special confiscation, and art. 311 makes the maximum fine for legal persons five times that for natural persons; those are the cybercrime Livre, not the data-protection Titre, and do not attach to art. 209.

In force · 13 Mar 2023 checked 10 Sep 2026 Code du numérique art. 209 ↗ high confidence

Central African Republic 1

Central African Republic Binding

Loi 24.001 art. 30 — the access limb without the bar: the only tracked statute that lets you contest an automated decision but never forbids one

Binds Responsables de traitement, and through the art. 6 definition also sous-traitants, being any natural or legal person, public or private, any other body or association that processes data on the controller's behalf. The art. 4 scope is territorial-plus-effects and unusually explicit about the public sector: the Law applies to processing carried out in the context of the activities of an establishment of a controller or a processor on the territory of the Central African Republic, whether or not the processing takes place in the Central African Republic; to processing that deploys effects in the Central African Republic even where those effects arose abroad or through a controller established abroad; to processing concerning public security, defence, the investigation and prosecution of criminal offences or state security, subject to derogations fixed by other laws in force; to processing not provided for by a special law; and to processing in the context of court proceedings. Art. 4 excludes purely personal or domestic processing by a natural person, and temporary technical copies made for transmission and network access provision. Art. 31 removes the art. 30 right altogether for processing concerning public security and for the collection of information necessary to establish offences and pursue the consequent proceedings, and lets the controller refuse requests that are manifestly abusive by their number or their repetitive or systematic character, with the burden of proof on the controller in case of contestation. For state-security, defence and public-security processing the access and rectification rights are exercised indirectly through the agency rather than against the controller. No ex ante gate attaches to automated decision-making or to profiling: the only prior-authorisation regimes in the Law are art. 28, which subjects the interconnection of files held by legal persons managing a public service with differing public interests, processing operated by the State for users of remote e-administration services, and interconnection of files with differing purposes, to the prior authorisation of the agency — an interconnection must not entail discrimination or prejudice to rights, freedoms and guarantees — and arts. 24 to 27, which govern transfers. Those transfer articles are the first on the tracker to draw the free-flow perimeter around CEMAC and CEEAC rather than around a national adequacy list: a controller may transfer personal data to a state that is not a member of CEMAC or CEEAC only where that state ensures a sufficient level of protection, the agency must be informed before any such transfer, and art. 27 lets the agency authorise a transfer to a non-adequate non-member state where the controller offers sufficient guarantees, which may result from appropriate contractual clauses. Impact tier: all entities.. Article 30 of Loi 24.001 du 25 janvier 2024 portant protection des données à caractère personnel is the Central African Republic's only operative automated-decision provision, and it is an access limb, not a bar. It sits in Chapitre VI, Des droits liés au traitement des données à caractère personnel, which opens at art. 29 with the right of any person showing a legitimate motive to object at any time and free of charge to the processing of their personal data, and a free-standing right to object to the use of their data for prospection without having to justify a motive. Art. 30 then gives every person the right to be informed of the processing of their data, subject to proof of identity, and to obtain from the controller three things: information on the purposes of the processing, the categories of personal data processed and the recipients or categories of recipient to whom the data are communicated; the communication of all the data concerning them together with any available information as to their origin; and — the automated-decision limb — les informations permettant de connaître et de contester le mécanisme du traitement automatisé en cas de décision prise sur le fondement de celui-ci et produisant des effets juridiques à l'égard de l'intéressé, the information allowing the person to know and to contest the mechanism of the automated processing where a decision is taken on the foundation of that processing and produces legal effects in respect of them. That is the Directive 95/46/EC art. 12(a) third-indent form word for word, and it is the whole of it. The right is exercised free of charge, on the spot or remotely, and must be granted without delay, with a copy of the data conforming to the content of the processing delivered on request. What the Central African Republic does not have is the second half of the Directive template. There is no art. 15-style rule anywhere in the Law providing that a decision producing legal effects may not be taken on the sole foundation of an automated processing, no deeming clause for contractual decisions, no human-intervention right, and no GDPR art. 22 right of objection to automated decisions. The word automatisé appears exactly three times in the fifty-eight articles: in the art. 6 definition of Profilage, in the art. 6 definition of Traitement, and in this indent of art. 30. Nothing prohibits an automated decision in the Central African Republic; art. 30 only entitles the person, after the fact and on their own initiative, to be told how the machine worked and to argue with it. The Law is therefore the thinnest automated-decision regime yet recorded in the African block, and the only one where the rule is purely reactive.

Force. Art. 58, the Law's final provision, is explicit and self-executing: la présente Loi qui prend effet à compter de la date de sa promulgation, est enregistrée et publiée au Journal Officiel — the Law takes effect from the date of its promulgation, and publication in the Journal Officiel is a separate, non-suspensive formality. That removes the ambiguity that forced a medium confidence on Morocco, Congo-Brazzaville, Gabon and Cameroon, where the final article was a bare publication clause and the publication-to-force rule had to be assumed. Nothing in the Law defers art. 30. Confidence is nevertheless medium, for a different and narrower reason: the promulgation date is not legible in the copy read. The text was read in the scanned copy published by the Autorité de Régulation des Communications Électroniques et des Postes, the Central African regulator, and its title page carries only LOI N° 24.001 PORTANT PROTECTION DES DONNEES A CARACTERE PERSONNEL with no date, while the date block on the signature page — over the signature of President Faustin-Archange Touadéra — falls inside the stamped and handwritten region of the scan and does not survive text extraction. The date recorded here, 25 January 2024, comes from ARCEP's own regulation index, which cites the instrument as Loi 24.001 du 25 janvier 2024, portant protection des données à caractère personnel and lists it immediately beside Loi 24.002 du 21 février 2024, relative à la cybersécurité et à la lutte contre la cybercriminalité. That is the publishing regulator's own citation of the file it hosts, not a news report, and the 24.001 numbering is consistent with a January 2024 first law of the year; but it is one step removed from the face of the enacted text, so the entry is not marked high. The one dated duty in the Law has already run: art. 57 gives the Ministère en charge de l'Economie Numérique, des Postes et Télécommunications a period of twelve (12) months from promulgation to put in place the agency in charge of personal data protection, which expired on 25 January 2025, and provides that until the agency is in place its missions are discharged by the supervising Ministry. Whether the agency has since been constituted was not verified and does not affect the existence of the art. 30 duty, which runs against controllers directly; it affects only which body answers an indirect-access request under art. 32 and which body opens an administrative sanction file. Art. 58 also provides that a decree in Council of Ministers shall fix, as needed, the modalities of application of the Law; art. 30 is not among the provisions that await one and is operative on its own terms. Supersession: none. The Central African Republic had no dedicated data-protection statute before Loi 24.001 — its adjacent instruments are Loi 18.002 du 17 janvier 2018 régissant les communications électroniques, Loi 22.002 du 11 janvier 2022 régissant les transactions électroniques and the companion Loi 24.002 du 21 février 2024 relative à la cybersécurité, none of which carries an automated-decision rule. Nothing on the tracker is superseded by this row. No AI-specific statute is in force and the Law does not define artificial intelligence; Gabon's Loi 025/2023 remains the only Francophone African data-protection statute that does. Text read article by article across the fifty-eight articles of the ARCEP copy, covering the arts. 1 to 5 object and scope, the art. 6 definitions, the arts. 7 to 21 principles and sensitive-data regime, the arts. 22 to 27 transfer chapter, the art. 28 interconnection chapter, the arts. 29 to 36 rights chapter, the arts. 37 to 46 agency and administrative-sanction chapter, the arts. 47 to 56 penal chapter and the arts. 57 and 58 final provisions. Source, re-verified 26 August 2026. The live ARCEP link this row carried is gone: arcep.cf now serves a single «Site en construction» placeholder page at its root and answers 404 for every document path, so the regulator's whole document tree went with the rebuild. The citation moves to the Internet Archive's capture of 22 June 2026 of the same ARCEP-hosted file, which is the official copy at the official path as it stood before the rebuild, and which was downloaded and re-read this run — 5.85 MB, a scanned promulgated original opening «LOI N° 24.001 PORTANT PROTECTION DES DONNEES A CARACTERE PERSONNEL — L'ASSEMBLEE NATIONALE A DELIBERE ET ADOPTE, LE PRESIDENT DE LA REPUBLIQUE, CHEF DE L'ETAT PROMULGUE LA LOI DONT LA TENEUR SUIT». Art. 30 in that capture still carries the limb this row rests on, «les informations permettant de connaître et de contester le mécanisme du traitement automatisé en cas de décision prise sur le fondement de celui-ci et produisant des effets juridiques à l'égard de l'intéressé», and art. 6 still carries the profiling definition. The same archival treatment is already used for Burkina Faso's Loi 001-2021 after cil.bf went the same way. Finding a live official host for the Law is carried as an open follow-up.

Stated maximum penalty — No penalty in the Law attaches to art. 30 by name, and the route to it is administrative. The agency's administrative sanctions are pronounced on the basis of a report drawn up by its services or by a member it designates; the report is notified to the controller, who may make written and oral observations and be represented or assisted, and the rapporteur may speak but does not take part in the deliberation. Decisions are reasoned, notified, made public, and may be published in journals the agency designates at the sanctioned person's cost, and they may be appealed to the administrative courts. The ceiling is turnover-based and is the operative maximum for an art. 30 refusal: le montant de la sanction pécuniaire ne peut excéder 5% du chiffre d'affaires hors taxes du dernier exercice clos, recovered as a debt due to the State. Every sanction decision must carry a period within which the object of the dispute is to be modified or suppressed, and the agency may go to the competent court by way of référé to obtain, if need be under a penalty payment, any security measure necessary to safeguard the rights and freedoms mentioned in art. 1. The penal chapter, Section 2 of Chapitre VIII, does not reach the access right, but it does reach the neighbouring art. 29 objection right, which is the closest criminal exposure a Central African controller running automated processing faces: two (2) to five (5) years' imprisonment and a fine of one million (1,000,000) to ten million (10,000,000) FCFA for anyone who processes the personal data of a natural person despite that person's request for rectification or objection, where the request is founded on legitimate grounds. The rest of the chapter, for context on the scale: six (6) months to five (5) years and 100,000 to 5,000,000 FCFA for obstructing the agency's missions; six (6) months to two (2) years and 100,000 to 2,000,000 FCFA for negligently processing without the prior formalities required by law; two (2) to five (5) years and 1,000,000 to 10,000,000 FCFA for collecting personal data by fraudulent, unfair or unlawful means; the same range for diverting a file from its initial purpose, notably on the occasion of recording, classification or transmission; six (6) months to two (2) years and 100,000 to 2,000,000 FCFA for retaining data beyond the period declared to the agency, unless the retention is for historical, statistical or scientific purposes on the conditions provided by law; and two (2) to five (5) years and 1,000,000 to 10,000,000 FCFA for bringing to the knowledge of an unqualified third party, without the data subject's authorisation, data whose disclosure harms the person's standing or the intimacy of their private life. The court may order the erasure of all or part of the data processed in the commission of an offence, and the agency's members and agents are empowered to verify that erasure. The Procureur de la République must inform the agency's Director General of prosecutions under the Law, and the trial court may call the Director General or their representative to file or develop observations at the hearing.

In force · 25 Jan 2024 checked 21 Sep 2026 Loi 24.001 art. 30 ↗ medium confidence

Republic of the Congo 1

Republic of the Congo Binding

Loi n° 29-2019 art. 13 — the Directive-shaped bar whose fine arrives only if the controller defies the formal notice

Binds Responsables de traitement and, through art. 12, anyone acting under their authority with access to personal data. The prior-formality regime runs through arts. 32 to 40: art. 32 and art. 33 carry the dispensations from formalities that art. 93 later cross-refers to, arts. 33 to 36 set the declaration regime, and art. 40 governs processing authorised by regulatory act, for which art. 94 requires the Commission to inform the Government so that it may take measures to end an established violation, the Government having fifteen days to report back on the action taken. Neither profiling nor automated decision-making is listed as a category attracting prior authorisation, so Congo imposes no ex ante gate on the processing art. 13 governs. Art. 82 provides for prior consultation of the Commission and arts. 90 and 91 for a data protection officer who must have due regard, in performing their tasks, to the risk associated with processing operations having regard to their nature, scope, context and purposes. The art. 13 bar binds the courts under its first limb and, under its second, every decision-maker whose decision produces legal effects in regard to a natural person, with no size or sector threshold. Impact tier: all entities.. Article 13 of Loi n° 29-2019 du 10 octobre 2019 portant protection des données à caractère personnel is the Republic of the Congo's operative automated-decision rule. It closes Chapitre 1 of Titre II on the principles governing processing, immediately after art. 12, which provides that a person acting under the authority of the controller and having access to personal data may process them only on the controller's instruction, and immediately before art. 14, which governs sensitive data. It has three unnumbered paragraphs and follows the Directive 95/46/EC art. 15 template closely. The first: no judicial decision involving an appraisal of the conduct of a natural person may have as its foundation an automated processing of personal data intended to evaluate certain aspects of their personality. The second: no decision producing legal effects in regard to a natural person may be taken on the sole foundation of an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third is a deeming clause rather than a true exception: decisions taken in the context of the conclusion or performance of a contract, and for which the person concerned was put in a position to present their observations, and decisions satisfying the requests of the person concerned, are not regarded as taken on the sole foundation of an automated processing. As in Guinea, Madagascar and Gabon, the judicial limb omits the word "seul" that the second limb carries, so a Congolese court appraising conduct may not rest on such a processing at all. The second limb takes the narrow Directive trigger confined to decisions producing legal effects, which places Congo with Gabon, Togo, Senegal, Morocco and Algeria rather than with the wide-trigger group. What distinguishes this row from every other Francophone entry is the thinness of what surrounds it. The Law creates no right to know the logic underlying an automated processing — the words logique, raisonnement and profilage appear nowhere in it — no human-review right, no right to a fresh non-automated decision, and no definition of profiling. Art. 13 is a bare prohibition with a deeming clause and nothing else.

The Law carries no commencement article. Art. 101, its final provision, is a bare publication and execution clause — the present Law shall be published in the Journal officiel de la République du Congo and executed as a law of the State — and nothing in the text defers art. 13. The date recorded here is the date of publication of the gazette in which the Law appears: Journal officiel de la République du Congo n° 45-2019, whose issue date, printed on the running heads of the issue, is Thursday 7 November 2019. The Law itself is dated 10 October 2019 at Brazzaville, over the signatures of President Denis Sassou-Nguesso, Prime Minister Clément Mouamba, the Minister of Justice Aimé Ange Wilfrid Bininga and the Minister of Posts, Telecommunications and the Digital Economy Léon Juste Ibombo, and it is by that promulgation date that it is universally cited. The gazette date is preferred here over the promulgation date because art. 101 attaches publication rather than promulgation, which is the same choice made for Togo. Confidence is medium because the Congolese general publication-to-force rule was not verified against a primary source: if force runs from promulgation rather than from publication the operative date is 10 October 2019, four weeks earlier, and if the general rule adds a clear-days delay after publication it is later. Both candidate dates are long past, so the lifecycle of this row is unaffected either way. Art. 100 is transitional and is not a deferral of art. 13, which is a prohibition rather than a conformance duty: from entry into force, all data processing had to meet the Law's prescriptions within two years where operated for the State, a public establishment, a decentralised administrative entity or a private-law legal person managing a public service, and within one year for everyone else, so the outer conformance window closed in November 2021 on the date recorded here. Art. 99 subjects already-created public-sector processing to a declaration only. The Law abrogates nothing expressly and names no predecessor statute, so nothing is superseded on the tracker. Text read in the Journal officiel itself, published by the Secrétariat général du Gouvernement, covering the whole of the Law from art. 1 to the signature block, including the definitions, the arts. 12 to 14 principles, the arts. 32 to 40 formalities, the arts. 90 and 91 data-protection-officer provisions and the arts. 92 to 101 sanctions and final chapters. No AI-specific statute or guidance is in force in the Republic of the Congo. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. the Republic of the Congo deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 23 October 2020, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. Art. 14(5) of the Convention states the same bar as art. 13 and admits no exception of any kind — no contract limb, no consent limb, no legal-authorisation limb. Art. 13's third limb is a deeming clause rather than a true exception, but it operates as one: a decision taken in the context of the conclusion or performance of a contract and for which the person concerned was put in a position to present their observations, and a decision satisfying the person's own requests, are treated as not taken on the sole foundation of automated processing, and so fall outside the prohibition entirely. The Convention has no deeming clause and no observations proviso, so the same contractual decision that escapes art. 13 is caught by art. 14(5). The national statute is carried here as the operative rule, because it is the instrument that has a supervisory authority behind it and a penalty attached to it, and the Convention runs behind it as a stricter parallel rule. This is recorded as a divergence rather than resolved: neither instrument repeals or qualifies the other, the Republic of the Congo has not legislated the Convention into domestic law by a separate instrument, and the domestic reception question — whether art. 14(5) is directly effective in the Republic of the Congo, as arts. 18 and 144 of the Mozambican and Namibian constitutions respectively make it there — has not been separately verified for the Republic of the Congo and is not asserted here. A controller relying on an exception the statute grants therefore stands on solid statutory ground and unresolved treaty ground.

Stated maximum penalty — The route to art. 13 is administrative, it is two-step, and the fine is not available for the breach itself. Art. 92 gives the Commission a catch-all first step: it may pronounce a warning against a controller not respecting the obligations flowing from the present Law, and a mise en demeure to cause the breaches concerned to cease within the time limit it fixes. Because that is drafted against the Law's obligations generally rather than against an enumerated list, it reaches art. 13. Art. 93 then supplies the teeth, but only conditionally: if the controller does not comply with the mise en demeure addressed to them, the Commission may, after a contradictory procedure, pronounce a provisional withdrawal of the authorisation granted or a provisional prohibition of processing not exceeding three months, a definitive withdrawal of the authorisation or a definitive prohibition of processing, an injunction to cease the processing where it falls under the declaration regime or benefits from the arts. 32 and 33 dispensations, and a pecuniary fine of one million to one hundred million francs CFA, recovered in accordance with the legislation on the recovery of State debts. A controller that breaches art. 13 and then complies with the resulting mise en demeure is therefore exposed to no fine at all. Art. 94 supplies an urgency track independent of that sequence: where the implementation of a processing or the exploitation of personal data entails a violation of rights and liberties, the Commission may, after a contradictory procedure, decide the interruption of the processing for a maximum of three months, the locking of certain data for a maximum of three months, or the temporary or definitive prohibition of a processing contrary to the Law. Art. 95 requires sanctions to rest on a report by a designated member, notified to the controller, who may file observations and be represented or assisted; art. 96 allows sanctions to be made public and inserted in publications at the sanctioned person's expense; art. 97 opens recourse against the Commission's sanctions and decisions to the Cour suprême. On the penal side the Law creates no offence of its own: art. 98 provides simply that infringements of the provisions of the present Law are provided for and repressed by the Penal Code and by the law on combating cybercrime, which places Congo with Senegal and Burkina Faso as a statute that refers all criminal enforcement out to other instruments.

In force · 7 Nov 2019 checked 20 Sep 2026 Loi n° 29-2019 art. 13 ↗ high confidence

Switzerland 1

Switzerland Binding

revFADP art. 21 — the automated-decision article that never prohibits anything

Binds Every controller within the Act's scope, private or federal, with no size, sector or turnover threshold — enterprise, SME and federal body alike. The obligation is drafted onto «the controller» without qualification, and the small-and-medium carve-outs that exist elsewhere in the revFADP do not reach it: the exemption in art. 12(5) from keeping a record of processing activities, granted to businesses with fewer than 250 employees whose processing poses a low risk of a violation of personality, is an exemption from the record duty alone and has no counterpart for art. 21. Switzerland is not an EU or EEA member and the GDPR does not supply this rule domestically, so art. 21 is the operative automated-decision provision for anyone processing in or into Switzerland. Extraterritorial reach follows art. 3(1), under which the Act «applies to circumstances that have an effect in Switzerland, even if they are initiated abroad» — a marketplace test written more broadly than GDPR art. 3(2), with no establishment or targeting requirement on its face, so an offshore scoring engine producing a considerable adverse effect on a person in Switzerland is inside the scope. Art. 14 requires a controller with no domicile or registered office in Switzerland to designate a representative in Switzerland in the cases it lists. Hiring, credit scoring, insurance underwriting and tenant screening all sit squarely in the wording: each turns on a decision exclusively automated and each produces either a legal consequence or a considerable adverse effect. Two boundaries are worth stating because they are where the article stops. First, «based exclusively on automated processing» — a decision with a human materially in the loop is outside art. 21 altogether, and the Act supplies no gloss on how much review defeats exclusivity. Second, profiling as such is not caught: the revFADP defines profiling in art. 5(f) and high-risk profiling in art. 5(g), and attaches consequences to them elsewhere, but art. 21 is triggered by the decision and its effect, not by the profiling that fed it.. Article 21 of the Federal Act on Data Protection of 25 September 2020 (SR 235.1) is the closest thing Switzerland has to GDPR art. 22, and the difference starts with the heading, which is worth quoting because almost every secondary account renames it. The official English rubric is «Duty to provide information in the case of an automated individual decision» — not «automated individual decision-making», and not a prohibition. Nothing in the article forbids a solely automated decision. Art. 21(1) provides that «the controller shall inform the data subject about any decision that is based exclusively on automated processing and that has a legal consequence for or a considerable adverse effect on the data subject (automated individual decision)». The trigger is therefore disjunctive and the second limb is softer than the GDPR's: a «considerable adverse effect» reaches further down than «similarly significantly affects», and the Swiss text needs no legal consequence at all if the adverse effect is considerable. Art. 21(2) supplies the safeguard pair: «It shall on request allow the data subject to express their point of view. The data subject may request that the automated individual decision be reviewed by a natural person.» Both limbs are reactive — they arm only on request, and the controller owes nothing until asked. Art. 21(3) then disapplies paras 1 and 2 entirely where (a) «the automated individual decision is directly connected with the conclusion or the processing of a contract between the controller and the data subject and the data subject's request is granted», or (b) «the data subject has explicitly consented to the decision being automated». Limb (a) is narrower than it looks and is the one most often mis-summarised: the contract connection alone does not suffice, because the exception also requires that the data subject's request be granted. A solely automated contractual refusal — the declined loan, the rejected policy, the failed tenancy screen — is precisely the case the exception does not cover, so the duty bites hardest exactly where the outcome is adverse. Art. 21(4) is the public-sector rule: a federal body issuing an automated individual decision «must designate the decision accordingly», a labelling duty owed without any request, and para. 2 falls away where art. 30(2) of the Administrative Procedure Act of 20 December 1968 or another federal act denies the data subject a hearing before the decision is taken. There is no right to an explanation of the logic anywhere in art. 21. The nearest thing sits in the art. 25 right of access, which is a general access right and not an automated-decision one.

In force since 1 September 2023, and the date belongs to the totally revised Act rather than to any amendment of it. The Federal Act on Data Protection was adopted by the Federal Assembly on 25 September 2020; art. 74(2) left commencement to the Federal Council, which fixed it by decision (BRB) of 31 August 2022, and the consolidated Fedlex text carries the running head «of 25 September 2020 (Status as of 1 September 2023)» with the closing line «Commencement date: 1 September 2023». There was no transition period and no staged entry into force for art. 21: unlike the 2018 EU changeover there was no two-year runway, and unlike the Mauritian scheme there is no power to appoint different dates for different sections. The Act replaced the Federal Act on Data Protection of 19 June 1992 outright, and the 1992 Act contained no automated-decision provision at all, so 1 September 2023 is the first date on which any Swiss automated-decision rule bound a private controller. Two adjacent dates should not be carried into this row. The Data Protection Ordinance (DPO, SR 235.11) of 31 August 2022 commenced the same day but adds nothing on automated decisions. And the Council of Europe's modernised Convention 108+, which Switzerland signed on 10 October 2018 and whose art. 9(1)(a) carries a right not to be subject to a solely automated decision, is not yet in force — it needs 38 ratifications under its own amending-protocol terms and Switzerland's ratification followed the revFADP rather than preceding it, so the treaty is not an independent operative source here in the way the Malabo Convention is for Namibia. Convention 108 in its original 1981 form, which Switzerland ratified on 2 October 1997, has no automated-decision article. One live supersession watch: Switzerland and the EU concluded a package of bilateral agreements in 2025 whose institutional provisions could bear on the adequacy footing this Act was drafted to protect, and the European Commission's adequacy decision for Switzerland, adopted 15 January 2024 under GDPR art. 45, is subject to periodic review. Neither touches the text of art. 21, and neither is treated as changing it here.

Stated maximum penalty — CHF 250,000 — but on a natural person, on complaint only, and not for every breach of art. 21, and each of those three qualifications is load-bearing. The revFADP gives the Federal Data Protection and Information Commissioner no power to impose an administrative fine at all; this is the structural difference from the GDPR and the reason the headline figure is so often misread as a corporate exposure. Art. 60(1) provides that «on complaint, a fine not exceeding 250,000 francs shall be imposed on private persons who: a. violate their duties under Articles 19, 21 and 25–27, in that they wilfully provide false or incomplete information; b. fail wilfully: 1. to provide information to the data subject in accordance with Articles 19 paragraph 1 and 21 paragraph 1». Three limits follow from that text. It reaches art. 21(1), the duty to inform, and it does not reach art. 21(2): a controller who receives a request for human review and simply refuses it commits no offence under art. 60, because para. 2 appears nowhere in the list. It requires wilfulness — negligence is not enough. And it is an offence prosecuted «on complaint» (Antragsdelikt), not ex officio. Art. 64 then decides who pays. Art. 64(1) routes corporate criminal liability to arts. 6 and 7 of the Federal Act of 22 March 1974 on Administrative Criminal Law, and art. 64(2) provides that «if a fine not exceeding 50,000 francs is under consideration and if the identification of the perpetrators in accordance with Article 6 ACLA requires measures that would be disproportionate in view of the potential penalty, the authority may decide not to pursue these persons but instead to order the business to pay the fine». So the CHF 250,000 maximum is aimed at the responsible individual, and the route to fining the undertaking instead is capped at CHF 50,000 and is available only as a proportionality shortcut. Art. 65(1) makes prosecution and adjudication a matter for the cantons, with the FDPIC able under art. 65(2) to file a complaint and exercise the rights of a private claimant; art. 66 sets a five-year statute of limitations. The FDPIC's own powers under art. 51 are corrective rather than pecuniary — it may order processing to be adjusted, suspended or terminated and data to be deleted. Impact tier: all entities.

In force · 1 Sep 2023 checked 14 Sep 2026 revFADP art. 21 ↗ high confidence

Côte d'Ivoire 1

Côte d'Ivoire Binding

Loi 2013-450 art. 25 — no judicial, administrative or private decision appraising human conduct may rest on automated profiling, with no carve-out at all

Binds Responsables du traitement within the scope of art. 3, which subjects to the Law any collection, processing, transmission, storage and use of personal data by a natural person, the State, local authorities or legal persons of public or private law; any processing, automated or not, of data contained in or intended to form part of a file; any processing implemented on national territory; and any processing concerning public security, defence, investigation and prosecution of criminal offences or State security, subject to derogations fixed by other legislation in force. Art. 4 excludes processing by a natural person in the exclusive course of personal or domestic activities where the data are not intended for systematic communication to third parties or for dissemination, and temporary copies made for technical transmission and access purposes. Prior declaration to the Autorité de protection is a standing precondition under art. 5, with prior authorisation required under art. 7 for genetic, medical and research data, offence and conviction data, national identification numbers, biometric data, public-interest processing and transfers to third countries, and art. 13 requiring a decree for processing on behalf of the State. The art. 25 bar binds courts under its first limb and every administrative or private decision-maker under its second, irrespective of size or sector. Impact tier: all entities.. Article 25 of Loi n° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel is Côte d'Ivoire's operative automated-decision rule. It sits at the end of Chapitre 4 (principes-directeurs du traitement des données à caractère personnel), immediately before the cross-border-transfer article, and has two limbs in two unnumbered paragraphs. The first is addressed to the courts: no judicial decision involving an appraisal of the conduct of a natural person may have as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality. The second reaches beyond the courts and is drafted more widely than any comparable African provision: no administrative or private decision involving an appraisal of human conduct may have as its sole foundation an automated processing of personal data giving a definition of the profile or of the personality of the person concerned. Two features distinguish it. First, the second limb is not confined to decisions producing legal effects and carries no significant-effect threshold either — the trigger is an appraisal of human conduct, whoever takes the decision and whatever its effects, so it is wider on its face than Morocco's and Algeria's art. 11. Second, and unusually, the Law supplies no carve-out whatever: there is no contract-formation or contract-performance deeming clause, no consent exception, no legal-authorisation exception and no opportunity-to-present-observations proviso. The Law also creates no right to know the logic underlying an automated processing — the art. 29 access right runs to information enabling the data subject to know and to contest the processing, the confirmation that data are processed, communication of the data and of any available information as to their origin, and information on purposes, categories and recipients — and no right to obtain human intervention or a fresh non-automated decision. The Law carries no definition of profiling; art. 25 speaks of an automated processing giving a definition of the profile or the personality of the person concerned.

Art. 54, the final article, is a bare publication clause — the Law "sera publiée au Journal officiel de la République de Côte d'Ivoire et exécutée comme loi de l'Etat" — and the Law contains no commencement article and defers nothing. The text was adopted by the Assemblée nationale, promulgated by the President at Abidjan on 19 June 2013 and published in the Journal officiel de la République de Côte d'Ivoire of 8 August 2013 at pp. 474 to 482, which is the date recorded here; the promulgation date of 19 June 2013 appears in the title and above the presidential signature. Confidence is medium for the same reason as Morocco's and Algeria's art. 11: the Ivorian general publication-to-force rule was not itself read against a primary source, so it could not be confirmed whether force attaches on the day the Journal officiel is published or after the customary jour franc. Art. 53 is transitional and not a deferral of art. 25: controllers already processing personal data had six months from the entry into force of the Law to bring themselves into conformity, a period that closed in 2014. Two typesetting defects in the gazetted text are recorded for candour and neither touches art. 25: the Chapitre 2 heading on p. 476 and the opening of art. 32 on p. 479 both carry a stray line reading "du secrétaire permanent de la Commission nationale du Fonds pour l'Environnement mondial", plainly imported in error from another text in the same issue. Coverage symmetry against the ten African rows already tracked: art. 25 belongs to the Directive 95/46/EC art. 15 line that reaches West Africa through art. 42 of the ECOWAS Supplementary Act A/SA.1/01/10 on personal data protection, and it is the third member of the Directive family on the tracker alongside ma-loi0908-art11 and dz-loi1807-art11. The African picture is now four-way: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37 and rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36 and ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11 and now ci-loi2013450-art25; and a Directive-family statute from which the automated-decision article is simply absent = Tunisia's Loi organique 2004-63, which is why each Francophone statute is read article by article rather than assumed. Within the Directive family Côte d'Ivoire is the outlier in both directions: it is the widest, because its second limb reaches any administrative or private decision appraising human conduct rather than only decisions producing legal effects, and it is the barest, because Morocco and Algeria both deem contract decisions with an opportunity to present observations outside the bar while Côte d'Ivoire states no exception at all. Like Morocco and Algeria it grants no human-review right; unlike Morocco, which has the art. 7(c) right to know the logic of an automated processing, Côte d'Ivoire has no logic-disclosure right at all. Text read page by page in the Journal officiel de la République de Côte d'Ivoire of 8 August 2013 as published by the Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire, which art. 46 designates as the Autorité de protection. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. Côte d'Ivoire deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 3 April 2023, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. This is the second of the two party rows where the overlay changes nothing, and here the national law is the stricter instrument on both axes. Art. 14(5) of the Convention admits no exception of any kind, and neither does art. 25, which supplies no contract-formation or contract-performance deeming clause, no consent exception, no legal-authorisation exception and no opportunity-to-present-observations proviso. Art. 25 is then wider in scope than the treaty: its second limb reaches any administrative or private decision appraising human conduct, where art. 14(5) reaches only a decision producing legal effects or significantly affecting the person to a substantial degree. The Convention adds no stricter rule in Côte d'Ivoire, and the absence of a divergence here is a checked finding rather than an open question.

Stated maximum penalty — No criminal offence attaches to art. 25. The Law's three penal provisions each name their own conduct and none of them reaches an automated decision: art. 21 punishes the collection and processing of data revealing racial, ethnic or regional origin, filiation, political opinions, religious or philosophical convictions, trade-union membership, sexual life, genetic data or health with ten to twenty years' imprisonment and a fine of 20,000,000 to 40,000,000 francs CFA; art. 22 punishes direct marketing by any means of communication using the personal data of a natural person who has not given prior consent with one to five years' imprisonment and a fine of 1,000,000 to 10,000,000 francs CFA; and art. 45 punishes obstruction of the Autorité de protection with one month to two years' imprisonment and a fine of 1,000,000 to 10,000,000 francs CFA. The route that does reach art. 25 is administrative. Art. 49 lets the Autorité de protection issue a warning to a controller that does not respect the obligations arising under the Law and a formal notice (mise en demeure) to cease the failures observed within a period it fixes. Art. 50 lets it decide, after an adversarial procedure, to interrupt the processing, to block certain data or to prohibit temporarily or definitively a processing contrary to the Law where implementation entails a violation of rights and freedoms. Art. 51 lets it, after hearing a controller or processor that has not complied with the Law and with the formal notice addressed to it, pronounce provisional withdrawal of the authorisation, definitive withdrawal of the authorisation, or a pecuniary sanction proportionate to the gravity of the failures and to the advantages drawn from them; that pecuniary sanction may not exceed 10,000,000 francs CFA, and on a repeated failure within five years from the date on which a previous pecuniary sanction became definitive it may not exceed 100,000,000 francs CFA or, in the case of an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of 500,000,000 francs CFA. Art. 51 adds that these administrative and pecuniary sanctions apply without prejudice to penal sanctions, and art. 52 leaves the modalities of withdrawal and of recovery of the pecuniary sanction to decree.

In force · 8 Aug 2013 checked 21 Sep 2026 Loi n° 2013-450 art. 25 ↗ medium confidence

Chile 2

Chile Binding

Código del Trabajo Cap. X — ban on discriminatory automated decision-making and algorithm access for digital-platform work

Binds Digital service platform companies as defined in Art. 152 quáter Q — undertakings that, by themselves or through third parties, administer or manage a computer or IT system or application to intermediate the provision of services by digital-platform workers — for services provided in Chilean territory, in respect of both dependent and independent platform workers (Art. 152 quáter P). Impact tier: enterprise (platform operators), with duties owed to every platform worker.. Ley 21.431 inserted Chapter X, 'Del trabajo mediante plataformas digitales de servicios', into Title II of Book I of the Código del Trabajo. Art. 152 quinquies E prohibits discrimination through automated decision-making: in implementing its algorithms the platform must respect equality and non-discrimination and take all measures needed to avoid any discrimination between workers, expressly in work allocation, the offer of bonuses and incentives and the calculation of pay; apparently neutral employer conduct whose result disproportionately affects one or more workers also counts as discrimination; and the platform must inform its workers of the mechanisms and procedures it adopts in giving effect to that rule. Art. 152 quinquies D adds a transparency and information right: platform-held worker data are strictly confidential, the worker may at any time request access to their personal data — in particular ratings data that bear on their work — which must be delivered within fifteen working days, may request portability in a structured, generic, commonly used format, and, for proper supervision by the competent authorities, the platform must on request give access to the programming of the algorithm, to full and sufficient explanations of how it makes its decisions, to the data it was trained on and to every other factor relevant to full compliance with the law. Art. 152 quinquies C requires the worker to be told the place of performance, the identity of the user and the means of payment before accepting a job.

Commencement is on the face of the law: Artículo primero transitorio of Ley 21.431 provides that the law enters into force on the first day of the sixth month following its publication in the Diario Oficial. The law was promulgated 8 March 2022 and published 11 March 2022 (BCN metadata fecha_promulgacion 2022-03-08, fecha_publicacion 2022-03-11), giving 1 September 2022, which is also the date stated in the BCN official summary of the norm. Text read in the Biblioteca del Congreso Nacional LeyChile XML for idNorma 1173544 and cross-checked against the consolidated Código del Trabajo (DFL 1 of 2002/2003, idNorma 207436), where Arts. 152 quinquies C, D, E and I all appear unamended. Verified 2026-08-15 after the BCN www.bcn.cl/leychile/consulta/obtxml endpoint returned HTTP 429 on repeated attempts; the same service is reachable without the quota error on the backend host servicios-leychile.bcn.cl, which is what the LeyChile front end itself calls. Artículo segundo transitorio (three years to meet the requirement of Art. 19 of the Code) and Artículo tercero transitorio (three annual Consejo Superior Laboral evaluation reports) have both expired. This is Chile's peer of mx-lft-plataformas-algoritmo and of Art. 20 of the CAC Algorithmic Recommendation Provisions (cn-algo-recommendation); unlike the Mexican chapter it carries no right to human review of deactivation decisions. AIL-300 computation check (2026-08-31): 1 September 2022 verified against the statutory text. Artículo primero transitorio of Ley 21.431 reads verbatim «La presente ley entrará en vigencia el primer día del sexto mes siguiente a su publicación en el Diario Oficial» (LeyChile XML for idNorma 1173544, fechaPublicacion 2022-03-11). Like Ley 21.719 this names a calendar day rather than setting a plazo, so Código Civil arts. 48–50 have nothing to compute and art. 49's «después de la medianoche» rule does not engage. March 2022 is the month of publication and is not a month «siguiente» to it; counting from April 2022, the sixth following month is September 2022, first day 1 September 2022.

Stated maximum penalty — Art. 152 quinquies I makes the Dirección del Trabajo the supervisor of Chapter X, singling out the obligations in Arts. 152 quáter Z and 152 quinquies E, and applies the fines of Art. 506 of the Código del Trabajo, doubled on repeat offence: 1 to 5 UTM for micro enterprises, 1 to 10 UTM for small enterprises, 2 to 40 UTM for medium enterprises and 3 to 60 UTM for large enterprises, according to the gravity of the infringement. The UTM is re-set monthly by the Servicio de Impuestos Internos, so the peso value of each band moves each month.

In force · 1 Sep 2022 checked 15 Sep 2026 Código del Trabajo Cap. X (Ley 21.431) ↗ high confidence
Chile Binding

Ley 19.628 Art. 8° bis (inserted by Ley 21.719) — right to object to solely-automated decisions and profiling

Binds Controllers of personal data ('responsables de datos'), public and private, within the scope of Ley 19.628 as amended, including controllers not established in Chile whose processing is aimed at offering goods or services to data subjects in Chile or at monitoring their behaviour, expressly including its analysis, tracking, profiling or prediction. Impact tier: all entities.. Ley 21.719, which overhauls Chilean data-protection law and creates the Agencia de Protección de Datos Personales, inserts a new Art. 8° bis into Ley 19.628 headed 'Decisiones individuales automatizadas, incluida la elaboración de perfiles'. The data subject has the right to object to, and not to be subject to, decisions based on the automated processing of their personal data, including profiling, that produce legal effects on them or significantly affect them. The right does not apply where the decision is necessary to conclude or perform a contract between the subject and the controller, where the subject has given prior express consent in the form prescribed by Art. 12, or where a law so provides and lays down safeguards. In all cases of automated decision-making, including those three exceptions, the controller must adopt the measures needed to secure the subject's rights and freedoms, their right to information and transparency, and their right to obtain an explanation, to human intervention, to express their point of view and to request review of the decision. 'Elaboración de perfiles' is defined in the new Art. 2 w) as any automated processing used to evaluate, analyse or predict a person's professional performance, economic situation, health, preferences, interests, reliability, behaviour, location or movements. Two related duties attach: Art. 14 ter l) requires the controller to disclose the existence of automated decisions and profiling together with meaningful information on the logic applied and the expected consequences, and Art. 15 bis makes a data-protection impact assessment mandatory where there is systematic and exhaustive evaluation of personal aspects based on automated processing or decisions, such as profiling, producing significant legal effects.

Ley 21.719 was published in the Diario Oficial on 13 December 2024. Artículo primero transitorio provides that the amendments to Ley 19.628, Ley 20.285 and Ley 19.496 contained in the first, second and third permanent articles enter into force on the first day of the twenty-fourth month after publication, i.e. 1 December 2026 — the same date carried in the BCN norm metadata (fecha_vigencia 2026-12-01, idNorma 1209272). Artículo segundo transitorio required the implementing regulations within six months of publication and Artículo cuarto transitorio required the first Agency board to be appointed six months before entry into force; implementation instruments already published include Decreto 12 of 17 June 2025 creating the ministerial implementation commission, Resolución Exenta 202503748 of 19 December 2025 approving the model contractual clauses for international transfers, and Resolución Exenta 1400 of 24 June 2026 on the procedures for Arts. 54 and 55, the last two of which themselves take effect on 1 December 2026. Text read in the Biblioteca del Congreso Nacional LeyChile XML for idNorma 1209272 via the backend host servicios-leychile.bcn.cl after the public www.bcn.cl endpoint returned HTTP 429. Chile's peer of br-lgpd-art20, cn-pipl-art24, kr-pipa-art37-2-adm and ar-ley25326-art20; unlike Argentina's Art. 20 it is a full GDPR-style right with explanation, human intervention and review, and unlike Brazil's Art. 20 it is not yet in force. Postponement risk (as of 2026-08-17): 1 December 2026 remains the legally operative date on the face of the law — no decree or amending law has changed it — but on 4 August 2026 co-Minister of Economy Daniel Mas publicly confirmed the government is evaluating postponing entry into force, because the Agencia de Protección de Datos Personales still has no seated Consejo Directivo: the Senate rejected the President's first slate of three nominees in May 2026 for lack of the required two-thirds quorum, and the June 2026 statutory deadline to appoint the board has lapsed. No amending bill has yet been introduced. Source: https://www.emol.com/noticias/Economia/2026/08/04/1207539/gobierno-postergar-ley-datos-personales.html Update (2026-09-04): on 1 September 2026 the Executive formally introduced a bill to the Senate, with urgency, to postpone Ley 21.719's entry into force from 1 December 2026 to 1 December 2027 and to expand the Agencia's Consejo Directivo from 3 to 5 members; the bill has not passed, so 1 December 2026 remains the operative statutory date. Source: https://www.df.cl/economia-y-politica/congreso/gobierno-ingresa-al-congreso-proyecto-que-posterga-por-un-ano-la-entrada-en AIL-300 computation check (2026-08-31): 1 December 2026 is verified against the statutory text, not derived by arithmetic. Artículo primero transitorio reads verbatim «entrarán en vigencia el día primero del mes vigésimo cuarto posterior a la publicación de esta ley en el Diario Oficial» (LeyChile XML for idNorma 1209272 via servicios-leychile.bcn.cl, fechaPublicacion 2024-12-13). That clause designates a calendar day, not a plazo, so the Código Civil rules on computing statutory terms have nothing to move: art. 48 governs «todos los plazos de días, meses o años» and fixes the same-numbered-day rule for month-plazos, and art. 49 provides that where «se exige que haya transcurrido un espacio de tiempo para que nazcan o expiren ciertos derechos» those rights arise only «después de la medianoche» ending the last day — which is precisely the trap that moved py-ley7593-art33 by a day. Neither applies here, because no period has to elapse: the article names the first day of a stated month. December 2024 is the month of publication and so is not «posterior a la publicación»; the first posterior month is January 2025 and the twenty-fourth is December 2026, giving 1 December 2026 — the same date carried in the BCN norm metadata.

Stated maximum penalty — Enforced by the Agencia de Protección de Datos Personales under the new sanction regime of Ley 19.628. Art. 35: minor infringements draw a written warning or a fine of up to 5,000 UTM, serious infringements up to 10,000 UTM and very serious infringements up to 20,000 UTM. Obstructing or impeding the legitimate exercise of the right to object is a serious infringement under Art. 34 ter e); any other breach of the rights and duties of the law that is not classified as serious or very serious is a minor infringement under Art. 34 bis f). Repeat infringement allows a fine of up to three times the amount for the infringement committed, and for an infringer that is not a smaller enterprise under Art. segundo of Ley 20.416 repeating a serious or very serious infringement, up to 2% or 4% of annual turnover from sales, services and other business activities in the last calendar year. Repeated very serious fines within twenty-four months allow suspension of processing operations for up to thirty days (Art. 38). For public bodies the fine is 20% to 50% of the monthly salary of the head of the infringing body.

Applies 1 Dec 2026 checked 22 Sep 2026 Ley 19.628 Art. 8° bis (Ley 21.719) ↗ high confidence

Cameroon 1

Cameroon Binding

Loi n° 2024/017 art. 44 — the first GDPR-shaped bar in Francophone Africa, in the only African statute that makes profiling itself a crime

Binds Responsables de traitement and sous-traitants, who art. 20 makes subject to the same obligations in respect of processing activity. The art. 2 scope is unusually wide: the Law governs any processing of personal data carried out by the State, decentralised territorial collectivities or any other natural or legal person; any processing of the personal data of any person established, resident or in transit in Cameroon; any processing carried out by a controller or processor established in Cameroon; and any processing carried out in a territory where Cameroonian law applies by virtue of international law or duly ratified conventions. The transit limb is worth noting — it reaches the data of travellers passing through. Art. 3 excludes purely personal or domestic processing not intended for systematic communication to a third party or for dissemination, temporary technical copies made in transmission and access provision, and processing for literary, artistic, public-interest archival, scientific or historical research, statistical or journalistic purposes. Cameroon is also the only jurisdiction in the African block that gates processing generally rather than by category: art. 19(1) subjects the processing of personal data to the prior obtention of an authorisation delivered by the Autorité de protection des données à caractère personnel, and art. 19(2) adds a separate prior authorisation for any interconnection or interoperability process involving sensitive data files relating to minors, with the modalities of delivery left to regulation. Automated decision-making and profiling are not singled out for their own ex ante gate because everything already needs one. Art. 29 requires a processing register, art. 27(2) an annual security report to the Authority, and art. 25 a risk evaluation on criteria and validation modalities fixed by regulation. The art. 44 right binds every controller taking a decision based exclusively on automated processing, with no size, sector or legal-effects threshold — Cameroon states no requirement that the decision produce legal effects or significantly affect the person, which makes its trigger wider than the GDPR's. Impact tier: all entities.. Article 44 of Loi n° 2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun is Cameroon's operative automated-decision rule, and it is the first entry in the Francophone African block that is built on the GDPR rather than on Directive 95/46/EC. It sits in Titre III, Des droits de la personne concernée, which opens at art. 37 and runs through erasure and digital oblivion (arts. 37 and 38), access (art. 39), objection (art. 40), direct-marketing consent (art. 41), rectification (art. 42) and portability (art. 43). Art. 44(1) gives the data subject the right to object to any decision based exclusively on the automated processing of their personal data, including profiling. Art. 44(2) admits two exceptions and no more: where the data subject has been informed of the use of the automated decision-making system and has given prior, explicit and informed consent; and where the processing is authorised by law, provided that law lays down appropriate measures safeguarding the rights, freedoms and legitimate interests of the data subject. There is no contract limb — the carve-out that Directive-derived statutes such as Congo, Gabon, Togo and Senegal all carry for decisions taken in the conclusion or performance of a contract is simply absent, so a Cameroonian controller cannot excuse an automated decision by pointing to a contract. Art. 44(3) then supplies the safeguard package: the data subject also has the right to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision founded on the automated processing. Cameroon therefore joins the GDPR-lineage group of Kenya, Nigeria and Rwanda as its first Francophone member, and it states all three limbs of the art. 22(3) safeguard against a shorter exception list than the GDPR itself carries. The transparency side is carried by art. 21, the controller's information duty, which must be discharged at the latest at collection and which lists, among the rights whose existence must be disclosed, the right not to be subject to an individual automated decision, including profiling, and a distinct right to information on the taking of an automated decision, the underlying logic and the envisaged consequences of the processing. Profilage is defined in the definitions article as automated processing of personal data consisting in using them to evaluate certain personal aspects relating to a natural person, notably their health, preferences, location and economic situation. Art. 33 requires a prior data-protection impact assessment for any type of processing liable to engender a high risk to the rights and freedoms of natural persons.

Force. The Law carries no commencement article: art. 75, its final provision, says that the present Law, which abrogates all prior contrary provisions, shall be registered, published according to the urgency procedure, then inserted in the Journal Officiel in French and in English. The date recorded here is the promulgation date printed on the face of the Law over the signature of President Paul Biya at Yaoundé, 23 December 2024, which is also the date from which the Law's own transitional clock runs. Confidence is medium for the same reason as Morocco, Congo-Brazzaville and Gabon: the Cameroonian general publication-to-force rule was not verified against a primary source, so if force runs from insertion in the Journal Officiel rather than from promulgation the operative date is somewhat later. Nothing turns on the difference for the lifecycle of this row, because the date that actually matters to duty-holders has now passed on either reading. That date is 23 June 2026: art. 73 gives natural and legal persons in charge of the processing of personal data a period of eighteen (18) months from the date of promulgation of the present Law to conform to its provisions. Eighteen months from 23 December 2024 expired on 23 June 2026, so the conformance window closed roughly two months before this entry was written and art. 44 is fully operative against existing controllers. Art. 73 is a transitional conformance window on the Indonesian and Rwandan pattern, not a deferred commencement — it does not postpone the Law itself, which is why the row is dated from promulgation rather than from the end of the window. Two further caveats. First, art. 74 provides that particular texts shall specify, as needed, the modalities of application of the Law, and several provisions expressly await regulation: the art. 19(3) authorisation modalities, the art. 25(1) risk-evaluation criteria, the art. 32(3) transfer-authorisation modalities and the art. 35 monitoring and control modalities. Art. 44 is not among them — it is self-executing on its own terms and needs no implementing text. Second, the Autorité de protection des données à caractère personnel that the Law creates and that arts. 54 to 61 arm with the administrative sanctions had not been verified as operational when this entry was written, which affects who can enforce art. 44 administratively but not whether the duty exists; the arts. 62 to 71 civil and penal routes do not depend on the Authority existing. Supersession: the Law abrogates all prior contrary provisions without naming a predecessor data-protection statute, because there was none — before 23 December 2024 Cameroon was one of the last African states with no dedicated personal data protection law, its nearest instruments being Loi n° 2010/012 du 21 décembre 2010 on cybersecurity and cybercriminality and Loi n° 2010/013 on electronic communications, neither of which carries an automated-decision rule. Nothing on the tracker is superseded by this row. No AI-specific statute is in force in Cameroon and the Law does not define artificial intelligence; Gabon remains the only Francophone African data-protection statute that does. Text read page by page in the certified true copy published by the Presidency of the Republic (Secrétariat général, Service du fichier législatif et réglementaire), covering the arts. 1 to 5 scope and definitions, the arts. 6 to 18 principles, the art. 19 prior-formalities chapter, the arts. 20 to 35 controller obligations, the art. 36 interconnection chapter, the arts. 37 to 46 rights chapter, and the arts. 54 to 75 sanctions and final chapters.

Stated maximum penalty — Cameroon carries the heaviest enforcement apparatus of any African row on the tracker, and it is the only one in which profiling is itself a crime. Art. 65 punishes with three (03) to ten (10) years' imprisonment and a fine of one million (1,000,000) to twenty million (20,000,000) francs CFA, or one of those two penalties only, the controller or processor who carries out or causes to be carried out a processing of personal data for profiling purposes. That is a free-standing offence attaching to the act of profiling rather than to any breach of the art. 44 right, and it has no analogue anywhere else in the African block: in Ghana, Uganda, Madagascar, Congo-Brazzaville, Gabon, Morocco and Algeria no penal article reaches the automated-decision provision at all. Read with the art. 5 definition of profilage — automated processing used to evaluate personal aspects relating to a natural person, notably health, preferences, location and economic situation — art. 65 exposes ordinary commercial scoring, segmentation and recommendation practice to a custodial sentence, and it is not qualified by any of the art. 44(2) exceptions, which are drafted against art. 44(1) and not against the offence. Art. 71 lifts the ceiling for legal persons: notwithstanding the criminal liability of their directors, legal persons may be declared criminally liable and sentenced to a fine of fifty million (50,000,000) to one billion (1,000,000,000) francs CFA where the offences provided for by the Law have been committed by the persons responsible for them. Art. 64(1) supplies the route aimed at art. 44 itself: one (01) to three (03) years' imprisonment and a fine of fifty thousand (50,000) to one million (1,000,000) francs CFA, or one of those two only, for the controller or processor who carries out or causes to be carried out a processing despite the objection of the data subject, where the processing responds to direct-marketing purposes or where the objection is founded on grounds provided for by law — and an art. 44(1) objection is founded on grounds provided for by law. Art. 63 punishes fraudulent, unfair or unlawful collection or access with two to five years and 200,000 to 5,000,000 francs CFA, doubled where accompanied by locking or encryption; art. 67 punishes purpose diversion and incompatible further processing with six months to two years and 500,000 to 5,000,000 francs CFA; art. 69 punishes unlawful international transfer with three to ten years and 2,000,000 to 20,000,000 francs CFA. On the administrative side, art. 54 gives the Authority a ten (10) day mise en demeure, an injunction to bring the processing into conformity under a penalty payment not exceeding one hundred thousand (100,000) francs CFA per day of delay, and, on non-compliance, suspension of the activity covered by the authorisation, withdrawal of the authorisation, or prohibition of any personal-data processing activity. Art. 55 exposes processing without prior authorisation to 5,000,000 to 50,000,000 francs CFA; art. 56 exposes refusal to make requested information available to the data subject to 1,000,000 to 10,000,000 francs CFA, which is the administrative route reaching an art. 21 or art. 39 failure; art. 57 exposes breach of the Authority's référentiel to 5,000,000 to 20,000,000 francs CFA; art. 61 exposes breach of a cahier des charges obligation to 10,000,000 to 100,000,000 francs CFA. Art. 62 preserves the civil route: on a serious infringement of the rights mentioned in the Law the data subject may ask the competent court, ruling under the urgency procedure, to order any measure necessary to safeguard their rights, if need be under a penalty payment, and may separately seek reparation.

In force · 23 Dec 2024 checked 21 Sep 2026 Loi n° 2024/017 art. 44 ↗ medium confidence

China 5

China Binding

China PIPL Art. 24 — automated decision-making transparency, opt-out and explanation

Binds Personal information handlers (organisations and individuals that independently determine the purposes and means of processing) processing personal information within China, and — under Art. 3 — handlers outside China processing the personal information of natural persons in China to provide them products or services or to analyse or assess their conduct. 'Automated decision-making' is defined in Art. 73(2) as activities that automatically analyse or assess an individual's behavioural habits, interests or economic, health or credit situation by computer program, and make decisions. Impact tier: all entities.. Personal information handlers using personal information for automated decision-making must ensure the transparency of the decision-making and the fairness and impartiality of the result, and may not impose unreasonable differential treatment on individuals in transaction prices or other transaction conditions. Where information push delivery or commercial marketing is carried out through automated decision-making, an option not targeted at the individual's personal characteristics must be offered at the same time, or a convenient way to refuse must be provided. Where an automated decision has a major effect on an individual's rights and interests, the individual may require the handler to explain it and may refuse a decision made solely by automated means. Art. 55(2) additionally requires a personal information protection impact assessment before any automated decision-making, with the report and processing record kept at least three years (Art. 56).

Text verified in two official versions carrying identical wording of Arts. 24, 55, 66, 73 and 74: the NPC text at http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html (http only — npc.gov.cn does not answer on https, so the cited link is the CAC republication) and the Cyberspace Administration of China republication cited here. Commencement is on the face of the statute: PIPL Art. 74 states the Law takes effect 1 November 2021 (adopted by the NPC Standing Committee 20 August 2021). Art. 24 is the general personal-data ADM duty and is distinct from, and cumulative with, China's AI-specific CAC instruments already tracked (cn-genai-interim, cn-deep-synthesis, cn-ai-labelling, cn-anthropomorphic-ai, cn-ai-agents-opinions): the trigger here is personal-information processing, not the provision of an AI service. Note the second paragraph is the statutory basis for the 'convenient refusal' switch that later CAC algorithm rules operationalise, and the first paragraph is the basis for enforcement against algorithmic differential pricing. Coverage-symmetry note (2026-08-15): the CAC Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (in force 1 March 2022) are a separate, not-yet-tracked instrument — logged as a follow-up gap, not merged into this row.

Stated maximum penalty — PIPL Art. 66: order to correct, warning, confiscation of unlawful gains, and an order to suspend or terminate the offending app; if correction is refused, a fine up to RMB 1,000,000 plus RMB 10,000-100,000 on the directly responsible persons. Where the circumstances are serious, a provincial-level or higher authority may confiscate unlawful gains and impose a fine up to RMB 50,000,000 or 5% of the prior year's turnover, order suspension of business or closure for rectification, and notify the competent authority to revoke the business permit or licence; RMB 100,000-1,000,000 on the directly responsible persons, who may also be barred for a period from serving as director, supervisor, senior manager or personal information protection officer. CAC-led enforcement.

In force · 1 Nov 2021 checked 4 Sep 2026 PIPL Art. 24 (2021) ↗ high confidence
China Binding

CAC Algorithmic Recommendation Provisions — disclosure, opt-out and algorithm filing

Binds Any provider applying algorithmic recommendation technology to supply internet information services within the territory of the PRC (Art. 2). 'Applying algorithmic recommendation technology' is defined as using generative/synthetic, personalised push, ranking and selection, retrieval and filtering, or scheduling and decision-making algorithms to provide information to users — a definition wide enough to cover feeds, search ranking, content moderation filters and platform dispatch systems, not only recommender feeds. The filing, disclosure-number and security-assessment duties in Arts. 24, 26 and 27 bind only the subset of providers with public-opinion attributes or social-mobilisation capacity. Impact tier: all entities.. Providers of internet information services that use recommendation algorithms must tell users conspicuously that an algorithmic recommendation service is being provided and publicise its basic principles, purpose and main operating mechanisms (Art. 16); offer an option not targeted at the user's personal characteristics or a convenient way to switch the recommendation service off, and let users select or delete the personal-characteristic tags used for recommendation (Art. 17); periodically review, assess and verify the algorithm's mechanisms, models, data and outputs, and not deploy models that induce addiction or excessive consumption (Art. 8); and label unlabelled algorithmically generated or synthesised information before further transmission (Art. 9). Providers with public-opinion attributes or social-mobilisation capacity must additionally file with the CAC internet information service algorithm filing system within 10 working days of starting service — submitting the provider name, service form, application field, algorithm type, algorithm self-assessment report and the intended public-disclosure content — file changes within 10 working days and deregister within 20 working days of termination (Art. 24), display the filing number and a link to the disclosure on their site or app (Art. 26), and carry out a security assessment (Art. 27). Sector rules also apply: protection duties for minors (Art. 18), the elderly (Art. 19), gig workers subject to algorithmic work dispatch (Art. 20), and a ban on unreasonable differential treatment of consumers on price or other transaction terms — algorithmic price discrimination (Art. 21).

Commencement is on the face of the instrument: Art. 35 states the Provisions take effect 1 March 2022, and the promulgation order records adoption at the 20th CAC executive meeting of 2021 on 16 November 2021, agreement by MIIT, the Ministry of Public Security and SAMR, and signature on 31 December 2021 (published 4 January 2022) as Order No. 9 of the four departments. Full Chinese text of Arts. 1-35 read at the cited CAC page. Distinct from, and cumulative with, the CAC instruments already tracked: cn-pipl-art24 is the statutory personal-information basis for the Art. 17 off-switch, while these Provisions are the operative administrative regime (filing system, self-assessment report, filing number display). Where a service also generates or synthesises content, cn-deep-synthesis, cn-genai-interim and cn-ai-labelling apply in parallel. Note npc.gov.cn is http-only; this instrument is a departmental rule (bumen guizhang), so the CAC publication is the authoritative text.

Stated maximum penalty — Art. 31: for breach of Arts. 7, 8, 9(1), 10, 14, 16, 17, 22, 24 or 26, where no other law or administrative regulation provides otherwise — warning, circulated criticism and an order to rectify within a time limit; if rectification is refused or the circumstances are serious, an order to suspend information updates plus a fine of RMB 10,000 to 100,000, with public-security penalties or criminal liability where applicable. Art. 33: obtaining a filing by concealment or false material means revocation of the filing, warning, circulated criticism and, in serious cases, suspension of information updates plus a fine of RMB 10,000 to 100,000. Art. 32 routes breaches of Arts. 6, 9(2), 11, 13, 15, 18, 19, 20, 21, 27 and 28(2) to the penalties of the underlying laws (e.g. PIPL Art. 66, up to RMB 50,000,000 or 5% of turnover, and the Minors Protection Law). Enforced by the CAC with MIIT, public-security and market-regulation authorities.

In force · 1 Mar 2022 checked 4 Sep 2026 CAC Algorithmic Recommendation Provisions (Order No. 9) ↗ high confidence
China Binding

AI-content labelling (+ GB 45438-2025)

Binds AI-content service & propagation platforms, app stores, and users. Explicit (visible) and implicit (metadata/watermark) labels on AI-generated content.

Stated maximum penalty — CAC administrative penalties

In force · 1 Sep 2025 checked 4 Sep 2026 CAC AI-Labelling Measures ↗ high confidence
China Binding

China AI Agents Implementation Opinions (CAC/NDRC/MIIT)

Binds Developers and deployers of AI agent services in China; mandatory compliance for healthcare, transportation, media, and public safety sectors; guidance-level for others. First national policy framework for AI agents. Mandatory for 19 priority sectors (healthcare, transport, media, public safety): filing, compliance testing, product recall provisions. Establishes three-tier decision authority model. AI-generated content labeling required. Enforceable via existing CSL/DSL/PIPL frameworks.

Published and operative from May 8, 2026 (jointly issued by CAC, NDRC, MIIT). Three-tier decision authority model: decisions requiring human-only authority; decisions requiring user approval; decisions agent may handle autonomously. High-risk sector filing and testing obligations enforceable under Cybersecurity Law, Data Security Law, PIPL. No standalone penalty regime; enforcement via existing frameworks.

Stated maximum penalty — Enforcement via CSL/DSL/PIPL (no standalone penalties specified)

In force · 8 May 2026 checked 4 Sep 2026 CAC/NDRC/MIIT AI Agents Implementation Opinions (May 2026) ↗ high confidence
China Binding

Anthropomorphic AI Interactive Services Measures

Binds Providers of anthropomorphic AI interactive services (virtual companions, emotional chatbots, human-like AI) publicly available in mainland China. Dedicated compliance regime for AI companion services, virtual chatbots and emotionally interactive AI; mandates AI-identity disclosure, minor protections, usage-time warnings, and prohibits inducing emotional dependence.

In force 15 Jul 2026. No confirmed enforcement actions as of 2026-08-08: exhaustive cross-check (Bird & Bird, IAPP, Covington, CAC official news/enforcement index, DigitalPolicyAlert) found no penalty decisions or enforcement notices. CAC does not publish a searchable administrative-penalty registry. A claim of 12 fines / RMB 4.2M circulates in AI-generated blog content (Cubbbix, Aug 2026; republished by Ethicore Substack verbatim) — not independently verifiable and treated as unconfirmed.

Stated maximum penalty — CAC administrative penalties, including fines of RMB 10,000-200,000; service suspension

In force · 15 Jul 2026 checked 4 Sep 2026 CAC Anthropomorphic AI Interim Measures (2026) ↗ high confidence

Cabo Verde 1

Cabo Verde Binding

Lei 133/V/2001 art. 23.º — the Lusophone prohibition rewritten to the GDPR's shape, and the second the regulator can licence

Binds Responsáveis pelo tratamento — controllers — with subcontratantes (processors) bound through art. 24(3)-(6) of the republished text. The scope article is the clearest break with the other two Lusophone rows: Lei 121/IX/2021 replaced art. 2 with a GDPR art. 3-shaped reach rather than the Lei 67/98 «means situated in national territory» test that Angola and São Tomé still use. Art. 2(1) applies the Law to processing by wholly or partly automated means and to non-automated processing of personal data contained in or intended for files. Art. 2(2) then reaches processing carried out (a) in the context of the activities of an establishment of a controller or processor, public or private, situated in national territory, irrespective of whether the processing occurs inside or outside the territory; (b) outside national territory in a place where Cabo Verdean law applies by force of international law; and (c) by a controller or processor not established in national territory that processes the personal data of data subjects who are in national territory, where the processing activities relate to the offering of goods or services to those data subjects, irrespective of whether a payment is required, or to the monitoring of their behaviour where that behaviour takes place in national territory. A foreign scoring, credit or hiring-assessment operator that has no presence in Cabo Verde but profiles people who are there is therefore inside art. 23. Art. 2(3) adds video surveillance and other capture and diffusion of sounds and images allowing identification, where the controller is domiciled or seated in national territory or uses a network access provider established there; art. 2(4) obliges a controller covered by extraterritoriality or immunity to designate a representative established in national territory, communicated to the CNPD. Impact tier: all entities — art. 23 carries no employee-count, turnover, sector or high-risk-system threshold, and the art. 5(1)(j) profiling definition expressly names professional performance and economic situation, which puts hiring and credit-scoring deployers squarely in scope. Art. 40 separately makes the processing of personal data relating to the credit and solvency of data subjects subject to prior authorisation by the CNPD, so a credit-scoring operator meets an ex ante gate as well as art. 23.. Article 23.º of Lei n.º 133/V/2001, de 22 de janeiro, in the consolidated text republished by Lei n.º 121/IX/2021, de 17 de março, is Cabo Verde's automated-decision provision, and it is the third Lusophone row on the tracker after Angola and São Tomé e Príncipe. All three descend from Portugal's Lei 67/98, but Cabo Verde is the one that has been rewritten since the GDPR, and the rewrite shows. Under art. 23(1), «qualquer pessoa tem o direito de não ficar sujeita a uma decisão que produza efeitos na sua esfera jurídica ou que a afete de modo significativo, tomada exclusivamente com base num tratamento automatizado dos seus dados pessoais, incluindo a definição de perfis» — any person has the right not to be subject to a decision producing effects in their legal sphere or significantly affecting them, taken exclusively on the basis of automated processing of their personal data, including profiling. The 2021 amendment cut the evaluative limb that Angola and São Tomé still carry — the requirement that the processing be «destinado a avaliar determinados aspectos da sua personalidade, designadamente a sua capacidade profissional, o seu crédito, a confiança de que é merecedora ou o seu comportamento» — and put profiling in its place. So Cabo Verde's bar no longer asks what the processing was for: any solely automated decision over the legal-effects-or-significant-effect threshold is caught, evaluative or not, which makes it wider than either of its Lusophone siblings and puts it in the same shape as the GDPR's own art. 22. «Definição de perfis» is then defined in art. 5(1)(j) in GDPR art. 4(4) terms — any automated processing that uses personal data to evaluate certain personal aspects of a natural person, in particular to analyse or predict aspects concerning their professional performance, economic situation, health, personal preferences, interests, reliability or conduct. The ways out are three. Art. 23(2) permits the decision under a legal authorisation, or with the person's consent where it occurs in the conclusion or performance of a contract and either their own request to conclude or perform was satisfied or adequate measures exist guaranteeing the defence of their legitimate interests and their ability «expor o seu ponto de vista, designadamente o seu direito de representação e expressão» — to express their point of view, namely their right of representation and expression. Art. 23(3) then carries the limb that until now stood alone on the tracker as Angola's: «pode ainda ser permitida a tomada de uma decisão nos termos do número 1, quando autorizadas pela CNPD e desde que sejam tomadas medidas de garantia a defesa dos interesses legítimos do titular dos dados» — the decision may further be permitted where the Comissão Nacional de Proteção de Dados authorises it, provided measures guaranteeing the defence of the data subject's legitimate interests are taken. Both clauses descend from art. 13(3) of Portugal's Lei 67/98, so the regulator-licence route is a shared Lusophone inheritance rather than an Angolan invention, and Cabo Verde and Angola are the two jurisdictions on the tracker whose supervisory authority can licence an otherwise-prohibited automated decision case by case. On disclosure Cabo Verde is the most generous of the three: art. 14(1)(c) gives the data subject, on request and without excessive delay or cost, «o conhecimento da lógica subjacente ao tratamento automatizado dos dados que lhe digam respeito, no que se refere às decisões automatizadas, incluindo a definição de perfis, referida no número 1 do artigo 23.º» — knowledge of the logic underlying the automated processing of their data as regards automated decisions including profiling, cross-referring art. 23(1) by name. São Tomé gives the «razões», the reasons; Angola gives nothing at all. What Cabo Verde does not give is a notice duty: the art. 13 information list, which the same 2021 law rewrote and extended to the contacts of the data protection officer and the legal basis of the processing, carries no automated-decision item and no logic item, so the right is reactive — invocable only by someone who already suspects a machine decided. There is no right to obtain human intervention and no right to contest the decision after the fact. Impact tier: all entities.

Force. The date carried here is the date on which the current wording of the automated-decision rule took effect. Lei n.º 121/IX/2021, de 17 de março — the second amendment to the general legal regime for the protection of the personal data of natural persons approved by Lei n.º 133/V/2001, de 22 de janeiro, as amended by Lei n.º 41/VIII/2013, de 17 de setembro — was approved by the Assembleia Nacional on 11 February 2021, promulgated by President Jorge Carlos de Almeida Fonseca on 1 March 2021, signed on 8 March 2021 and published in the Boletim Oficial da República de Cabo Verde, I Série, n.º 28, de 17 de março de 2021, at pp. 883-906. Its art. 6 (Entrada em vigor) provides «a presente lei entra em vigor trinta dias após a sua publicação», thirty days after publication, which puts the amended text in force on 16 April 2021. The obligation itself is older and continuous: art. 2 of the 2021 Law amends art. 14.º of Lei 133/V/2001, which is the article the republication in its art. 5 renumbers as art. 23.º of the consolidated text, and the parent Law's own art. 71 (Entrada em vigor) used the identical thirty-day formula against publication on 22 January 2001, so the first Cabo Verdean automated-decision bar has been in force since 21 February 2001. What the 2021 Law changed is substantive and is why the later date is carried: it replaced nos. 1 and 2 of the article outright, dropping the Lei 67/98 evaluative limb and inserting «incluindo a definição de perfis» together with the new art. 5(1)(j) profiling definition, while leaving no. 3 — the CNPD authorisation route — untouched, which the amending text marks by reproducing it as «3. []». Supersession is therefore recorded rather than duplicated: this row supersedes nothing on the tracker, and the pre-2021 wording is not published as a separate entry. One divergence inside the single gazette issue is recorded rather than resolved: in the amending body at art. 2, the new art. 14(1) reads «tomada exclusivamente com base num tratamento automatizado, incluindo a definição de perfis», while the republished consolidated text at art. 23(1) reads «tomada exclusivamente com base num tratamento automatizado dos seus dados pessoais, incluindo a definição de perfis». The republished text governs — art. 5(1) of the amending Law provides that the modifications are inserted into Lei 133/V/2001 by substitution and art. 5(2) republishes the Law in its new text together with the amending Law — and it is the republished wording that is quoted in this entry, with the amending-body wording noted so the difference is not silently smoothed over. Art. 4 of the amending Law separately revokes art. 48.º of the 2001 Law. Transitional: art. 70 of the republished text gave processing existing in manual files at entry into force a six-month window for conformity with arts. 8, 11, 13 and 14 — art. 23 is not in that list and binds without a transitional window. No AI-specific statute is in force in Cabo Verde and the Law does not define artificial intelligence. Text read in full in the copy of the Boletim Oficial pages published by the Comissão Nacional de Proteção de Dados, the supervisory authority the Law creates — the file is the gazette typesetting itself, carrying the BO running heads, page numbers 883-906 and the kiosk.incv.cv watermark, not a re-keyed edition. Coverage of the read: the amending Law arts. 1-6 in full, including the enumeration of amended articles and the entry-into-force and republication clauses; and in the republished consolidated text, art. 2 scope, art. 5 definitions, arts. 13 information, 14 access and 23 automated individual decisions verbatim, art. 24 security and processors, arts. 39-41 notification and prior control, arts. 47-58 civil liability and the administrative infractions with their coimas, and arts. 59-71 the criminal subsection, accessory sanctions, transitional provisions and entry into force. Confidence high: art. 23 and art. 14(1)(c) were read verbatim in the gazette text, both entry-into-force clauses are explicit thirty-day formulas against dated publications, and the fine attaching to art. 23 was traced to the enumerated list in art. 50(1)(b) rather than assumed. Computation of the thirty-day vacatio verified 31 Aug 2026 against Cabo Verde's own rule and it does not move. Art. 6 of Lei n.º 121/IX/2021 reads «a presente lei entra em vigor trinta dias após a sua publicação»; the Código Civil in the text reconstituted by Portaria n.º 68-A/97, de 30 de Setembro, art. 5.º (Começo da vigência da lei) provides at no. 2 that «entre a publicação e a vigência da lei decorrerá o tempo que a própria lei fixar ou, na falta de fixação, o que for determinado em legislação especial», so the Code fixes no counting rule of its own and refers out. The legislação especial is Lei n.º 87/VII/2011, which sets the default vacatio «em todo o território nacional e no estrangeiro no 5.º dia após a sua publicação no Boletim Oficial, devendo este prazo contar-se a partir do dia imediato ao da disponibilização do diploma no sítio da Internet gerido pela INCV». That is a named-day construction: the diploma takes effect ON the n-th day after publication, the count starting the day immediately after. Applied to the thirty days of art. 6, with publication on 17 March 2021, day 1 is 18 March and day 30 is 16 April 2021 — the date carried. The Paraguayan failure mode does not engage here: «trinta dias após a sua publicação» designates a day rather than requiring a term to elapse before the Law can apply, so there is no midnight-of-the-last-day question to resolve. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. Cabo Verde deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 5 February 2022, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. Art. 14(5) of the Convention states the same bar as art. 23.º and admits no exception of any kind, where art. 23.º admits three routes. Art. 23.º(2) permits the decision under a legal authorisation, or with the person's consent where it occurs in the conclusion or performance of a contract and either their own request was satisfied or adequate measures guarantee their legitimate interests. Art. 23.º(3) adds the Angolan limb: the decision may also be permitted where the CNPD authorises it and safeguard measures are taken. Neither the legal-authorisation route nor the regulator-authorisation route has any counterpart in the Convention, whose art. 12(2)(h) gives the national authority a sanctioning power rather than a power to dispense from art. 14(5). The national statute is carried here as the operative rule, because it is the instrument that has a supervisory authority behind it and a penalty attached to it, and the Convention runs behind it as a stricter parallel rule. This is recorded as a divergence rather than resolved: neither instrument repeals or qualifies the other, Cabo Verde has not legislated the Convention into domestic law by a separate instrument, and the domestic reception question — whether art. 14(5) is directly effective in Cabo Verde, as arts. 18 and 144 of the Mozambican and Namibian constitutions respectively make it there — has not been separately verified for Cabo Verde and is not asserted here. A controller relying on an exception the statute grants therefore stands on solid statutory ground and unresolved treaty ground.

Stated maximum penalty — 100,000$00 to 1,000,000$00 Cabo Verdean escudos, and the fine reaches art. 23 by name. Art. 50 (Outras infrações) of the republished text makes it an administrative infraction punishable with a coima of a minimum of 100,000$00 and a maximum of 1,000,000$00 for entities that fail to observe the obligations established in arts. 6.º, 13.º, 14.º, 20.º, 23.º, 25.º, 33.º and 43.º(3), or that fail to designate a representative under art. 2(4). Art. 23 — the automated-decision bar — and art. 14 — the access right carrying the logic-disclosure limb — are both inside that enumerated list, which puts Cabo Verde with São Tomé e Príncipe, where art. 32(1) also names the automated-decision article, and against Angola, where art. 29 appears in neither art. 51 contravention list and enforcement has to run through a complaint, a judicial reparation claim or the crime of qualified disobedience. Art. 50(2) doubles the limits where the obligations in arts. 7, 8, 11, 12, 35 and 36 are the ones breached. Art. 52(1) makes negligence always punishable in the art. 50 infractions and art. 52(2) makes attempt punishable in arts. 49 and 50, so an operator cannot answer an art. 23 charge by saying the profiling was inadvertent. The neighbouring band is higher but does not reach art. 23: art. 49 punishes negligent failure to notify the CNPD, or maintaining network access for non-compliant controllers after notification, with 50,000$00 to 500,000$00 for a natural person and 300,000$00 to 3,000,000$00 for a legal person or entity without legal personality, doubled under art. 49(2) where the data are subject to prior control under art. 40. Application of the coimas belongs under art. 56 to the president of the CNPD on the Commission's prior deliberation, and that deliberation is an enforceable title if not challenged in the legal period; art. 58 gives the proceeds to the CNPD; art. 57 makes clear that paying the coima does not dispense the infringer from performing the omitted duty. Alongside the coimas, art. 69 allows accessory sanctions — temporary or definitive prohibition of the processing, blocking, erasure or total or partial destruction of the data, publicity of the condemnatory decision at the convicted party's expense in the most widely circulated periodical of the comarca for not less than 30 days, and public warning or censure of the controller. The criminal subsection sits behind that and does not reach art. 23 directly: art. 59 punishes with up to one year's imprisonment or a fine up to 120 days the intentional omission of a notification or authorisation request under arts. 39 and 40, false information in one, diversion or use of data incompatibly with the purpose of collection, unlawful interconnection, failure to comply within a deadline fixed by the CNPD, and maintaining network access after being notified not to; arts. 60-61 punish undue access and the vitiation or destruction of data; art. 62 makes it qualified disobedience to fail, after notification, to interrupt, cease or block processing, to refuse the CNPD the cooperation demanded, or to fail to erase or destroy data — so once the CNPD orders an art. 23 profiling operation stopped, defying that order is a crime. Arts. 64-67, added by the 2021 amendment, create the further offences of diversion of data, use of data incompatibly with the purpose of collection, unlawful interconnection and insertion of false data. Art. 51(1) provides that where the same act is both a crime and an administrative infraction, the agent is always punished as for the crime.

In force · 16 Apr 2021 checked 13 Sep 2026 Lei 133/V/2001 art. 23.º ↗ high confidence

Germany 1

DE Binding

Germany AI Market Surveillance Act (KI-MIG)

Binds AI providers, importers, distributors, and deployers of AI systems operating in Germany under EU AI Act scope (Reg. EU 2024/1689). Designates Bundesnetzagentur (BNetzA) as Germany's lead AI authority; establishes enforcement architecture for EU AI Act in Germany, including AI regulatory sandboxes (KI-Reallabore) and domestic penalty regime.

National implementing law for EU AI Act. EU phased obligations still apply: Art.50 transparency in force Aug 2, 2026; high-risk Annex I AI → Aug 2, 2028 (per the Digital Omnibus, Reg. (EU) 2026/1744); full high-risk Annex III → Dec 2, 2027.

Stated maximum penalty — €35M or 7% global turnover (prohibited AI practices); €15M or 3% (high-risk violations); €50K for domestic procedural violations (KI-MIG §§15–17)

In force · 29 Jul 2026 checked 7 Sep 2026 KI-MIG ↗ high confidence

Algeria 1

Algeria Binding

Loi 18-07 art. 45 bis 1 (ex-art. 11) — the automated-decision rule now reaches only criminal-justice processing; Loi 25-11 repealed the general-purpose rule outright

Binds Only the actors listed exhaustively in art. 45 bis: the judicial authority; services and bodies legally empowered to search out offences and identify their perpetrators, within the limits of their attributions and competences; auxiliaires de justice, within their legal attributions and for a period proportionate to the missions entrusted to them; and the services of the prison administration. Art. 45 bis further requires such processing to identify its controller, purpose, data subjects, the third parties to whom the data may be communicated, the origin of the data and its security measures, dispenses with the prior consent of the data subject notwithstanding arts. 7 and 8, and confines the data collected to the Title's own purposes. The first limb of art. 45 bis 1 binds the courts themselves. Ordinary responsables du traitement outside the criminal-justice context are no longer bound by any automated-decision rule in Loi 18-07 following the repeal of art. 11. The Law's territorial scope (art. 4) is unchanged: controllers established on Algerian territory or in a State whose legislation is recognised as equivalent, and controllers not established in Algeria that resort to processing means situated on Algerian territory other than for transit. Art. 6, as rewritten by art. 2 of Loi 25-11, now excludes from the Law only data processed by a natural person in the exclusive course of personal or domestic activities and not destined for communication or dissemination, and data relating to national defence and national security.. Article 11 of Loi n° 18-07, which was Algeria's general-purpose automated-decision rule, was repealed outright on 24 July 2025 by art. 7 of Loi n° 25-11 (« Sont abrogées, les dispositions des articles 10 et 11 de la loi n° 18-07 »). It was not renumbered or re-enacted in the general part of the Law. Its wording survives, almost verbatim, as art. 45 bis 1 — but art. 6 of Loi 25-11 places that article inside a newly created Titre V bis (arts. 45 bis to 45 bis 14) headed « Traitement des données à caractère personnel à des fins de prévention et de détection des infractions, d'investigations, d'enquêtes, de poursuites pénales, d'exécution et d'application des peines ». Art. 45 bis 1 keeps three limbs: judicial decisions requiring an appraisal of a person's conduct may not be founded on the sole automated processing of personal data involving an evaluation of aspects of their personality; no other decision producing legal effects may be taken on the sole basis of an automated processing whose object is to characterise a person or to evaluate aspects of their personality; and decisions taken in concluding or performing a contract where the person was put in a position to present observations, together with decisions satisfying that person's own request, are deemed not taken on that sole basis. What changed is scope, not wording. Art. 45 bis, the opening article of the same Title, states exhaustively who may carry out processing under it — the judicial authority, services and bodies legally empowered to investigate offences and identify their perpetrators, auxiliaires de justice, and the prison administration services — and confines data collected under the Title to those same purposes. An ordinary private-sector controller in Algeria is therefore no longer subject to any automated-decision restriction under Loi 18-07: employment screening, credit and insurance scoring and similar profiling decisions lost their statutory constraint on 24 July 2025. Loi 25-11 also inserts, for the first time, a statutory definition of « profilage » into art. 3 of Loi 18-07 (by art. 2 of Loi 25-11), and narrows the art. 6 exclusions to purely domestic processing and to national-defence and national-security data — criminal-justice data, previously excluded from the Law altogether, is now inside it and governed by Titre V bis. The Law still carries no right to an explanation of the logic involved and no human-review right; the opportunity to present observations exists only inside the contractual deeming clause.

Repeal and relocation verified directly against the Journal officiel: JO n° 48 of 28 Moharram 1447 corresponding to 24 July 2025, Loi n° 25-11, at p. 14 of the French edition. Art. 7 of Loi 25-11 repeals arts. 10 and 11 of Loi 18-07 outright and does not renumber them in place; art. 6 of Loi 25-11 inserts Titre V bis (arts. 45 bis to 45 bis 14), whose art. 45 bis 1 carries the former art. 11 wording. The open question left by the first pass — whether any automated-decision restriction still reaches general, non-law-enforcement controllers — is now closed on the text and closed in the negative. Two things settle it. First, Loi 25-11 contains exactly eight articles (art. 1 object, art. 2 rewriting arts. 3 and 6, art. 3 adding art. 27 bis on the national authority's regional poles, art. 4 adding Chapitre I bis on the data protection delegate, art. 5 adding Chapitre 1 bis 1 on processing registers, art. 6 adding Titre V bis, art. 7 the repeal, art. 8 the publication clause), so no general-scope replacement for art. 11 was enacted anywhere. Second, art. 45 bis — the opening article of the Title in which the surviving rule sits — states that processing for the Title's purposes « ne peut être effectué que par » the judicial authority, legally empowered investigating services, auxiliaires de justice and the prison administration, and confines data collected under the Title to those purposes. The Title therefore has a closed personal scope, and the « toute autre décision » limb of art. 45 bis 1 is bounded by it. One textual oddity is recorded rather than resolved: the third-paragraph deeming clause about contract formation and performance is a private-law construct carried over verbatim from art. 11, and sits awkwardly inside a criminal-justice title — it reads as an unadapted transposition rather than as a signal of wider scope, but no Algerian interpretive authority on the point was located. Date: art. 8 of Loi 25-11 is a bare publication clause with no commencement article and no deferral, so the date used is the date of the Journal officiel that carries the Law, 24 July 2025, read from the masthead of the JORADP French edition. Confidence stays medium for the same reason it was medium before: the Algerian general publication-to-force rule (art. 4 of the Code civil, Ordonnance n° 75-58) is not primary-source verified, because the 1975 Journal officiel volumes on JORADP are image scans with no recoverable text layer, so it could not be confirmed whether force attaches on the day of publication or the day after. Previously this row recorded art. 11 of Loi 18-07 with a date of 10 June 2018 (JO n° 34) and described it as binding controllers generally, including for hiring; that is wrong for any date after 24 July 2025 and the roles and topics have been narrowed accordingly.

Stated maximum penalty — No criminal offence attaches to art. 45 bis 1. Loi 25-11 has eight articles and none of them touches the penal chapter (arts. 56 to 74) or the sanction articles 46 and 47 of Loi 18-07 — verified article by article against the enacted text. The penal chapter enumerates the articles it punishes and, having been drafted in 2018, cannot and does not name art. 45 bis 1; art. 47's fixed fine of 500,000 DA remains confined to arts. 32, 34, 35, 36 and to the notifications under arts. 4, 14 and 16. The only route that reaches art. 45 bis 1 is art. 46, under which non-observance of the provisions of the Law by the responsable du traitement leads the Autorité nationale to take administrative measures: a warning, a mise en demeure, provisional withdrawal for a period not exceeding one year or definitive withdrawal of the declaration receipt or the authorisation, and a fine for which the text fixes no amount. Decisions of the national authority are appealable to the Conseil d'Etat. Whether art. 46 is a workable route against a court or a prosecuting service — the actors art. 45 bis 1 now principally addresses — is not resolved by the text: art. 45 bis 12 gives the national authority verification and inspection powers under the Title but expressly reserves the prerogatives of the judicial power.

In force · 24 Jul 2025 checked 21 Sep 2026 Loi n° 18-07 art. 45 bis 1 (ex-art. 11) ↗ medium confidence

Ecuador 2

Ecuador Binding

LOPDP art. 20 — the automated-decision right that drops «solely»: «única o parcialmente»

Binds Responsables and encargados del tratamiento — controllers and processors. Art. 3 reaches processing carried out anywhere in national territory, controllers or processors domiciled in Ecuador, and controllers or processors not established in Ecuador that process the data of subjects residing in Ecuador where the activity relates to offering goods or services to them, payment required or not, or to monitoring their behaviour in Ecuador; a fourth limb picks up cases where Ecuadorian law applies by contract or by public international law. Art. 20 covers administrative acts and private decisions alike, so there is no public-sector carve-out — the sanctions articles instead split the tariff between public servants and private or state-owned entities. Impact tier: all entities.. Art. 20 of the Ley Orgánica de Protección de Datos Personales (Quinto Suplemento del Registro Oficial Nº 459 of 26 May 2021, adopted 10 May 2021) is titled «Derecho a no ser objeto de una decisión basada única o parcialmente en valoraciones automatizadas» — a right not to be subject to a decision based wholly OR PARTLY on automated valuations. The two words «o parcialmente» are the finding. Every other transposition in the atlas of the GDPR art. 22 family keeps the «solely» limb, and the argument that partial automation with a human rubber-stamp escapes the rule is the most contested question in that family; Ecuador removed the question from the text in 2021. The effects threshold is widened in the same sentence: the decision has to «produzcan efectos jurídicos en él o que atenten contra sus derechos y libertades fundamentales» — produce legal effects in the subject OR infringe their fundamental rights and freedoms — where GDPR art. 22(1) asks for a similarly significant effect. The right is also built as a bundle of five active entitlements rather than an abstention: a reasoned explanation of the decision taken (a), the filing of observations (b), «los criterios de valoración sobre el programa automatizado» — the valuation criteria bearing on the automated program itself (c), the types of data used and the source they were obtained from (d), and challenge of the decision before the controller or processor (e). There are four exceptions, one more than the GDPR has: contract, authorising law (widened to include a judicial order or the reasoned mandate of a competent technical authority, with adequate safeguards established), explicit consent, and — with no counterpart in the GDPR — «la decisión no conlleve impactos graves o riesgos verificables para el titular», a de minimis exit for decisions carrying no serious impact or verifiable risk for the subject. Two closing sentences have no GDPR counterpart either: advance waiver of the right through mass adhesion contracts cannot be required, and the right is stated explicitly to the subject, by any suitable medium, no later than the first communication. That last sentence reverts to «basada únicamente en valoraciones automatizadas» — the notification duty is drawn back to solely-automated decisions while the right itself covers partly-automated ones, an internal inconsistency present in the gazette text. Art. 21 carries a dedicated companion right for children and adolescents: on top of art. 20, sensitive data and the data of children and adolescents are not processed this way absent the express authorisation of the subject or their legal representative, or an essential public interest assessed against international human-rights standards satisfying legality, proportionality and necessity and including specific safeguards; adolescents from 15 may consent as subjects in their own right. Arts. 12(14) and 12(17) make the transparency proactive — the existence of automated valuations and decisions, profiling included, forms part of the information given at collection.

In force since 26 May 2021: the Disposición Final states «La presente Ley entrará en vigencia una vez publicada en el Registro Oficial», and publication was in the Quinto Suplemento del Registro Oficial Nº 459 of that date. The corrective-measures and sanctions regime is the exception — Disposición Transitoria Primera delayed it by two years from publication, so fines became available on 26 May 2023, and Disposición General Séptima states in terms that the rights «podrá ser exigido por el titular independientemente de la entrada en vigor del régimen sancionatorio», an explicitly enforceable-but-unfineable interval that no other instrument in the atlas spells out. Art. 20 was verified against the scanned gazette itself — page 23 of the Asamblea Nacional's copy of the Quinto Suplemento — and that reading corrected the commercial rendering: the gazette lists five lettered entitlements a) to e), where the widely circulated Lexis-typeset edition folds «e. Impugnar la decisión» into item d) by reading the letter «e» as the conjunction. Ecuador's data-protection authority, the Superintendencia de Protección de Datos Personales, has been operating since 2023 and issues general norms under art. 76(5) of the Law. No amendment: the government-hosted consolidated editions of November 2024 and July 2025 both carry «Estado: Vigente / Fecha de última reforma: No aplica», and no reforming law was found through August 2026.

Stated maximum penalty — Split by the identity of the offender, not by the article breached. Art. 71 sets the light tariff — 1 to 10 unified basic salaries for a public servant, or 0.1% to 0.7% of the previous financial year's turnover for a private entity or state-owned enterprise. Art. 72 sets the serious tariff — 10 to 20 unified basic salaries, or 0.7% to 1% of turnover. Art. 73 defines turnover as sales of goods and services net of VAT and directly related taxes. There is a finding in the lists themselves. Neither art. 67 nor art. 68 names art. 20, so a controller that denies the right lands in art. 67(1) — failing to process, processing out of time or unjustifiably refusing a subject's petition — which is a LIGHT infraction; art. 70(1), the processor's list, is a catch-all reaching any processing «sin observar los principios y derechos desarrollados en la presente Ley», which is a SERIOUS one. The same refusal is therefore fined an order of magnitude apart depending on whether the entity acted as controller or as processor. Art. 72 also carries a cross-border enforcement fallback: where the offender has no domicile or legal representation in Ecuador, the resolution is notified to the data-protection authority of its principal place of business to carry the measures through.

In force · 26 May 2021 checked 15 Sep 2026 LOPDP art. 20 ↗ high confidence
Ecuador Binding

SPDP Norma General on personal data in AI systems — a regulator-made AI rulebook with a four-role supply chain

Binds Controllers and processors that develop, train, implement, deploy or supply AI systems processing the personal data of Ecuadorian data subjects, wherever the system or the supplier is located (art. 1), in the four capacities defined by art. 2 — developer, deployer, distributor, implementer. Art. 1 excludes AI systems that do not process personal data within the material and territorial scope of the LOPDP, so the norm has no reach over models trained only on non-personal data. Impact tier: all entities.. Resolución Nº SPDP-SPD-2026-0009-R of the Superintendente de Protección de Datos Personales, signed in Quito on 12 February 2026, issues the «Norma General para la Garantía del Derecho de Protección de Datos Personales en el Uso de Sistemas de Inteligencia Artificial». It is secondary legislation made under art. 76(5) of the LOPDP rather than a statute, and it is the closest thing Ecuador has to an AI act. Art. 1 fixes the scope: the principles, rights and obligations of the LOPDP, its General Regulation and SPDP secondary norms are of obligatory compliance for controllers and processors that develop, train, implement, deploy and/or provide AI systems processing the data of Ecuadorian subjects, «con independencia de la ubicación del sistema o del proveedor» — regardless of where the system or the supplier sits. Art. 2 adds a four-role supply-chain taxonomy layered onto the controller/processor pair: desarrollador (generates or creates the system), desplegador (uses a system to deliver a service, excluding non-professional personal activity), distribuidor (a supply-chain party other than the developer, deployer or implementer that markets or supplies the system), and implementador (commissions development or embeds a system into internal procedures). Art. 4 states that where personal data are processed directly in AI systems, the art. 20 right not to be subject to a wholly or partly automated decision, the right to information and the right to object are guaranteed at all times. Art. 5 lists the standing obligations: clear, specific and transparent information to the subject about processing carried out through AI systems, including the purposes and the automated character of the processing; risk management and data-protection impact assessment; administrative, technical, physical, organisational and legal security measures scaled to the categories and volume of data, the state of the art, best practice and cost, with identification of probable risks; entry of AI-mediated processing in the register of processing activities (RAT); and audit of the general functioning of the system by reference to its risk level. Art. 6 places the risk management and impact assessment before development begins. Art. 7 makes security continuous and adds that automated decisions of AI systems producing legal impacts or affecting the rights and freedoms of subjects are entered in the RAT, which is made available to the SPDP. Art. 10 gives the SPDP power to audit AI systems and to impose corrective measures under the LOPDP or precautionary measures under the Código Orgánico Administrativo. Art. 8 routes non-compliance to the LOPDP's existing sanctions regime rather than creating a tariff of its own. The norm does not classify systems by risk tier, has no prohibited-practices list and no conformity assessment — it is a data-protection overlay on AI, not a product-safety regime.

In force since 10 March 2026, the date the Registro Oficial published it. The Disposición Final states «Esta resolución entrará en vigencia a partir de su publicación en el Registro Oficial», and the resolution was «dada y firmada en Quito, D. M., el 12 de febrero del 2026» by Superintendente Fabrizio Peralta-Díaz; the gazette citation is Registro Oficial Año I Nº 240 of Tuesday 10 March 2026, an ordinary edition rather than a supplement, where the norm runs from page 49 to page 56 under the heading FUNCIÓN DE TRANSPARENCIA Y CONTROL SOCIAL / SUPERINTENDENCIA DE PROTECCIÓN DE DATOS PERSONALES. The gazette text was read in full against the signed copy the SPDP publishes at https://spdp.gob.ec/wp-content/uploads/2026/02/ResolIA.pdf and is the same instrument: same ten articles, same four-role taxonomy in art. 2, same Disposición Final, same signature block. Between 29 August 2026, when the entry was first drafted, and this verification the citation could not be produced — the SPDP's own publication page carries no gazette stamp and none of its later 2026 resolutions (0020-R, 0021-R and 0022-R of May 2026, all checked) recites this one — so the row was held at lifecycle proposed with an empty date rather than asserting an in-force date that could not be sourced. The citation was found through the gazette's own site search at registroficial.gob.ec, which returns the edition's SUMARIO and a download link for the full PDF.

Stated maximum penalty — No tariff of its own. Art. 8 states that controllers and processors breaching the LOPDP, its General Regulation or this general norm through the use of AI systems are sanctioned under the sanctions regime already provided by law, which is arts. 67 to 73 of the LOPDP: 1 to 10 unified basic salaries or 0.1% to 0.7% of turnover for light infractions, 10 to 20 unified basic salaries or 0.7% to 1% of turnover for serious ones. The obligations this norm creates — impact assessment, security measures, the RAT entry — map onto art. 68's serious-infraction list for controllers, where failure to run an impact assessment when one was required (68(5)) and failure to keep the national register current (68(10)) already appear, so the practical exposure of an AI-specific breach is the serious band. Art. 10's audit and corrective or precautionary measures operate independently of any fine.

In force · 10 Mar 2026 checked 15 Sep 2026 SPDP-SPD-2026-0009-R ↗ high confidence

Egypt 1

Egypt Binding

Executive Regulations of the Personal Data Protection Law (Ministerial Decree 816/2025) art. 4 — a processor using personal data for AI training or emerging technologies must follow recognised local, regional and international principles and cause the data subject no harm

Binds المعالج, the processor, defined by Law 151/2020 as any natural or legal person who by virtue of their profession or expertise is authorised to process personal data on behalf of the controller under an agreement and on the controller's instructions; مادة (١) of the Regulations takes the Law's definitions unchanged. The duty is unqualified as to size, sector or data volume: it attaches to any processor that puts personal data through AI-training operations or emerging and innovative technologies. A processor established outside Egypt without a branch or representative office inside the country must, under مادة (٤) أولاً item 5, appoint a representative in Egypt approved by the Centre for the duration of its licence or permit, and a natural-person processor must appoint an agent inside Egypt, so the duty reaches extraterritorial AI-training work carried out on Egyptian personal data. Supervision is by المركز, the Personal Data Protection Centre, whose inspectors hold judicial-officer status under مادة (٤) أولاً item 4. Impact tier: all entities.. Article 4 of the Executive Regulations of Law No. 151 of 2020, headed «السياسات والإجراءات والضوابط والشروط والتعليمات والمعايير القياسية لالتزامات معالج البيانات الشخصية», sets out the processor's obligations in two limbs, أولاً the controls and technical standards and ثانيًا the procedures and policies. The seventh item of the first limb is Egypt's only express artificial-intelligence obligation: «٧- التزام المعالج بالتعامل مع البيانات الشخصية ، حال معالجتها واستخدامها لعمليات تدريب الذكاء الاصطناعى والتقنيات الناشئة والمبتكرة ، وفقًا للمبادئ المتعارف عليها محليًا وإقليميًا ودوليًا ، بما يضمن استخدام تلك التقنيات بالصورة التى لا يترتب عليها ثمة ضرر بالشخص المعنى بالبيانات .» — the processor is bound, when handling personal data in the course of processing it and using it for artificial-intelligence training operations and emerging and innovative technologies, to do so in accordance with the principles recognised locally, regionally and internationally, in a way that ensures those technologies are used in a form that entails no harm to the data subject. The clause is a duty of conduct with two components: an external-standards component, which imports whatever principles are «recognised» at the three named levels without naming an instrument, and a no-harm component, which is an outcome test on the data subject. It is not a right the data subject exercises, it is not conditioned on consent, and it carries no notice, reconsideration or human-review machinery. The sentence is the only occurrence of الذكاء الاصطناعى in the Regulations. Its placement matters and is reproduced here rather than smoothed over: the parallel controller article, مادة (٣) أولاً, runs to eight items and has no equivalent limb — its item 7 is the inspector-access duty and its item 8 the volume-and-quality duty — so on the face of the gazetted text the AI-training duty binds المعالج alone.

Primary source read: the certified gazette copy of the Executive Regulations published by the Personal Data Protection Centre itself, i.e. الوقائع المصرية — العدد ٢٤٤ تابع (أ) فى أول نوفمبر سنة ٢٠٢٥. The file is an MRC scan whose page text is JBIG2-coded with a /JBIG2Globals segment, which is why three earlier passes on this issue recorded it as unreadable; it is readable once the globals stream is prepended to the JBIG2 chunk list, and all 41 pages were decoded and read in the Arabic. Printed page 2 carries the enacting instrument, قرار وزير الاتصالات وتكنولوجيا المعلومات رقم ٨١٦ لسنة ٢٠٢٥ بإصدار اللائحة التنفيذية لقانون حماية البيانات الشخصية الصادر بالقانون رقم ١٥١ لسنة ٢٠٢٠; printed page 3 carries its المادة الأولى (the annexed Regulations are put into effect) and its المادة الثانية, «يُنشر هذا القرار فى الوقائع المصرية ، ويُعمل به من اليوم التالى لتاريخ نشره», signed د/ عمرو سميح طلعت. Gazette date 1 November 2025 and entry into force 2 November 2025 are therefore taken from the gazette, not from the regulator's website prose. The Regulations therefore bind from 2 November 2025, and that is the date carried on this row. Separately, the Centre states on its own site that a one-year compliance period runs from entry into force, i.e. to 2 November 2026. That period is reported rather than verified: it is not in the enacting decree's two articles and not in the Regulations' own text as gazetted, it derives from the transitional provision of Law 151/2020, and the Law's gazetted Arabic could not be read this run, so the 2 November 2026 date is stated here as the regulator's statement and is not relied on for the lifecycle. Checked negative, recorded so no later pass re-derives it: the Egyptian framework has NO GDPR art. 22 analogue. The Regulations' own الفهرس (printed pages 4 to 6) lists every heading through printed page 41 and contains no automated-decision or profiling heading; مادة (١) is a purely referential definitions article that takes the Law's definitions and adds none of its own; and the substantive articles 2 to 18 were read in full without finding a right not to be subject to a solely-automated decision. On the Law side, مادة (٢) of the Regulations, ثانيًا, item 1 confirms that PDPL art. 2 is the data-subject-rights article («إعلام الشخص المعنى بالبيانات بحقوقه وفق المادة (٢) من القانون»), and the Centre's own «Egypt's Personal Data Protection Framework» deck states at its page 12 that «the PDPL establishes nine fundamental rights for data subjects (PDPL Article 2)» and enumerates all nine — to be informed, of access, of withdrawal, of rectification, to erasure, to restrict, to object, of portability, and to be notified in case of data breach. No automated-decision or profiling right appears. The gazetted Arabic of the Law itself remains unreadable in this environment (the Centre's PDPL PDF draws every glyph as vector outlines, carries no text layer, no ToUnicode CMap and no page raster, and a full Wayback CDX sweep of mcit.gov.eg returns no copy of Law 151/2020), so the nine-rights list rests on a regulator publication rather than on statutory text and the absence of an art. 22 analogue is stated at that strength. The Centre's guidance treats automated decision-making as a factor inside the fairness principle rather than as a standalone right: its Data Protection Principles guideline lists «the use of automated decision-making and profiling: whether the processing involves automated decisions producing legal or significant effects on the data subject without human oversight» among the matters that bear on whether processing is fair. Coverage symmetry against the African rows already live — za-popia-s71, ke-dpa-s35, ng-ndpa-s37, gh-dpa-s41, rw-law058-2021-art21, tz-pdpa-s36, ma-loi0908-art11 and ug-dppa-s27 — Egypt is the odd one out and is deliberately not shaped like them. Every one of those eight is an automated-decision right sitting in a data-subject-rights chapter, whether of the UK Data Protection Act 1998 s. 12 lineage (Ghana, Tanzania, Uganda) or of the GDPR art. 22 lineage (Kenya, Nigeria, Rwanda, Morocco, South Africa). Egypt has no such right at all. What it has instead is a duty of conduct on the processing side, which is why this row is filed on the AI-training clause rather than on a rights article. One further AI-adjacent rule exists in the same instrument and is carried separately as eg-erpdpl-art14-children.

Stated maximum penalty — Not quantified here, deliberately. The Regulations create the duty but carry no fine of their own: enforcement runs through the licence and permit regime they build, under which a متحكم or معالج must hold a licence or تصريح from the Centre before collecting or processing at all (مادة (٢) أولاً item 1, مادة (٣) أولاً item 1 and مادة (٤) أولاً item 1), the Centre's inspectors are مأمورو الضبط القضائى with a right of access to the electronic records (مادة (٣) أولاً item 7, مادة (٤) أولاً item 4), and every licence application must carry an إقرار بالوفاء بالجزاءات المالية والتعويضات التى يقرها المركز (printed page 42, item 8). The monetary scale sits in the penalties chapter of Law 151/2020 itself, and that text could not be read from any reachable official host this run, so no figure is published rather than a figure taken from a secondary summary.

In force · 2 Nov 2025 checked 14 Sep 2026 Executive Regulations of the PDPL art. 4 (Ministerial Decree 816/2025) ↗ high confidence

European Union 2

EU Comprehensive

Article 50 transparency & deepfake labelling

Binds Providers & deployers of interactive, synthetic-content or biometric AI. Disclosure of AI interaction; marking of AI-generated content.

In force 2 August 2026. Commission adopted Guidelines on Transparency Obligations under Art. 50 on 20 July 2026, C(2026) 5054 final (https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems) (soft law, interpretive guidance on chatbots, deepfakes, emotion recognition, AI-generated text). No enforcement actions by national authorities reported as of 2026-08-09; first enforcement expected Q4 2026 as national market surveillance authorities build capacity (10 of 27 member states advanced implementation). Note: marking/watermarking of systems already on market before 2 Aug 2026 deferred to 2 Dec 2026 per Reg. (EU) 2026/1744.

Stated maximum penalty — Up to 3% turnover or €15M

In force · 2 Aug 2026 checked 10 Sep 2026 EU AI Act ↗ high confidence
EU Comprehensive

Art. 50(2) marking retrofit — synthetic-content systems placed on the market before 2 Aug 2026

Binds Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content placed on the EU market before 2 August 2026. Four-month transitional period: providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text and were placed on the EU market before 2 Aug 2026 have until 2 Dec 2026 to implement the Art. 50(2) machine-readable marking of synthetic output.

Added by the Digital Omnibus on AI, Regulation (EU) 2026/1744, Article 1(39)(b), which adds a new paragraph 4 to Article 111 of Regulation (EU) 2024/1689 (OJ L, 24.7.2026). Recital (38) describes it as a transitional period of four months for providers who had already placed their systems on the market. Distinct from the Article 50 transparency entry, which binds from 2 Aug 2026, and from the new Article 5 CSAM/NCII prohibitions, which share the 2 Dec 2026 date but sit in the higher Article 99(3) penalty tier.

Stated maximum penalty — Up to 3% turnover or €15M

Applies 2 Dec 2026 checked 22 Sep 2026 EU AI Act Art. 111(4) (Digital Omnibus) ↗ high confidence

Gabon 3

Gabon Binding

Loi n° 025/2023 art. 77 — the recast that carries the Francophone family's only statutory definition of artificial intelligence

Binds Responsables de traitement, on the terms of the art. 4 scope: the Law applies to any collection, processing, transmission, storage and use of personal data by a natural person or by public-law or private-law legal persons, and to any processing, automated or not, of personal data contained or intended to be contained in a file. Art. 78 subjects automated processing to a declaration to the APDPVP, excepting the processing mentioned in arts. 80, 81 and 82 or in art. 111; art. 79 requires the declaration to carry an undertaking that the processing satisfies the Law's requirements, to be addressed by any means leaving a trace, and requires the controller to notify data breaches likely to seriously affect fundamental rights and freedoms to the competent supervisory authority without excessive delay. Neither profiling nor automated decision-making is listed as a category attracting prior authorisation, so Gabon imposes no ex ante gate on the processing art. 77 governs. Art. 206 and art. 207 distinguish controllers holding a récépissé or an authorisation from de facto controllers holding neither. The art. 77 bar binds the courts under its first limb and, under its second, every decision-maker whose decision produces legal effects in regard to a person, with no size or sector threshold. Impact tier: all entities.. Article 77 of Loi n° 025/2023 du 12 juillet 2023 portant modification de la loi n° 001/2011 du 25 septembre 2011 relative à la protection des données à caractère personnel is Gabon's operative automated-decision rule. Like its predecessor it is not a free-standing article: the automated-decision paragraphs are appended to the article governing data relating to offences, convictions and security measures, which reserves such processing to public and judicial authorities and legal persons managing a public service acting within their legal remit, and to auxiliaires de justice for the strict needs of the missions the law confers on them. Three unnumbered paragraphs follow. The first: no judicial decision involving an appraisal of a person's conduct may have as its foundation a computerised processing of data intended to evaluate certain aspects of their personality. The second: no other decision producing legal effects in regard to a person may be taken on the sole foundation of an automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third deems decisions taken in the context of the conclusion or performance of a contract, and for which the person concerned was put in a position to present their observations, and those satisfying the requests of the person concerned, not to be issued from an automated processing. As in Guinea, Madagascar and Congo, the judicial limb omits the word "seul" that the second limb carries. The second limb takes the narrow Directive 95/46/EC trigger confined to decisions producing legal effects. What sets Gabon apart from every other Francophone row on the tracker is the surrounding apparatus, which is GDPR-grade and, uniquely, AI-aware on the face of the statute. The definitions article defines Intelligence Artificielle as a logical and automated process generally resting on an algorithm which is able to carry out well-defined tasks, adding that any tool used by a machine constitutes an artificial intelligence; it separately defines raw data in the field of artificial intelligence as data having undergone no transformation since its initial observation, input data in the field of artificial intelligence as data used for machine learning or for the decision-making of the system, and the artificial neuron by reference to whether it should be activated. It also defines Profilage as a processing using an individual's personal data with a view to analysing and predicting their characteristics, and Portabilité. Art. 43, the access right, carries the full GDPR transparency package: the existence of automated decision-making, including profiling, and at least in such cases meaningful information about the underlying logic as well as the significance and the envisaged consequences of that processing for the person concerned, together with a distinct right for the data subject to obtain on request knowledge of the reasoning underlying the processing of the data where the results of that processing are applied to them. Gabon is therefore the one jurisdiction in this block where the automated-decision bar sits alongside both a logic-disclosure right and a reasoning right.

Supersession: this row replaces, and does not duplicate, the automated-decision provision of Loi n° 001/2011 du 25 septembre 2011, which carried the same rule at its art. 50 in the same unusual placement, appended to the article on offence and conviction data. Loi n° 025/2023 is styled a modification of the 2011 Law but is in substance a full recast, running to 221 articles against the predecessor's shorter frame and renumbering throughout; its art. 221 provides that the present Law, which abrogates all prior contrary provisions, notably certain provisions of Loi n° 001/2011, shall be registered, published in the Journal Officiel and executed as a law of the Republic. Because the abrogation is of contrary provisions rather than of the 2011 Law as a whole, and because the recast reproduces the automated-decision rule rather than repealing it, the obligation is continuous from 2011; only the article number, the wording and the enforcement apparatus changed. The wording changes are small but real: the 2011 judicial limb read "traitement automatisé" where the 2023 text reads "traitement informatisé", and the 2011 deeming clause read that such decisions are not regarded as taken on the sole foundation of an automated processing, where the 2023 clause reads that they are not considered as issued from an automated processing. The institutional change is larger: the Commission nationale pour la protection des données à caractère personnel created by the 2011 Law is replaced by the Autorité pour la Protection des Données Personnelles et de la Vie Privée, the APDPVP, which is the body named throughout the enforcement chapter. The Law carries no commencement article and art. 221 is a bare registration, publication and execution clause, so nothing is deferred. The date recorded here is the date of the gazette in which the Law was promulgated and published: Journal Officiel de la République Gabonaise n° 218 Bis of 15 July 2023, printed on the running head of every page of the issue. The Law itself is dated 12 July 2023 at Libreville, and the promulgating decree in the same issue bears the same date. Confidence is medium because the Gabonese general publication-to-force rule was not verified against a primary source: if force runs from promulgation the operative date is 12 July 2023, three days earlier. Both candidate dates are long past, so the lifecycle of this row is unaffected either way. On sourcing: the official gazette host journal-officiel.ga returned HTTP 503 on every path when this entry was first checked, so the text was originally read in the scan of Journal Officiel n° 218 Bis published by the AFAPDP, the association of Francophone data-protection authorities of which Gabon's regulator is a member. Re-checked 24 August 2026: journal-officiel.ga is now reachable. Its own pages confirm the citation directly — https://journal-officiel.ga/20089-166-pr-/ carries Décret n° 166/PR du 12/07/2023 promulgating the Law and citing Journal Officiel n° 218 Bis du 15 Juillet 2023, and https://journal-officiel.ga/20085-025-2023-/ hosts the law text itself (headed "Loi N° 025/2023 du 09/07/2023", the National Assembly adoption date, distinct from the 12 July promulgation decree). The source_url now points at the official gazette site directly rather than at the AFAPDP mirror. Care is needed with that issue: it also carries Loi n° 027/2023 on cybersecurity and cybercrime, whose own arts. 49 to 66 create heavy imprisonment and fine penalties that have nothing to do with the data-protection Law and must not be attributed to it. Text read across the whole of Loi n° 025/2023, including the definitions, the arts. 4 to 6 scope, the art. 43 access right, arts. 77 to 79, and the arts. 199 to 221 recourse, control, sanctions and final chapters. The definitions article of this Law is the only place in the Francophone African block where artificial intelligence is defined in a binding data-protection statute; separately, Gabon now also has an AI-specific instrument outside the data-protection Law — see ga-ord0011-2026-ai-content.

Stated maximum penalty — Art. 77 is reached by the administrative catch-all in art. 203, which provides that the Authority appraises and pronounces, without graduation, according to the breach of the present Law established, a warning against a controller not respecting the obligations flowing from the Law, a mise en demeure to cause the established breaches to cease within the time limit it fixes, and a pecuniary sanction. The phrase "sans graduation" matters: unlike Congo, where the fine becomes available only once a mise en demeure has been defied, the Gabonese Authority is expressly freed from any obligation to escalate through the list in order. Art. 204 sets the pecuniary regime. Where the controller does not comply with the mise en demeure addressed to them they may be summoned to a hearing, and after contradictory debate the APDPVP may pronounce a provisional suspension of the collection and processing of personal data for three months, becoming definitive on expiry, and a fine of one million to one hundred million francs CFA. The amount must be proportionate to the gravity of the breaches and to the advantages derived from them. On a first breach it may not exceed ninety-eight million four hundred thousand francs CFA. On recidivism it may not exceed three hundred million francs CFA or, in the case of an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of one hundred and ninety-six million francs CFA. That absolute ceiling on the percentage limb is distinctive and is worth reading carefully: because the 5 per cent figure is itself capped at one hundred and ninety-six million francs CFA, the turnover limb binds only undertakings with pre-tax turnover below roughly 3.9 billion francs CFA, and above that threshold the percentage ceases to have any effect — the opposite of how the equivalent ceilings work in Guinea, Côte d'Ivoire, Niger and Burkina Faso, where the percentage is the escalating term. Where the APDPVP has pronounced a pecuniary sanction that has become definitive before the criminal court has finally ruled on the same or connected facts, the court may order the pecuniary sanction to be set off against the fine it pronounces. Art. 205 allows warnings to be made public and, where the controller is in bad faith, the insertion of sanctions in publications at the sanctioned person's expense. Art. 206 exposes a controller holding a récépissé or authorisation who does not respect the Law's obligations, after mise en demeure, to suspension of the récépissé or authorisation for up to two months, definitive withdrawal on expiry of the suspension, and a fine of one million to one hundred million francs CFA. Art. 207 treats a controller holding neither as a de facto controller, exposed to a fine of one million to one hundred million francs CFA together with a mise en demeure to regularise. Art. 208 supplies emergency powers, including interruption of the processing for a maximum of three months, where implementation of a processing or exploitation of data entails a violation of rights and liberties. On the penal side art. 213 punishes obstruction of the APDPVP with six months to one year's imprisonment and a fine of one million to ten million francs CFA; no penal article of this Law reaches art. 77.

In force · 15 Jul 2023 checked 21 Sep 2026 Loi n° 025/2023 art. 77 ↗ medium confidence
Gabon Binding

Ordonnance n° 0011/PR/2026 Chapitre VII (arts. 32-34) — deepfake prohibitions, a 24-hour AI-content takedown right, and the audit of AI detection and marking systems

Binds Art. 2 scope: the ordonnance applies to every user, editor or host of online social networks and digital platforms as soon as the content diffused is accessible on, or produces its effects on, Gabonese territory, and it also covers the treatment of any offer of publicly accessible online communication goods or services, whether free or for consideration. Art. 32's prohibitions attach to the content itself «indépendamment de leur lieu de création», so they reach content generated abroad; art. 41 gives the référé judge express extraterritorial competence. Art. 33's twenty-four-hour takedown duty binds the éditeur and the hébergeur as defined in art. 3 — respectively the person who by an active role and moderation power controls and implements diffusion, and the person who supplies the technical means of storage and public availability of third-party content. Art. 34's audit power reaches any social network or platform on which AI detection and marking systems are deployed. No size, turnover or user-number threshold appears anywhere in the ordonnance. Impact tier: all entities.. Chapitre VII of Ordonnance n° 0011/PR/2026 du 26 février 2026 portant réglementation de l'usage des réseaux sociaux et des plateformes numériques — «De la régulation des contenus générés par intelligence artificielle» — is Gabon's first AI-specific binding rule, and it consists of exactly three articles. Art. 32 prohibits on national territory, «indépendamment de leur lieu de création», four classes of AI-generated content: hypertrucages realistically depicting an identifiable natural person in sexual situations without their express consent; hypertrucages of a public or private figure attributing to them false statements or conduct of a nature to cause serious harm to public order, national security or the dignity of persons; the representation of sexual situations involving minors, whatever the technical modality; and imitation of the visual or sound identity of a Gabonese State institution for disinformation purposes. Its closing paragraph makes content falling under those prohibitions liable to «la saisine immédiate du juge des référés». Art. 33 gives any identifiable natural person represented in AI-generated content published on a social network or digital platform without their consent a droit de signalement: the right to seise the editor or host to remove the illicit content within a maximum of twenty-four hours from the report, and, on refusal or inaction within that period, to go directly to the Haute Autorité de la Communication or the competent courts. Art. 34 lets the Haute Autorité de la Communication or the Ministère Public, on its own initiative, commission an independent technical audit of the AI-content detection and marking systems deployed on a social network or platform. Two provisions outside the chapter carry the AI rule further. Art. 42, in the référé numérique procedure created by arts. 39 to 44, lists among the provisional measures the juge des référés may order «l'apposition forcée d'un marquage d'origine sur un contenu généré par intelligence artificielle» — a court-ordered origin marking, alongside temporary suspension of an account or content, targeted de-referencing and publication of a correction; art. 41 gives that judge expressly territorial and extraterritorial competence and requires a ruling «d'heure à heure». Art. 52 supplies the one AI-specific criminal aggravator in the ordonnance: identity usurpation via a social network or platform is punished by five years' imprisonment and a fine of up to 20,000,000 FCFA, but where the same offences are committed «par le biais d'une intelligence artificielle» the penalty rises to ten years' imprisonment and a fine of up to 50,000,000 FCFA. The definitions article, art. 3, defines Contenu généré par intelligence artificielle as any text, image, video, audio or synthetic content created or substantially modified by an automated algorithmic system; Hypertrucage ou deepfake as image, audio or video content generated or manipulated by an artificial intelligence resembling existing persons, objects, places, entities or events and which would falsely appear authentic or truthful to a person; Intelligence Artificielle as a logical and automated process generally resting on an algorithm able to carry out well-defined tasks — the same formula as the Loi n° 025/2023 definition; and Marquage d'origine as a technical process allowing persistent and verifiable identification that a content was generated or modified by an artificial-intelligence system. The general labelling duty that gives that last definition its operative effect is not here: it sits in art. 53, in the transitional chapter, and is deferred — tracked separately as ga-ord0011-2026-art53-marquage.

Corrected 1 September 2026 against the primary gazette text, which had not been read when this row was first written on the same date; the original row rested on secondary legal commentary and was wrong in two respects that mattered. First, it recorded a labelling duty for AI-generated content as in force from 8 April 2026. The ordonnance contains no labelling duty in Chapitre VII at all: the marking obligation is in art. 53, in Chapitre XI «Des dispositions transitoires, diverses et finales», and it is expressly subject to a twelve-month period running from publication, so it does not bite until April 2027. That limb has been split out into ga-ord0011-2026-art53-marquage at lifecycle dateset. Second, the original row carried «fines up to 50,000,000 FCFA» as the penalty, taken from press reporting. Chapitre X, arts. 45 to 52, is the penal chapter, and none of arts. 45, 46, 47, 48, 50 or 51 attaches to arts. 32, 33 or 34: they punish, respectively, failure to publish mandatory identity information, an host's failure to give the editor identification means, failure to insert a right of reply within forty-eight hours, failure in the duty to combat the diffusion of illicit content, obstruction of the Haute Autorité de la Communication, and phishing. The 5,000,000 to 50,000,000 FCFA band the press attributed to the AI rules is the band of arts. 45, 46 and 48. The only penalty in the ordonnance that is AI-specific on its face is the final paragraph of art. 52, recorded in the penalty field here. There is no criminal penalty attached to art. 32 itself; its enforcement route is the référé numérique of arts. 39 to 44, which is a provisional-measures procedure, and art. 43 provides that any measure the référé judge orders expires automatically if no proceedings on the merits are commenced within one month of the seisin. Structure confirmed against the text: 55 articles in 11 chapters, signed at Libreville 26 February 2026 by the President of the Republic and countersigned by the Ministers of the Digital Economy, Defence, Communication and Media, the Interior and Justice. Art. 55 is a bare abrogation-of-contrary-provisions, registration and publication clause with no deferred commencement, so arts. 32 to 34, 39 to 44 and 52 took effect on publication. The date recorded is the opening date of the gazette issue in which the ordonnance was published, Journal Officiel de la République Gabonaise n° 110 covering 8 to 15 April 2026; the issue is dated as a week rather than as a day, so the true publication date lies between 8 and 15 April 2026, and confidence is set to medium on that account alone — every other statement in this row is read directly off the gazette text at pages 135 to 141. On sourcing: the official gazette host journal-officiel.ga carries the landing page for this instrument at https://journal-officiel.ga/22404-0011-pr-2026-/ but its port 443 timed out on every attempt this session, as it did when the Loi n° 025/2023 row was first written. The source_url therefore points at a complete scan of Journal Officiel n° 110 itself — every page carries the gazette's own running head «JOURNAL OFFICIEL DE LA REPUBLIQUE GABONAISE — 8 AU 15 AVRIL 2026 — N° 110» and its own pagination — rather than at a landing page that cannot be opened. Note one scanning artefact in the gazette itself: the AI aggravator paragraph of art. 52 prints the currency as «FCEA», a typographic error for FCFA, which is the unit used in every other penal article of the same chapter. Two companion ordonnances of the same date in the same issue, 0012/PR/2026 amending the Code de la Communication and 0013/PR/2026 on the Haute Autorité de la Communication, are not separately tracked: neither carries an AI-specific rule. Distinct from, and additional to, the automated-decision rule of the data-protection statute at Loi n° 025/2023 art. 77 — see ga-loi0252023-art77. Source moved 16 September 2026 off directinfosgabon.com (a Gabonese news site) onto the Journal Officiel's own host: the live page at https://journal-officiel.ga/22404-0011-pr-2026-/ still times out on port 443 from this egress, as it has every session since this row was written, so the citation is the Internet Archive's capture of that same official page — https://web.archive.org/web/20260611101549/https://journal-officiel.ga/22404-0011-pr-2026-/ — the CAR/Senegal/São Tomé remedy. The archived page is the gazette's own HTML rendering of Ordonnance n° 0011/PR/2026, not a scan, and its full text of arts. 32-34, 42, 45-53 and the signature block (Libreville, 26 February 2026, Brice Clotaire Oligui Nguema, countersigned by the Ministers of Digital Economy, Defence, Communications, Interior and Justice) was re-read end to end against this row and against ga-ord0011-2026-art53-marquage; every fact, including the «FCEA» typo for FCFA in art. 52's AI aggravator, matches verbatim. No substantive change.

Stated maximum penalty — No penal article of the ordonnance attaches to arts. 32, 33 or 34. Enforcement of the art. 32 prohibitions runs through the référé numérique of arts. 39 to 44: the juge des référés, seised by the Ministère Public, the Haute Autorité de la Communication or any person justifying an interest to act, rules «d'heure à heure» with territorial and extraterritorial competence and may order temporary suspension of an account or of a content, targeted de-referencing, publication of a correction, and forced application of an origin marking on AI-generated content; where a viral content causes manifestly serious disturbance, art. 44 adds temporary traffic slowing in identified zones, restriction of specific functionalities and temporary suspension of access to a platform, for a maximum of seventy-two hours. Art. 43 makes every such measure temporary and expires it automatically if no proceedings on the merits begin within one month of the seisin. The single AI-specific criminal penalty is the final paragraph of art. 52: where identity usurpation by means of a social network or digital platform — usurping a third party's identity or using data identifying them, so as to disturb their tranquillity or that of others, harm their honour, standing or interests, or with intent to commit, aid or encourage an illegal activity constituting a délit or a crime, which the preceding paragraph punishes with five years' imprisonment and a fine of up to 20,000,000 FCFA — is committed «par le biais d'une intelligence artificielle», the penalty is ten years' imprisonment and a fine of up to 50,000,000 FCFA. Breach of the art. 33 twenty-four-hour takedown duty is reachable in practice only through art. 48, the general duty of editors and hosts to combat the diffusion of illicit content, punished by one year's imprisonment and a fine of 5,000,000 to 50,000,000 FCFA or one of those penalties only — art. 3 defines contenu illicite as content harming human dignity, privacy, honour, bonnes mœurs or administrative security, which the art. 32 categories will usually satisfy, but the ordonnance does not make that link expressly.

In force · 8 Apr 2026 checked 21 Sep 2026 Ordonnance 0011/PR/2026 arts. 32-34 ↗ medium confidence
Gabon Binding

Ordonnance n° 0011/PR/2026 art. 53 — AI-content detection tooling, visible and permanent origin marking, and metadata handover, due twelve months after publication

Binds «Tout éditeur de réseau social ou de plateforme numérique» — the éditeur only, not the hébergeur, on the art. 3 definitions: the éditeur is the natural or legal person who, by an active role and a power of moderation, controls and implements the diffusion of communications, publications or information on a communication service, social network or online digital platform. Combined with the art. 2 scope, the duty reaches any such editor whose diffused content is accessible on, or produces its effects on, Gabonese territory, with no size, turnover or user-number threshold and no domestic establishment requirement. Impact tier: all entities.. Art. 53 is the opening article of Chapitre XI, «Des dispositions transitoires, diverses et finales», and it is where the operative AI-content labelling duty of the Gabonese ordonnance actually sits. Every editor of a social network or digital platform is required, within a period of twelve months from the publication of the ordonnance, to do four things. To implement effective technical age-verification mechanisms on every new registration. To deploy automatic detection tools for AI-generated content published or shared on its services, according to technical standards set by the texts in force — standards that art. 54 leaves to implementing regulations and that had not been issued as at 1 September 2026. To apply a visible, clear and permanent marking to any content identified as generated or substantially modified by an artificial-intelligence system, accessible to the user without any additional action on their part. And to preserve, and to transmit to the Haute Autorité de la Communication within eight days, the origin metadata of AI-generated content that is the subject of a judicial or administrative investigation. Read with art. 3, which defines Marquage d'origine as a technical process allowing persistent and verifiable identification that a content was generated or modified by an artificial-intelligence system, the third indent is a synthetic-content labelling mandate of the same family as EU AI Act art. 50, but placed on the platform rather than on the generator, and framed as a detection-and-marking duty rather than a provider disclosure. The second indent is unusual in a comparative view: it requires platforms to run AI-content detection, not merely to pass through a label the generator applied. Art. 34, in the AI chapter, presupposes this article by giving the Haute Autorité de la Communication and the Ministère Public power to commission an independent technical audit of «les systèmes de détection et de marquage des contenus générés par intelligence artificielle» deployed on a platform.

Split out of ga-ord0011-2026-ai-content on 1 September 2026 once the primary gazette text was read. The original single row recorded the labelling duty as in force from publication; it is not. Art. 53 opens the transitional chapter and gives «un délai de douze mois à compter de la publication de la présente ordonnance». Applying the commencement method: this is a direct offset from publication, not a named day and not an elapsed-term formula, so it is computed rather than looked up. The one uncertainty is the base date. Journal Officiel de la République Gabonaise n° 110 is dated as a week, «8 au 15 avril 2026», printed on the running head of every page, and not as a single day; Gabonese press reporting of the publication settles on 8 April. The date recorded here is therefore the earliest date on which the twelve-month period can expire, 8 April 2027, and the outer bound is 15 April 2027. Confidence is medium for that reason and for that reason only. Three further points on the shape of this deadline. It is a compliance deadline running against the editor, not a commencement date for the article: the ordonnance itself has been in force since publication, and art. 55 defers nothing. The second indent is conditioned on technical standards «définis par les dispositions des textes en vigueur», and art. 54 provides that regulatory texts determine as needed the provisions necessary for application of the ordonnance; no such text had been published as at 1 September 2026, so the detection-standard limb has no content yet and the deadline may in practice be reached with the standard still unissued. That is a watch item, not a reason to move the date. And the first indent, age verification, is not an AI duty at all; it is recorded here because it shares the article and the same twelve-month clock, and because art. 3 sets the digital age of majority at sixteen. Source: the same scan of Journal Officiel n° 110 used for the Chapitre VII row, art. 53 at page 141 of the issue; the official host journal-officiel.ga timed out on port 443 throughout this session. Source moved 16 September 2026 off directinfosgabon.com (a Gabonese news site) onto the Journal Officiel's own host: the live page at https://journal-officiel.ga/22404-0011-pr-2026-/ still times out on port 443 from this egress, as it has every session since this row was written, so the citation is the Internet Archive's capture of that same official page — https://web.archive.org/web/20260611101549/https://journal-officiel.ga/22404-0011-pr-2026-/ — the CAR/Senegal/São Tomé remedy. The archived page is the gazette's own HTML rendering of Ordonnance n° 0011/PR/2026, not a scan, and its full text of arts. 32-34, 42, 45-53 and the signature block (Libreville, 26 February 2026, Brice Clotaire Oligui Nguema, countersigned by the Ministers of Digital Economy, Defence, Communications, Interior and Justice) was re-read end to end against this row and against ga-ord0011-2026-art53-marquage; every fact, including the «FCEA» typo for FCFA in art. 52's AI aggravator, matches verbatim. No substantive change.

Stated maximum penalty — None stated. Art. 53 carries no penalty of its own, and Chapitre X, the penal chapter at arts. 45 to 52, does not reference it: arts. 45 and 46 punish identity-information failures, art. 47 the right of reply, art. 48 the general duty to combat illicit content, art. 50 obstruction of the Haute Autorité de la Communication, and arts. 51 and 52 phishing and identity usurpation. Because the ordonnance predates any implementing text under art. 54, there is at present no stated sanction for an editor that reaches April 2027 without detection tooling or origin marking in place. Two indirect routes exist. Art. 34 lets the Haute Autorité de la Communication or the Ministère Public commission an independent technical audit of the detection and marking systems on its own initiative, and art. 50 punishes obstruction of the Authority — refusing to communicate useful information or documents to its members or authorised agents, concealing or destroying them, or supplying information not conforming to the records — with one year's imprisonment and a fine of 2,000,000 to 20,000,000 FCFA or one of those penalties only, which is the sanction an editor would face for stonewalling such an audit rather than for failing the underlying duty. Separately art. 42 lets the juge des référés order forced application of an origin marking on a given AI-generated content, which is a per-content remedy and not a sanction for breach of art. 53.

Applies 8 Apr 2027 checked 21 Sep 2026 Ordonnance 0011/PR/2026 art. 53 ↗ medium confidence

Georgia 1

Georgia Binding

Law on Personal Data Protection art. 19 — a GDPR-shaped automated-decision right whose exceptions cover only profiling, whose safeguards must be asked for, and whose fine tops out at GEL 20 000

Binds Controllers and processors. Art. 2(1) applies the Law to processing wholly or partly by automated means within the territory of Georgia, to non-automated processing of data forming part of or destined for a filing system, and — the extraterritorial hook — to processing by a controller not established in Georgia using technical means available in Georgia, except where those means serve solely to transit data. That is a means-based test rather than the GDPR's targeting test, so it can reach a foreign operator with equipment in Georgia and no Georgian customers. Such a controller must appoint a special representative in Georgia before processing begins (art. 36). Art. 19 sits in Chapter III (arts. 13-25), the rights chapter, so it binds anyone who is a controller for the decision in question. Art. 2(2)-(4) carve out purely personal or household processing and put semi-automated and non-automated processing of state-secret data for crime prevention, investigation and prosecution outside the Law; automated and semi-automated processing by those same institutions stays inside it. No sectoral limit and no size threshold applies to art. 19 — the SME relief in this Law runs to the data protection officer duty (art. 33) and to the size of the fine, never to the automated-decision right.. Art. 19 of the Law of Georgia on Personal Data Protection (No. 3144-XIმც-Xმპ of 14 June 2023) is titled «ავტომატიზებული ინდივიდუალური გადაწყვეტილების მიღება და მასთან დაკავშირებული უფლებები» — automated individual decision-making and related rights. Art. 19(1) gives the data subject the right not to be subject to a decision taken solely by automated means, including on the basis of profiling, which produces for them a legal effect or an effect of other substantial significance. Three features separate it from GDPR art. 22, and all three are in the Georgian text, not artefacts of translation. First, the exception clause is narrower than the prohibition it qualifies. Art. 19(1) reads «გარდა იმ შემთხვევისა, როდესაც პროფაილინგის საფუძველზე გადაწყვეტილების მიღება» — except where the taking of the decision *on the basis of profiling* is (a) based on the data subject's explicitly expressed consent; (b) necessary for concluding or performing a contract between the data subject and the controller; or (c) provided for by law or by a subordinate normative act issued within delegated statutory powers. The prohibition in the opening limb covers any solely automated decision; the escape hatches are drafted only for profiling-based ones. On the face of the text a solely automated decision that does not rest on profiling — a hard-coded threshold rule, for instance — has no exception route at all. Second, the safeguards are reactive. Art. 19(2) opens «მონაცემთა სუბიექტის შესაბამისი მოთხოვნისა» — upon the data subject's respective request — the controller must take appropriate measures to protect the subject's rights, freedoms and legitimate interests, including by involving human resource in the decision-making process, and by giving the subject the possibility to express a view and to contest the decision. GDPR art. 22(3) makes the same three safeguards a standing duty the controller owes without being asked; Georgia makes the subject go first, and gives no deadline for the controller's answer. Third, the human-review carve-out is inverted in the official English translation and must be read from the Georgian. The Georgian parenthesis is «(გარდა ამ მუხლის პირველი პუნქტის „გ“ ქვეპუნქტით გათვალისწინებული შემთხვევისა)» — human involvement is required *except* in the case under paragraph 1(c), the law-or-subordinate-act limb. matsne's English renders this as «including by involving human resources in the decision-making as provided for by paragraph 1(c)», which says the opposite: that human involvement attaches to the statutory limb. The Georgian reading is the GDPR-aligned one — human review for the consent and contract routes, none for decisions the legislature itself mandated — and the Georgian text governs. Art. 19(3) permits special-category data in such decisions only in the cases at art. 6(1)(a), (f) and (j), and only where appropriate safeguards for the subject's rights, freedoms and legitimate interests exist. The transparency limb is request-triggered, not proactive. Art. 13(1)(g) entitles the data subject, on request and free of charge, to «the decision made as a result of automated processing, including profiling, and the logic involved in making such a decision, as well as its impact on the processing and the expected results of the processing», answered within 10 working days and extensible by 10 more. But arts. 24 and 25 — the proactive notice lists for data collected from the subject and from third parties, the slots occupied by GDPR arts. 13(2)(f) and 14(2)(g) — were read item by item and contain no automated-decision or logic item at all. A Georgian controller therefore never has to volunteer that a decision was machine-made; the subject has to know to ask. The DPIA duty is independent and unconditional. Art. 31(2)(a) makes a data protection impact assessment mandatory whenever a controller «makes decisions, in a fully automated manner, including on the basis of profiling, having legal, financial or other significant consequences for a data subject» — no high-risk screening test first, and note that it adds *financial* consequences to the trigger, which GDPR art. 35(3)(a) does not name. Art. 31 and its penalty at art. 80 commenced on 1 June 2024, three months after art. 19 itself.

In force since 1 March 2024. Art. 90(2) of the Law names articles 7-30 among those commencing on that date, which carries art. 19 and its penalty route at art. 72; the Law itself was promulgated on the website of the Legislative Herald on 3 July 2023 but art. 90(1) commenced only the final provisions then. The DPIA trigger at art. 31(2)(a) and its penalty at art. 80 followed on 1 June 2024 under art. 90(3). Art. 89 declared the previous Law on Personal Data Protection of 28 December 2011 invalid from the same 1 March 2024 date, and art. 88(1) keeps the 2011 Law alive only for administrative liability for offences committed before it. Art. 19 has not been amended: the consolidated text as at 10 June 2026 carries no amendment footnote on art. 19, while thirteen other articles carry one for Law of Georgia No 1289 of 17 December 2025. That amendment did not touch the rule but did move the regulator — see the max_penalty field.

Stated maximum penalty — GEL 20 000 in total, which is roughly USD 7 400 — the lowest ceiling of any GDPR-family automated-decision rule in the atlas. Breach of art. 19 is an administrative offence under art. 72, «violation of the rights of a data subject provided for by Chapter III (except for Article 22)». The tariff is fixed, not a range: art. 72(1) gives a warning or GEL 1 000 for a natural person, public institution, non-commercial legal entity, or an undertaking whose annual turnover does not exceed GEL 500 000, and GEL 1 500 for a legal person, branch of a foreign enterprise or individual entrepreneur above that turnover line. Art. 72(2) raises it to GEL 2 000 / 3 000 where two or more Chapter III rights are violated; art. 72(3) and (4) raise the same two tiers to GEL 1 500 / 3 000 and GEL 3 000 / 5 000 respectively where an aggravating circumstance is present. Failing the art. 31 impact assessment is a separate offence under art. 80 at GEL 2 000 / 3 000, or GEL 3 000 / 5 000 aggravated. Art. 64(2) then caps the aggregate: where offences are found in a single inspection or dealt with in one set of proceedings, total fines may not exceed GEL 10 000 for the lower tier and GEL 20 000 for the upper. Art. 64(3) bars double-counting the same act across articles. Enforcement passed from the Personal Data Protection Service to the State Audit Office of Georgia and the Auditor General under Law of Georgia No 1289 of 17 December 2025 (website, 23 December 2025), which rewrote Chapter VI as «Principles of Activities of the State Audit Office in the Field of Data Protection»; the data subject's route under art. 22 now runs to the State Audit Office, a court, or a superior administrative body. Art. 52 non-monetary measures may be imposed alongside a fine.

In force · 1 Mar 2024 checked 23 Sep 2026 PDP Law art. 19 ↗ high confidence

Ghana 1

Ghana Binding

Data Protection Act s. 41 — notice-based right against solely-automated decisions, plus an automatic duty to notify and reconsider

Binds Data controllers within the scope of s. 45(1): those established in Ghana processing data in Ghana; those not established in Ghana but using equipment or a data processor carrying on business in Ghana to process the data; and processing in respect of information originating partly or wholly from Ghana. Section 45(3) treats as established in Ghana an individual ordinarily resident there, a body incorporated under Ghanaian law, a partnership or person registered under the Registration of Business Names Act, 1962 (Act 151) or the Trustees Incorporation Act, 1962 (Act 106), an unincorporated joint venture or association operating in part or in whole in Ghana, and any other person maintaining an office, branch or agency there; s. 45(2) requires a controller not incorporated in Ghana to register as an external company. Registration with the Data Protection Commission is a standing precondition of processing: s. 53 prohibits processing personal data without registration and s. 56 makes failure to register an offence. The s. 41 duties bind any controller that takes a solely-automated decision significantly affecting an individual, irrespective of size. Impact tier: all entities.. Section 41 of the Data Protection Act, 2012 (Act 843), headed “Rights in relation to automated decision-taking”, carries Ghana's operative automated-decision rule, in the block of data-subject rights at ss. 35 to 44. Subsection (1) entitles an individual at any time, by notice in writing to a data controller, to require the controller to ensure that any decision taken by or on behalf of the controller which significantly affects that individual is not based solely on the processing by automatic means of personal data in respect of which that individual is the data subject. Subsection (2) then operates despite the absence of such a notice: where a decision which significantly affects an individual is based solely on that processing, the controller shall as soon as reasonably practicable notify the individual that the decision was taken on that basis, and the individual is entitled, by notice in writing, to require the controller to reconsider the decision within twenty-one days after receipt of the notification. Subsection (3) gives the controller twenty-one days after receipt of that notice to inform the individual in writing of the steps it intends to take in compliance with that notice. Subsection (4) disapplies the section where the decision is made in the course of considering whether to enter into a contract with the data subject, with a view to entering into the contract, in the course of performance of the contract, for a purpose authorised or required by or under an enactment, or in other circumstances prescribed by the Minister. Subsection (5) lets the Commission, if satisfied on a complaint by a data subject that a person taking a decision has not complied, order the controller into compliance; subsection (6) preserves the rights of third parties. Section 43 separately gives a data subject who suffers damage or distress through a controller's contravention of a requirement of the Act a right to compensation from that controller.

Commencement is not stated on the face of the Act. Section 99 provides that the Minister shall specify the date when the Act comes into force by publication in the Gazette, and the enacted text records only a Date of Gazette notification of 18 May 2012, which is the publication of the Act itself and not the appointed commencement. The Data Protection Commission — the statutory supervisory authority established by s. 1 of this Act, so the body whose own existence dates from the appointed day — states on its Who We Are page that the Commission “was established by the Data Protection Act 2012 (Act 843) which came into force 16th October 2012”. That regulator statement is the date recorded here. The underlying ministerial commencement instrument itself could not be retrieved: the Commission publishes no commencement or Executive Instrument in its media library, and Ghana has no online official gazette that serves the instrument. The date is therefore taken from the supervisory authority's own publication rather than from the gazette notice, and should be revisited if the instrument surfaces. Section 41 carries no separate or deferred commencement of its own. Act 843 remains the principal Act: it has no amendment on the Commission's records and the Commission has published no automated-decision or AI guidance under it, so the statutory text is the whole of the binding rule. Ghana is the tracker's fourth African jurisdiction, after South Africa, Kenya and Nigeria. Its drafting is the oldest of the four and is modelled on the UK Data Protection Act 1998 s. 12 rather than on GDPR Art. 22: the right is exercised by written notice rather than existing as a standing prohibition, and the contract carve-out in s. 41(4) is wider than the GDPR-style exceptions in ke-dpa-s35 and ng-ndpa-s37 because it excludes pre-contractual consideration and contract performance outright, without requiring compensating safeguards. Against that, s. 41(2) is stronger than all three peers on one axis: the duty to notify and the right to demand reconsideration bite automatically whenever a solely-automated significant decision is taken, without the data subject having served any prior notice, and both legs run on a hard twenty-one-day clock, where ke-dpa-s35 says only “within a reasonable period” and za-popia-s71 and ng-ndpa-s37 set no deadline at all. Text read in the copy of the Act published by the Data Protection Commission, the supervisory authority established under it. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. Ghana deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 3 June 2019, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. The divergence here is the widest of the sixteen, and it runs on two axes at once. Art. 14(5) of the Convention is a standing prohibition that operates of its own force and admits no exception — no contract limb, no consent limb, no legal-authorisation limb. s. 41 is neither: the right is exercised by written notice from the data subject rather than existing as a standing bar, so absent a notice the decision is simply lawful in Ghana; and s. 41(4) then disapplies the section for decisions made in the course of considering whether to enter into a contract with the data subject, with a view to entering into it, in the course of its performance, or for a purpose authorised or required by or under an enactment. Automated hiring and credit decisions sit squarely inside that carve-out. On the Convention's wording the same decisions are barred outright, with no notice required and no carve-out available. The national statute is carried here as the operative rule, because it is the instrument that has a supervisory authority behind it and a penalty attached to it, and the Convention runs behind it as a stricter parallel rule. This is recorded as a divergence rather than resolved: neither instrument repeals or qualifies the other, Ghana has not legislated the Convention into domestic law by a separate instrument, and the domestic reception question — whether art. 14(5) is directly effective in Ghana, as arts. 18 and 144 of the Mozambican and Namibian constitutions respectively make it there — has not been separately verified for Ghana and is not asserted here. A controller relying on an exception the statute grants therefore stands on solid statutory ground and unresolved treaty ground.

Stated maximum penalty — Section 41 non-compliance is not itself an offence. The route to a sanction runs through the Commission: on a complaint by a data subject under s. 41(5) the Commission may order the controller to comply, and where the Commission is satisfied that a controller has contravened or is contravening any of the data protection principles it shall serve an enforcement notice under s. 75 requiring specified steps or a halt to specified processing. Failure to comply with an enforcement notice or an information notice is an offence under s. 80(1), punishable on summary conviction by a fine of not more than one hundred and fifty penalty units or a term of imprisonment of not more than one year, or both. Section 95 sets a general penalty, for an offence under the Act for which no penalty is specified, of a fine of not more than five thousand penalty units or imprisonment of not more than ten years, or both, and s. 94(2) applies the same five-thousand-penalty-unit ceiling to offences under Regulations made under the Act. Section 43 gives the data subject a separate civil claim for compensation for damage or distress caused by a failure to comply with a requirement of the Act. Penalty units are valued under the Fines (Penalty Units) Act, 2000 (Act 572), which is not part of Act 843.

In force · 16 Oct 2012 checked 17 Sep 2026 Data Protection Act s. 41 (Act 843) ↗ high confidence

Guinea 1

Guinea Binding

Loi L/2016/037/AN art. 27 — the strictest Francophone automated-decision bar, with no exception of any kind and a general penalty running to 7% of turnover

Binds Responsables du traitement and their sous-traitants, subordonnés and préposés. The prior formalities are set out in Chapitres V and VI: art. 7 subjects six categories to prior authorisation before any implementation — genetic and medical data and scientific research in those fields, data on offences, convictions or security measures pronounced by the courts, national identification numbers or identifiers of the same nature including telephone numbers, biometric data, public-interest processing including for historical, statistical or scientific purposes, and transfers to a third country — while art. 8 lets the Authority establish norms simplifying or exempting the declaration duty for the most common categories, and art. 6 exempts processing for which a data protection correspondent has been designated except where a third-country transfer is envisaged. Art. 9 fixes the minimum contents of a request for opinion, a declaration or an authorisation request, art. 11 the channels for filing, and art. 12 gives the Authority two months, extendable once by two months on a reasoned decision, to accept or refuse — with the notable rule that silence beyond those periods amounts to implicit acceptance of the declaration or a tacit authorisation, and that an appeal against a refusal is not suspensive. Profiling and automated decision-making appear in none of the art. 7 authorisation categories, so Guinea, like Togo and unlike Burkina Faso and Niger, imposes no ex ante gate on the processing art. 27 governs. Art. 17 requires a reasoned opinion of the Authority before processing on behalf of the State, a public-law legal person or a private-law legal person managing a public service is authorised by regulation, in the fields of State security, national defence or public security, the prevention, investigation, establishment or prosecution of criminal offences or the execution of criminal convictions or security measures, the population census, and the processing of salaries, pensions, taxes, duties and other settlements. The art. 27 bar binds the courts under its first limb and every administrative or private decision-maker appraising human conduct under its second, irrespective of size or sector. Impact tier: all entities.. Article 27 of Loi n° L/2016/037/AN du 28 juillet 2016 relative à la cybersécurité et la protection des données à caractère personnel is Guinea's operative automated-decision rule. It sits in Chapitre VIII on the guiding principles of personal-data processing, between the art. 26 press-and-Penal-Code saving and the art. 28 cross-border-transfer article, in two unnumbered paragraphs. The first: no judicial decision involving an appraisal of the conduct of a natural person may have as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality. The second: no administrative or private decision involving an appraisal of human conduct may have as its sole foundation an automated processing of personal data giving a definition of the profile or of the personality of the person concerned. Two things make this the strictest formulation in the Francophone family tracked. First, the judicial limb does not contain the word "seul", so it bars any judicial decision appraising conduct from resting on such a processing at all, whatever else the court also relies on, while the qualifier is present in the second limb of the same article. That asymmetry is not unique to Guinea, and an earlier version of this entry wrongly said it was: Madagascar's art. 3, Congo-Brazzaville's art. 13, Gabon's art. 77 and Algeria's art. 11 all drop the qualifier from the judicial limb and keep it in the other, which makes the pattern a shared inheritance of the Francophone family rather than a Guinean innovation. What Guinea combines with it is what no other row does: its wide second limb reaches any administrative or private decision appraising human conduct, not merely decisions producing legal effects as in Congo, Gabon, Togo, Morocco and Algeria. Second, and like Côte d'Ivoire, Mali and Burkina Faso, the Law supplies no carve-out whatever — no contract exception, no consent exception, no legal-authorisation exception and no opportunity to present observations. The Law creates no right to know the logic underlying an automated processing: art. 30 lists what must be given at collection and art. 31 the access right, which runs to information enabling the data subject to know and to contest the processing, confirmation, communication of the data and their origin, and purposes, categories and recipients. There is no human-review right and no right to a fresh non-automated decision, and the Law carries no definition of profiling. What the rights chapter does carry, unusually for a 2016 Francophone statute and evidently drawn from the then-new GDPR rather than from the Directive, is a right to erasure and digital oblivion in arts. 35 to 39 and a right to data portability in art. 40.

Unusually for this block, the commencement rule is express and needs no inference. Art. 65, the final article, reads that the present Law, which abrogates all prior contrary provisions and enters into force from the date of its promulgation, shall be registered and published in the Journal Officiel de la République de Guinée and executed as a law of the State. The date stamped in the signature block over the signature of President Prof. Alpha Condé at Conakry is 28 July 2016, and 28 July 2016 is therefore the date recorded here. This resolves a discrepancy that runs through the secondary record: several repositories, including the copy indexed by the Cour Suprême, cite the Law as "du 26 juillet 2016", while the National Assembly's own page and the copy published by ANSSI Guinée carry 28 July. The enacted text read for this entry carries 28 July, and because art. 65 attaches force to promulgation rather than to publication, the Journal Officiel date does not need to be established for the date on this row to be sound. Confidence is medium rather than high for one reason only: the promulgation date is a rubber stamp impressed into a blank on the signature page of a scanned document rather than typeset, and the Journal Officiel citation for the Law could not be established from a primary source, so the two-day margin around 26-28 July 2016 cannot be closed by a second official instrument. Art. 63 is transitional and is not a deferral of art. 27: controllers had a maximum of one year from promulgation to bring themselves into conformity, a period that closed on 28 July 2017. Art. 64 leaves unspecified application modalities to decrees, orders and decisions. The abrogation in art. 65 names no statute, so no predecessor is superseded on the tracker. Guinea is not an ECOWAS outlier by accident: it is a founding member, and its art. 27 takes the wider ECOWAS Supplementary Act A/SA.1/01/10 drafting in its second limb — any administrative or private decision appraising human conduct — placing it with Côte d'Ivoire, Burkina Faso, Niger and Mali rather than with Togo, Morocco and Algeria, whose second limb is confined to decisions producing legal effects. Within that ECOWAS group Guinea is the strictest, because its judicial limb alone omits the word "seul". The Law is a combined instrument: cybersecurity and cybercrime occupy roughly its first two thirds and personal data protection the last, with the data-protection part restarting its own definitions at p. 34 of the enacted text and running from art. 1 to art. 65. Text read page by page in the copy published by the Agence Nationale de la Sécurité des Systèmes d'Information, the Guinean State agency, including the definitions, arts. 7 to 13, 14 to 17, 18 to 29, 30 to 40, 41 to 43 and 55 to 65. The pages were read as page images because the file is a scan with no text layer. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. Guinea deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 16 October 2018, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. This is one of two party rows where the overlay changes nothing. Art. 14(5) of the Convention admits no exception of any kind — no contract limb, no consent limb, no legal-authorisation limb — and neither does art. 27, which supplies no carve-out whatever and not even an opportunity-to-present-observations proviso. The two instruments state the same absolute bar, so the Convention adds no stricter rule in Guinea and there is no divergence to record. It is worth stating positively rather than leaving silent: the absence of a Malabo note on this row reflects convergence, not an unchecked question. The Convention likewise adds nothing on explanation, since arts. 16 and 17 carry no automated-decision or logic item, which is the same gap art. 27 leaves.

Stated maximum penalty — Guinea is the one jurisdiction in this block where the automated-decision bar is directly and heavily enforceable, and the reason is that art. 56 is a general catch-all rather than a list of named offences. Art. 56 provides that any controller, or their processor, subordinate or agent, who does not respect the provisions of the present Law shall be punished by a fine of 50,000,000 to 150,000,000 Guinean francs. On recidivism within the five years following the date on which that fine became definitive, the fine is raised to an amount which may not exceed 1,500,000,000 Guinean francs and, where an undertaking is concerned, to an amount which may not exceed 7 per cent of pre-tax turnover for the last closed financial year. Because art. 56 is drafted against "les dispositions de la présente loi" without enumeration, it reaches art. 27 on its face — no other Francophone row on the tracker has a penalty that reaches its automated-decision article directly, and the 7 per cent turnover ceiling is the highest in the block, against 5 per cent in Côte d'Ivoire, Niger and Burkina Faso. Art. 55 separately punishes obstruction of the Authority in charge of Personal Data Protection, or failure to comply with its decisions and injunctions, with six months to three years' imprisonment and a fine of 20,000,000 to 150,000,000 Guinean francs, with accomplices liable to the same penalties and the Procureur de la République or competent judge to be informed without delay. Art. 57 leaves the modalities of recovery of the Authority's pecuniary sanctions to regulation. Art. 58 allows administrative and penal sanctions to be aggravated on recidivism at the discretion of the Authority or the competent judicial authority, with imprisonment doubled and fines doubled for a natural person and doubled to quintupled for a legal person. Art. 59 allows additional sanctions of the same nature as those in the cybercrime law. Art. 60 requires that sanctions be published at least in the Journal Officiel, on the Authority's website and on the CERT's, in a newspaper or legal-notices journal and at the registry of the competent court, the last two at the convicted person's expense. Art. 61 preserves the sanctions available under the cybercrime law, and art. 62 aligns limitation periods with the Penal Code and the Code of Criminal Procedure.

In force · 28 Jul 2016 checked 21 Sep 2026 Loi n° L/2016/037/AN art. 27 ↗ medium confidence

Equatorial Guinea 1

Equatorial Guinea Binding

Ley 1/2016 art. 13(b) — impugnación de valoraciones: disclose the program, challenge any decision, but nothing forbids the machine

Binds Responsables del fichero o del tratamiento, defined at art. 4(i) as any natural or legal person, public or private, engaged in the processing of personal data, and encargados del tratamiento through the art. 8 processor-contract regime. Art. 2 makes the scope explicitly dual-sector: the Law applies to the personal data of all citizens recorded on any kind of medium, in the public sector as much as in the private, that make them susceptible of processing or of later use by other natural or legal persons or by public and private entities, where that processing is carried out or used on means situated in the national territory, or where Equatoguinean legislation applies to a controller not established in the country. Art. 2(2) additionally brings electoral, statistical, civil-registry and criminal-registry files, and images and sounds obtained by security video cameras, within the Law subject to their specific rules. Art. 3 excludes files kept by natural persons in the exercise of exclusively personal or domestic activities, files established for organised crime and terrorism, and files relating to classified matters — an unusually broad security carve-out that removes the whole of the state-security sector from art. 13(b). Art. 14 further disapplies the rights: controllers of files held for police or tax purposes may deny access, rectification, opposition or cancellation having regard to the gravity and danger that might follow for the defence of the State or public security, the protection of third-party rights, or ongoing investigations; and where the information could affect national defence, national security, or the prevention and investigation of criminal and administrative offences and delinquency in general, the controller is not merely permitted but obliged to refuse. A refused data subject must first lodge a queja or reposición with the controller who decided the processing, and only after exhausting that internal route may they claim to the Órgano Rector de Protección de Datos Personales, which resolves with reasons. No ex ante gate attaches to automated decision-making or to profiling: there is no impact assessment, no prior authorisation for scoring, and no notification duty specific to automated processing. Public files are created by Decree under art. 19 and entered in the Registro General de Protección de Datos, whose contents any person may consult under art. 13(c). Impact tier: all entities.. Article 13(b) of Ley núm. 1/2016, de 22 de julio, de Protección de Datos Personales is Equatorial Guinea's automated-decision provision, and it is the Spanish LOPD form, not the Directive 95/46/EC form that every other Central African row on the tracker carries. Título III, Garantía y protección de los derechos de las personas, opens at art. 13 with a single article listing the citizen's rights, and the second of them is headed Impugnación de valoraciones: El interesado tendrá derecho a obtener información del responsable del fichero sobre los criterios de valoración de sus datos personales y de su comportamiento, y el programa utilizados en el tratamiento de los mismos, pudiendo impugnar todo acto administrativo o decisión que implique una valoración de su conducta o comportamiento y definición de sus características o personalidad — the data subject has the right to obtain from the file controller information on the criteria used to evaluate their personal data and their behaviour, and on the program used in processing them, and may challenge any administrative act or decision that involves an evaluation of their conduct or behaviour and a definition of their characteristics or personality. Two features make it wider than the templates around it. First, the disclosure limb reaches el programa utilizado — the program itself, not merely the logic involved — which is the most explicit software-disclosure wording of any statute on the tracker. Second, the challenge limb carries no solely-automated trigger and no legal-effects threshold: it bites on todo acto administrativo o decisión involving a profiling-style evaluation, whether a machine or a human reached it, where the GDPR art. 22 family and the Directive art. 15 family both require that the decision be based solely on automated processing and produce legal or similarly significant effects. What Equatorial Guinea does not have is a prohibition. There is no rule anywhere in the Law that a decision may not be taken on the sole basis of automated processing, no human-intervention right, no right to express a point of view, and no obligation to disclose the existence of automated decision-making up front: art. 13(b) is exercised after the fact, by an interesado who already suspects they were scored. The Law is otherwise LOPD-lineage throughout — arts. 5 to 12 carry consent, purpose limitation, data quality, processor contracts, security and secrecy, and art. 13 gathers access, the impugnación limb, consultation of the Registro General de Protección de Datos, rectification and cancellation within fifteen days, and a damages right into one article. It is the first Hispanophone row in the African block and the first anywhere on the tracker to place the challengeable object at acto administrativo o decisión rather than at automated decision.

Force. The Disposición Final is a twenty-day vacatio: La presente Ley entrará en vigor a los veinte (20) días de su publicación en el Boletín Oficial del Estado, sin perjuicio de su publicación en los demás Medios Informativos Nacionales. The Law was given at Malabo on 22 July 2016 over the signature of President Obiang Nguema Mbasogo, and the date recorded on this entry is that date, the one the instrument carries on its face and cites itself by (Ley Núm. 1/2016, de fecha 22 de Julio). The Boletín Oficial del Estado issue in which it was published is not stated in the official copy read and the Equatoguinean BOE is not published online, so the exact day on which the twenty days expired cannot be pinned to a primary source; the entry is marked medium for that reason alone. Nothing turns on it for a 2026 reader — the vacatio ran out in 2016 on any publication date and the Law has been in force for a decade — but the in-force date is a range in August or September 2016, not a verified day, and it is recorded as such rather than assumed. One structural condition does remain open. Art. 15 provides that the Órgano Rector de Protección de Datos Personales, que será creado mediante Decreto, is the body that protects the rights derived from the Law; the Law itself does not constitute it, and no creating Decree was found on the Equatoguinean government hosts. Art. 35 covers the gap on the enforcement side: the Ministro de Telecomunicaciones y Nuevas Tecnologías exercises the sanctioning power under the Law against any infringer, on a procedure opened and instructed by the Dirección General de Nuevas Tecnologías, or where applicable by the Órgano Rector, with an appeal by recurso de alzada to the Consejo de Ministros within thirty days. So art. 13(b) is enforceable today through the Ministry whether or not the Órgano Rector exists; what the missing Decree affects is the art. 14(3) claim route, which names the Órgano Rector as the body that resolves a refusal. Supersession: none. Equatorial Guinea had no dedicated data-protection statute before Ley 1/2016 and no AI-specific statute is in force; the Law does not define artificial intelligence, and Gabon's Loi 025/2023 remains the only data-protection statute in the African block that does. Text read in the official scanned copy published by the Ministerio de la Función Pública y la Reforma Administrativa, which satisfies Primary Source First on the same basis as the Nigeria, Burkina Faso, Gabon and Chad copies; the WorldLII mirror Cloudflare-blocks automated retrieval and was not relied on. The copy is a 45-page image-only scan with no text layer and was read as page images. Coverage of the read: arts. 1 to 15 in full (object, scope, exclusions, definitions, the Título II principles, the whole of the art. 13 rights list, the art. 14 exceptions and the art. 15 tutela article), art. 19 on public files, and the whole of the Título VI sanctioning regime — art. 35 competence, arts. 39 to 41 the three infringement classes, art. 42 the penalty scale, art. 43 the graduation criteria, art. 44 procedure — plus the Disposición Final. The intervening arts. 16 to 34, on the police-file regime, public and private files, the Registro General, international transfers and the authority's inspection powers, were read by heading and spot-check; no automated-decision or profiling rule appears in them, and art. 13(b) is the Law's only evaluation-and-challenge provision. Computation of the twenty-day vacatio verified 31 Aug 2026; it cannot move, and the residual on this row is confirmed to be the anchor rather than the count. The Disposición Final reads «entrará en vigor a los veinte (20) días de su publicación en el Boletín Oficial del Estado», which reproduces the default formula of the Código Civil applied in Equatorial Guinea — the Code approved by Real Decreto de 24 de julio de 1889, whose art. 2.1 provides «las leyes entrarán en vigor a los veinte días de su completa publicación en el Boletín Oficial del Estado, si en ellas no se dispone otra cosa». Its art. 5.1 supplies the count: «siempre que no se establezca otra cosa, en los plazos señalados por días, a contar de uno determinado, quedará éste excluido del cómputo, el cual deberá empezar en el día siguiente», and art. 5.2 adds that «en el cómputo civil de los plazos no se excluyen los días inhábiles», so there is no weekend or holiday deferral either. The clause is therefore a named-day offset — the Law takes effect ON the twentieth day, counted from the day after publication — and not a term that must elapse first, so the Paraguayan failure mode is excluded on the text. What remains open is unchanged and is not a computation problem: the Boletín Oficial del Estado issue is not published online, so the publication date the twenty days run from is unknown, the entry continues to carry the Law's own date of 22 July 2016, and the confidence stays medium for that reason. One caveat on the second source: the copy of the Code read is the metropolitan Spanish text, referring to «el ordenamiento jurídico español», so it evidences the received rule as circulated for Equatorial Guinea rather than a Guinean redaction of it.

Stated maximum penalty — Administrative, and the route to art. 13(b) is explicit. Art. 40 makes it an infracción grave to obstruct, impede or hinder the exercise of the rights of access, rectification, cancellation and opposition by the interested or affected person (art. 40(b)), and separately to fail to attend to the requests, complaints and claims of interested or affected persons (art. 40(g)) — either limb catches a controller who refuses an art. 13(b) request for the valuation criteria or the program used. Art. 42(1)(b) sets the grave scale: a fine of 500,001 to 5,000,000 FCFA, suspension of the file's activity and of the processing of personal data, and sealing of the premises or installations for a period not exceeding fifteen (15) working days. Below that, art. 42(1)(a) puts leves at amonestación, written warning, or a fine of 200,000 to 500,000 FCFA; art. 39(f) sweeps any other breach of the Law that is not grave or muy grave into that class. Above it, art. 42(1)(c) puts muy graves at fines of 5,000,001 to 15,000,000 FCFA together with one or more of seizure of equipment and other material, definitive closure of the premises and installations, disqualification of the infringer from the activity of file-keeping and personal-data processing for one year or definitively, and cancellation and revocation of the administrative resolution, authorisation or concession creating the file and of its entry in the Registro General de Protección de Datos. Art. 42(2) adds that in grave or muy grave cases where the processing, communication, transfer or international transfer could impair the fundamental rights of those affected, the sanctioning body may require public and private controllers alike to cease the unlawful use, and art. 42(3) lets it immobilise the files by reasoned resolution if that requirement is not met. Art. 43 grades the sanction by the proportionality of the harm and its social or economic repercussion, intentionality, continuity, the volume of processing, the unlawful benefit obtained, the degree of participation, recidivism, and the nature of the harm caused to the interested and to third parties. Separately from the sanctioning regime, art. 13(e) gives the data subject a damages right — before the ordinary courts against private files, and under the State responsibility rules against public ones.

In force · 22 Jul 2016 checked 21 Sep 2026 Ley 1/2016 art. 13(b) ↗ medium confidence

Indonesia 1

Indonesia Binding

UU 27/2022 (PDP Law) Arts. 10 and 34 — objection to solely-automated decisions and mandatory impact assessment

Binds Personal-data controllers ('Pengendali Data Pribadi') within the scope of Art. 2: any person, public body or international organisation acting inside Indonesian jurisdiction, and those outside it whose acts have legal effect in Indonesia or affect Indonesian data subjects abroad. Processing by a natural person for purely personal or household activity is excluded. Impact tier: all entities.. Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi is Indonesia's general data-protection statute. Art. 10(1) gives the data subject the right to object to a decision taken solely on the basis of automated processing, including profiling, that produces legal effects or has a significant impact on them; Art. 10(2) leaves the procedure for lodging that objection to a Government Regulation (Peraturan Pemerintah). Art. 34(1) separately obliges the personal-data controller to carry out a personal-data-protection impact assessment where processing carries a high potential risk to the data subject, and Art. 34(2)(a) lists automated decision-making with legal effect or significant impact on the data subject as the first such high-risk category — alongside large-scale processing, systematic evaluation, scoring or monitoring, data matching or combination, and the use of new technologies. The elucidation of Art. 10(1) defines 'pemrofilan' as electronically identifying a person by reference to matters including employment history, economic condition, health, personal preferences, interests, reliability, behaviour, location or movements.

Enacted and promulgated in Jakarta on 17 October 2022; Lembaran Negara 2022 No. 196, Tambahan Lembaran Negara No. 6820. Art. 76 provides that the Act enters into force on the date of promulgation, so 17 October 2022 is the in-force date. Art. 74 is a transitional rule, not a deferred commencement: controllers, processors and other parties involved in personal-data processing were given at most two years from promulgation to align their processing with the Act, so the adjustment window closed on 17 October 2024 and the duties are now fully exigible. Two implementation caveats, both verified rather than assumed. First, the implementing Government Regulation has since been issued: Peraturan Pemerintah No. 33 Tahun 2026 tentang Pelindungan Data Pribadi, signed 16 July 2026, which enters into force 16 January 2027 and sets out the procedure for objecting to automated processing (Art. 10(2)) and for personal-data-protection impact assessments (Art. 34(3)), among other implementing rules; until then those procedures remain undetailed. Provenance flag, 10 September 2026: that Government Regulation is so far attested only by commercial legal databases and press reporting and is NOT yet confirmable against any primary Indonesian corpus, so its number, its 16 July 2026 signature date and its 16 January 2027 commencement are unverified pending the official salinan. Checked and ruled out: the JDIH of the Kementerian Sekretariat Negara, whose 2026 collection ceilings at 2 July 2026 across every instrument type — the highest Peraturan Pemerintah on file is No. 31 of 2026, promulgated 2 July — so PP 33 lies beyond the corpus ceiling rather than being absent from it; the JDIH of the Kementerian Komunikasi dan Digital, the ministry of record, whose entry for UU 27/2022 still reports «Peraturan Pelaksanaan: Data belum Tersedia»; peraturan.bpk.go.id, which returns HTTP 403 to every request; jdihn.go.id, the national JDIH portal, which refuses the connection; and peraturan.go.id, which does not resolve. One secondary account puts commencement at 15 rather than 16 January 2027, a further reason to hold the date open. Nothing in the row's own duties, dates or lifecycle turns on this paragraph. Second, Art. 57(1) lists the provisions carrying administrative sanctions and Art. 34(1) is on that list while Art. 10 is not — the sanctioned duty is the impact assessment, while the Art. 10 right is exercised through the supervisory body and the dispute-resolution route of Chapter XIII. Indonesia's peer of br-lgpd-art20, cn-pipl-art24, kr-pipa-art37-2-adm, ar-ley25326-art20 and cl-ley21719-art8bis: like Brazil and Argentina it is already in force, and like Chile it pairs the objection right with a mandatory impact assessment, but unlike Korea it grants no express right to an explanation or to human re-processing. Text read in the full statutory text published by the JDIH of the Kementerian Komunikasi dan Digital, the ministry of record for the Act; the Sekretariat Negara salinan (LN 2022/196) is a scanned image and carries no text layer, and peraturan.bpk.go.id returned HTTP 403 to every request.

Stated maximum penalty — Administrative sanctions under Art. 57 for breach of the Art. 34(1) impact-assessment duty: written warning, temporary suspension of processing, erasure or destruction of the personal data, and/or an administrative fine of at most 2 per cent of annual revenue or annual receipts measured against the variable of the violation, imposed by the supervisory body. Art. 57(5) leaves the procedure for imposing those fines to a Government Regulation; Peraturan Pemerintah No. 33 Tahun 2026, signed 16 July 2026 and in force from 16 January 2027, is the regulation now issued. That regulation is reported rather than primary-source-confirmed, and the fine-imposition procedure therefore remains unconfirmed — see status_note.

In force · 17 Oct 2022 checked 23 Sep 2026 UU 27/2022 Arts. 10, 34 (LN 2022/196) ↗ high confidence

India 1

India Binding

IT Rules — synthetic-content (deepfake) labelling

Binds Intermediaries, significant social-media intermediaries (5M+ users), GenAI tool providers. Mandatory labels on AI-generated (SGI) content; 3-hour government-ordered takedown; significant-platform traceability.

Stated maximum penalty — Loss of safe harbour; IT Act offences

In force · 10 Feb 2026 checked 17 Sep 2026 IT Rules 2026 amendments (SGI) ↗ high confidence

Japan 1

Japan Comprehensive

Japan Election AI Labelling & Platform Obligations (2026 Amendment)

Binds All internet users (duty not to spread false election information); candidates and campaign organisations (AI labelling obligation); large-scale platform operators (X, YouTube, Meta) operating in Japan. AI-generated election content must display an 'AI作成' label; large social media platforms must implement harm-mitigation measures and publish annual reports covering election misinformation. Applies from March 2027.

Passed the House of Councillors July 13, 2026; promulgated July 17, 2026 as Law No. 58 of Reiwa 8 (令和8年法律第58号). Amends the Public Offices Election Law and the Platform Countermeasures Act (情プラ法). Enforcement March 1, 2027 ahead of April 2027 unified local elections. No new criminal penalties for platform duties (political compromise). AI-generated content that could be mistaken for authentic footage must display 'AI作成' label; clearly identifiable illustrations/animation are exempt.

Stated maximum penalty — No new criminal penalties created; existing election law criminal provisions (Art. 235-2) continue to apply to candidates

Applies 1 Mar 2027 checked 20 Sep 2026 Election SNS Regulation Law (Law No. 58/2026, Amendment) ↗ high confidence

Kenya 1

Kenya Binding

Data Protection Act s. 35 — right against solely-automated decisions, with written notification and a right to reconsideration

Binds Data controllers and data processors within the scope of s. 4, that is those established or ordinarily resident in Kenya and processing personal data while in Kenya, and those not so established or resident but processing personal data of data subjects located in Kenya. Registration with the Office of the Data Protection Commissioner under ss. 18 and 19 is a precondition of acting as a controller or processor, subject to the thresholds set by the Data Protection (Registration of Data Controllers and Data Processors) Regulations. The s. 35 duties bind any controller or processor that takes a solely-automated decision with legal or significant effect. Impact tier: all entities.. Section 35 of the Data Protection Act No. 24 of 2019 gives every data subject a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning or significantly affects the data subject (s. 35(1)). The right does not apply where the decision is necessary for entering into or performing a contract between the data subject and a data controller, is authorised by a law to which the controller is subject and which lays down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, or is based on the data subject's consent (s. 35(2)). Where a controller or processor does take such a decision, s. 35(3) imposes two duties: it must as soon as reasonably practicable notify the data subject in writing that a decision has been taken based solely on automated processing, and the data subject may then, after a reasonable period from receipt of that notification, request the controller or processor to reconsider the decision or to take a new decision that is not based solely on automated processing. On receipt of such a request the controller or processor must within a reasonable period consider the request including any relevant information the data subject provides, comply with it, and inform the data subject in writing of the steps taken in compliance and of the outcome (s. 35(4)). Section 35(5) empowers the Cabinet Secretary to make further provision by Regulations. Section 31 separately makes a data protection impact assessment mandatory where a processing operation is likely to result in high risk to the rights and freedoms of a data subject.

Commencement is stated on the face of the published Act: the gazetted text of the Data Protection Act No. 24 of 2019 records a Date of Assent of 8 November 2019 and a Date of Commencement of 25 November 2019, and s. 35 carries no deferred or separately-appointed commencement. The Office of the Data Protection Commissioner was constituted in November 2020 and has exercised its enforcement powers since; the section itself has been operative from 25 November 2019. Kenya is the tracker's second African jurisdiction, added in the same sweep as za-popia-s71. Section 35 follows the GDPR Art. 22 shape more closely than the South African provision does: it grants an express right to demand a new decision that is not based solely on automated processing, which POPIA s. 71 does not, and it attaches an affirmative written-notification duty on the controller rather than leaving disclosure to a request. It stops short of the Korean kr-pipa-art37-2-adm model in that it confers no standalone right to an explanation of the criteria used. Text read in the official copy of the Act published by the Office of the Data Protection Commissioner, the supervisory authority established by Part II of the Act; new.kenyalaw.org and kenyalaw.org return HTTP 403 to non-browser clients, so the ODPC copy is cited.

Stated maximum penalty — Section 63 caps the administrative penalty the Data Commissioner may impose by penalty notice, in relation to an infringement of a provision of the Act, at five million Kenyan shillings, or in the case of an undertaking one per centum of its annual turnover of the preceding financial year, whichever is lower; s. 62 governs the penalty notice and s. 58 the enforcement notice that ordinarily precedes it. Section 65 gives a person who suffers damage by reason of a contravention a right to compensation from the controller or processor. Section 73 provides a general penalty, for offences under the Act for which no specific penalty is prescribed, of a fine not exceeding three million shillings or imprisonment for a term not exceeding ten years, or both. Appeals against administrative action lie to the High Court under s. 64.

In force · 25 Nov 2019 checked 23 Sep 2026 Data Protection Act s. 35 (No. 24 of 2019) ↗ high confidence

Kyrgyzstan 2

Kyrgyzstan Binding

Digital Code art. 197 - tell consumers they are talking to an AI, tell people they are being emotion- or biometrically classified, and label deepfakes

Binds Owners and users of AI systems that interact with natural persons as consumers (part 1); users of emotion-recognition and biometric-classification systems (part 2); users of AI systems for deepfakes (part 4). Danger tier is irrelevant here - a minimal-danger chatbot owes part 1 - and there is no size, sector or nationality threshold. Part 1's register limb additionally reaches the sectoral regulator of the national ecosystem, which must publish the same information on its own site.. Art. 197 is Kyrgyzstan's transparency article and, unlike the rest of Chapter 23, it applies to AI systems at any danger level. Part 1 obliges owners and users who design, develop or apply AI systems in order to interact with natural persons as consumers to inform those consumers of the fact that they are interacting with an AI system, except where it is obvious from the circumstances; it further declares information about the use of AI systems within digital-environment legal relations to be publicly accessible information, which must be posted in accessible and intelligible form both on the sites of the users of those systems and on the site of the sectoral regulator of the national ecosystem - a disclosure register duty that goes beyond the EU AI Act art. 50 equivalent. Part 2 requires users of systems intended for emotion recognition or for the classification of natural persons by biometric characteristics to inform the persons concerned that such a system is being applied to them; Kyrgyzstan regulates these by notification rather than banning them in workplaces and education as the EU does. Part 4 requires users of AI systems for deepfakes to disclose the artificial origin or alteration of the material. Part 3 disapplies parts 1 and 2 - not part 4 - for functions where informing would frustrate lawful use for defence, national security, or public order in the detection, prevention and investigation of crime and criminal prosecution; part 5 disapplies part 4 for lawful use protecting those same goods or in exercise of the freedom of scientific, technical and artistic creativity, teaching and learning, which is a notably wide carve-out from deepfake labelling. Part 6 conditions every one of those exceptions on necessary measures having been taken to protect the affected human and civil rights and freedoms.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. Art. 197 needs no implementing act and none has been issued: the duties are self-executing on the text, and neither Resolution No. 770 nor Order No. 1181-т touches transparency. What has NOT been located is any published register on the site of the sectoral regulator of the national ecosystem under part 1, which the article requires; that is recorded as an open follow-up rather than asserted either way.

Stated maximum penalty — Nothing. There is no administrative offence for failing to disclose AI interaction, for applying emotion recognition or biometric classification without notifying the person, or for publishing an unlabelled deepfake. Art. 228-10 of the Code of Offences, the only AI-specific offence, covers the art. 192(2) targeted-unlawful-harm prohibition alone (200 расчетных показателей for natural persons, 650 for legal persons, at 100 som per показатель). Kyrgyzstan therefore sits at the opposite end from Kazakhstan on this one point: Kazakhstan's KoAP art. 641-1 does penalise failure to inform users about misleading synthetic outputs, at 15 to 100 MRP, while Kyrgyzstan's identical duty carries no fine at all.

In force · 6 Feb 2026 checked 5 Sep 2026 KG Digital Code art. 197 ↗ high confidence
Kyrgyzstan Binding

Digital Code arts. 194-196 - self-classified high-danger AI needs a signed public declaration of conformity before first use

Binds Владельцы (owners) and пользователи (users) of AI systems that the owner's own danger assessment classifies as high-danger, plus, by art. 126, every provider of a digital wellbeing service that uses AI within the service, without any assessment step. Duties split by role: arts. 194 and 195 fall on the owner, art. 196 on the user, and art. 196(3) moves the owner's set onto a rebrander, repurposer or substantial modifier. No size or sector threshold; Resolution No. 770 para. 2 restates the scope as all owners irrespective of legal form, sectoral affiliation or ownership.. Where the art. 193 danger assessment returns a system whose use raises the risk of harm to the protected goods to a level requiring risk management, art. 194(1) makes it a «система искусственного интеллекта повышенной опасности» - a high-danger AI system - and the Digital Code's substantive regime attaches for the whole life cycle. The classification is comparative and self-executed rather than annex-driven: it asks whether the system raises risk relative to alternative ways of doing the same thing, and art. 194(3) expressly excludes systems whose role in the decision or action is purely auxiliary and does not raise risk. Art. 194(4) hands the Cabinet of Ministers the four requirement families - risk management, system characteristics (openness, explainability, controllability, accuracy, reliability, digital resilience), digital data quality, and technical documentation - and all four now exist as annexes to Resolution No. 770. Art. 194(5) lists seven owner duties: conform to the mandatory requirements; implement and maintain a risk-management system across the whole life cycle; produce proper technical documentation; preserve the system logs while the system is under its control; confirm conformity before first application; remedy identified non-conformities; and, on demand of the competent state body, suspend - and on a final court act terminate - design and development carried on in breach. Art. 195 is the gate: before a high-danger system may be applied, its owner must adopt a declaration of conformity in the form and content approved by the Cabinet of Ministers, cast as a digital document, signed with a qualified digital signature, and posted on the owner's website as a publicly accessible digital record. Art. 196 then binds the user (deployer): operate per the manual, keep the processed data relevant, maintain effective supervision with named responsible persons and allocated resources, notify the owner and suspend use the moment there is ground to believe the manual-compliant use could cause harm, preserve logs, and suspend or terminate on official demand or court act. Art. 196(2) adds an explanation right where the output feeds a decision capable of infringing rights: general information about the system's characteristics and operating principles must be published on the site for consumer-facing systems and supplied in accessible form otherwise, and anyone whose interests the decision touches may demand, free of charge, information letting them understand and check how the result about them was arrived at. Art. 196(3) transfers the owner's duties to whoever puts the system into service under their own name or mark, changes its purpose, makes substantial modifications, or turns it into a high-danger system - the EU AI Act art. 25 pattern - and art. 196(4) releases the original owner in the latter two cases. Art. 196(5) exempts purely personal or family use from most duties, but makes that user and whoever gave them access jointly and severally liable where third-party rights are infringed. One sector is classified by statute rather than by assessment: art. 126 declares AI systems used to deliver digital wellbeing services to be high-danger systems as a matter of law.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. The regime is operable rather than pending: Cabinet of Ministers Resolution No. 770 of 2 December 2025 («Эркин-Тоо» No. 96 (3753) of 5 December 2025) supplies all four art. 194(4) requirement families as annexes 2 to 5, and the art. 195 declaration was completed separately by Cabinet of Ministers Order No. 1181-т of 31 December 2025, which approved the Requirements for the content of the declaration of conformity of high-danger AI systems. Both are «Действует» in ЦБД. Resolution No. 770 commences fifteen days after the Code, i.e. 21 February 2026 on the arithmetic of its own para. 4; the ЦБД card states no dateOfEntry for it.

Stated maximum penalty — Nothing, in administrative terms. The Code of Offences contains no article penalising application of a high-danger AI system without a declaration, non-conformity with the Resolution No. 770 requirements, absence of a risk-management system, loss of logs, or refusal of the art. 196(2) explanation. Art. 228-10, the only AI-specific offence, is confined to the art. 192(2) targeted-unlawful-harm prohibition (200 расчетных показателей for natural persons, 650 for legal persons; the расчетный показатель is 100 som, so 20,000 and 65,000 som). What does bite is non-monetary and, for an operating business, heavier: art. 194(5)(7) and art. 196(1)(7) let the competent state body order suspension of design, development or application on demand, with termination on a final court act. Civil exposure is the other real channel - art. 192(3) makes owners and users liable for harm caused, and for digital wellbeing services art. 127(2) lets the consumer elect a statutory compensation of 100 to 400 расчетных показателей (10,000 to 40,000 som) in place of proving damages, with the burden on the provider to disprove causation.

In force · 6 Feb 2026 checked 5 Sep 2026 KG Digital Code arts. 194-196 ↗ high confidence

South Korea 2

S. Korea Comprehensive

Korea PIPA Art. 37-2 — rights against fully automated (AI) decisions

Binds Personal information controllers in Korea (and, via Art. 26(8), their processors) that make significant decisions about individuals through fully automated systems, including AI systems. Where a decision made by processing personal data with a completely automated system — expressly including systems applying artificial-intelligence technologies — significantly affects a data subject's rights or duties, the data subject may object to it and may request an explanation. On objection or an explanation request the controller must not apply the automated decision absent compelling reason, or must take necessary measures such as re-processing with human involvement and providing an explanation. Controllers must also publicly disclose the criteria and procedures for automated decisions and how personal data is processed in them.

Inserted by the PIPA amendment Act No. 19234, promulgated 14 March 2023. Addenda Art. 1(1) defers Art. 37-2 (and Art. 75(2) 24) to 'the date one year elapses after the date of promulgation' = 15 March 2024, unlike the bulk of the amendment which took effect 15 September 2023. Art. 37-2(1) excludes automatic dispositions by administrative authorities under Art. 20 of the Framework Act on Administration, and the right to object does not apply where the automated decision is made under Art. 15(1) 1, 2 or 4 (consent, statutory obligation, or performance of a contract) — in those cases only the explanation/review rights remain. Detailed procedures are set by the PIPA Enforcement Decree (Arts. 44-2 to 44-5), also effective 15 March 2024. Distinct from and additional to the AI Basic Act duties (see kr-aibasic-transparency, kr-aibasic-highimpact): this duty is triggered by personal-data processing, not by AI-operator status.

Stated maximum penalty — Administrative fine up to KRW 30 million for failing to take the measures required by Art. 37-2(3) (PIPA Art. 75(2) 24); PIPC enforcement

In force · 15 Mar 2024 checked 10 Sep 2026 PIPA Art. 37-2 (Act No. 19234) ↗ high confidence
S. Korea Comprehensive

AI Basic Act — transparency & labelling

Binds AI business operators offering AI products/services in Korea (extraterritorial). Pre-notify users that a service uses AI; label generative and realistic synthetic outputs.

MSIT enforcement grace period of AT LEAST one year from 22 Jan 2026 before administrative fines are imposed — confirmed in an MSIT primary release (English press release on the AI Basic Act Enforcement Decree legislative notice, 12 Nov 2025: https://www.msit.go.kr/eng/bbs/view.do?sCode=eng&mPid=2&mId=4&bbsSeqNo=42&nttSeqNo=1191). That release states MSIT "will implement a grace period of at least one year before administrative fines are imposed" and that "efforts are currently underway to gather opinions to finalize the detailed operation plan and duration of this grace period" — so ~22 Jan 2027 is a FLOOR, not a confirmed end date, and the release states no exception or carve-out to the grace period. The 22 Jan 2026 in-force date is separately primary-sourced (law.go.kr).

Stated maximum penalty — Admin fine up to ₩30M

In force · 22 Jan 2026 checked 23 Sep 2026 AI Basic Act ↗ high confidence

Kazakhstan 2

Kazakhstan Binding

AI Law art. 21 — tell users AI was involved, and machine-readably mark every synthetic output you distribute

Binds Art. 21(1) is expressed impersonally and attaches to whoever produces or supplies goods, works or services using AI systems, so it reaches commercial and public suppliers alike with no size or sector threshold. Arts. 21(2), (3) and (5) place the marking, informing and output-conformity duties on собственники и (или) владельцы of the AI systems concerned — owners and holders — again without threshold. The administrative offence backing the synthetic-output limb is graded by business size, from natural person through small, medium and large business entities.. Art. 21 of Law No. 230-VIII carries Kazakhstan's transparency and synthetic-media rules, and unlike the labelling provisions in Russia's 243-FZ it is a genuine duty rather than an entitlement. Art. 21(1) requires that users be informed that goods, works and services are produced or supplied using AI systems — a broad, unthresholded disclosure obligation attached to the commercial offering itself, not merely to generated content. Art. 21(2) then provides that dissemination of synthetic results of AI activity is permitted only on condition that they are marked in machine-readable form AND accompanied by a visual or other form of warning that the user can actually perceive without methods that impede such perception — a dual-layer requirement, machine-readable plus human-perceptible, with an express anti-obfuscation limb. Art. 21(3) places responsibility for informing users about synthetic outputs on the owners or holders of the systems, and art. 21(5) makes the owner and (or) holder responsible for ensuring that the outputs of AI systems conform to the requirements of Kazakh legislation generally. Art. 21(4) is the signpost that matters for automated decision-making: requirements for taking decisions on the basis of exclusively automated processing of personal data are set by the personal-data legislation, i.e. art. 19-1 of Law No. 94-V, tracked separately at kz-pd-art19-1. Art. 22 supports art. 21 by mandating machine-readable forms that allow conditions to be recognised automatically and unambiguously by AI systems and other data-processing means, with the procedure for developing, applying and distributing them to be determined by the authorised body — so the technical standard for the art. 21(2) marking is delegated and not yet fixed on the face of the statute.

In force since 18 January 2026. Art. 31 commences the Law «по истечении шестидесяти календарных дней после дня его первого официального опубликования», with no article carved out. The А́ділет record card gives first official publication as the newspapers «Егемен Қазақстан» No. 222 (31202) and «Казахстанская правда» No. 222 (30600), both of 18 November 2025, with the Reference Control Bank of NPA in electronic form following on 20 November 2025. The sixty days run from 19 November 2025 and expire at the end of 17 January 2026, so the Law entered into force on 18 January 2026. А́ділет serves the text as «Обновленный» (consolidated and current), database state 19 August 2026, and flags the only pending change — Law No. 326-VIII of 24 June 2026 — as a future «Примечание ИЗПИ» note rather than as applied text. Note that the machine-readable marking standard contemplated by arts. 21(2) and 22(3) is to be determined by the authorised body and no such act has been identified as at 21 August 2026, so the form of compliant marking is not yet fixed even though the duty itself is in force.

Stated maximum penalty — KoAP art. 641-1(1)(1) penalises the failure by owners or holders of AI systems to inform users about synthetic results of the system's activity that are capable of misleading them, where the act or omission carries no indicia of a criminal offence. First offence: 15 MRP for natural persons, 20 MRP for small business entities and non-commercial organisations, 30 MRP for medium business entities, 100 MRP for large business entities. Repeat within a year of a penalty being imposed: 30, 50, 70 and 200 MRP respectively, together with suspension or prohibition of the operation of the AI system. Two limits are worth stating precisely. The offence is drafted around informing about synthetic outputs «которые могут ввести их в заблуждение» — capable of misleading — so it is narrower than art. 21(2), which conditions dissemination of ALL synthetic results on marking; and it does not reach the art. 21(1) duty to disclose that goods, works or services are produced using AI at all. Cases are decided by the authorised body in the field of artificial intelligence under KoAP art. 692-3. Amounts are stated in the mесячный расчетный показатель (MRP, monthly calculation index), the statutory unit the Code uses; the tenge value of one MRP is reset every year by the republican budget law, so the MRP figures rather than a converted tenge sum are the stable statement of the penalty.

In force · 18 Jan 2026 checked 5 Sep 2026 KZ AI Law art. 21 ↗ high confidence
Kazakhstan Binding

Personal Data Law art. 19-1 — automated processing that changes your rights is banned without consent, and objections get three working days

Binds Собственник и (или) оператор, а также третье лицо — the owner and (or) operator of a personal-data database and any third party, with no size, sector or turnover threshold, so enterprise, SME and public body are covered alike. Note that the art. 19-1 duty runs to the third party as well as to the owner and operator, which is broader than the equivalent Russian and Uzbek provisions. The general exclusions in art. 19 for the exercise by state bodies of their statutory functions, for private notaries, private court enforcement agents and advocates, and for collection and processing for statistical, sociological or scientific purposes attach to art. 19 and not to art. 19-1.. Kazakhstan's automated-decision rule is new: art. 19-1 was added to the Law No. 94-V of 21 May 2013 «О персональных данных и их защите» by Law No. 231-VIII of 17 November 2025, the companion act to the AI Law, and it took effect on 18 January 2026. Art. 19-1(1) prohibits automated processing of personal data as a result of which the subject's rights or legitimate interests arise, change or cease, except where the subject's consent has been obtained or in cases provided by the laws of Kazakhstan. Three drafting choices distinguish it from the neighbouring regimes the tracker already carries. First, the trigger is the automated PROCESSING rather than a decision taken on its basis, and art. 1(2-3) of the Law defines automated processing as processing by an informatisation object that excludes the participation of the owner, operator or third party in the process — so the exclusivity test sits in the definition. Second, the consequence limb is drafted as rights or legitimate interests arising, changing or ceasing, which is narrower than Russia's art. 16 «иным образом затрагивающих» catch-all but avoids GDPR art. 22(1)'s significance threshold. Third, and unlike both Russia's art. 16(2) and Uzbekistan's art. 24, there is NO contract exception and NO written-form qualifier on the consent: ordinary consent under the Law suffices, which makes the exit both easier to reach and less formal than Russia's art. 9(4) written consent with identity-document particulars. Art. 19-1(2) is a standing, proactive duty on the owner, operator and third party to explain to the subject the procedure of the automated processing of their personal data and its possible consequences, to provide the opportunity to state an objection to that processing, and to explain how the subject may protect their rights, freedoms and legitimate interests. Art. 19-1(3) then gives THREE WORKING DAYS from receipt to consider the objection and notify the subject of the outcome — markedly tighter than Uzbekistan's ten days and Russia's thirty — and preserves the right to challenge the acts or omissions of the owner, operator or third party in the manner established by law. As in Russia and Uzbekistan, nothing obliges the controller to change the decision, and no right to human intervention or to an explanation of the LOGIC is expressed. Note for anyone working from the earlier research note: art. 20 of this Law is not the relevant provision — it is a general guarantee that personal data are protected by the state — and the automated-processing rule is art. 19-1.

In force since 18 January 2026. The Сноска to art. 19-1 records that Chapter 2 was supplemented with the article by Law No. 231-VIII of 17 November 2025 «по вопросам искусственного интеллекта и цифровизации», commencing on expiry of sixty calendar days after first official publication. The Әділет record card for 231-VIII gives that publication as «Егемен Қазақстан» No. 222 (31202) and «Казахстанская правда» No. 222 (30600), both 18 November 2025, so the period expired at the end of 17 January 2026 and the article took effect on 18 January 2026 — the same day as the AI Law. Art. 19-1 has not itself been amended since; the pending Law No. 326-VIII of 24 June 2026 is flagged by ИЗПИ against arts. 19(1), 22(2) and others but not against art. 19-1. Text checked in the consolidated redaction, database state 19 August 2026.

Stated maximum penalty — No penalty is addressed to art. 19-1 specifically. KoAP art. 641-1, the AI offence created alongside it by Law No. 232-VIII, covers only the synthetic-output information failure and the high-risk risk-management failure, and neither reaches automated processing under the Personal Data Law. Breach therefore falls back on the general personal-data offences in the Code — principally KoAP art. 79, unlawful collection and processing of personal data (not art. 79-1, which is a public-order offence unrelated to personal data) — whose bands are not specific to automated processing, and on the art. 27 remedies of the Law itself. This entry states no figure rather than importing an adjacent band, because the offence that would apply depends on which limb of art. 19-1 was breached and the Code contains no automated-processing article.

In force · 18 Jan 2026 checked 20 Sep 2026 KZ Personal Data Law art. 19-1 ↗ medium confidence

Morocco 1

Morocco Binding

Loi 09-08 art. 11 — neutrality of the effects of automated processing: bar on decisions grounded solely in automated profiling

Binds Controllers within the scope of art. 2: processing of personal data wholly or partly by automated means, and non-automated processing of personal data contained in or intended to form part of manual files, where the controller is established on Moroccan territory and carries on an activity there, or is not established in Morocco but resorts, for the purposes of processing personal data, to automated or non-automated means situated on Moroccan territory. A controller in the second case must designate a representative established in Morocco who is substituted for it in the rights and obligations arising under the Law. Prior declaration to, or prior authorisation from, the Commission Nationale de contrôle de la protection des Données à caractère Personnel is a standing precondition of processing under arts. 12 and 13, with art. 12 requiring prior authorisation for sensitive-data and other listed processing. The art. 11 bar binds any controller taking a decision with legal effects grounded solely in automated profiling or personality evaluation, irrespective of size, and its first paragraph binds courts. Impact tier: all entities.. Article 11 of Law No. 09-08 relating to the protection of individuals with regard to the processing of personal data, headed “Neutralité des effets d'un traitement automatisé”, carries Morocco's operative automated-decision rule. Its first paragraph provides that no judicial decision involving an appraisal of a person's conduct may be founded on automated processing of personal data intended to evaluate certain aspects of that person's personality. Its second paragraph extends the bar beyond the courts: no other decision producing legal effects in respect of a person may be taken on the sole basis of automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. Its third paragraph sets the carve-out: decisions taken in the course of the conclusion or the performance of a contract, and for which the data subject has been put in a position to make observations, are not regarded as taken on the sole basis of automated processing, and neither are decisions granting a request made by the data subject. Article 7(c) supplies the companion transparency right, entitling the data subject to knowledge of the logic underlying any automated processing of personal data concerning them, alongside the confirmation and communication rights in art. 7(a) and (b). Article 11 is a transposition of art. 15 of Directive 95/46/EC by way of the French model, drafted in 2009 and so predating the GDPR: it speaks of automated processing intended to profile or to evaluate personality rather than of “profiling” as a defined term, and the safeguard it names is an opportunity to make observations rather than human intervention.

Law 09-08 was promulgated by Dahir nº 1-09-15 of 22 safar 1430 (18 February 2009) and published, together with the dahir, in Bulletin Officiel nº 5714 of 7 rabii I 1430 (5 March 2009), the date recorded here. The Law contains no commencement clause and no deferred-commencement mechanism: it ends at art. 67 and the dahir simply orders publication in the Bulletin Officiel. The date is confirmed directly against the Secrétariat Général du Gouvernement's own Bulletin Officiel sommaire index, which records Dahir nº 1-09-15 as “Publié le 05.03.2009” in B.O. nº 5714, and no longer rests only on the header of the CNDP copy. What is still unverified is the general Moroccan rule tying entry into force to that publication: it predates the SGG sommaire index and returns nothing on it, so it has not been read against a primary source, and that single gap is why confidence stays medium rather than high. Nothing turns on more than a few days either way — Décret nº 2-09-165 of 25 joumada I 1430 (21 May 2009), taken for the application of the Law, was itself published in B.O. nº 5744 on 18 June 2009, so the Law was operative that year on any reading. Article 67 is transitional only: it gave persons already carrying on processing before publication a maximum of two years, running from the date of the CNDP's installation as recorded by an administrative act published in the Bulletin Officiel, to regularise their declarations and authorisations, and on its own terms it reaches the declaration and authorisation regime rather than the art. 11 bar. Décret nº 2-09-165 was taken for the application of the Law; the CNDP publishes it only in Arabic, but the SGG sommaire supplies its French particulars, cited above. Coverage symmetry against the four African rows already tracked: Morocco is the oldest drafting of the five and the only one in the Directive 95/46/EC lineage rather than the GDPR art. 22 or UK DPA 1998 s. 12 lineages. Structurally it is closest to za-popia-s71 — both are prohibitions whose contract exception is conditioned on the data subject having had an opportunity to make representations, and neither grants human intervention or a fresh decision — but Morocco is narrower in two ways and wider in one. It is narrower in that its bar reaches only decisions producing legal effects, with no “substantial degree” or “significant effect” limb as in South Africa, Kenya, Nigeria, Rwanda, Tanzania and Ghana, and in that its disclosure duty sits in art. 7(c) as an access right rather than inside the automated-decision article as in za-popia-s71(3). It is wider in that its first paragraph binds courts directly, which no other row on the tracker does. It carries no deadline. Text read in the copy of the Law published by the CNDP, the supervisory authority instituted by the Law. Supersession checked 23 August 2026 against the SGG Bulletin Officiel sommaire search, the official gazette index, and cleared: an exact-expression search for “09-08” anywhere in a sommaire returns eight texts across the whole series, of which only two concern this Law — the promulgating Dahir nº 1-09-15 (B.O. 5714) and the application Décret nº 2-09-165 (B.O. 5744) — with no “modifiant et complétant la loi nº 09-08” entry anywhere; and a search restricted to texts of the nature “Loi” for the exact expression “données à caractère personnel” returns exactly one result in the entire series, Loi 09-08 itself, so no successor statute has replaced it either. The index was current to B.O. nº 7536 bis of 21 August 2026 when this was run. This was the Coverage Symmetry follow-up opened by the Algeria correction of 23 August 2026, where art. 11 of Loi 18-07 was repealed outright and its rule relocated into a law-enforcement-only title: Morocco does not share that defect. Art. 11's second paragraph is on its face addressed to “aucune autre décision” beyond the judicial decisions of the first paragraph, so it binds ordinary controllers, and the roles and topics carried here are the same ones the thirteen other African rows in this lineage carry.

Stated maximum penalty — Article 11 has no dedicated penalty: the criminal tier in Chapter VII attaches to named articles and art. 11 is not among them. Article 53 punishes a controller that refuses the access, rectification or objection rights under arts. 7, 8 and 9 with a fine of MAD 20,000 to MAD 200,000 per infringement, which reaches the art. 7(c) right to know the logic underlying automated processing but not the art. 11 bar itself. The nearest general route is art. 63, under which a controller that refuses to apply the decisions of the Commission Nationale is liable to imprisonment of three months to one year and a fine of MAD 10,000 to MAD 100,000, or one of those penalties only; art. 62 punishes obstruction of the Commission's supervisory functions with imprisonment of three to six months and a fine of MAD 10,000 to MAD 50,000, or one of them. Article 64 doubles the fines where the offender is a legal person, without prejudice to penalties on its officers, and allows partial confiscation of assets, confiscation under art. 89 of the Penal Code, and closure of the establishment where the offence was committed; art. 65 doubles the sanctions on repeat offence within a year of a final conviction. Article 66 lets sworn agents of the Commission, alongside judicial police officers, investigate and record infringements by procès-verbal for transmission to the Crown Prosecutor within five days.

In force · 5 Mar 2009 checked 20 Sep 2026 Loi 09-08 art. 11 ↗ medium confidence

Moldova 2

Moldova Binding

Law 160/2026 art. 11 — a flat ban on solely automated decisions by police, prosecutors, courts and prisons

Binds Competent authorities only, and the Law defines the purpose rather than the institution. Art. 1(1) covers processing by competent authorities for the prevention of criminal offences, including prevention of and protection against threats to public order and public security; the detection or investigation of offences or the conduct of criminal prosecution; the trial of criminal cases; and the execution of criminal penalties or safety measures. Art. 2(2) applies it to processing wholly or partly by automated means and to non-automated processing of data forming part of a filing system. Art. 2(3) excludes processing of state-secret data under Law no. 245/2008 so far as necessary and proportionate for national security and defence. The division of labour with the general statute is clean: art. 2(2)(c) of Law 195/2024 carves the same law-enforcement purposes out of the general regime, so a Moldovan police, prosecution, judicial or prison body processing for those purposes answers to art. 11 of this Law and not to art. 22 of Law 195/2024, while the same body processing for any other purpose — its own staff records, for instance — answers to art. 22. Art. 3(1) imports the art. 4 definitions of Law 195/2024, including «creare de profiluri», so the profiling concept is identical across the two. Private controllers are outside this Law entirely.. Law no. 160 of 30 July 2026 on the protection of personal data processed for the purpose of preventing and combating crime transposes Directive (EU) 2016/680, and its art. 11 is drafted as a prohibition rather than as a right the data subject must assert. Art. 11(1): «O decizie întemeiată exclusiv pe prelucrarea automată, inclusiv pe crearea de profiluri, care produce un efect juridic negativ pentru persoana vizată sau care o afectează în mod semnificativ se interzice, cu excepția cazului în care este autorizată de actele normative ce prevăd garanții adecvate pentru drepturile și libertățile persoanei vizate, cel puțin dreptul de a obține intervenția umană din partea operatorului» — a decision based solely on automated processing, including profiling, which produces an adverse legal effect for the data subject or significantly affects them is prohibited, unless authorised by normative acts that provide adequate safeguards, at minimum the right to obtain human intervention from the controller. Two differences from the general regime at art. 22 of Law 195/2024 are load-bearing. First, the only way out is a normative act: there is no contract limb and no consent limb, so a competent authority cannot cure a solely automated decision by obtaining agreement. Second, the effect that triggers the bar is an adverse one — «un efect juridic negativ» — rather than any legal effect. Art. 11(2) bars such decisions from resting on the special categories of data at art. 7 unless appropriate safeguards for the rights, freedoms and legitimate interests of the data subject are in place, and art. 11(3) separately prohibits profiling that results in discrimination against natural persons on the basis of those special categories — an outright ban with no authorisation route at all.

In force since 23 August 2026, stated as a calendar date rather than derived: art. 45(1) reads «Prezenta lege intră în vigoare la data de 23 august 2026». That is 3 days after publication — the Law was adopted on 30 July 2026, promulgated by Presidential Decree no. 729-X of 14 August 2026 and published in Monitorul Oficial nr. 382-385 of 20 August 2026 at art. 404 — and it is the same day the general statute Law 195/2024 took effect, which is plainly deliberate: art. 45(2) uses the occasion to amend arts. 63(3), 86(1) and 87(3) of Law 195/2024 so that the Centre's fining powers reach processors and not only controllers. The two acts were designed as a pair and neither can be read alone: this Law borrows the general statute's definitions (art. 3(1)), its complaint procedure (art. 44(2), citing Chapter VIII section 2 of Law 195/2024) and its fine-setting criteria (art. 43(2), citing art. 87). Moldova had no separate law-enforcement data-protection regime before this — the repealed Law no. 133/2011 covered both spheres — so art. 11 is a new rule rather than a re-enactment. AIL-300 computation check (2026-08-31): out of scope for the publication-relative sweep. Art. 45(1) fixes an express calendar date — «Prezenta lege intră în vigoare la data de 23 august 2026» — rather than a period running from publication, so no rule on the reckoning of terms applies.

Stated maximum penalty — Up to 2 000 000 Moldovan lei, imposed by the National Centre for Personal Data Protection on the controller or the processor. Art. 43(1) sets a single band, without the turnover alternative that art. 88 of Law 195/2024 carries, and it attaches to two triggers: (a) a finding of an infringement of this Law, which includes art. 11, and (b) failure to comply with a corrective measure, a temporary or definitive limitation on processing, or a suspension of data flows ordered by the Centre, or refusal of access. Art. 43(2) applies the art. 87 criteria of Law 195/2024 to the setting of the amount, and art. 43(3) sends the money to the state budget. The same taper applies: art. 46(1) sets the fine actually applied at 10 per cent of the amount determined in the first year, 40 per cent in the second and 100 per cent from the third, so the effective ceiling in the year to 23 August 2027 is 200 000 lei. Art. 44 adds an internal-reporting channel — any employee of a competent authority may complain to the Centre about a suspected infringement, the Centre must keep the reporter's identity confidential, and retaliation in the professional context is prohibited. Impact tier: public sector.

In force · 23 Aug 2026 checked 14 Sep 2026 Law 160/2026 art. 11 ↗ high confidence
Moldova Binding

Law 195/2024 art. 22 — GDPR art. 22 transposed verbatim, in force since 23 August 2026, with the fine phased in over three years

Binds Controllers and processors, with the GDPR's own reach. Art. 2(1) applies the Law to processing wholly or partly by automated means and to non-automated processing of personal data forming part of a filing system. Art. 3(1) catches processing in the context of the activities of an establishment of a controller or processor in Moldova regardless of where the processing happens; art. 3(2) reaches a controller or processor with no establishment in Moldova where the processing relates to offering goods or services to data subjects in Moldova, whether or not payment is required, or to monitoring their behaviour in Moldova; art. 3(3) adds Moldovan diplomatic missions and consular offices. There is no small-entity threshold, no turnover floor and no public/private split — art. 88(4) states that the fines apply to public authorities and institutions as well. Four carve-outs sit at art. 2(2): state secrets under Law no. 245/2008, purely personal or household activity, processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, which Law no. 160/2026 governs instead, and data on deceased persons except in the art. 52 case. Hiring is squarely covered: the art. 4 definition of profiling names «performanța la locul de muncă» first, and an automated sift producing a hiring outcome at least similarly significantly affects the candidate. Credit scoring and insurance pricing fall the same way. A decision with a human materially in the loop is outside art. 22(1), which reaches only decisions based «exclusiv» on automated processing; the Law supplies no gloss on what degree of human involvement defeats that.. Art. 22 of Law no. 195 of 25 July 2024 on the protection of personal data gives the data subject «dreptul de a nu fi supusă unei decizii bazate exclusiv pe prelucrarea automatizată, inclusiv pe crearea de profiluri, care produce efecte juridice pentru persoana vizată sau o afectează în mod similar într-o măsură semnificativă» — the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject or similarly significantly affects them. The three exceptions at art. 22(2) are the GDPR set unchanged: (a) necessary for entering into or performing a contract between the data subject and a controller; (b) authorised by normative acts that also lay down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests; (c) based on the data subject's explicit consent. In the contract and consent cases art. 22(3) requires the controller to implement suitable measures safeguarding rights, freedoms and legitimate interests, «cel puțin dreptul acesteia de a obține intervenție umană din partea operatorului, de a-și exprima punctul de vedere și de a contesta decizia» — at minimum the right to obtain human intervention from the controller, to express a point of view and to contest the decision. Art. 22(4) bars such decisions from resting on the special categories at art. 9(1) unless art. 9(2)(a) or (g) applies and safeguards are in place. The transparency limb is proactive rather than reactive: arts. 13(2)(f), 14(2)(g) and 15(1)(h) each require the controller to disclose «existența unui proces decizional automatizat, inclusiv crearea de profiluri, menționat la art. 22 alin. (1) și (4)» together with meaningful information about the logic involved and about the significance and envisaged consequences of the processing — on collection from the data subject, on collection from a third party, and again on a subject access request. Art. 35(3)(a) makes a data protection impact assessment mandatory where a systematic and extensive evaluation of personal aspects rests on automated processing, including profiling, and forms the basis of decisions producing legal effects or similarly significantly affecting the person. «Creare de profiluri» is defined at art. 4 in GDPR terms and names performance at work first among the aspects it covers.

In force since 23 August 2026, and the date is derived rather than stated on the face of the article. Art. 89(1) reads «Prezenta lege intră în vigoare la expirarea a 24 de luni de la data publicării în Monitorul Oficial al Republicii Moldova»; the Law was published in Monitorul Oficial nr. 367-369 (9305-9307) of 23 August 2024 at art. 574, having been promulgated by Presidential Decree no. 1592-IX of 21 August 2024, so the 24 months expire on 23 August 2026. The National Centre for Personal Data Protection states the same date. The 24-month figure is itself a change from the drafting stage — the Ministry of Justice draft carried 12 months — so the draft text circulating on the government consultation portal is not a safe source for this date. Art. 90(3) repealed, on the same day, Law no. 182/2008 on the Centre's regulations, Law no. 133/2011 on the protection of personal data, and arts. 74-1 to 74-3 and 42-3-4 of the Contravention Code no. 218/2008 — so the automated-decision rule that Moldova had carried since 2011 is superseded rather than supplemented, and data-protection enforcement has moved from contravention proceedings to administrative fines imposed by the Centre. Art. 90(8) preserves consents given under Law 133/2011 where the manner of giving them meets the conditions of the new Law. Law no. 160 of 30 July 2026 amended arts. 63(3), 86(1) and 87(3) of this Law with effect from the same 23 August 2026, extending the fining power to processors as well as controllers. Moldova ratified Protocol CETS 223 amending Convention 108 by Law no. 36 of 20 March 2026 and consented on 15 May 2026, but that Protocol has not entered into force — Moldova's own deposit made it the 34th Party, four short of the 38 that art. 37(2) requires — so its art. 9(1)(a) adds nothing here and the operative rule is the domestic one. The count is exact rather than approximate: the Netherlands' official Treaty Database record for CETS 223, revised 13 June 2026 and re-read on 14 September 2026, carries 46 Parties of which exactly 34 have a non-empty ratification date, Moldova's 15 May 2026 being the most recent, and no entry-into-force date is recorded for any Party. The Council of Europe's Consultative Committee (T-PD) reached the same figure from the depositary's side at its 50th plenary of 9-11 June 2026, congratulating Moldova on becoming the 34th Party — which supersedes the 33 recorded in the 49th plenary report of 5 November 2025, a count taken before the Moldovan deposit.

Stated maximum penalty — Up to 2 000 000 Moldovan lei or, in the case of an undertaking, up to 2 per cent of total annual turnover for the year preceding the sanction, whichever is the higher. Art. 88(2)(b) places «drepturile persoanelor vizate, în conformitate cu art. 12-22» in the higher of the Law's two fine bands, and art. 22 sits inside that range; the lower band at art. 88(1), 1 000 000 lei or 1 per cent, covers controller and processor obligations under arts. 8, 11, 25-39, 42 and 43 and does not reach art. 22. Art. 87(4) caps the total at the amount set for the gravest breach where several provisions are infringed in one or connected processing operations, and art. 87(3) requires intent or negligence. The money is phased in: art. 90(4) applies 10 per cent of the fine set by the Centre in the first year, 40 per cent in the second and 100 per cent from the third, so the ceiling in the year to 23 August 2027 is effectively 200 000 lei or 0.2 per cent of turnover. Enforcement runs through the National Centre for Personal Data Protection, which under art. 87(2) may issue a warning instead of a fine for a minor infringement or where a fine would be a disproportionate burden on a natural person, and which publishes summaries of its decisions under art. 84(3). Art. 85(2) gives at least two months for voluntary payment, and decisions are enforced under the Execution Code. Impact tier: all entities.

In force · 23 Aug 2026 checked 14 Sep 2026 Law 195/2024 art. 22 ↗ high confidence

Montenegro 1

Montenegro Binding

ZZPL art. 15a — a Directive 95/46 art. 15 prohibition, not a GDPR art. 22 right: no consent exit, no human-intervention safeguard, and no fine attached to the prohibition itself

Binds Controllers of personal data filing systems and their processors, public and private alike. Art. 7 applies the Act to processing of personal data carried out automatically, in whole or in part, or otherwise, where the data form or will form part of a filing system. Art. 8 carves out processing for defence and national security purposes (except the supervision provisions) unless another law provides otherwise, and processing by a natural person for their own needs. Art. 15a binds whoever takes the decision — the deployer of the system, not its vendor — and reaches state authorities, state administration bodies, local self-government and local administration bodies, companies, other legal persons, entrepreneurs and natural persons alike, which is the same list art. 74 uses when it sets the fine bands.. Art. 15a of the Zakon o zaštiti podataka o ličnosti («Službeni list Crne Gore» br. 79/08 of 23.12.2008, 70/09, 44/12, 22/17, 77/24) is Montenegro's automated-decision rule, and it is the first entry in the atlas drafted from Directive 95/46 art. 15 rather than from GDPR art. 22. Art. 15a(1): «Prilikom odlučivanja o pravima, obavezama i interesima lica, procjenjivanje njegovih ličnih svojstava i sposobnosti (rezultati rada na radnom mjestu, pouzdanost, kreditna sposobnost, ponašanje i sl.), koji su od značaja za odlučivanje, ne mogu se zasnivati isključivo na automatskoj obradi podataka.» Four structural differences from the GDPR generation follow. First, the form: this is a prohibition binding whoever takes the decision, not a right the data subject must invoke, so nothing turns on the person objecting. Second, the trigger: there is no definition of profiling anywhere in the Act and no ‘legal effects or similarly significantly affects’ threshold — what brings a decision inside art. 15a is its subject-matter (rights, obligations and interests) and the fact that it evaluates personal characteristics and abilities, with an illustrative list that reads as workplace, credit and conduct scoring. Third, the exits: art. 15a(2) admits only two, and neither is consent. «1) u toku zaključivanja ili izvršavanja ugovora uvažen zahtjev lica čiji se podaci obrađuju ili postoje odgovarajuće mjere zaštite njegovih zakonitih interesa (mogućnost da lice izrazi svoje mišljenje i sl.); 2) to zakonom propisano, pod uslovom da su propisane mjere zaštite zakonitih interesa lica.» Where GDPR art. 22(2)(c), Serbia's art. 38(2)(3) and North Macedonia's art. 26(2)(в) all let explicit consent license a solely-automated decision, Montenegro does not — the prohibition is narrower in its trigger but harder to contract out of. Fourth, the safeguards: they are not a free-standing paragraph as in GDPR art. 22(3) but a condition inside the contract exit, and the only one named is the possibility for the person to express an opinion. There is no express right to obtain human intervention from the controller and no right to contest the decision. Nor is there a special-categories bar of the GDPR art. 22(4) kind. The transparency limb is reactive only. Art. 43(1) obliges the controller, on a written request and after verifying identity, to reply within 15 days on whether it processes the person's data, and art. 43(2)(7) adds to that reply the «načinu automatske obrade ličnih podataka u slučaju iz člana 15a ovog zakona» — the manner of the automated processing in an art. 15a case. Nothing requires the controller to volunteer the existence of automated decision-making, so there is no analogue to GDPR arts. 13(2)(f) and 14(2)(g); a person who does not ask is not told. In the same reactive posture, art. 26 requires the controller to keep a record of its filing systems, art. 27 to notify the Agency before establishing an automatic filing system, and art. 28 to obtain the Agency's prior consent for automatic processing presenting a special risk — which expressly includes processing «koji se odnose na procjenu ličnosti, sposobnosti ili ponašanje», the same evaluative processing art. 15a is about. Art. 28 is the closest thing in the Act to a DPIA, and it is a licensing step rather than an assessment. Like North Macedonia's ZZLP and unlike Serbia's ZZPL and Albania's Law 124/2024, this Act has no Law Enforcement Directive part, so there is no police-side counterpart to Serbia's art. 39 or Albania's art. 53.

In force since 17 August 2012 and unamended since. Art. 15a was not in the Act as adopted: the supervisory authority's own official English translation of the consolidation at «Sl. list CG» 79/08 and 70/09 runs straight from Article 15 to Article 16 with nothing in between. It was inserted by the Zakon o izmjenama i dopunama Zakona o zaštiti podataka o ličnosti at «Sl. list CG» 44/12 of 09.08.2012, which the Official Gazette's own register records as having entered into force on 17.08.2012, and the Agency's consolidated text stamped for 79/08, 70/09 and 44/12 — archived before the next amendment — already carries art. 15a in the wording in force today. Neither later amendment touches it. The 2017 amendment (22/17 of 03.04.2017) is four articles long and, on the Government's own bill as tabled in the Skupština, changes only art. 28(1) (adding Agency consent for video surveillance of public areas), art. 37(3) (cutting footage retention from one year to six months), art. 40 and a new art. 40a. The 2024 amendment (77/24 of 05.08.2024, in force 13.08.2024) is a ‘Zakon o izmjeni’ — a single change — and art. 15a reads identically in the Agency's post-77/24 consolidated text. The Official Gazette records the Act's status as ‘Važeći’ and lists no successor. SUPERSESSION WATCH: on 7 August 2026 the Government tabled two bills that would replace this regime wholesale — the Predlog zakona o zaštiti podataka o ličnosti (EPA 1164 XXVIII, act no. 23-3/26-12), whose član 22 ‘Automatizovano donošenje pojedinačnih odluka, uključujući profilisanje’ is a GDPR art. 22 transposition with a defined profilisanje, a DPIA trigger for systematic evaluation and the full art. 13–14 disclosure duties; and the Predlog zakona o zaštiti podataka o ličnosti koje obrađuju nadležni organi u svrhu sprečavanja, istraživanja, otkrivanja ili gonjenja krivičnih djela ili izvršenja krivičnih sankcija (EPA 1165 XXVIII, act no. 23-3/26-13), which would give Montenegro the LED-side act it currently lacks. Update (2026-09-15): both bills were adopted by the Skupština at the Sixth extraordinary session of 2026 (session reported 5 September 2026 by Montenegrin legal-press coverage of the Assembly's own session agenda). Official Gazette publication and an entry-into-force date have not yet been confirmed from a primary Sluzbeni list CG citation; art. 15a remains the governing text until publication and any transitional period run. Re-check for the Sluzbeni list CG number and the transitional-provision entry-into-force date on the next Montenegro rotation. Supersession watch (added 2026-09-21): the two Government bills noted above as tabled 7 August 2026 have since been enacted as a single Zakon o zaštiti podataka o ličnosti (Službeni list Crne Gore br. 133/2026 od 11.9.2026), adopted by the Skupština 4 September 2026, signed by President Milatović 8 September 2026 (Decree No. 01-009/26-1569/2), in force 19 September 2026, and applicable from 19 March 2027. Its art. 23 is a GDPR art. 22-style automated-decision right that will replace this art. 15a prohibition once applicable. This row remains the operative rule until 19 March 2027 and is not yet retired. A new obligation row for the 2026 Law's art. 23 needs drafting once the primary gazette/consolidated text can be fetched (me.propisi.net and gov.me both failed to render readable text to this run's tools); flagged as a coverage gap rather than drafted from secondary sources alone.

Stated maximum penalty — None for the prohibition itself; €500–€20,000 for a legal person that fails the transparency limb attached to it. Art. 74(1) lists 21 misdemeanours and art. 15a is not among them, so a controller that bases a decision solely on automatic processing outside the two art. 15a(2) exits commits no offence under this Act. What is fineable is the reply: art. 74(1)(18) covers failure to deliver the art. 43(1) notification — which by art. 43(2)(7) must describe the manner of the automated processing in an art. 15a case — within 15 days of the request. The bands under art. 74 are €500–€20,000 for a legal person, €150–€6,000 for an entrepreneur, and €150–€2,000 for the responsible person in a legal entity, in a state authority, in a state administration body, in a local administration or local self-government body, and for a natural person. Two neighbouring items reach the same evaluative processing from the other side: art. 74(1)(9) fines failure to notify the Agency before establishing an automatic filing system (art. 27(1)), and art. 28 makes the Agency's prior consent a precondition for automatic processing that assesses personality, ability or conduct. The Agency's own supervisory route is art. 71 — an order or prohibition, whose breach is art. 74(1)(21) — which is how a solely-automated decision would in practice be stopped, since the prohibition carries no fine of its own. This is the same structural gap as Serbia's art. 39(3) and Albania's art. 53(3), but reached from the opposite direction: there the enumeration is drawn entirely from the GDPR Part and omits the LED rule; here there is only one Part and the enumeration simply skips art. 15a.

In force · 17 Aug 2012 checked 21 Sep 2026 ZZPL art. 15a ↗ high confidence

Madagascar 1

Madagascar Binding

Loi n° 2014-038 art. 3 — the wide automated-decision bar stated as a founding principle, with no exception and a 5% turnover catch-all behind it

Binds Responsables de traitement, on the terms of the art. 5 scope: the Law applies to any processing of personal data, automated or not, contained or intended to be contained in files, carried out in whole or in part on Malagasy territory, excluding processing for exclusively personal activities and processing for the sole purposes of journalism or literary or artistic expression. Art. 6 fixes the applicable-law rules. The prior-formality regime runs through Chapitre VI: art. 43 sets the declaration channel and art. 44 the categories reserved to a regulatory act, with art. 76 providing that processing governed by art. 44 and already created is subject only to a declaration. Neither profiling nor automated decision-making appears as a category attracting prior authorisation, so Madagascar, like Guinea and Togo and unlike Burkina Faso and Niger, imposes no ex ante gate on the processing art. 3 governs. The art. 3 bar itself binds two distinct classes of decision-maker with no size or sector threshold: under its first limb the courts, and under its second every administrative and private decision-maker appraising human conduct. Art. 52 provides for a délégué à la protection des données who exercises their functions independently, receives no instructions from the controller and may not be sanctioned for exercising them. Impact tier: all entities.. Article 3 of Loi n° 2014-038 du 9 janvier 2015 sur la protection des données à caractère personnel is Madagascar's operative automated-decision rule, and it is placed as a founding principle rather than as an operative duty: it sits in Chapitre premier, Dispositions générales, immediately after art. 2, which declares that data processing must serve every person and respect human identity, human rights, privacy and individual and public liberties, and immediately before art. 4, which creates the Commission Malagasy de l'Informatique et des Libertés. The article has two unnumbered paragraphs. The first: no judicial decision involving an appraisal of human conduct may have as its foundation an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The second: no administrative and private decision involving an appraisal of human conduct may have as its sole foundation an automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. Three features of the drafting matter. The judicial limb does not carry the word "seul", while the second limb of the same article does, so a court appraising conduct may not rest on such a processing at all, whatever else it also relies on. The second limb takes the wide trigger — any administrative and private decision involving an appraisal of human conduct — rather than the narrow Directive 95/46/EC trigger confined to decisions producing legal effects, which is what Congo-Brazzaville, Gabon, Togo, Morocco and Algeria use. And the Law supplies no carve-out whatever: no contract exception, no consent exception, no legal-authorisation exception, and no opportunity to present observations. Madagascar therefore joins Côte d'Ivoire, Mali, Burkina Faso and Guinea in barring the conduct outright rather than deeming some decisions outside it. The Law does create a logic right, but it is narrower than the bar it accompanies: the third indent of the art. 23 access right entitles a data subject to the information enabling them to know and to contest the logic underlying an automated processing where a decision has been taken on its foundation and produces legal effects in their regard. Art. 3's own second limb is not limited to legal effects, so a decision appraising conduct without legal effects is barred by art. 3 while falling outside the art. 23 logic right. There is no human-review right, no right to a fresh non-automated decision, and the Law carries no definition of profiling.

The Law carries no commencement article. Its final provision, art. 78, is a bare publication and execution clause — the present Law shall be published in the Journal Officiel and executed as a law of the State — and nothing in the text defers art. 3 or any other article. The date recorded here, 9 January 2015, is the date of promulgation stamped in the signature block at Antananarivo over the signature of President Rajaonarimampianina Hery Martial, and it is the date by which the Law is universally cited, including in the ILO NATLEX record. The Law is numbered for 2014 and promulgated in 2015 because it was adopted by the National Assembly in 2014 and cleared by the Haute Cour Constitutionnelle first: the preamble recites décision n° 02-HCC/D3 du 07 janvier 2015, two days before promulgation. Confidence is medium for one reason only, and it is the same reason as for Morocco, Algeria and Togo: because art. 78 attaches publication rather than force, the operative date depends on the Malagasy general publication-to-force rule, which was not verified against a primary source, and the Journal Officiel issue and date for the Law could not be established from an official source. If Malagasy law makes force turn on Journal Officiel publication rather than on promulgation, the true date is later than the one recorded here by the length of the publication lag, and the row would need amending. Art. 76 is transitional and is not a deferral of art. 3: all processing implemented before entry into force had one year from publication to conform, on a sectoral timetable fixed by the Commission and published in the Journal Officiel, a period long since closed. Art. 77 leaves application modalities to regulatory texts. The Law abrogates nothing expressly and names no predecessor statute, so nothing is superseded on the tracker. Text read end to end — all 78 articles, from the exposé des motifs to the signature block — in the edition published by the Unité de Gouvernance Digitale, the Malagasy State's digital-governance unit, which serves the full statutory text as HTML and credits CNLEGIS, the State's legislative database, as its source. No AI-specific statute or guidance is in force in Madagascar.

Stated maximum penalty — Art. 3 is not an offence, and none of the penal articles reaches it — but the administrative route does, because art. 55 is a general catch-all. Art. 55 provides that the Commission Malagasy de l'Informatique et des Libertés may pronounce against a controller, in the event of a breach of one or more of the provisions of the present Law and after a contradictory procedure, a warning, a mise en demeure, a pecuniary sanction, and the further measures the article lists, with pecuniary sanctions doubled on recidivism. Because art. 55 is drafted against "une ou plusieurs des dispositions de la présente loi" without enumeration, it reaches art. 3 on its face. Art. 59 caps the pecuniary sanction: its amount must be proportionate to the gravity of the breaches and to the advantages derived from them, and it may not exceed 5 per cent of pre-tax turnover for the last closed financial year — the same ceiling as Côte d'Ivoire, Niger and Burkina Faso, and below Guinea's 7 per cent. Art. 57 allows any sanction decision to be coupled with an injunction to make, within a time limit the Commission sets, any modification or deletion it judges useful. Art. 58 requires the sanction to rest on a report notified to the controller, who may file written and oral observations and be represented or assisted, and provides that sanction decisions may be appealed to the Conseil d'Etat. Art. 60 makes sanction decisions public, allows the identity of natural persons to be anonymised, and lets the Commission order their insertion in publications or newspapers at the sanctioned person's expense. The penal articles, by contrast, are a closed list of named offences and none of them names art. 3: art. 61 punishes obstruction of the Commission with six months to two years' imprisonment and a fine of 800,000 to 8,000,000 Ariary; art. 62 failure to observe prior formalities, six months to two years and 200,000 to 2,000,000 Ariary; art. 63 unlawful processing of sensitive data, offence files or the national identification number by reference to arts. 14, 15, 17 and 18, two to five years and 800,000 to 8,000,000 Ariary; art. 64 breach of the art. 15 security measures; art. 65 unfair collection, two to five years and 1,000,000 to 10,000,000 Ariary; art. 66 misuse of purpose; art. 67 disregard of a founded rectification or objection request; art. 68 breach of the art. 27 information duty; art. 69 breach of the art. 23 access right; art. 70 over-retention; and art. 71 disclosure harming the person's standing or private life, two to five years and 1,000,000 to 10,000,000 Ariary. Art. 72 allows erasure of the data to be ordered in any of those cases and art. 73 requires the Procureur de la République to notify the Commission's president of prosecutions.

In force · 9 Jan 2015 checked 20 Sep 2026 Loi n° 2014-038 art. 3 ↗ medium confidence

North Macedonia 1

North Macedonia Binding

ZZLP art. 26 — GDPR art. 22 transposed almost word for word, in force since 24 February 2020, with a 4%-of-income fine and no euro alternative underneath it

Binds Controllers and processors, public and private alike. Art. 2(1) applies the Act to wholly or partly automated processing of personal data and to non-automated processing of data forming part of, or intended to form part of, a filing system, with the household exemption in art. 2(2). Art. 3 gives it the GDPR's reach: establishment in North Macedonia regardless of where the processing happens (art. 3(1)); a controller or processor not established in North Macedonia whose processing relates to offering goods or services to data subjects in North Macedonia — payment or no payment — or to monitoring their behaviour where that behaviour takes place in North Macedonia (art. 3(2)); and a controller established where the law of North Macedonia applies by virtue of international law (art. 3(3)). The duty in art. 26 falls on whoever takes the decision, so the deployer of the system rather than its vendor.. Art. 26 of the Закон за заштита на личните податоци («Службен весник на РСМ» бр. 42/20, 294/21, 101/25) is North Macedonia's automated-decision rule and it tracks GDPR art. 22 closely enough that the differences are worth naming precisely. Art. 26(1): «Субјектот на личните податоци има право да не биде предмет на одлука заснована единствено на автоматизирана обработка, вклучувајќи го и профилирањето што предизвикува правни последици за него или на сличен начин значително влијае на него.» Same trigger as the GDPR — a decision resting solely on automated processing, profiling included, producing legal effects or similarly significantly affecting the person — and, unlike Albania's «pasoja të ngjashme të rënda», no re-drafting of the effects threshold. Art. 26(2) carries the three exits verbatim: (а) necessary for concluding or performing a contract between the data subject and the controller; (б) permitted by a law applying to the controller that itself provides suitable measures safeguarding rights, freedoms and legitimate interests; (в) based on the data subject's explicit consent. Art. 26(3) attaches the safeguards to exits (а) and (в) only, again as in GDPR art. 22(3), and spells out the minimum content: «право на обезбедување на човечка интервенција од страна на контролорот, право на изразување на личен став и право на оспорување на таквата одлука» — human intervention by the controller, the right to express a personal view, the right to contest the decision. Art. 26(4) bars such decisions from resting on special categories of personal data unless art. 13(2) point 1) or point 7) applies, with safeguards in place; art. 13(2)(1) is explicit consent and art. 13(2)(7) is substantial public interest on the basis of law, so the cross-reference lands exactly where GDPR art. 22(4) does via art. 9(2)(a) and (g). Art. 26 does not stand alone: arts. 17(1)(6), 18(1)(7) and 19(1)(8) each require the controller to disclose «постоењето на автоматизиран процес на одлучување, вклучувајќи го и профилирањето како што е наведено во членот 26 ставови (1) и (4)», together with meaningful information about the logic involved and the significance and envisaged consequences, and art. 39(3)(а) makes a systematic and extensive automated evaluation feeding such decisions a trigger for a data-protection impact assessment. There is no law-enforcement counterpart in this Act — the ZZLP has eleven chapters and none of them is a Law Enforcement Directive part, so North Macedonia has no analogue to Serbia's art. 39 or Albania's art. 53 inside this statute.

In force since 24 February 2020, and binding on every controller without transitional relief since 24 August 2021. Art. 124: «Овој закон влегува во сила осмиот ден од денот на објавувањето во ‘Службен весник на Република Северна Македонија’.» Publication was in issue 42 of 16 February 2020 at page 95 — the date is stamped on every page of the Agency's own copy of the Act and the issue-and-page citation is confirmed independently by the publisher's Хронолошки регистар за 2020, entry 813 — so the eighth day is 24 February 2020. Art. 119 then gave controllers and processors 18 months from entry into force to bring their operations into line, which ended on 24 August 2021; that period was a grace window for compliance, not a suspension of the Act, and it has been closed for five years. Both amendments were checked against art. 26 and neither touches it. The Закон за изменување и дополнување на ЗЗЛП at 294/21 (Хронолошки регистар за 2021, entry 627, issue 294 page 34) is not reflected in art. 26, whose text is identical in the original 42/20 gazette copy and in the consolidated text. The Закон за дополнување на ЗЗЛП of 14 May 2025 («Службен весник на РСМ» бр. 101 од 21 мај 2025) amends only arts. 48 and 56, inserting NATO member states alongside EU member states in the international-transfer rules, and enters into force on the day of publication. Art. 122 is a supersession trigger written into the Act: the provisions of chapters II (except art. 12), III, IV (except arts. 46 and 47), V and VIII cease to apply upon North Macedonia's accession to the European Union. Art. 26 sits in chapter III, «Права на субјектот на личните податоци», so it is scheduled to fall away in favour of the GDPR itself on accession — the same construction as art. 100 of Albania's Law 124/2024.

Stated maximum penalty — Up to 4% of total annual income, and — this is the divergence from the GDPR that matters — with no euro floor underneath the percentage. Breach of art. 26 is listed at art. 111(1)(15) («не ги исполнува обврските за регулирање на автоматското донесување на поединечни одлуки, вклучувајќи го и профилирањето според одредбите на членот 26 од овој закон»), which places it in the second of the Act's two offence categories: art. 110 is Category I at up to 2% and art. 111 is Category II at up to 4%. The Category II ceiling is «глоба во износ до 4% од вкупниот годишен приход на контролорот или обработувачот - правно лице, (изразена во апсолутен износ)» for the business year preceding the year of the offence, or for the shorter period since the entity began operating. Where GDPR art. 83(5) sets €20 000 000 or 4% of worldwide annual turnover, whichever is higher, art. 111(1) offers only the percentage, so the exposure of a low-revenue controller is bounded by its own income rather than by a fixed statutory sum. The accompanying personal fines are small and fixed: art. 111(2) €300–500 in denar equivalent for the responsible person in the legal entity, art. 111(3) €100–500 for an official in a state authority, art. 111(4) €100–250 for a natural-person controller or processor. Art. 113 lists the mitigating and aggravating factors that set the amount within the band.

In force · 24 Feb 2020 checked 10 Sep 2026 ZZLP art. 26 ↗ high confidence

Mali 1

Mali Binding

Loi 2013-015 art. 2 — a one-limb bar, stated as a founding principle, on decisions with legal effects resting solely on computerised profiling, with no exception of any kind

Binds Responsables du traitement within the scope of arts. 4 and 5. Art. 4 applies the Law to any processing of personal data carried out wholly or partly on national territory. Art. 5 subjects to the Law any processing of personal data by the State, local authorities, personalised public bodies, natural persons and private-law legal persons; any processing implemented by a controller established on national territory or not, excluding means used only for transit on that territory; and any processing concerning public security, national defence, the investigation and prosecution of criminal offences or State security, even where linked to an important economic or financial interest of the State, subject to the derogations provided by the Law or by other texts. Art. 6 excludes processing by a natural person in the exclusive course of personal or domestic activities where the data are not intended for systematic communication to third parties or for dissemination, and temporary copies made in the course of technical transmission and access activities. Art. 57 makes declaration to the Autorité de Protection des Données à caractère Personnel a standing precondition, and provides that where that formality has been omitted in bad faith the Autorité imposes the appropriate administrative sanction assessed by reference to the gravity of the fault. The art. 2 bar binds any decision-maker whose decision induces legal effects, irrespective of size or sector. Impact tier: all entities.. Mali's automated-decision rule is not in a rights chapter at all: it is the third paragraph of art. 2, in Chapitre I of Loi n° 2013-015 du 21 mai 2013 portant protection des données à caractère personnel en République du Mali, the chapter headed "De l'objet". Article 2 opens with the founding principle that informatics must be at the service of every person and must respect human identity, human rights, private life and public and individual freedoms, states that everyone has a right to the protection of the personal data concerning them, and then provides that no decision inducing legal effects with regard to a person may be taken on the sole basis of a computerised processing intended to define the profile of the person concerned or to evaluate certain aspects of their personality. Three features make it the leanest formulation in the Francophone family. It has one limb only — there is no separate bar addressed to the courts, which every other Francophone row on the tracker carries. It states no exception whatever: there is no contract deeming clause, no consent exception, no legal-authorisation exception and no opportunity to present observations, so on its face it shares that absence with Côte d'Ivoire's art. 25 alone. And it speaks of a "traitement informatique" rather than a "traitement automatisé", which is the older French formula. The companion right sits in art. 12, in Chapitre V on the rights of persons: everyone has the right to obtain from a controller the communication, in an intelligible form, of all the data concerning them together with any available information as to their origin, and — the operative half for automated decisions — the information and the reasoning used in computerised processing whose results are relied on against them. That right is exercised free of charge, on the spot or remotely, must be answered without delay, and a copy of the data conforming to the content of the processing is delivered on request; where there is a risk of concealment or disappearance of the data the Autorité may order any appropriate measure. There is no defined term for profiling and no right to obtain human intervention or a fresh non-automated decision.

The Law contains no commencement article: Chapitre X, headed "Des dispositions finales", consists of art. 69 alone, which provides only that practical implementation matters not covered by the Law are to be supplied by deliberation of the Autorité de Protection des Données à caractère Personnel in conformity with the spirit of the Law, and the text then ends with the promulgation formula "Bamako, le 21 mai 2013" and the signature of the interim President of the Republic, Professor Dioncounda Traoré. The date recorded here is the date of the Journal officiel de la République du Mali that carries the Law: fifty-fourth year, numéro 26 of 28 June 2013, pp. 1002 to 1011, whose masthead, table of contents entry and per-page footers were read directly. That is the same basis used for Morocco, Algeria and Côte d'Ivoire. Confidence is medium for the same reason: the Malian general publication-to-force rule was not itself read against a primary source, so it could not be confirmed whether force attaches on the day of publication of the Journal officiel or after a delay. Art. 68 is transitional and not a deferral of art. 2: public services and natural or legal persons whose activity before the date of promulgation consisted, principally or incidentally, in processing personal data had a maximum of six months to conform, failing which their activities are deemed contrary to the Law and must cease without delay — a period that closed in 2013. The Law was adopted by the Assemblée nationale in its sitting of 9 May 2013. Text read in the Journal officiel itself, which is the official gazette published by the Secrétariat général du Gouvernement. Supersession checked and closed, 24 August 2026: the amending law exists and art. 2 is untouched by it. Loi n° 2017-070 du 18 décembre 2017 portant modification de la Loi n° 2013-015 was read in full in the official gazette, Journal officiel de la République du Mali n° 53 of 2017 at pp. 2115-2116, located through the Secrétariat général du Gouvernement's own gazette search. It has exactly two articles. Its art. 1 provides that "les articles 21, 25, 36, 42 et 49 de la Loi n° 2013-015 du 21 mai 2013 sont modifiés ainsi qu'il suit", and every one of the five replaced articles is institutional: art. 21 recomposes the Autorité's deliberating organ as fifteen members on a single seven-year non-renewable mandate and sets the forty-five-day replacement rule, art. 25 sets the oath sworn before the Cour suprême by members and before the Tribunal de grande instance by staff with access to personal data, art. 36 requires the annual activity report to the President, the Prime Minister and the President of the National Assembly, art. 42 caps extraordinary sessions at five days, and art. 49 requires the Autorité to adopt its rules of procedure at its inaugural sitting. Art. 2 of the amending law is a bare abrogation of prior contrary provisions, "notamment celles de la Loi n° 2013-015" — it repeals what conflicts with the five new institutional articles, not the Law, and nothing in it conflicts with the automated-decision rule. The third paragraph of art. 2 of the 2013 Law therefore stands exactly as enacted and as recorded in this row, and the Law was adopted in the National Assembly sitting of 29 November 2017 and promulgated at Bamako on 18 December 2017 by President Ibrahim Boubacar Keïta. That amendment is also the only one there has ever been: a search of the SGG gazette index for "données à caractère personnel" restricted to texts of type Loi returns exactly two results across the whole series — the 2013 Law and this 2017 amendment — so there is no second amending law and no successor statute, and the twelve texts the index returns for "caractère personnel" across all types are otherwise decrees and arrêtés on the Autorité's membership, remuneration and filing fees. The secondary sources that describe the Law as "modifiée" are correct as to the fact of amendment and correct as to its subject-matter; nothing they describe reaches this row. Confidence is held at medium for the unchanged reason recorded above — the Malian general publication-to-force rule, which bears on the date and not on the substance — and not out of any residual doubt about supersession. Coverage symmetry against the fourteen African rows already tracked: art. 2 belongs to the Directive 95/46/EC art. 15 line but is the shortest and oldest-sounding member of it, and it is the only automated-decision provision on the tracker that sits inside a purposes-and-principles article rather than in a rights or obligations chapter. Against its neighbours: Senegal's art. 48, Morocco's and Algeria's art. 11 all carry a judicial limb and a contract deeming clause, and Mali has neither; Côte d'Ivoire's art. 25 and Niger's art. 52 carry a judicial limb and, in Côte d'Ivoire's case, no exception, so Mali and Côte d'Ivoire are the only two African rows with no exception at all, and Mali is the barer of the two because it lacks the judicial limb. Mali's art. 12 reasoning-disclosure right is, word for word in substance, the third paragraph of Niger's art. 52 — the right to know and contest the information and the reasoning used in processing whose results are relied on against the person — which puts Mali and Niger together as the only Francophone rows on the tracker with that right, though Niger states it inside the automated-decision article itself and adds an artificial-intelligence clause that Mali has nothing resembling. The four-way African lineage picture is unchanged: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, sn-loi200812-art48, ci-loi2013450-art25, ne-loi202259-art52, bj-code-num-art401 and now ml-loi2013015-art2; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — No offence reaches art. 2. Art. 58 provides that, save where the Law makes special provision in computing matters, the classification of offences and the penalties applicable to them are those defined by the Penal Code, the Code des personnes et de la famille, the electoral law and the other laws creating offences in the field of personal data protection, with procedure governed by the Code de Procédure Pénale. The Law's own two fine articles name their own conduct and neither names an automated decision. Art. 65 punishes with a fine of 5,000,000 to 20,000,000 francs the communication to unauthorised third parties of, or unauthorised or unlawful access to, personal data engaging fundamental rights, individual freedoms or private life; the diversion or any modification of the purpose of a collection or processing without the express and reasoned authorisation of the Autorité; collection by fraudulent, unfair or unlawful means, or processing of nominative information concerning a natural person despite that person's objection where the objection is founded on legitimate reasons connected to their fundamental rights or private life; automated processing of nominative personal data for health research in violation of laws and regulations; and, outside the cases provided by law, placing or keeping in computerised memory nominative data concerning offences, convictions or national security measures, that last offence applying also to non-automated or mechanographic files. Art. 66 punishes with a fine of 2,500,000 to 10,000,000 francs processing nominative information without taking all precautions to preserve its security, in particular against distortion or damage, and placing or keeping in computerised memory, without the prior agreement of the person concerned, nominative data revealing directly or indirectly racial or ethnic origins, political, philosophical or religious opinions or trade-union membership. The route that reaches art. 2 is administrative and is set out in art. 61, which lists the Law's administrative sanctions exhaustively: a warning against any good-faith controller that has not observed the administrative formalities of collection, processing and management laid down by the Law or by the Autorité's regulatory acts; a mise en demeure of the controller at fault to bring itself into conformity; an injunction to cease personal-data processing activities in case of fault; and withdrawal of the agrément where the Autorité finds it necessary. Art. 62 lets the Autorité use every technical means in its possession to secure the automatic execution of its decision; art. 63 requires administrative sanction decisions to be reasoned on pain of nullity and notified to those concerned; art. 59 confirms that the Autorité imposes the administrative and pecuniary sanctions flowing from the Law without prejudice to criminal sanctions and may institute simple-police contraventions by lawfully made regulations; art. 67 lets the Autorité settle any pecuniary sanction by transaction at the offender's request, subject to the scales fixed by law; and art. 56 lets the President of the Autorité denounce any infringing user to the Procureur de la République or bring a complaint before the competent courts. Art. 60 leaves civil actions to the Code de Procédure Civile, Commerciale et Sociale and the Régime Général des Obligations. Notably, art. 61 attaches no fine to a breach of art. 2 — the administrative list stops at withdrawal of agrément.

In force · 28 Jun 2013 checked 20 Sep 2026 Loi n° 2013-015 art. 2 ↗ medium confidence

Mauritania 1

Mauritania Binding

Loi n° 2017-020 art. 19 — the pre-GDPR bar with no exception at all, and a judicial limb the others do not have

Binds Every controller within art. 3, which sets four cumulative reaches: any processing of personal data carried out by a natural person, by the State, by local authorities, or by legal persons of public or private law; any automated or non-automated processing of data contained in or intended to figure in a file, excepting the processing at art. 4; any processing implemented by a controller on Mauritanian territory or anywhere Mauritanian law applies; and any processing implemented by a controller, established on Mauritanian territory or not, that has recourse to processing means situated on the national territory. That last limb is the means-in-territory test rather than the GDPR's targeting test, so a foreign controller computing an automated decision on Mauritanian infrastructure is caught while one scoring Mauritanian residents entirely from abroad may not be. No size or sector threshold applies — enterprise, SME, public body and individual controllers alike. The first paragraph of art. 19 binds a different addressee entirely: the courts, and by extension anyone submitting automated behavioural assessment into judicial proceedings. Hiring sits inside the second paragraph only where the outcome produces legal effects — the termination or refusal of a contract of employment does; a ranked shortlist on its own is harder to place, and the Law gives no gloss. Two neighbouring articles matter for scope: art. 12 prohibits collection and processing revealing racial, ethnic, linguistic or regional origin, filiation, political opinions, religious or philosophical convictions, trade-union membership, sexual life, genetic data or health data, subject to the art. 13 exceptions, so a profiling model drawing on those inputs fails at art. 12 before art. 19 is reached; and art. 18 requires prior consent for direct marketing by any means of communication.. Article 19 of Loi n° 2017-020 du 22 juillet 2017 sur la protection des données à caractère personnel is two paragraphs, and the first has no counterpart in any other row on the tracker. It provides that «aucune décision de justice impliquant une appréciation sur le comportement d'une personne, ne peut avoir pour fondement un traitement automatisé des données à caractère personnel destiné à évaluer certains aspects de sa personnalité» — no judicial decision involving an assessment of a person's conduct may be founded on automated processing of personal data intended to evaluate certain aspects of their personality. That is a rule addressed to courts, not to controllers, and it bars algorithmic input into sentencing, bail and any other judicial appraisal of behaviour outright. The second paragraph is the general bar: «aucune décision, produisant des effets juridiques à l'égard d'une personne, ne peut être prise sur le seul fondement d'un traitement automatisé des données à caractère personnel destiné à définir le profil de l'intéressé ou à évaluer certains aspects de sa personnalité» — no decision producing legal effects with respect to a person may be taken on the sole basis of automated processing intended to define that person's profile or to evaluate certain aspects of their personality. This is art. 2 of France's Loi n° 78-17 in its pre-2018 wording, carried across whole, and it is the pre-GDPR shape in three respects. It has no exception limb of any kind — no contract, no consent, no legal authorisation, nothing — so on its face it is as absolute as art. 14(5) of the Malabo Convention. It has no profiling definition; «définir le profil» does the work as an ordinary-language phrase. And its threshold is narrower than the modern one: it catches decisions producing «effets juridiques» only, with no «significantly affects» limb, so a purely commercial automated refusal with no legal effect falls outside the second paragraph even where it would be caught in Zambia, Mauritius or under the Convention. There is no explanation limb anywhere in the Law. The art. 53 right of access runs to five items — information allowing the person to know and where appropriate contest the processing, confirmation, communication of the data in accessible and intelligible form, purposes and categories and recipients, and envisaged third-country transfers — and none of them is a logic item; the information duty at collection runs to nine items ending at the right to ask to be removed from the file, and carries no automated-decision item either. There is no right to human intervention and no right to contest the decision as such. Mauritania is the Angola shape at a different latitude: the machine decision is forbidden and never has to be explained.

Dated 22 July 2017 and published in the Journal Officiel de la République Islamique de Mauritanie no. 1400 of 15 November 2017, which is the date printed in the running head of every page of the official text. Article 101 is the standard promulgation formula — «La présente loi sera exécutée comme loi de l'Etat et publiée au Journal Officiel de la République Islamique de Mauritanie» — signed at Nouakchott on 22 July 2017 by President Mohamed Ould Abdel Aziz, Prime Minister Yahya Ould Hademine and the Minister for Employment, Vocational Training and Information and Communication Technologies. There is no deferred commencement clause and no proclamation power, so the law date is carried here, consistent with how every other Francophone row on the tracker is dated. Two qualifications keep this row at medium rather than high confidence, and neither is about the text of art. 19. First, arts. 99 and 100 create a transitional regime that runs from a compound trigger: «à compter de la date d'entrée en vigueur de la présente loi et de la mise en place effective de l'Autorité de Protection des Données à caractère personnel», existing processing had three years to conform where operated for the State, a public establishment, a local authority or a private legal person managing a public service, and two years otherwise, with art. 100 deeming unregularised processing to have been carried on without declaration or authorisation. The Autorité de Protection des Données à caractère personnel was not stood up in 2017 — its members were sworn in years later — so the transitional clock started late, and while art. 19 is a prohibition rather than a formality subject to régularisation, an enforcement action grounded on the pre-authority period would meet that argument. Second, the currency. The fines in this Law are stated in ouguiyas as they stood in 2017; Mauritania redenominated on 1 January 2018 at ten old ouguiya (MRO) to one new ouguiya (MRU), so every figure in the Law reads ten times larger than its present-day equivalent unless converted. Mauritania deposited its instrument of ratification of the Malabo Convention on 9 May 2023, and that deposit is the fifteenth — it is the instrument that triggered art. 36 and brought the Convention into force for every party on 8 June 2023. So Mauritania is both bound by art. 14(5) and the reason art. 14(5) binds anyone. Where the two diverge they diverge very little: neither art. 19 nor art. 14(5) admits any exception, and the only real gap is that the Convention adds a «significantly affects to a substantial degree» limb that art. 19's «effets juridiques» threshold does not reach.

Stated maximum penalty — Administrative only, and no criminal penalty attaches to art. 19. The penal section, arts. 84 to 98, was read article by article: art. 84 obstruction of the Authority, art. 85 processing without the prior formalities, art. 86 processing subject to an art. 77, 78 or 79 measure, art. 87 collection by fraudulent, unfair or unlawful means, art. 88 processing without the required security measures, art. 89 processing despite the person's opposition, art. 90 storing sensitive data without express consent, arts. 91 to 94 retention beyond purpose, diversion of purpose and breach of confidentiality. None of them names art. 19 and no article of the Law cross-refers to it, so a solely-automated decision is not, on its own, an offence in Mauritania. What does reach it is art. 80: for breaches of the legal and regulatory provisions on personal data, and beyond the measures at arts. 77 to 79 (warning, mise en demeure, provisional or definitive withdrawal of authorisation, interruption of processing for up to three months, blocking of data), the Authority may impose pecuniary sanctions proportionate to the gravity of the breach — on a first breach not exceeding ten million ouguiyas, and on a repeat breach within five years of a previous sanction becoming final not exceeding fifty million ouguiyas or, for an undertaking, 5% of pre-tax turnover for the last closed financial year. Read in post-redenomination currency those ceilings are MRU 1,000,000 and MRU 5,000,000 respectively. Article 82 permits publication of the sanction at the sanctioned party's expense; art. 83 gives a right of appeal to the Cour Suprême. Article 96 makes legal persons other than the State, local authorities and public establishments criminally liable for offences under the Law committed on their behalf, and art. 97 sets corporate fines at five times the natural-person maximum, with dissolution available — but that machinery hangs off the penal articles, which art. 19 is not among. Impact tier: all entities.

In force · 22 Jul 2017 checked 20 Sep 2026 Loi n° 2017-020 art. 19 ↗ medium confidence

Mauritius 1

Mauritius Binding

Data Protection Act 2017 s. 38 — the African automated-decision bar that a criminal penalty actually backs

Binds Every controller and processor within the Act's reach. Section 3(1) binds the State expressly and s. 3(2) treats each Ministry or Government department as separate from every other, so a public-sector automated decision is in scope on the same terms as a private one — a drafting choice worth noting, because the Convention's own machinery assumes a national authority policing both. Section 3(3) applies the Act to processing of personal data wholly or partly by automated means, and to non-automated processing where the data form or are intended to form part of a filing system. The exclusions at s. 3(4) are narrow: exchanges of information between Ministries, Government departments and public sector agencies on a need-to-know basis, and processing by an individual in the course of a purely personal or household activity. There is no size, sector or turnover threshold, so the bar reaches enterprise, SME, public body and — Mauritius being a substantial offshore financial centre — the management companies and global-business licensees the Data Protection Office has issued separate registration advice to. Hiring is in scope through the s. 2 definition of profiling, which names «performance at work» among the personal aspects it covers, and credit, insurance and AML/CFT screening decisions fall the same way; the s. 38(2)(b) legal-authorisation limb is the one most likely to be reached for by a regulated financial institution, and it is the limb that requires the authorising law itself to lay down safeguards. The s. 5(i) function of the Commissioner is the tell that this was drafted with automated decisions in mind: the Commissioner is to «examine any proposal for automated decision making or data linkage that may involve an interference with, or may otherwise have an adverse effect, on the privacy of individuals and ensure that any adverse effect of the proposal on the privacy of individuals is minimised».. Section 38(1) of the Data Protection Act 2017 (Act 20/2017) provides that «every data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or significantly affects him». Mauritius passed the Act on 8 December 2017, three days before the GDPR's own application date was a year away, and the transposition is close: s. 38(2) carries the three exceptions in GDPR order — (a) necessary for entering into, or performing, a contract between the data subject and a controller; (b) authorised by a law to which the controller is subject «and which lays down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests»; (c) based on the data subject's explicit consent. Two refinements distinguish it from the Zambian and Francophone rows. Section 38(3) bars any automated processing intended to evaluate certain personal aspects relating to an individual from being based on special categories of personal data — an outright prohibition rather than a consent-gated permission, and stricter on its face than GDPR art. 22(4), which allows special-category automated decisions on explicit consent or substantial public interest. And s. 38(5) narrows the safeguard duty to the contract and explicit-consent limbs at s. 38(2)(a) and (c), leaving the s. 38(2)(b) legal-authorisation route to be policed by the safeguards the authorising law itself must lay down. Mauritius also has the fullest explanation limb of the four Malabo parties added in this pass, and it runs in three places. Section 23(1)(g), the information duty at collection, requires the controller to give «the existence of automated decision making, including profiling, and information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject» — proactive, not on request. Section 37(2)(h) repeats the same item inside the right of access, so it is available reactively too. And s. 38(4) adds a specific overlay: where an exception at s. 38(2) is relied on, the s. 23 information «shall include information as to the existence of processing for a decision of the kind referred to in subsection (1) and the envisaged effects of such processing on the data subject». Section 34(2)(a) then makes a data protection impact assessment mandatory before «a systematic and extensive evaluation of personal aspects relating to individuals which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the individual or significantly affect the individual».

In force since 15 January 2018, by proclamation. Section 58(1) provides that the Act «shall come into operation on a date to be fixed by Proclamation» and s. 58(2) allows different dates for different sections; the header of the official Data Protection Office text records «Proclaimed by [Proclamation No. 3 of 2018] w.e.f. 15 January 2018», with no sectional split, so the whole Act including s. 38 has run from that date. The surrounding dates are all distinct and none of them is the operative one: passed by the National Assembly on 8 December 2017, assented by President Bibi Ameenah Firdaus Gurib-Fakim on 22 December 2017, published in the Government Gazette of Mauritius No. 120 of 23 December 2017. The Act is not a first-generation instrument — s. 56 repeals the Data Protection Act 2004, and s. 57 carries transitional provisions, so a Mauritian automated-decision rule of some kind predates 2018; the 2017 rewrite is what put the GDPR-shaped s. 38 in place and that is the date carried here. Mauritius ratified the Malabo Convention on 6 March 2018 and deposited on 14 March 2018 — the earliest deposit of the four parties added in this pass, and eight weeks after its own Act commenced — so from 8 June 2023 both instruments bind. Where they diverge the statute is the operative rule and the treaty runs behind it, because art. 14(5) of the Convention admits no contract, consent or legal-authorisation exception while s. 38(2) admits all three. Mauritius is also the only one of the four whose national law goes further than the Convention in the other direction: art. 16 and art. 17 of the Convention carry no logic item at all, while ss. 23(1)(g), 37(2)(h) and 38(4) carry three overlapping ones. So the Mauritian position is a bar with more exits than the treaty allows, guarded by an explanation duty the treaty never imposed.

Stated maximum penalty — A fine not exceeding 200,000 rupees and imprisonment for a term not exceeding 5 years, under s. 43(1) — and unlike Zambia, the route to it is explicit on the face of the section. Part VII (rights of data subjects, ss. 37-41) contains no penalty of its own, but s. 43(1) is drafted to sweep: «Any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act shall, on conviction, be liable to a fine not exceeding 200,000 rupees and to imprisonment for a term not exceeding 5 years». The words «or who otherwise contravenes this Act» are what carry a s. 38 breach into the penalty; without them the Mauritian position would be the Zambian one. Note the conjunction: the subsection reads «and» rather than «or» between fine and imprisonment, which on a literal reading makes both cumulative on conviction rather than alternative — an unusual drafting result, recorded as it stands rather than softened. Section 43(2) adds that the Court may order forfeiture of any equipment or article used or connected with the offence, and may order or prohibit the doing of any act to stop a continuing contravention. Separately, s. 42 creates a specific unlawful-disclosure offence, with s. 42(5) reaching a person who offers to sell personal data obtained in breach of it and s. 42(6) treating an advertisement indicating that personal data is or may be for sale as an offer to sell. Enforcement short of prosecution runs through the Commissioner: s. 6 investigation of complaints, s. 7 power to require information, s. 8 preservation order and s. 9 enforcement notice, with a right of appeal under s. 51 and the special jurisdiction of the Tribunal under s. 52. Impact tier: all entities.

In force · 15 Jan 2018 checked 14 Sep 2026 Data Protection Act 2017 s. 38 ↗ high confidence

Mexico 1

Mexico Binding

LFT Capítulo IX Bis — algorithmic work-management policy and human review for digital-platform workers

Binds Natural or legal persons that operate or manage digital platforms assigning tasks, services or jobs to workers in Mexico, in their capacity as employer, where the service requires the worker's physical presence (Art. 291-A/291-B); users, consumers or beneficiaries ordering through the app are not employers. Impact tier: enterprise (platform operators), with duties owed to every platform worker.. Chapter IX Bis of the Ley Federal del Trabajo, added by the decree published in the Diario Oficial de la Federación (Edición Vespertina) of 24 December 2024, treats work mediated by a digital platform that requires the worker's physical presence as a subordinate employment relationship (Art. 291-A) and regulates the algorithm that runs it. Art. 291-J requires the rules for assigning tasks, services or jobs through algorithms or analogous mechanisms to be transparent, clear and known to every platform worker, defines an algorithm as a decision-making system that exercises command and supervision over the worker in an automated or analogous way, and requires the platform to produce an 'algorithmic work-management policy' document in plain language covering (I) the consequences of complying or not complying with instructions, including expected waiting, travel and service times; (II) the consequences and impact of third-party ratings; (III) the incentives and penalties used to influence intensity, quality, frequency, timing or pace of work; (IV) any categories whose membership affects task allocation and their general rules; and (V) any other criteria feeding algorithmic decisions, including those affecting access to future tasks, bonuses or sanctions. That policy forms part of the employment contract, has to be known at the start of the relationship and re-accepted on any change, and the algorithm has to be reasonable in its requirements, not endanger the worker's health or integrity, and not operate as a factor of discrimination. Art. 291-P separately requires platforms to provide a channel to review decisions that affect or interrupt a worker's connection or access to the platform, and requires that channel to be run by staff with autonomy and review power — expressly not by algorithms or similar mechanisms; deactivation without a written notice stating the conduct relied on, accompanied by a detailed task, connection-time and rating report, is void.

Commencement is on the face of the decree: Transitorio Primero of the DOF decree of 24 December 2024 provides that it enters into force 180 days after publication, i.e. 22 June 2025. Text read in the Cámara de Diputados reproduction of the DOF Edición Vespertina of 24 December 2024 (LFT_ref49_24dic24.pdf) and cross-checked against the consolidated LFT (Última Reforma DOF 14-05-2026), where Arts. 291-A to 291-Q and Art. 997-B all carry the note 'Artículo adicionado DOF 24-12-2024'. Transitorio Segundo required IMSS/INFONAVIT to publish general rules for an obligatory pilot on social-security enrolment (Art. 291-K V and VI) within 5 days of entry into force; that pilot affects the enrolment duties only, not the Art. 291-J algorithmic-policy or Art. 291-P human-review duties, which apply from 22 June 2025 without a pilot phase. Distinct from mx-lft-lfda, which is the May 2026 performer-voice/image AI reform of the same statute. This is Mexico's peer of the CAC Algorithmic Recommendation Provisions Art. 20 tracked at cn-algo-recommendation. AIL-300 computation check (2026-08-31): 22 June 2025 verified. Transitorio Primero reads verbatim «El presente Decreto entrará en vigor 180 días después de su publicación en el Diario Oficial de la Federación» (Cámara de Diputados reproduction of the DOF Edición Vespertina of 24 December 2024). Mexico has no general civil-code rule on computing statutory terms that could shift this: the Código Civil Federal's counting articles, arts. 1176–1180, sit under the rubric «De la Manera de Contar el Tiempo para la Prescripción» and are confined to prescription — including art. 1180, which defers a term expiring on a feriado, so it is immaterial that 22 June 2025 fell on a Sunday. The governing construction is instead CCF art. 3, which states the default vacatio in the identical grammatical form — «obligan y surten sus efectos tres días después de su publicación en el Periódico Oficial» — a direct offset from the publication date with the day of publication excluded, while art. 4 confirms that a disposition fixing its own commencement governs from that day. 24 December 2024 plus 180 days on that reading is 22 June 2025. Unlike Paraguay's art. 57 the transitorio does not require a term to have elapsed («transcurridos»), so the py-ley7593-art33 correction has no analogue here.

Stated maximum penalty — Art. 997-B LFT (added DOF 24-12-2024), applied by the labour authorities and independent of any sanction under other laws: 1,000 to 25,000 times the Unidad de Medida y Actualización (UMA) for failing to issue the algorithmic work-management policy of Art. 291-J or to notify changes to it; 500 to 25,000 UMA for failing to establish the Art. 291-P review mechanisms; 2,000 to 25,000 UMA for not registering the model contract under Art. 291-G; and 250 to 5,000 UMA for breach of the special employer duties in Art. 291-K. The UMA is set annually by INEGI, so the peso value of each band moves each February.

In force · 22 Jun 2025 checked 15 Sep 2026 LFT Cap. IX Bis (DOF 24-12-2024) ↗ high confidence

Mozambique 1

Mozambique Binding

Malabo Convention art. 14(5) — the automated-decision bar that binds by treaty, in a country with no data-protection law

Binds Anyone processing personal data in Mozambique. The Convention's scope article, art. 9(1), reaches (a) any collection, processing, transmission, storage or use of personal data by a natural person, the State, local communities and public or private corporate bodies; (b) any automated or non-automated processing of data contained in or meant to be part of a file; (c) any processing of data undertaken in the territory of a State Party; and (d) processing relating to public security, defence, research, criminal prosecution or State security, subject to exceptions in other extant laws. Art. 9(2) excludes purely personal or household processing not systematically communicated to third parties, and temporary technical copies made for network transmission. The territorial hook at art. 9(1)(c) is a processing-in-territory test, narrower than the GDPR art. 3 targeting test Cabo Verde adopted in 2021 and narrower than the Democratic Republic of the Congo's art. 184, which reaches processing carried out abroad; a foreign scoring or hiring-assessment operator with no processing activity in Mozambique is not obviously caught. Impact tier: all entities — art. 14(5) carries no employee-count, turnover, sector or high-risk-system threshold, and its «intended to evaluate certain personal aspects» trigger is the classical Directive 95/46/EC art. 15(1) formula that reaches credit scoring, hiring assessment and conduct profiling alike. The practical qualification is enforcement rather than scope. Almost all of the Convention's machinery is routed through a «national protection authority»: art. 10(2) makes processing subject to a declaration before it, art. 10(4) makes genetic, health-research, offence, file-interconnection, national-identifier and biometric processing subject to its prior authorisation, art. 12 gives it audit and sanctioning powers, and art. 14(6)(b) makes it the gate for third-country transfers. Mozambique has not established one. The Autoridade Nacional de Proteção de Dados is to be created by the Proposta de Lei approved by the Council of Ministers on 3 March 2026 and still before the Assembleia da República. Until it exists, the substantive rule at art. 14(5) stands without an administrative enforcer, and the realistic routes are constitutional (art. 71 of the Constitution restricts the use of informatics for recording and processing individually identifiable data) and ordinary civil liability.. Mozambique has no national data-protection statute, and yet a solely-automated-decision prohibition binds there — it arrives by treaty rather than by legislation. Article 14(5) of the African Union Convention on Cyber Security and Personal Data Protection, adopted at Malabo on 27 June 2014, provides that «a person shall not be subject to a decision which produces legal effects concerning him/her or significantly affects him/her to a substantial degree, and which is based solely on automated processing of data intended to evaluate certain personal aspects relating to him/her». Mozambique signed on 29 June 2018, ratified on 2 December 2019 by Resolução n.º 5/2019 of the Assembleia da República, and deposited its instrument with the Chairperson of the African Union Commission on 21 January 2020. Under art. 18 of the Constitution of the Republic of Mozambique, validly approved and ratified international treaties are in force in the Mozambican legal order after official publication and for as long as they bind the State internationally, with the same rank as infra-constitutional acts of the Assembly and the Government — so the Convention is domestic law in Mozambique, not merely an international undertaking. The drafting of art. 14 is the thing to read closely, because the same article speaks in two registers. Paragraph 1 is addressed to governments: «State Parties shall undertake to prohibit any data collection and processing revealing racial, ethnic and regional origin...» — a duty to legislate, discharged only by passing a law. Paragraph 5 is not framed that way at all. It states a rule about what may be done to a person, in the passive voice, addressed to nobody in particular, and it therefore reads as self-executing in a way paragraph 1 does not. That split inside one article is why this row is carried at medium confidence rather than high: the obligation is real and its wording is direct, but no Mozambican court has been shown to apply it and no domestic instrument repeats it. What the Convention conspicuously does not do is explain. The bar has no exceptions — no contract limb, no consent limb, no legal-authorisation limb, unlike art. 15(2) of Directive 95/46/EC from which it descends and unlike every Lusophone and Francophone row on the tracker — so on its face it is the most absolute automated-decision prohibition tracked anywhere. But art. 16, the right to information, lists eight items (a)-(h) — identity, purposes, categories, recipients, removal, access and rectification, retention period, proposed transfers — and none of them is an automated-decision or logic item. Art. 17, the right of access, lists four items and carries neither. Art. 18 gives a right to object on legitimate grounds; art. 19 gives rectification, blocking and erasure. There is no right to obtain human intervention, no right to contest the decision, and no logic disclosure anywhere in the Convention. Mozambique is therefore the Angola shape reached by a different road: the machine decision is forbidden and never has to be explained. Impact tier: all entities.

Force since 8 June 2023, and the date is computed from the instrument rather than taken from a summary. Art. 36 (Entry into Force) provides that the Convention «shall enter into force thirty (30) days after the date of the receipt by the Chairperson of the Commission of the African Union of the fifteenth (15th) instrument of ratification». There is no separate per-State entry-into-force clause, so the Convention entered into force on the same day for every State that had already deposited, Mozambique included. On the African Union's own status list (dated 8 July 2024, the depositary's record), the deposits in chronological order are Senegal 16/08/2016, Mauritius 14/03/2018, Guinea 16/10/2018, Namibia 01/02/2019, Ghana 03/06/2019, Rwanda 21/11/2019, Mozambique 21/01/2020, Angola 11/05/2020, Congo 23/10/2020, Zambia 24/03/2021, Togo 19/10/2021, Cape Verde 05/02/2022, Niger 16/03/2022, Côte d'Ivoire 03/04/2023, Mauritania 09/05/2023 and São Tomé & Príncipe 15/02/2024. Mauritania is the fifteenth; thirty days after 9 May 2023 is 8 June 2023, which is the date carried here. Mozambique's own dates on that list are signature 29/06/2018, ratification 02/12/2019 and deposit 21/01/2020 — all three earlier than entry into force, which is why the treaty's date governs and not the deposit. The ratifying instrument is Resolução n.º 5/2019 of the Assembleia da República, whose subject the Imprensa Nacional de Moçambique — the state printer that publishes the Boletim da República — records verbatim in its catalogue as ratifying the African Union Convention on Cybersecurity and Personal Data Protection adopted at the 23rd Ordinary Session in Malabo on 27 June 2014. Secondary Mozambican legal commentary dates that Resolução to 20 June 2019 and places it in Boletim da República I Série n.º 119; the Imprensa Nacional catalogue page itself interleaves citations across adjacent items and attributes a 2023 Boletim reference to this 2019 Resolução, so the gazette page number is not asserted here and the Resolução's own text was not read. That gap does not touch the date carried, which comes from art. 36 and the depositary's list, nor the substance, which comes from the Convention text. Confidence medium, and the reason is domestication rather than dating: art. 8(1) frames the Convention's personal-data chapter as a commitment by each State Party «to establishing a legal framework», which is an argument that the chapter as a whole is programmatic, while art. 14(5) is drafted as a directly-worded rule and art. 18 of the Constitution receives ratified treaties into the domestic order with statutory rank. No national implementing law exists, no supervisory authority exists, and no penalty attaches. What Mozambique does have is not a substitute. Lei n.º 3/2017, de 9 de Janeiro (Lei de Transacções Electrónicas) carries a personal-data chapter at arts. 63-65 — accuracy and purpose limitation, notice on indirect collection, security, access, reasoned refusal and objection at art. 63(6), a bar on cross-institution sharing at art. 64, and a designated responsible individual at art. 65 — and none of it touches automated decisions or profiling; the words «perfil» and «perfis» do not occur in the Law, and every occurrence of «automatizado» is the UNCITRAL automated-message-system vocabulary of arts. 35, 37 and 40 about contract formation, input errors and automated calling systems, not about decisions taken on people. INTIC, the national ICT institute, publishes the same enumeration of the country's current data-protection framework — Constitution art. 71, Lei 3/2017 arts. 63-65, Decreto n.º 67/2017 on e-government interoperability, and the regulation on intermediate electronic service providers — and none of those instruments regulates automated decision-making. Watch item: the Proposta de Lei establishing the Regime Jurídico de Proteção de Dados Pessoais was approved by the Council of Ministers at its 6th ordinary session on 3 March 2026 and sent to the Assembleia da República; it creates the ANPD and, if gazetted, will supersede this row's basis with a domestic one. Two further Mozambican laws were published in the Boletim da República on 1 July 2026 and take effect on 29 September 2026 — Lei n.º 13/2026 on cybersecurity and Lei n.º 14/2026 on cybercrime — neither of which has been read in full here and neither of which is claimed to carry an automated-decision or AI obligation. Coverage symmetry: art. 14(5) binds all sixteen States that have deposited, and eleven of them already carry a national row on the tracker (Senegal, Guinea, Ghana, Rwanda, Angola, Congo-Brazzaville, Togo, Cabo Verde, Niger, Côte d'Ivoire, São Tomé e Príncipe), where the national statute is the operative rule and this treaty is background. The four remaining parties — Mauritius, Namibia, Zambia and Mauritania — are not yet tracked and are recorded as a follow-up coverage gap; Namibia in particular has no national data-protection statute and is expected to be the same shape as this row. Guinea-Bissau is a closed negative on the same sweep: it signed the Convention on 31 January 2015 but has never ratified it, has no data-protection law and no data-protection authority, and the legislation index of ARN, its national regulator, lists only the 2013 telecommunications decrees.

Stated maximum penalty — None stated, and that is the honest answer rather than an unresearched one. The Malabo Convention attaches no fine, no imprisonment and no administrative sanction to art. 14(5). Its sanctioning provisions run the other way: art. 12(2)(h) empowers the national protection authority to impose administrative and monetary sanctions on data controllers, but leaves the amounts to national law, and Mozambique has neither designated an authority nor set amounts. The Convention's own penal content sits in Chapter III on cybercrime — offences against computer systems and computerised data — and does not reach the automated-decision rule. Nor does domestic Mozambican law supply a figure: Lei n.º 3/2017's Chapter X on inspection and contraventions attaches to that Law's own duties, not to the Convention's, and art. 14(5) has no counterpart in it. The practical consequence for a deployer is that art. 14(5) is a rule of conduct without a tariff: the exposure is a civil claim, a constitutional challenge under art. 71 of the Constitution, or the retrospective risk that the pending Proposta de Lei, once enacted, gives the new Autoridade Nacional de Proteção de Dados both a domestic prohibition and a penalty band to apply. This entry deliberately records no monetary range rather than importing one from a peer jurisdiction.

In force · 8 Jun 2023 checked 20 Sep 2026 Malabo Convention art. 14(5) ↗ medium confidence

Namibia 1

Namibia Binding

Malabo Convention art. 14(5) — the second country where the automated-decision bar arrives only by treaty

Binds Anyone processing personal data in Namibia, on the Convention's own scope article. Art. 9(1) reaches (a) any collection, processing, transmission, storage or use of personal data by a natural person, the State, local communities and public or private corporate bodies; (b) any automated or non-automated processing of data contained in or meant to be part of a file; and (c) processing carried out in the territory of a State Party or by a controller using means situated on that territory. There is no size, sector or turnover threshold — enterprise, SME and public body alike — and no national supervisory authority stands between the rule and the party it binds, because Namibia has not established one. Hiring, credit scoring and insurance underwriting all sit inside the wording: the bar catches any decision producing legal effects or significantly affecting a person to a substantial degree where it rests solely on automated processing «intended to evaluate certain personal aspects». Two Namibian instruments were checked and neither supplies a competing rule. Article 13(1) of the Constitution gives a right against interference with the privacy of homes, correspondence or communications save as in accordance with law and as necessary in a democratic society — a privacy right, not a data-processing regime, with no automated-decision content. And the Data Protection Bill, drafted in successive versions since 2013 and most recently circulated as the Data Protection Bill 2023, does contain a solely-automated-decision provision with consent and contract exceptions and a human-intervention safeguard — but it has not been enacted. The Ministry of Information and Communication Technology indicated in August 2025 that the Bill was in its final stages and would be tabled between September and October 2025; as at this check no enactment has been traced, and until it is gazetted the Convention is the only automated-decision rule in force in Namibia. When the Bill does pass, art. 144's «unless otherwise provided by ... Act of Parliament» means this row must be superseded rather than duplicated.. Namibia has no data-protection statute in force, and an automated-decision prohibition binds there anyway. Article 14(5) of the African Union Convention on Cyber Security and Personal Data Protection, adopted at Malabo on 27 June 2014, provides that «a person shall not be subject to a decision which produces legal effects concerning him/her or significantly affects him/her to a substantial degree, and which is based solely on automated processing of data intended to evaluate certain personal aspects relating to him/her». Namibia never signed the Convention: on the African Union's own status list its signature column is empty, and it acceded on 25 January 2019, depositing its instrument with the Chairperson of the African Union Commission on 1 February 2019. Reception into domestic law is more direct here than in Mozambique. Article 144 of the Constitution of the Republic of Namibia, in Chapter 21, provides that «unless otherwise provided by this Constitution or Act of Parliament, the general rules of public international law and international agreements binding upon Namibia under this Constitution shall form part of the law of Namibia» — automatic incorporation, with no publication precondition of the kind Mozambique's art. 18 imposes, and Namibia is conventionally described as one of the more thoroughly monist constitutions on the continent for exactly this clause. The qualification to read carefully is «under this Constitution»: art. 63(2)(e) gives the National Assembly the power and function «to agree to the ratification of or accession to international agreements which have been negotiated and signed in terms of Article 32(3)(e)», so incorporation runs through the National Assembly's agreement to accession, not through the executive act alone. The other qualification is the opening words — «unless otherwise provided by this Constitution or Act of Parliament» — which means a future Namibian Data Protection Act could displace art. 14(5) rather than merely supplement it — though as at 11 September 2026 no such bill has been introduced in either House, on the Parliament of Namibia Bill Register itself. As in Mozambique, the Convention forbids without ever explaining: art. 16 lists eight information items (a) to (h) and art. 17 four access items, and none of them is an automated-decision or logic item; art. 18 gives objection on legitimate grounds and art. 19 rectification, blocking and erasure. There is no right to human intervention and no right to contest, and no exception of any kind — no contract limb, no consent limb, no legal-authorisation limb.

Force since 8 June 2023, on the Convention's own entry-into-force clause rather than on anything Namibian. Art. 36 provides that the Convention «shall enter into force thirty (30) days after the date of the receipt by the Chairperson of the Commission of the African Union of the fifteenth (15th) instrument of ratification», and there is no separate per-State entry-into-force clause, so a party that deposited before the fifteenth is bound from the collective date and not from its own deposit. On the African Union's status list of 8 July 2024 the fifteenth deposit is Mauritania's, on 9 May 2023; thirty days later is 8 June 2023. Namibia's accession on 25 January 2019 and deposit on 1 February 2019 both precede that comfortably — Namibia is the sixth deposit in date order — so the treaty's own date governs. The same list records 21 signatures, 16 ratifications and 16 deposits out of 55 African Union member states. Confidence is medium, and the reason is domestication rather than dating, exactly as for the Mozambique row this one is modelled on. Article 14 speaks in two registers within a single article: para. 1 is addressed to governments — «State Parties shall undertake to prohibit any data collection and processing revealing racial, ethnic and regional origin...» — a duty to legislate discharged only by passing a law, and art. 8(1) frames the whole personal-data chapter the same programmatic way, as a commitment «to establishing a legal framework». Para. 5 is not drafted that way at all: it states, in the passive and addressed to nobody in particular, a rule about what may be done to a person, and so reads as self-executing where its own para. 1 does not. No Namibian court has been shown to apply it, no domestic instrument repeats it, and no supervisory authority exists to enforce it. What is stronger here than in Mozambique is the reception clause itself: art. 144 incorporates without requiring publication, where Mozambique's art. 18 conditions entry into the domestic order on official publication. What is weaker is that art. 144 is expressly subject to being overridden by an Act of Parliament — but no such Act is before Parliament. Verified 11 September 2026 against the Parliament of Namibia's own Bill Register (https://laws.parliament.na/Bill-register), which lists every bill from 2019 to B. 1 - 2026 at every stage from first reading to gazette: there is no data-protection bill on it. The register's search endpoint returns zero rows for «Data», «Protection», «Privacy» and «Artificial», and the endpoint was validated first on controls that do match («Marriage» returns the Divorce (Dissolution of Marriage) Bill as well as the Marriage Bill, so it is a substring search and the empty results are real, not a broken query). A Namibian data-protection bill has been in ministerial preparation for several years, but it has not been introduced in either House, so the displacement risk in art. 144 is latent and not imminent, and art. 14(5) remains the operative rule.

Stated maximum penalty — None stated. The Malabo Convention attaches no fine, no imprisonment and no administrative sanction to art. 14(5). Its sanctioning provisions run in the other direction: art. 12(2)(h) empowers the national protection authority to impose administrative and monetary sanctions on data controllers, leaving the amounts to national law, and Namibia has neither established that authority nor legislated any amounts. No monetary range is recorded here rather than one imported from a peer jurisdiction. A Namibian data subject subjected to a solely automated decision therefore has a rule in force and no statutory remedy attached to it; the available routes are constitutional — art. 13 privacy, art. 18 administrative justice, and art. 25 enforcement of fundamental rights before the courts — and none of them is a data-protection penalty. This will change on enactment of the Data Protection Bill, which carries its own enforcement machinery; until then the entry is deliberately silent on quantum. Impact tier: all entities.

In force · 8 Jun 2023 checked 20 Sep 2026 Malabo Convention art. 14(5) ↗ medium confidence

Niger 1

Niger Binding

Loi 2022-59 art. 52 — automated individual decisions: a two-limb bar, a right to know and contest the reasoning, and an express artificial-intelligence disclosure duty at collection

Binds Responsables du traitement and sous-traitants within the scope of arts. 3 and 4. Art. 3 subjects to the Law any collection, processing, transmission, storage and use of personal data by legal persons of public or private law and by natural persons; any processing, automated or not, of personal data contained in or intended to form part of a file; and any processing concerning public security, defence, investigation and prosecution of criminal offences or State security, subject to derogations defined by the Law or other legislation in force. Art. 4 applies the Law to processing implemented by a controller or processor established on national territory and in any place where national law applies. Prior formalities are a standing precondition: art. 31 requires prior authorisation from the Haute Autorité à la Protection des Données à caractère Personnel for, among others, any processing permitting profiling or behavioural analysis, biometric processing, unique-identifier processing, interconnection of files, and transfers to third countries, and art. 79 requires every private-law legal person acting as a controller to appoint an internal data protection correspondent, with public-sector controllers appointing a point focal in that role. The first limb of art. 52 binds the courts themselves; the second binds every administrative and private decision-maker; the third and fourth paragraphs bind any controller whose results are relied on against a person, and the fourth bites at the moment of collection wherever the processing falls within artificial intelligence. Impact tier: all entities.. Article 52 of Loi n° 2022-59 du 16 décembre 2022 relative à la protection des données à caractère personnel, headed "Décision individuelle basée sur le traitement automatisé", is Niger's operative automated-decision rule and the richest of the Directive-family provisions tracked in Africa. It has five paragraphs. The first bars any judicial decision involving an appraisal of the conduct of a natural person from having as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality. The second bars any administrative or private decision involving an appraisal of human conduct from having as its sole foundation an automated processing of personal data giving a definition of the profile or the personality of the person concerned. The third creates a free-standing right: every person has the right to know and to contest the information and the reasoning used in processing, automated or not, whose results are relied on against them. The fourth is the artificial-intelligence clause, which Niger shares only with art. 19 of Burkina Faso's Loi n° 001-2021/AN and with no other row on the tracker — where that processing falls within artificial intelligence, the criteria and the nature of the personal data on which the processing is founded must be indicated to the person from the point of collection. The fifth supplies the exceptions: an automated individual decision is nevertheless admitted where it is founded on the explicit consent of the person concerned, necessary to the conclusion or performance of a contract between the person concerned and a controller, or authorised by a legislative or regulatory provision. Unlike Morocco, Algeria and Côte d'Ivoire, Niger defines profiling: art. 1 defines it as any automated processing of personal data with a view to evaluating certain personal aspects relating to a natural person, in particular to analyse or predict elements concerning work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Art. 31 separately subjects any processing permitting profiling or behavioural analysis to prior authorisation by the HAPDP. The Law grants no right to obtain human intervention or a fresh non-automated decision.

Supersession: art. 112 of Loi n° 2022-59 abrogates all prior contrary provisions and names in particular Loi n° 2017-28 du 3 mai 2017 relative à la protection des données à caractère personnel as modified by Loi n° 2019-71 du 24 décembre 2019. Loi 2017-28 is therefore no longer the operative Nigerien instrument and is not tracked. Art. 112 combines abrogation and publication in a single article — the Law "est publiée au Journal Officiel de la République du Niger et exécutée comme loi de l'Etat" — and there is no commencement article and no deferral of art. 52. The date recorded here is the date of promulgation printed on the face of the enacted text: "Fait à Niamey, le 16 décembre 2022", signed by the President of the Republic Mohamed Bazoum and countersigned by the Prime Minister Ouhoumoudou Mahamadou, with an ampliation by the Deputy Secretary-General of the Government. Confidence is medium and the reason is narrower than for Morocco, Algeria and Côte d'Ivoire, where the general publication-to-force rule was the only unverified link: here the date of the Journal officiel de la République du Niger that carries the Law could not be established at all, because no Nigerien official-gazette host resolved this run — sgg.gouv.ne, www.sgg.gouv.ne, journal-officiel.ne and assemblee.ne all fail to resolve — so the entry uses the promulgation date, and the true entry into force can only be that date or later. Art. 111, replaced by Ordonnance n° 2024-16 du 26 avril 2024, is transitional and not a deferral of art. 52: already-created processing operations carried out for the State, a public establishment, a local authority or a private-law body managing a public service are notified to the HAPDP, and from the date of entry into force all processing must meet the Law's prescriptions on pain of its sanctions. The text was read twice over: article by article in the enacted, signed forty-six-page copy of Loi n° 2022-59 published by the HAPDP, in which art. 52 was read directly on p. 27, and against the HAPDP's own April 2026 consolidated version, which integrates Loi n° 2023-31 du 4 juillet 2023, Ordonnance n° 2024-16 du 26 avril 2024 and Ordonnance n° 2024-29 du 24 juin 2024 and marks amended articles "(nouveau)". Art. 52 is not so marked and is identical in both, so no amendment has touched it; the consolidation renumbers the enacted art. 112 into arts. 112 and 113. The consolidated document states on its face that it is provided for information only and does not replace the official texts published in the Journal officiel, which is why the enacted copy is cited as the source. Coverage symmetry against the eleven African rows already tracked: art. 52 belongs to the Directive 95/46/EC art. 15 line that reaches West Africa through art. 42 of the ECOWAS Supplementary Act A/SA.1/01/10, which the Law's preamble expressly cites alongside the African Union Convention on Cyber Security and Personal Data Protection. Its first two paragraphs are word-for-word the two limbs of Côte d'Ivoire's art. 25, which makes those two the closest pair in Africa, but Niger then goes considerably further in both directions. It is stronger, because it adds the right to know and contest the information and reasoning relied on — a right Côte d'Ivoire lacks entirely and Morocco has only in the narrower art. 7(c) form — and because it names artificial intelligence and attaches a disclosure duty to it at the point of collection. That artificial-intelligence clause is not unique to Niger: art. 19 of Burkina Faso's Loi n° 001-2021/AN du 30 mars 2021 carries it in materially identical words, and Burkina Faso's Law predates Niger's by twenty months, so Burkina Faso is the source of the drafting and Niger the follower. Burkina Faso goes one step further still, because its art. 31 subjects predictive-artificial-intelligence decision-support processing to prior authorisation, which Niger does not. It is weaker, because Côte d'Ivoire states no exception at all while Niger admits explicit consent, contract and legal authorisation, which is the GDPR art. 22(2) exception set grafted onto a Directive-era bar. The four-way African lineage picture is unchanged: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, ci-loi2013450-art25 and now ne-loi202259-art52; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. Niger deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 16 March 2022, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. Art. 14(5) of the Convention states the same bar as art. 52 and admits no exception of any kind, where art. 52's fifth paragraph admits all three of the classical ones — the explicit consent of the person concerned, necessity for the conclusion or performance of a contract between that person and a controller, and authorisation by a legislative or regulatory provision. Each is a route the Convention does not open. Niger runs stricter than the treaty elsewhere, and the point is worth holding alongside: art. 31 subjects any processing permitting profiling or behavioural analysis to prior authorisation by the HAPDP, an ex ante gate the Convention does not impose, since neither profiling nor automated decision-making appears in the Convention's own prior-authorisation list at art. 10(4). The national statute is carried here as the operative rule, because it is the instrument that has a supervisory authority behind it and a penalty attached to it, and the Convention runs behind it as a stricter parallel rule. This is recorded as a divergence rather than resolved: neither instrument repeals or qualifies the other, Niger has not legislated the Convention into domestic law by a separate instrument, and the domestic reception question — whether art. 14(5) is directly effective in Niger, as arts. 18 and 144 of the Mozambican and Namibian constitutions respectively make it there — has not been separately verified for Niger and is not asserted here. A controller relying on an exception the statute grants therefore stands on solid statutory ground and unresolved treaty ground.

Stated maximum penalty — Niger is the first Directive-family row on the tracker where a penal article does reach part of the automated-decision provision, and the reach is partial. Art. 102 punishes obstructing without legitimate reason the exercise of a right conferred by the Law in the course of a processing of personal data with imprisonment of three months to two years and a fine of 1,000,000 to 20,000,000 francs CFA, or one of those penalties only. The third paragraph of art. 52 confers a right on the person — to know and contest the information and reasoning used — so art. 102 reaches a refusal of that right. The first two paragraphs of art. 52 are prohibitions on the decision-maker rather than rights of the person, and no offence in Chapitre XIV names them: arts. 95 to 104 are confined to unlawful sensitive-data processing (three months to five years and 5,000,000 to 50,000,000), unconsented direct marketing (three months to three years and 1,000,000 to 10,000,000), obstruction of the HAPDP (three months to two years and 1,000,000 to 10,000,000), failure to take security precautions (three months to two years and 1,000,000 to 10,000,000), purpose deviation (three months to five years and 5,000,000 to 50,000,000), unauthorised communication of or access to files (three months to five years and 5,000,000 to 50,000,000), fraudulent, unfair or unlawful collection (three months to five years and 5,000,000 to 50,000,000), unlawful retention beyond the permitted period (three months to two years and 5,000,000 to 50,000,000) and unauthorised divulgation harming honour or privacy (three months to five years and 5,000,000 to 50,000,000, reduced to a fine of 500,000 to 1,000,000 where committed by imprudence or negligence). Art. 105 applies Penal Code arts. 59 to 61 on recidivism, and art. 106 lets the court order confiscation or erasure of the media carrying the data, ban the convicted controller from managing any processing for up to two years, and order publication of extracts in legal-notice journals at the convicted person's expense. The administrative route reaches the whole of art. 52. Art. 92 lets the HAPDP, after an adversarial procedure, issue a warning and a mise en demeure to end the failures within a period it fixes, and, if the controller does not comply, pronounce provisional or definitive withdrawal of the authorisation or a pecuniary sanction. Art. 93 lets it order interruption of the processing, blocking of certain data, or temporary or definitive prohibition of a processing contrary to the Law. Art. 94 fixes the ceiling: the pecuniary sanction is proportionate to the gravity of the failures and the advantages drawn from them and may not exceed 100,000,000 francs CFA, rising on a repeated failure within two years from the date the previous pecuniary sanction became definitive to 200,000,000 francs CFA or, for an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of 500,000,000 francs CFA, and applies without prejudice to penal sanctions. Art. 108 lets any person who claims to be injured in their private life by a processing, or whose complaint to the controller has gone unanswered, complain to the HAPDP; art. 109 makes the HAPDP's sanctions and decisions appealable to the Conseil d'Etat; and art. 110 preserves an effective judicial remedy, including urgent interim relief under astreinte where the infringement is serious and immediate.

In force · 16 Dec 2022 checked 21 Sep 2026 Loi n° 2022-59 art. 52 ↗ medium confidence

Nigeria 1

Nigeria Binding

Nigeria Data Protection Act s. 37 — right against solely-automated decisions, with a duty to provide human intervention on request

Binds Data controllers and data processors within the scope of s. 2(2): those domiciled in, resident in, or operating in Nigeria; any processing of personal data that occurs within Nigeria; and controllers or processors not domiciled, resident or operating in Nigeria that process personal data of a data subject in Nigeria. Section 2(1) applies the Act to processing whether by automated means or not, and s. 3(1) carves out processing carried out solely for personal or household purposes. The s. 37 right binds any controller taking a solely-automated decision with legal or similar significant effect, irrespective of size. A narrower registration and governance tier sits above it: a data controller or data processor “of major importance” — defined in s. 65 as one domiciled, resident or operating in Nigeria that processes personal data of more than such number of data subjects in Nigeria as the Commission may prescribe, or such other class the Commission may designate as processing data of particular value or significance to the economy, society or security of Nigeria — must register with the Commission under s. 44(1) within six months after the commencement of the Act or on becoming one, and must designate a Data Protection Officer under s. 32(1). Impact tier: all entities.. Section 37 of the Nigeria Data Protection Act, 2023 (Act No. 37 of 2023) carries Nigeria's operative automated-decision rule, in Part VI (rights of a data subject). Subsection (1) gives a data subject the right not to be subject to a decision based solely on automated processing of personal data, including profiling, which produces legal or similar significant effects concerning the data subject. Subsection (2) disapplies that right where the decision is necessary for entering into or the performance of a contract between the data subject and a data controller, is authorised by a written law which establishes suitable measures to safeguard the fundamental rights and freedoms and the interests of the data subject, or is authorised by the consent of the data subject. Subsection (3) is the operative duty on the controller: where an exception is relied on, the data controller shall implement suitable measures to safeguard the data subject's fundamental rights, freedoms and interests, including the rights to obtain human intervention on the part of the data controller, to express the data subject's point of view, and to contest the decision. Section 65 defines “automated decision-making” as a decision based solely on automated processing by automated means, without any human involvement. Section 36(3) separately gives a right to object at any time to processing for direct marketing purposes, which includes profiling to the extent that it is related to such direct marketing, and s. 36(4) requires processing for those purposes to stop on objection.

Commencement is stated on the face of the enacted Act: the gazetted text prints “[12th Day of June, 2023]” immediately above the enacting formula, and s. 37 carries no deferred or separately-appointed commencement, so the section has been in force since 12 June 2023. The Act was published by The Federal Government Printer, Lagos as a supplement to the Federal Republic of Nigeria Official Gazette No. 119, Vol. 110 of 1 July 2023, Government Notice No. 82, as Act No. 37, at pages A719 to A758. Section 37 follows the GDPR Art. 22 shape and is the closest of the tracker's three African provisions to it: unlike the South African za-popia-s71, which offers only representations plus disclosure of the underlying logic, Nigeria expressly grants human intervention, the right to express a point of view and the right to contest the decision; unlike the Kenyan ke-dpa-s35 it imposes no affirmative written-notification duty when a solely-automated decision is taken, and confers no express right to demand a fresh non-automated decision. Source access: the Nigeria Data Protection Commission is the statutory supervisory authority established by s. 4 of the Act and ndpc.gov.ng is the only official host that serves the Act text, but the host returns HTTP 403 (nginx, not a challenge page) to every non-browser client from this network, on the apex domain and on every subdomain except the services portal; nass.gov.ng's publications register does not carry the Act, and nigeriagazette.gov.ng does not resolve. The text cited here was therefore read from the Internet Archive's byte-for-byte capture of the NDPC-hosted gazette PDF at the source_url (capture of 31 May 2025, origin Last-Modified 1 March 2024): https://web.archive.org/web/20250531105744/https://ndpc.gov.ng/wp-content/uploads/2024/03/Nigeria_Data_Protection_Act_2023.pdf. No secondary or NGO copy was relied on. Not yet verified: the NDPC General Application and Implementation Directive 2025 (issued 20 March 2025) may add implementation detail on automated decision-making; every archived capture of it replays 503, so it is excluded from this entry and left for a later check.

Stated maximum penalty — Section 48 governs sanctions. After an investigation under s. 46, the Commission may order the controller or processor to remedy the violation, to compensate a data subject who has suffered injury, loss or harm, to account for the profits realised from the violation, or to pay a penalty or remedial fee (s. 48(2)). Under s. 48(3)–(5) that penalty may be up to the “higher maximum amount” for a data controller or data processor of major importance, being the greater of ₦10,000,000 and 2% of its annual gross revenue in the preceding financial year, or the “standard maximum amount” for one not of major importance, being the greater of ₦2,000,000 and 2% of that revenue. Failure to comply with a compliance order made under s. 47 is a separate offence under s. 49, punishable on conviction by a fine of up to the same higher or standard maximum amount, or imprisonment for a term not more than one year, or both. Section 51 gives a data subject who suffers injury, loss or harm a civil action for damages, and s. 50 allows an application to court for judicial review of a Commission order within 30 days.

In force · 12 Jun 2023 checked 22 Aug 2026 NDPA s. 37 (Act No. 37 of 2023) ↗ high confidence

Panama 1

Panama Binding

Ley 81 art. 19 — a Directive 95/46 automated-decision right that fires only on NEGATIVE legal effects, with three exits and no safeguards at all

Binds Responsables del tratamiento de los datos and custodios de la base de datos — controllers and the parties holding custody of the database on the controller's behalf — public or private, for profit or not. Art. 5 fixes the reach: databases located in the territory of the Republic of Panama that store personal data of nationals or foreigners, and databases whose controller is domiciled in the country, are subject to the Law and its regulation. There is no GDPR art. 3(2) targeting limb: a purely foreign controller with no Panamanian database and no Panamanian domicile is outside the Law even when it decides about people in Panama. Databases of subjects governed by leyes especiales are excluded, but only where those special laws or their implementing rules set the minimum technical standards needed for correct protection of personal data conforming to this Law; and art. 36 makes this Law's sanctions apply supletoriamente where a sector regulator's own statute does not expressly define the penalty for the breach complained of.. Art. 19 of Ley 81 de 26 de marzo de 2019, «Sobre Protección de Datos Personales» (Gaceta Oficial Digital Nº 28743-A of 29 March 2019), gives the data subject «derecho a no ser sujeto de una decisión basada únicamente en el tratamiento automatizado de sus datos personales, que produzca efectos jurídicos negativos o le produzca un detrimento a un derecho, cuyo objeto sea evaluar determinados aspectos de su personalidad, estado de salud, rendimiento laboral, crédito, fiabilidad, conducta, características o personalidad, entre otros». The shape is Directive 95/46 art. 15(1) rather than GDPR art. 22: the trigger is cumulative and its third limb is an OBJECT requirement — the decision must be one whose purpose is to evaluate personal aspects — and the illustrative list (work performance, creditworthiness, reliability, conduct) is the Directive's list carried across almost word for word. Two things are done to the effects threshold that no other rule in the atlas does together. First, «efectos jurídicos» is qualified as «NEGATIVOS»: a legal effect that helps the subject does not engage the right at all, where GDPR art. 22 and the whole Directive family are indifferent to whether the effect is adverse. Second, the alternative limb is not «significantly affects» but «le produzca un detrimento a un derecho» — detriment to a right — which trades an open-ended severity test for a narrower requirement that some right be impaired. The exits are three: consent of the subject; necessity to conclude or perform a contract or legal relationship between the controller and the subject; and authorisation by special laws or the norms developing them. Panama therefore adds a consent exit to the Directive's two — and then attaches NOTHING to any of them. There is no right to obtain human intervention, no right to express a point of view, no right to contest the decision, and no bar on running such decisions on sensitive data. Art. 19 is one sentence of prohibition followed by three ways out, and it is the barest automated-decision provision in the atlas: even Montenegro's pre-GDPR art. 15a folded the chance to express a view into its contract exit. The word «perfil» never appears in Ley 81. Profiling enters Panamanian law only through the reglamento, Decreto Ejecutivo Nº 285 de 28 de mayo de 2021 (Gaceta Oficial Digital Nº 29296-A of the same date), whose art. 2(7) defines «elaboración de perfiles» in the GDPR art. 4(4) terms and whose transparency articles then speak of «la existencia de decisiones automatizadas, incluida la elaboración de perfiles, a que se refiere el artículo 19 de la Ley 81 de 2019» — attributing to art. 19 a concept the article does not contain. The same reglamento supplies the disclosure limb the statute omits: on collection and on a subject access request the controller must give «información significativa sobre la lógica aplicada, así como la importancia y las consecuencias previstas de dicho tratamiento», which is GDPR art. 13(2)(f)/15(1)(h) language grafted on by executive decree rather than enacted by the legislature. Art. 21 of the Law voids any act or agreement between parties that limits the subject's rights — but it lists «acceso, revocación, cancelación, oposición o bloqueo» and does not name art. 19, so the anti-waiver clause does not on its face reach the automated-decision right, which the consent exit already lets a controller contract around.

In force since 29 March 2021. Art. 47 is the whole vigencia clause — «Esta Ley comenzará a regir a los dos años de su promulgación» — and it names no date, so the date has to be computed. The Law is dated 26 March 2019 and was published in Gaceta Oficial Digital Nº 28743-A of 29 March 2019, which on the Panamanian understanding of promulgación (publication in the Gaceta Oficial) puts entry into force two years later, on 29 March 2021. That reading is confirmed by the Executive itself in a primary source: the considerandos of the reglamento, Decreto Ejecutivo Nº 285 de 28 de mayo de 2021, record that Ley 81 «estableció, además, una prórroga para su entrada en vigor, efectiva a partir del 29 de marzo de 2021». Taking the date of the Law instead of the date of the gazette would give 26 March 2021; the Executive's own published reading is preferred over that computation and no conflict between two primary sources arises. The reglamento entered into force on its own promulgation (its art. 65), i.e. 28 May 2021. The Law was Proyecto 665 de 2018, approved in third debate on 24 October 2018. No amendment to Ley 81 has been located on the gazette record.

Stated maximum penalty — B/.1,000 to B/.10,000 — the whole range, with no turnover alternative and no separate corporate ceiling. Art. 38 grades infractions as leves, graves or muy graves; art. 40(2) makes it a GRAVE infraction to «infringir los principios y garantías establecidos en la presente Ley o en su reglamentación», and that catch-all is the route by which a breach of art. 19 is fineable, since neither art. 40 nor art. 41 names art. 19 and the ARCO-specific item at art. 40(4) reaches only access, rectification, cancellation and objection. Art. 43 attaches the consequences: a falta leve draws only a citación before the Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI), a falta grave draws «multas según su proporcionalidad», and a falta muy grave draws closure of the database registers or temporary or permanent suspension and disqualification of the processing activity, in each case without prejudice to the corresponding fine. The only figures in the statute are in art. 36, which directs ANTAI to fix the amounts by gravity «desde mil balboas (B/.1 000.00) hasta diez mil balboas (B/.10 000.00)». The balboa is at par with the US dollar, so the maximum exposure for the gravest breach of Panamanian data-protection law is about USD 10,000 — the lowest absolute ceiling of any rule in the atlas, and the reglamento does not raise it: Decreto Ejecutivo Nº 285 art. 62 supplies only graduation criteria (intent, recidivism, harm, duration, benefit obtained, turnover affected) within that band. Limitation runs at one year for leves, three for graves and five for muy graves (art. 63 of the reglamento). Art. 37 preserves a separate civil action before the courts for patrimonial and moral damage.

In force · 29 Mar 2021 checked 14 Sep 2026 Ley 81 art. 19 ↗ high confidence

Philippines 1

Philippines Binding

Data Privacy Act IRR Secs. 34 and 48 — automated decision-making: logic disclosure, NPC notification and the consent bar

Binds Personal information controllers and personal information processors within the scope of the Act and Rule II of the IRR, including entities not established in the Philippines that use equipment located in the country or maintain an office, branch or agency here. The Section 48 notification duty binds any controller whose automated processing becomes the sole basis for a decision significantly affecting a data subject; the Section 34 transparency and objection rights bind all controllers. Impact tier: all entities.. The Implementing Rules and Regulations of Republic Act No. 10173 (Data Privacy Act of 2012) carry the Philippines' operative automated-decision regime. Section 34 gives the data subject a right to be informed whether personal data are processed 'including the existence of automated decision-making and profiling', and requires the controller to furnish, before entry of the data into the processing system or at the next practical opportunity, the methods used for automated access together with 'meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject' (Sec. 34(a)(f)); the same section carries a right to object to processing 'including processing for direct marketing, automated processing or profiling', and a right of access to 'information on automated processes where the data will, or is likely to, be made as the sole basis for any decision that significantly affects or will affect the data subject'. Section 48 adds a filing duty and a substantive bar: a controller carrying out wholly or partly automated processing operations must notify the National Privacy Commission once the automated processing becomes the sole basis for making decisions about a data subject and the decision would significantly affect that subject, submitting the purpose of processing, the categories of data and data subjects, the consent forms or manner of obtaining consent, the recipients, the retention period, the 'methods and logic utilized for automated processing', the decisions that would be made on the basis of the processed data or that would significantly affect the rights and freedoms of the data subject, and the name and contact details of the data protection officer; and 'no decision with legal effects concerning a data subject shall be made solely on the basis of automated processing without the consent of the data subject'. Section 16(c)(6) of the Act itself carries the statutory root of the access right.

Commencement is computed from the face of the instrument. IRR Section 72 provides that the Rules take effect fifteen days after publication in the Official Gazette; the Rules were promulgated by the National Privacy Commission on 24 August 2016 and published in the Official Gazette on 25 August 2016, which places entry into force on 9 September 2016. IRR Section 67 gave controllers one year from that date to register their data processing systems or automated processing operations subject to notification, so that window closed on 9 September 2017 and the Section 48 duty is now fully exigible. The parent statute, Republic Act No. 10173, was approved on 15 August 2012 and took effect fifteen days after newspaper publication under its Section 45. Note the division of labour between statute and rules: RA 10173 Sec. 16(c)(6) grants only access to information on automated processes used as the sole basis for a significant decision, while the consent bar on solely-automated decisions with legal effects and the meaningful-information-about-the-logic requirement appear only in the IRR, at Secs. 48 and 34 respectively. Asian peer of cn-pipl-art24, kr-pipa-art37-2-adm and id-uu27-adm: like Indonesia and Korea it is already in force, and like Korea it reaches the logic of the decision, but unlike Korea it grants no express right to human re-processing — the Philippine mechanism is a consent gate plus a regulator filing rather than a post-hoc review right. Text read at the National Privacy Commission's own publication of the IRR and cross-checked against the Supreme Court E-Library copy (elibrary.judiciary.gov.ph/thebookshelf/showdocs/2/70735), which carries the identical Secs. 34, 48, 67 and 72. officialgazette.gov.ph returns HTTP 403 to non-browser clients, so the NPC copy is cited. AIL-300 computation check (2026-08-31): 9 September 2016 verified against a second primary source. IRR Section 72 sets the term at fifteen days after publication in the Official Gazette, and publication was on 25 August 2016. The Philippines has a genuine general rule of statutory construction on point, in the Preliminary Title of the Civil Code (Republic Act No. 386) on the Effect and Application of Laws: the final paragraph of art. 13 provides that «In computing a period, the first day shall be excluded, and the last day included». Excluding 25 August puts day 1 at 26 August and day 15 at 9 September 2016, the date carried — the last day is included, so the Rules take effect on it rather than the day after, and the Paraguayan «luego de transcurridos» problem has no analogue here. Section 31 of the Administrative Code of 1987 superseded art. 13's definition of a year as 365 days (CIR v. Primetown Property Group, G.R. No. 162155), but it left the first-day-excluded rule untouched and in any event this is a day-count. The same computation applied to the parent statute is consistent: RA 10173 was approved 15 August 2012 with the identical fifteen-day formula in its Section 45.

Stated maximum penalty — IRR Section 65 subjects violations of the Act, the Rules and Commission issuances to compliance and enforcement orders, cease and desist orders, a temporary or permanent ban on processing, or fines under a schedule published by the Commission. That schedule is NPC Circular No. 2022-01 (Guidelines on Administrative Fines, 8 August 2022): each infraction of a data subject right under Sec. 16 of the DPA affecting more than 1,000 data subjects is a grave infraction carrying 0.5 per cent to 3 per cent of the annual gross income of the preceding year, and 1,000 or fewer affected subjects is a major infraction carrying 0.25 per cent to 2 per cent, with total administrative fines capped at PHP 5,000,000. Criminal liability under Chapter VIII of the Act runs separately for the enumerated offences, for example unauthorised processing of personal information at one to three years' imprisonment and a fine of PHP 500,000 to PHP 2,000,000 under Sec. 25(a).

In force · 9 Sep 2016 checked 1 Sep 2026 DPA of 2012 IRR Secs. 34, 48 (RA 10173) ↗ high confidence

Serbia 2

Serbia Binding

Personal Data Law art. 38 — GDPR art. 22 transposed, applicable since 22 August 2019, penalty in fixed dinars

Binds Controllers and processors, on the GDPR's own reach, with no size, sector or turnover threshold and no public/private split. Art. 3(1) applies the Law to processing wholly or partly by automated means and to non-automated processing of personal data forming part of, or intended for, a filing system. Art. 3(3) catches a controller or processor with its seat, domicile or residence in the Republic of Serbia, within activities carried out on Serbian territory, regardless of where the processing operation itself happens. Art. 3(4) reaches a controller or processor with no seat, domicile or residence in Serbia where the processing concerns a data subject domiciled or resident in Serbia and the operations relate to (1) the offering of goods or services to that person on Serbian territory, whether or not payment is required, or (2) monitoring the person's activities where those activities are carried out on Serbian territory — so a foreign scoring, screening or pricing service that reaches Serbian residents is inside art. 38. Art. 3(2) excludes processing by a natural person for personal or household purposes. Hiring, credit scoring and insurance pricing are the paradigm cases: an automated sift producing a hiring outcome significantly affects the candidate's position within the meaning of art. 38(1). A decision with a human materially in the loop falls outside art. 38(1), which reaches only decisions taken «isključivo» on the basis of automated processing, and the Law supplies no gloss on what degree of human involvement defeats that. Competent authorities processing for the special purposes are outside this article by art. 38(5) and inside art. 39.. Art. 38 of the Zakon o zaštiti podataka o ličnosti («Službeni glasnik RS» br. 87/2018) is Serbia's general automated-decision rule and it tracks GDPR art. 22 clause for clause. Art. 38(1): «Lice na koje se podaci odnose ima pravo da se na njega ne primenjuje odluka doneta isključivo na osnovu automatizovane obrade, uključujući i profilisanje, ako se tom odlukom proizvode pravne posledice po to lice ili ta odluka značajno utiče na njegov položaj.» The trigger is a decision resting solely on automated processing, profiling included, that either produces legal consequences for the person or significantly affects their position — the second limb is drafted as «značajno utiče na njegov položaj» rather than the GDPR's «similarly significantly affects», dropping the comparison to the legal-effects limb and leaving the threshold to be read on its own terms. Art. 38(2) supplies the same three exits as GDPR art. 22(2): the decision is necessary for concluding or performing a contract between the data subject and the controller; it is based on a law that itself prescribes appropriate measures protecting the person's rights, freedoms and legitimate interests; or it rests on the person's explicit consent. Art. 38(3) then requires, in the contract and consent cases, at minimum three safeguards: the right to secure the participation of a natural person under the controller's control in the taking of the decision, the right of the data subject to express their point of view on the decision, and the right to contest the decision before the controller's authorised person. Art. 38(4) bars such decisions from resting on the special categories of art. 17(1) unless art. 17(2)(1) or (5) applies — explicit consent, or data manifestly made public by the person — and the safeguards are in place. Art. 38(5) carves the whole article out for processing by competent authorities for the special purposes defined in art. 6(3); those bodies answer to art. 39 instead, and the two articles between them leave no gap. Art. 40(1) allows arts. 36 to 39 to be restricted by law for national security, defence, public security, the prevention, investigation and detection of criminal offences and the other listed grounds, provided the restriction does not touch the essence of the right and is necessary and proportionate in a democratic society.

In force and applicable, and the applicability date is derived rather than stated as a calendar date. Art. 102 reads «Ovaj zakon stupa na snagu osmog dana od dana objavljivanja u ‘Službenom glasniku Republike Srbije’, a primenjuje se po isteku devet meseci od dana stupanja zakona na snagu, osim odredbe člana 98. ovog zakona koja se primenjuje od dana njegovog stupanja na snagu.» Publication was on 13 November 2018, so the eighth day is 21 November 2018 and the nine months expire on 21 August 2019. Because art. 102 starts application «po isteku» — upon the expiry of — that period, the first day of application is 22 August 2019, and the official register masthead on the promulgated text agrees: «Osnovni tekst na snazi od 21/11/2018, u primeni od 22/08/2019». A large body of Serbian practitioner commentary instead names 21 August 2019; the one-day divergence is a reading of «po isteku» and not a conflict between two primary sources, and 22 August 2019 is the date the enacted text supports. Art. 101 repealed the 2008 Law («Sl. glasnik RS» br. 97/08, 104/09 – dr. zakon, 68/12 – US, 107/12) from the same day of first application, so the art. 22 rule of the old Law is superseded rather than supplemented; art. 100 required all other statutes touching personal data to be aligned by the end of 2020. Supersession check, 26 August 2026: the Law is still cited as «Sl. glasnik RS» br. 87/2018 alone, with no amending gazette number in its masthead, so art. 38 stands as enacted. Serbia has no AI-specific statute in force. A first Law on Artificial Intelligence aligned with the EU AI Act has been announced by the Government for adoption by December 2026; no draft text has been published, so it is not tracked as an obligation here. The text relied on is the promulgated Law as published in «Službeni glasnik RS» br. 87/2018 of 13 November 2018, read end to end from the copy the Ministry of Public Administration and Local Self-Government hosts at https://mduls.gov.rs/wp-content/uploads/Zakon-o-zaštiti-podataka-o-ličnosti.pdf, which carries the Ukaz of promulgation signed by the President and the register masthead «Osnovni tekst na snazi od 21/11/2018, u primeni od 22/08/2019». The Pravno-informacioni sistem ELI cited as the source is the official gazette record but is served by a JavaScript-only portal, so it renders in a browser and not to a fetcher — that is the shell, not rot. Two government-hosted PDFs are traps and were ruled out: minrzs.gov.rs/sites/default/files/2018-11/Zakon o zastiti podataka o licnosti.pdf is the SUPERSEDED 2008 Law (97/08) despite its 2018 upload path, and it decodes only through a shifted-glyph font.

Stated maximum penalty — 50,000 to 2,000,000 dinara for a controller or processor that is a legal person. Art. 95(1)(19) names the breach expressly: a misdemeanour is committed where «se donese odluka koja proizvodi pravne posledice po lice na koje se podaci odnose isključivo na osnovu automatizovane obrade, suprotno čl. 38. i 39. ovog zakona», and it sits in the Law's top band at art. 95(1). Art. 95(4) fines an entrepreneur 20,000 to 500,000 dinara for the same misdemeanour, and art. 95(5) fines a natural person, the responsible person in a legal person, in a state body, in an authority of territorial autonomy or of a local self-government unit, and the responsible person in a representative office or business unit of a foreign legal person, 5,000 to 150,000 dinara. These are fixed-dinar misdemeanour fines set in the Law itself, not GDPR-style turnover percentages, and there is no turnover alternative anywhere in art. 95 — the ceiling for the largest multinational is the same 2,000,000 dinara as for the smallest Serbian company. Supervision and enforcement sit with the Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti; misdemeanour proceedings run before the misdemeanour courts. Impact tier: all entities.

In force · 22 Aug 2019 checked 1 Sep 2026 Personal Data Law art. 38 ↗ high confidence
Serbia Binding

Personal Data Law art. 39 — solely automated decisions banned for police, prosecutors and prisons, plus an exceptionless ban on discriminatory profiling

Binds Competent authorities only, and the Law defines the trigger by purpose rather than by institution. Art. 6(3) defines the «posebne svrhe» as processing by competent authorities for the prevention, investigation and detection of criminal offences, the prosecution of their perpetrators or the execution of criminal sanctions, including the prevention of and protection against threats to public and national security. Art. 1(2) brings that sphere inside this same statute, so Serbia — unlike Moldova, which split the GDPR and LED regimes into two acts — carries both regimes in one Law and divides them by article. The division is clean at the edges: art. 38(5) removes special-purpose processing from art. 38, and art. 7(1) forbids repurposing data collected for the special purposes unless a law provides for it. The same body processing for an ordinary purpose, its own staff records for instance, answers to art. 38 and not to art. 39. Private controllers are outside art. 39 entirely, with one edge: a private body exercising delegated public powers for a special purpose is a «nadležni organ» for these purposes. Art. 40(1) permits arts. 36 to 39 to be restricted by law on national-security, defence, public-security and criminal-justice grounds subject to the essence, necessity and proportionality test.. Art. 39 is the law-enforcement counterpart of art. 38 and, following LED art. 11, it is drafted as a prohibition on the authority rather than as a right the individual must invoke. Art. 39(1): «Zabranjeno je donošenje odluke isključivo na osnovu automatizovane obrade koju vrše nadležni organi u posebne svrhe, uključujući i profilisanje, ako takva odluka može da proizvede štetne pravne posledice po lice na koje se podaci odnose ili značajno utiče na položaj tog lica, osim ako je donošenje te odluke zasnovano na zakonu i ako su tim zakonom propisane odgovarajuće mere zaštite prava i sloboda lica na koje se podaci odnose, a najmanje pravo da se obezbedi učešće fizičkog lica pod kontrolom rukovaoca u donošenju odluke.» Three drafting choices matter. The effects limb is widened by «štetne» — the legal consequences must be harmful — but it also reaches a decision that merely «može» produce them, so the prohibition bites on capacity to harm rather than on realised harm. There is no consent exit and no contract exit: the single way out is a statutory basis that itself prescribes safeguards, and the floor for those safeguards is named in the article — the right to secure the participation of a natural person under the controller's control in the taking of the decision. And unlike art. 38(3), the person is given no right here to express a view or to contest the decision; the enabling statute must supply whatever more it supplies. Art. 39(2) bars such a decision from resting on the special categories of art. 18(1) unless appropriate protective measures are applied. Art. 39(3) is the provision with no analogue in art. 38 and the one most likely to be overlooked: «Zabranjeno je profilisanje koje dovodi do diskriminacije fizičkih lica na osnovu posebnih vrsta podataka o ličnosti iz člana 18. stav 1. ovog zakona.» That is a flat, exceptionless ban on discriminatory profiling on special-category grounds — it is not tied to any decision, to any effects threshold, or to the «isključivo automatizovana» qualifier, so it reaches profiling that merely feeds a human decision, and it admits no statutory override.

In force and applicable since 22 August 2019 on the same art. 102 timetable as art. 38 — entry into force on 21 November 2018, the eighth day after publication in «Sl. glasnik RS» br. 87/2018 of 13 November 2018, and application upon the expiry of nine months from that day. Art. 39 is new law rather than a re-enactment: the repealed 2008 Law had a single automated-decision provision covering both spheres and no prohibition addressed to law-enforcement bodies, and it had nothing resembling the art. 39(3) discriminatory-profiling ban. Supersession check, 26 August 2026: no amending gazette number appears in the Law's masthead, so art. 39 stands as enacted. Note for readers comparing regimes: art. 39(1) is narrower than art. 11 of Directive (EU) 2016/680 in requiring the legal consequences to be harmful, and wider in reaching decisions that merely may produce them; art. 39(3) has no counterpart in art. 38 and no exception clause at all. The text relied on is the promulgated Law as published in «Službeni glasnik RS» br. 87/2018 of 13 November 2018, read end to end from the copy the Ministry of Public Administration and Local Self-Government hosts at https://mduls.gov.rs/wp-content/uploads/Zakon-o-zaštiti-podataka-o-ličnosti.pdf, which carries the Ukaz of promulgation signed by the President and the register masthead «Osnovni tekst na snazi od 21/11/2018, u primeni od 22/08/2019». The Pravno-informacioni sistem ELI cited as the source is the official gazette record but is served by a JavaScript-only portal, so it renders in a browser and not to a fetcher — that is the shell, not rot. Two government-hosted PDFs are traps and were ruled out: minrzs.gov.rs/sites/default/files/2018-11/Zakon o zastiti podataka o licnosti.pdf is the SUPERSEDED 2008 Law (97/08) despite its 2018 upload path, and it decodes only through a shifted-glyph font.

Stated maximum penalty — 50,000 to 2,000,000 dinara for a controller or processor that is a legal person, under the same art. 95(1)(19) that covers art. 38 — the item is drafted against «čl. 38. i 39.» together — with 20,000 to 500,000 dinara for an entrepreneur under art. 95(4) and 5,000 to 150,000 dinara for a natural person or the responsible person in a legal person, a state body, an authority of territorial autonomy or a local self-government unit under art. 95(5). Two limits are worth stating plainly. First, art. 95(1)(19) is written around a decision that «proizvodi pravne posledice» taken solely on automated processing, so it maps onto art. 39(1) but does not obviously reach a standalone breach of the art. 39(3) discriminatory-profiling ban, which involves no decision at all — that prohibition carries no misdemeanour of its own. Second, because art. 95(5) addresses the responsible person, the practical sanction against a state body falls on an individual official. Supervision is the Poverenik's, whose special-purpose powers run under Chapter VII of the Law. Impact tier: public sector.

In force · 22 Aug 2019 checked 1 Sep 2026 Personal Data Law art. 39 ↗ high confidence

Russia 3

Russia Binding

152-FZ art. 16 — a solely automated decision is forbidden unless the person signed a written consent

Binds Every «оператор» — under art. 3(2) any state body, municipal body, legal person or natural person that, alone or jointly with others, organises and (or) carries out the processing of personal data and determines its purposes, composition and the operations performed. There is no size, sector or turnover threshold, so enterprise, SME, sole trader and public body are all covered. Art. 1(1) applies the Law to processing by federal and regional state bodies, other state and municipal bodies, legal persons and natural persons using automation means or without them where the processing corresponds to how it would be done with automation; art. 1(2) carves out processing by a natural person for purely personal and family needs, archival processing, and processing of information constituting a state secret. Art. 2(1) of Federal Law No. 242-FZ localisation duties sit separately and are not part of art. 16.. Russia's automated-decision rule predates the GDPR and is drafted as a flat prohibition with a very narrow way out. Article 16 of Federal Law No. 152-FZ of 27 July 2006 «О персональных данных» opens by forbidding outright the taking, on the basis of solely automated processing of personal data, of decisions «порождающих юридические последствия в отношении субъекта персональных данных или иным образом затрагивающих его права и законные интересы», except in the cases in part 2. The trigger is wider than the European one: the second limb catches any decision that «otherwise affects the rights and legitimate interests» of the person, with no significance qualifier at all, so nothing corresponding to GDPR art. 22(1)'s «similarly significantly affects» threshold has to be cleared. Part 2 then admits exactly two routes: the written consent of the data subject, or a case provided for by a federal law that also lays down measures to secure the person's rights and legitimate interests. There is no contract limb. GDPR art. 22(2)(a) lets a controller automate a decision that is necessary for entering into or performing a contract, and Zambia's s. 62(2) and Mauritius's s. 38(2) carry the same escape; Russia does not, so an automated credit refusal, tenancy screen or insurance decline taken in the course of contracting sits in the prohibition unless a signed consent exists. The consent route is also heavier than it looks, because art. 9(4) governs what a «согласие в письменной форме» has to contain — among other particulars the person's identity-document number and the date and issuing body of that document — and an electronic document signed with an electronic signature is the only equivalent of a handwritten signature. Part 3 is a standing, unconditional duty: the operator explains to the data subject «порядок принятия решения» — the procedure by which the decision is taken — and the possible legal consequences of it, provides the opportunity to state an objection to the decision, and explains how the person may protect their rights and legitimate interests. That duty is proactive rather than answer-on-request, which is stronger than GDPR arts. 13(2)(f) and 15(1)(h); but its object is the procedure, not «логика», so no meaningful-information-about-the-logic right exists anywhere in the Law. Part 4 gives the operator thirty days from receipt to consider the objection and notify the person of the result. It stops there: nothing obliges the operator to change the decision, and no right to obtain human intervention and no right to contest before a person are expressed as such. The rest of the Law is silent on automated decisions — the art. 14(7) access list runs to ten items and none of them is an automated-decision or logic item, and the art. 18(3) notice for data not collected from the subject runs to five items with no such limb either. The Law carries no AI-specific rule; its only three mentions of «искусственный интеллект» are cross-references to the Moscow AI experiment statute, Federal Law No. 123-FZ of 24 April 2020, and they are permissions to process anonymised data rather than obligations.

In force since 26 January 2007, and the 2006 date on the face of the Law is not the operative one. Art. 25(1) puts the Law in force «по истечении ста восьмидесяти дней после дня его официального опубликования». The official record card at pravo.gov.ru lists three publications — «Российская газета» No. 165 of 29 July 2006, «Парламентская газета» Nos. 126-127 of 3 August 2006, and Собрание законодательства РФ 2006 No. 31 (Part I) item 3451 — and the earliest of them, 29 July 2006, is the official publication for the purposes of Federal Law No. 5-FZ of 14 June 1994 art. 4. The 180-day period therefore ran from 30 July 2006 and expired at the end of 25 January 2007, putting the Law in force on 26 January 2007. Art. 16 in its present wording is the redaction of Federal Law No. 261-FZ of 25 July 2011, which rewrote much of the Law; the article has not been touched since. The most recent amendment to the Law, Federal Law No. 265-FZ of 26 July 2026, rewrote parts of art. 12 on cross-border transfers and left art. 16 alone, so the text checked here is the current consolidated official text.

Stated maximum penalty — Art. 24(1) of the Law only refers offenders to «предусмотренную законодательством Российской Федерации ответственность», so the amounts sit in the Code of Administrative Offences, and which paragraph applies depends on which part of art. 16 was breached. Taking the decision without the written consent that art. 16(2) requires is the offence in KoAP art. 13.11(2) — processing without the written consent of the data subject in the cases where that consent has to be obtained, or processing in breach of the requirements as to what the written consent has to contain — carrying 10,000-15,000 roubles for citizens, 100,000-300,000 for officials and 300,000-700,000 for legal persons, and on repetition under art. 13.11(2-1) 15,000-30,000, 300,000-500,000, 500,000-1,000,000 for individual entrepreneurs and 1,000,000-1,500,000 for legal persons. Failing the art. 16(3) duty to explain is the separate and much smaller offence in KoAP art. 13.11(4) — failure to provide the data subject with information concerning the processing of their personal data — at 40,000-80,000 roubles for legal persons. The general paragraph, art. 13.11(1), at 150,000-300,000 roubles for legal persons since Federal Law No. 420-FZ of 30 November 2024, expressly excludes the cases falling under parts 2 and 11-18, so it is the residual rather than the headline figure here. Enforcement is split: Roskomnadzor draws up the protocol under KoAP art. 28.3(2)(58) but does not impose the fine, because art. 13.11 cases are decided by a judge under KoAP art. 23.1. Art. 24(2) of the Law adds compensation for moral harm, recoverable independently of pecuniary damage and of the subject's losses.

In force · 26 Jan 2007 checked 1 Sep 2026 152-FZ art. 16 ↗ high confidence
Russia Binding

243-FZ art. 10(1) — whoever lets you use a large foundational model has to tell you who owns the output

Binds Any person that provides the ability to use a large foundational AI model as defined in art. 3(2) — not fewer than 1 billion parameters, general-purpose across a large number of tasks, and serving as the basis for creating and refining other software. The duty is expressed without a nationality, size or turnover limb, in contrast to arts. 6 to 8, which apply only to Russian legal persons developing models granted sovereign or national status. Art. 1(3) reserves to other federal laws and presidential acts the setting of special rules for defence, state security, operational-search activity, public order and property protection, public and road safety including counter-terrorism, anti-money-laundering and counter-terrorist-financing, emergency prevention, diplomatic and consular service and state administration, so those uses may be governed differently.. Federal Law No. 243-FZ of 26 July 2026 «О поддержке развития технологий искусственного интеллекта в Российской Федерации» is Russia's first AI statute, and this is its broadest genuine duty. Art. 10(1) requires «лица, предоставляющие возможность применения больших фундаментальных моделей искусственного интеллекта» — the persons who make a large foundational model available for use — to notify the user of two things unless another federal rule provides otherwise: to whom the rights belong in the results of intellectual activity obtained with the help of the model, and on what conditions the user is given access to, use of, and retention of those results, retention being qualified by technical possibility. Unlike arts. 6 to 8, the duty is not confined to sovereign or national models or to Russian developers, so it reaches any provider offering such a model to users in Russia. Its scope is set entirely by the art. 3(2) definition: a large foundational model is a computer program intended to perform intellectual tasks at a level comparable to or exceeding human intellectual activity, using algorithms and trained on data sets to infer patterns, supply information, take decisions or forecast results against human-set goals, simultaneously serving as the basis for creating and refining various kinds of software, containing not fewer than 1 billion parameters and applied to a large number of different tasks. Every cumulative limb has to be met, so smaller and narrow-purpose models fall outside the Law altogether. Art. 10(2) sits alongside as a permission rather than a duty: accessing information contained in copyright and neighbouring-rights objects for the practical application of what they contain, including machine extraction, comparison, classification and analysis of patterns, trends and correlations, and short-term reproduction in machine memory, is declared not to infringe — but only where it is done exclusively to train a sovereign and (or) national large foundational model, and only where the developer uses a lawfully obtained copy or the work had been communicated to the public and was available for analysis without technical restriction. A text-and-data-mining exception that is available only to models holding a state-conferred status is an unusual shape and worth noting when comparing it with the EU and Singapore exceptions.

The date on which this duty starts is 1 March 2027, not the 1 September 2026 date reported as the commencement of the Law. Art. 13(1) does put the Law in force on 1 September 2026, but art. 13(2) then defers arts. 8, 9 and 10 in full, together with art. 5(2) points 3 to 5 and art. 6 parts 2 to 5, to 1 March 2027. What actually commences on 1 September 2026 is the subject matter, aims, definitions and principles in arts. 1 to 4, the coordination and support-measure powers in art. 5(1) and art. 5(2) points 1 and 2, the statement of purpose in art. 6(1), the art. 7 list of what a status-holding developer may do, the bare liability referral in art. 11, and arts. 12 and 13 — none of which places a compliance duty on anyone. The official record confirms the position: the pravo.gov.ru register carries the Law as «Не вступил в силу» with a single original redaction marked «вступает в силу 01.09.2026». Adopted by the State Duma on 8 July 2026, approved by the Federation Council on 17 July 2026, officially published on the legal-information portal on 26 July 2026 under number 0001202607260003, and reproduced at Собрание законодательства РФ 2026 No. 30 item 4089 and in «Российская газета» of 31 July 2026.

Stated maximum penalty — None is stated in the Law. Art. 11 is a bare referral — participants in relations in the field of development, deployment and application of large foundational models bear responsibility «в соответствии с законодательством Российской Федерации» for breaches of the Law and of the acts adopted under it — and as at 21 August 2026 the Code of Administrative Offences carries no article addressed to large foundational AI models, so no monetary band attaches to art. 10(1). Where the failure to notify also amounts to a consumer-information failure or a personal-data breach, the existing KoAP articles apply on their own terms. This entry deliberately states no figure rather than importing one from an adjacent regime.

Applies 1 Mar 2027 checked 20 Sep 2026 243-FZ art. 10(1) ↗ high confidence
Russia Binding

243-FZ art. 9 — platforms above 500,000 daily users enable an AI label; nobody is made to apply one

Binds Owners of sites, site pages, information systems and computer programs meeting all of the art. 9(3) limbs at once: intended for or used by users to supply or distribute information via personal pages the users create; carrying information in the state language of the Russian Federation, in the state languages of republics within it, or in other languages of the peoples of Russia, on which advertising aimed at attracting the attention of consumers located in Russia may be distributed; and accessed within twenty-four hours by more than 500,000 internet users located in Russia. That is a large-platform threshold, so the practical population is a short list of user-generated-content services. Art. 9(1) and (2) address the person applying the model and the person providing the ability to apply it, but neither is placed under a duty by them.. Russia's first AI statute stops short of an AI-content labelling mandate, and the gap between what art. 9 says and what it is widely reported to say is the point of this entry. Art. 9(1) provides that a person who applies a large foundational model to create informational material in audio and (or) visual form «обеспечивается возможность размещения информационного предупреждения» — is provided with the possibility of placing an informational warning about the use of AI technologies. That is an entitlement, not a duty, and art. 9(2) confirms the reading by leaving the format, content and manner of placing the warning to be fixed by agreement between the person applying the model and the person providing the ability to apply it, which is not how a statutory labelling obligation is drafted. The single hard duty in the article is art. 9(3), and it falls on the platform rather than on the creator: the owner of a site or page of a site on the internet, or of an information system, or of a computer program that is intended for or used by its users to supply and (or) distribute information through personal pages they create, on which advertising directed at consumers located in Russia may be distributed, and access to which within twenty-four hours exceeds five hundred thousand internet users located in Russia, has to ensure that users distributing information created with large foundational models on their personal pages have the possibility of placing an informational warning about that use. The obligation is therefore to build and offer the labelling affordance, not to label, not to detect AI-generated material, and not to take anything down. Compare the EU AI Act art. 50 machine-readable marking duty on the generating provider and the deployer's disclosure duty, or the Chinese labelling measures, both of which put the duty on the party that makes or publishes the content: Russia's rule leaves the decision to label with the user and makes the large platform supply the button.

Art. 9 is one of the articles art. 13(2) defers: the Law enters into force on 1 September 2026 under art. 13(1), but arts. 8, 9 and 10, along with art. 5(2) points 3 to 5 and art. 6 parts 2 to 5, take effect on 1 March 2027. The platform enablement duty therefore does not bite on the commencement date that most accounts of the Law report. Adopted by the State Duma on 8 July 2026, approved by the Federation Council on 17 July 2026, officially published 26 July 2026 as number 0001202607260003 on the official legal-information portal, and carried at Собрание законодательства РФ 2026 No. 30 item 4089 and in «Российская газета» of 31 July 2026. The official register records the Law as not yet in force with a single original redaction commencing 1 September 2026.

Stated maximum penalty — None is stated in the Law. Art. 11 refers offenders to «законодательство Российской Федерации» generally, and as at 21 August 2026 no article of the Code of Administrative Offences is addressed to large foundational AI models or to the art. 9(3) enablement duty, so no figure can be stated. The separate marking rules that apply to advertising and to information intermediaries are outside this entry.

Applies 1 Mar 2027 checked 20 Sep 2026 243-FZ art. 9 ↗ high confidence

Rwanda 1

Rwanda Binding

Law No. 058/2021 art. 21 — right not to be subject to a decision based on automated data processing

Binds Data controllers, data processors and third parties within the scope of art. 2: those established or residing in Rwanda and processing personal data while in Rwanda, and those neither established nor resident in Rwanda that process the personal data of data subjects located in Rwanda. Article 2 reaches processing of personal data by electronic or other means through an automated or non-automated platform. Registration with the supervisory authority is a standing precondition of acting as a controller or processor: arts. 29 to 36 govern registration, the registration certificate, its renewal, modification and cancellation, and the register itself, and operating without a registration certificate is an administrative misconduct under art. 54. The art. 21 right binds any controller taking a solely-automated decision with legal or significant consequences, irrespective of size. The National Cyber Security Authority is the designated supervisory authority. Impact tier: all entities.. Article 21 of Law Nº 058/2021 of 13/10/2021 relating to the protection of personal data and privacy carries Rwanda's operative automated-decision rule, in Chapter III (rights of the data subject). Its first paragraph gives the data subject the right not to be subject to a decision based solely on automated personal data processing, including profiling, which may produce legal consequences or significant consequences to him or her. The second paragraph disapplies that right where the decision is based on the explicit consent of the data subject, is necessary for entering into or performance of a contract between the data subject and the data controller, or is authorised by Laws to which the data controller is subject and which also put in place suitable measures to safeguard the data subject's rights, freedoms and legitimate interests. The third paragraph adds a free-standing limit that binds even inside those exceptions: any automated processing of personal data intended to evaluate certain personal aspects relating to a natural person does not base on sensitive personal data unless one of the grounds in art. 10 is met. Article 3 supplies the definitions that give the rule its reach — item 11° defines profiling as a form of automated processing used to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements; item 8° defines legal consequences as consequences that negatively affect a person's legal status or legal rights; and item 7° defines significant consequences as consequences having an impact as significant as legal effects that negatively affect the behaviour and choices of a data subject. Two adjacent duties attach to the same processing: art. 14 requires the controller to disclose to the data subject the existence of automated decision making, including profiling, together with information about the logic involved and the significance and envisaged consequences of the processing, and art. 45 makes a personal data protection impact assessment mandatory where there is a systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing of personal data, including profiling, on which decisions producing effects concerning such persons are based.

Commencement is stated on the face of the Law and needs no separate instrument: art. 70 provides that the Law comes into force on the date of its publication in the Official Gazette of the Republic of Rwanda, and it was published in Official Gazette nº Special of 15/10/2021, so art. 21 has been in force since 15 October 2021. Article 67 gave a controller or processor already in operation a period not exceeding two years from that publication date to conform its operations to the Law; that transitional window closed on 15 October 2023 and does not defer art. 21 itself. Article 66 lets the competent organ, in collaboration with the supervisory authority, put in place regulations; no regulation specific to automated decision-making has been issued. Coverage symmetry against the four African rows already tracked: art. 21 is a standing prohibition in the GDPR art. 22 shape, like ke-dpa-s35 and ng-ndpa-s37 and unlike the notice-based gh-dpa-s41, but its remedy is the thinnest of the five — where Nigeria's s. 37(3) expressly grants human intervention, the right to express a point of view and the right to contest, and Kenya's s. 35(3)-(4) grants written notification plus reconsideration or a fresh non-automated decision, Rwanda's art. 21 sets out only the right and its exceptions and prescribes no safeguard measures inside the exceptions at all. It carries no hard deadline; the thirty-day and sixty-day clocks in arts. 19, 20 and 22 attach to objection, portability and restriction, not to art. 21. Its distinctive addition is the art. 21 third-paragraph bar on grounding evaluative automated processing in sensitive personal data, which none of the four peers has. Text read in the Official Gazette as published by the National Cyber Security Authority, the supervisory authority designated under the Law; the English, French and Ikinyarwanda columns of the gazette were read together and agree. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. Rwanda deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 21 November 2019, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. Art. 14(5) of the Convention states the same bar as art. 21 and admits no exception of any kind, where art. 21's second paragraph admits all three of the classical ones — explicit consent, necessity for entering into or performing a contract between the data subject and the controller, and authorisation by Laws to which the controller is subject. Every one of the three is a route the Convention does not open, and Rwanda prescribes no compensating safeguard inside them. Art. 21's third paragraph runs the other way and is stricter than the treaty: automated processing intended to evaluate personal aspects does not base on sensitive personal data absent a ground in the Law, a limit art. 14(5) has no counterpart for. The national statute is carried here as the operative rule, because it is the instrument that has a supervisory authority behind it and a penalty attached to it, and the Convention runs behind it as a stricter parallel rule. This is recorded as a divergence rather than resolved: neither instrument repeals or qualifies the other, Rwanda has not legislated the Convention into domestic law by a separate instrument, and the domestic reception question — whether art. 14(5) is directly effective in Rwanda, as arts. 18 and 144 of the Mozambican and Namibian constitutions respectively make it there — has not been separately verified for Rwanda and is not asserted here. A controller relying on an exception the statute grants therefore stands on solid statutory ground and unresolved treaty ground.

Stated maximum penalty — There is no offence specific to art. 21. Enforcement runs through Chapter VIII. Under art. 54 a listed administrative misconduct — including processing personal data contrary to the Law, operating without a registration certificate, failure to designate a personal data protection officer and the breach-notification failures — carries an administrative fine of not less than RWF 2,000,000 and not more than RWF 5,000,000, or one per cent of the global turnover of the preceding financial year, and for a corporate body or legal entity one per cent of that global turnover; the same article lets the supervisory authority make regulations determining further administrative misconducts and sanctions. The criminal tier in arts. 56 to 61 is narrower and does not name automated decision-making: art. 56 punishes accessing, collecting, using, offering, sharing, transferring or disclosing personal data contrary to the Law with one to three years' imprisonment and a fine of RWF 7,000,000 to RWF 10,000,000, or one of those penalties, and art. 60 punishes collecting or processing sensitive personal data contrary to the Law with seven to ten years' imprisonment and a fine of RWF 20,000,000 to RWF 25,000,000, or one of those penalties. Article 62 sets the corporate penalty for any of the arts. 56 to 61 offences at 5% of the annual turnover of the preceding financial year, and art. 63 lets the court order seizure or confiscation of the objects used and the proceeds gained, and permanent or temporary closure of the entity or premises. Article 65 gives a person who suffers serious damage from a controller's or processor's breach a claim for compensation before the competent court.

In force · 15 Oct 2021 checked 19 Sep 2026 Law No. 058/2021 art. 21 ↗ high confidence

Singapore 1

Singapore Binding

Singapore MAS — Agentic AI in Scope of Supervisory Expectations (binding AI Risk Management Guidelines pending)

Binds MAS-regulated financial institutions (banks, insurers, payment service providers, capital market intermediaries) using autonomous AI agents in Singapore. MAS's 5 Aug 2026 parliamentary reply states existing supervisory expectations already extend to AI agents used by financial institutions, and that MAS will continue to review and update these as needed. The binding instrument — MAS's proposed AI Risk Management Guidelines (consultation paper 13 Nov 2025) — remains in consultation, with a 12-month compliance transition once issued but no MAS-confirmed issuance date. Separately, MAS published a voluntary industry paper, SAFR (Safeguards for Agentic Finance at Runtime), on 3 Jul 2026 — SAFR itself is not binding.

MAS parliamentary reply (5 August 2026) by Deputy Prime Minister and MAS Chairman Gan Kim Yong states existing supervisory expectations (via tech-risk frameworks) already extend to AI agents; the reply's own language is that MAS will "continue to review... and update where necessary," not a declaration that a codified binding rule for agentic AI already exists. The binding track is MAS's proposed AI Risk Management Guidelines (consultation paper of 13 Nov 2025, para 4.7: 12-month transition period proposed after the Guidelines are issued); those Guidelines remain in consultation with no MAS-confirmed finalization date (Q4 2026 is market/analyst expectation, not a MAS commitment). SAFR (Safeguards for Agentic Finance at Runtime), published 3 July 2026, is an industry-led voluntary information paper, distinct from and not itself the binding Guidelines.

Stated maximum penalty — MAS administrative sanctions under financial institution licensing (no specific penalty quantum in parliamentary reply)

In force · 5 Aug 2026 checked 22 Sep 2026 MAS AI Risk Management Guidelines (proposed) / SAFR (voluntary) ↗ medium confidence

Senegal 1

Senegal Binding

Loi 2008-12 art. 48 — no decision with legal effects on the sole basis of automated profiling, and no judicial appraisal of conduct founded on one at all

Binds Responsables du traitement within the scope of art. 2, which subjects to the Law any collection, processing, transmission, storage and use of personal data by a natural person, by the State, by local authorities or by legal persons of public or private law; any processing, automated or not, of data contained in or intended to form part of a file, save the processing excluded by art. 3; any processing implemented by a controller on Senegalese territory or in any place where Senegalese law applies; and any processing implemented by a controller, established in Senegal or not, that resorts to means of processing situated on Senegalese territory, excluding means used only for transit. In that last case the controller must designate a representative established on Senegalese territory, without prejudice to actions that may be brought against the controller itself. Prior formalities are a standing precondition: declaration to the Commission de Protection des Données Personnelles is the default, art. 20 puts health, offence, interconnection, national-identifier, biometric and public-interest processing under prior authorisation, and art. 21 requires a regulatory act taken after the reasoned opinion of the Commission for State, public-establishment, local-authority and public-service processing touching State security, defence, public safety, criminal enforcement, the population census and sensitive data. The first paragraph of art. 48 binds the courts themselves; the second binds any controller taking a decision with legal effects, irrespective of size or sector. Impact tier: all entities.. Article 48 of Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel is Senegal's operative automated-decision rule. It sits in Chapitre III among the substantive processing obligations, between the direct-marketing prohibition in art. 47 and the cross-border-transfer regime in art. 49, and it has three paragraphs. The first is absolute and addressed to the courts: no judicial decision involving an appraisal of a person's conduct may have as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality — there is no consent, contract or safeguards exception to this limb. The second is the general rule: no decision producing legal effects with regard to a person may be taken on the sole basis of an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third supplies the only relief and operates by deeming rather than by exemption: decisions taken in the course of the conclusion or the performance of a contract and for which the person concerned has been put in a position to present their observations, and decisions satisfying the requests of the person concerned, are not regarded as taken on the sole basis of an automated processing. The Law carries no definition of profiling, no right to know the logic underlying an automated processing — the art. 58 information list stops at identity, purposes, categories, recipients, whether answering is compulsory, the right to be removed from the file, the existence of access and rectification rights, the retention period and any envisaged foreign transfers — and no right to obtain human intervention or a fresh non-automated decision. The safeguard it names is an opportunity to present observations, and it exists only inside the contractual deeming clause.

The Law contains no commencement article and, in the copy published by the Commission de Protection des Données Personnelles, no publication clause either: the text runs from the exposé des motifs to art. 78, which reserves the application measures for the digitised national identity card to a separate regulation, and stops there. The date recorded is therefore the date the Law itself bears, 25 January 2008. Confidence is medium, and for a reason one step weaker than Morocco's and Algeria's: not only was the Senegalese general publication-to-force rule not read against a primary source, but the date of the Journal officiel de la République du Sénégal carrying the Law could not be established at all, because no Senegalese gazette host resolved this run — jo.gouv.sn and www.jo.gouv.sn both fail to resolve over http and https. Entry into force can therefore only be that date or later. Art. 77 is transitional and not a deferral of art. 48: from the date of entry into force, processing operations carried out for the State, a public establishment, a local authority or a private-law body managing a public service had two years to conform and all other processing had one year, periods that closed in 2010 and 2009 respectively; art. 76 subjects already-created public-sector processing to declaration only, under art. 18. Décret n° 2008-721 du 30 juin 2008 was taken for the application of the Law; no date claim is drawn from it here. Supersession, re-checked 24 August 2026 against three independent official records and found negative. First, the CDP's own legislation index at cdp.sn/legislation/textes-legislatifs is a JavaScript-only single-page application — it serves a 457-byte shell to any non-executing client, which is why it previously read as a dead stub — and when rendered it carries exactly seven legislative texts: Loi n° 2008-12 du 25 janvier 2008 sur la protection des données à caractère personnel, Loi n° 2008-10 (LOSI), Loi n° 2008-08 (transactions électroniques), Loi n° 2008-11 (cybercriminalité), Loi n° 2008-41 du 20 août 2008 (cryptologie), and the two Lois n° 2016-29 and n° 2016-30 du 08 novembre 2016 — and those two amend the Code pénal (Loi 65-60) and the Code de procédure pénale (Loi 65-61) respectively, not Loi 2008-12. There is no text «modifiant et complétant» Loi n° 2008-12 anywhere in the regulator's own index, and Loi 2008-12 is still listed first as the governing statute. Second, the text itself was re-read end to end this run from the PDF the CDP serves out of its own document store: it opens «LOI n° 2008-12 du 25 janvier 2008 portant sur la Protection des données à caractère personnel», carries no «modifiée» marker, and still runs from the exposé des motifs to art. 78, with art. 48 in its three-paragraph form, art. 75 referring infringements to the Code pénal and the cybercrime law, and art. 77 carrying the two-year and one-year transitional periods — so the article this entry describes is verbatim the article in force. Third, the legislative record of the Assemblée nationale for the XVᵉ législature (2024-2029) at assemblee.sn shows no data-protection bill tabled or adopted; the only digital-sector statute in the 2026 session is Projet de loi n° 25/2026 relatif à la protection des Infrastructures d'Information Critiques (IIC) et à la sécurité numérique, adopted unanimously on 20 August 2026 by 127 votes, whose subject-matter is network and system security, operator duties and an Autorité nationale de Cybersécurité — not automated decision-making — and which is not yet promulgated, so it cannot yet displace anything; it is carried as a watch item rather than a supersession. Senegal therefore does NOT have Algeria's defect: art. 48 stands unrepealed and unamended. What is still missing is gazette-level confirmation, and that is a reachability problem rather than a doubt about the text: jo.gouv.sn has no A record at all and www.jo.gouv.sn resolves to 160.0.177.62 but refuses TCP on both 80 and 443 from this egress, so the Journal officiel issue and date carrying the Law still cannot be established, and confidence stays medium for that reason alone. Note also that assemblee-nationale.sn, the obvious guess for the parliament, is a dead host serving a MikroTik RouterOS login page; the live parliamentary site is assemblee.sn, linked from primature.sn. Source, re-verified 26 August 2026. The signed link into the CDP's own document store that this entry carried since 24 August 2026 is dead for every client, not merely for this egress: the store is a Supabase project and the project itself is now restricted, so both the signed object path and its public equivalent answer HTTP 402 with «Service for this project is restricted due to the following violations: exceed_cached_egress_quota». That is a hosting-quota failure at the regulator's end and it takes the whole of cdp.sn's document content with it. The source_url therefore reverts to the Commission de Protection des Données Personnelles' own legislation page, which is the regulator's publication of the Law, is live, and is the page from which a fresh document link is generated in a JavaScript-capable client; it serves a 457-byte shell to a non-executing client because it is a single-page application, which is the reason it was once mistaken for a dead stub. The text was nonetheless read end to end again this run, from the copy of the Law published by the Association francophone des autorités de protection des données personnelles, the association of francophone data-protection authorities of which the CDP is a member, at afapdp.org/wp-content/uploads/2018/05/Senegal-texte-de-loi-2008.pdf. Art. 48 in that copy is verbatim the article this entry describes: «Aucune décision de justice impliquant une appréciation sur le comportement d'une personne ne peut avoir pour fondement un traitement automatisé des données à caractère personnel destiné à évaluer certains aspects de sa personnalité» — then the legal-effects limb over «un traitement automatisé des données à caractère personnel destiné à définir le profil de l'intéressé ou à évaluer certains aspects de sa personnalité» — then the deeming clause for decisions «prises dans le cadre de la conclusion ou de l'exécution d'un contrat et pour lesquelles la personne concernée a été mise à même de présenter ses observations» and those «satisfaisant les demandes de la personne concernée». That copy adds one thing the CDP's copy did not carry: a promulgation formula, «La présente loi sera exécutée comme loi de l'Etat. Fait à Dakar, le 25 Janvier 2008», signed by President Abdoulaye Wade and Prime Minister Cheikh Hadjibou Soumaré, which corroborates the date the entry records. It still carries no commencement article and no Journal officiel number or date, so the gazette gap is unchanged and confidence stays medium. The gazette itself remains unreachable: jo.gouv.sn has no A record, www.jo.gouv.sn resolves to 160.0.177.62 and was retried on 26 August 2026 over plain HTTP, over HTTP/1.1 without h2 in the ALPN offer, and by IP with an explicit Host header, all three timing out; senegalservices.sn, the state service portal that also carries the Law, resolves to 160.0.176.112 and resets the TLS connection at ClientHello on every TLS version offered; and the ILO's NATLEX record for the Law, which would carry the gazette citation, is behind a JavaScript interstitial that answers 403. Coverage symmetry against the twelve African rows already tracked: art. 48 belongs to the Directive 95/46/EC art. 15 line, and within that family Senegal is the closest match to Morocco's art. 11 and Algeria's art. 11 anywhere in Africa — the three share the same three-paragraph shape, the same absolute judicial limb, the same legal-effects threshold on the second limb, and the same contractual deeming clause conditioned on an opportunity to present observations. That makes the Francophone family split cleanly in two: Senegal, Morocco and Algeria keep the Directive's own drafting, while Côte d'Ivoire's art. 25 and Niger's art. 52 take the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting, in which the second limb reaches any administrative or private decision appraising human conduct and the legal-effects threshold disappears. Senegal predates the Supplementary Act by two years, which is consistent with that split. The four-way African lineage picture is unchanged: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, ci-loi2013450-art25, ne-loi202259-art52 and now sn-loi200812-art48; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63. Source re-verified 27 August 2026, and the citation now reaches primary text again. The reversion to the CDP's legislation index made on 26 August 2026 was the best available then, but it is not primary text: cdp.sn was rebuilt as a Vite/React single-page application whose server answers 200 with the same 457-byte shell to every path, so the index page proves nothing to a non-executing client and carries no law. Reading that application's own bundle (cdp.sn/assets/index-D_qEA75k.js) exposes the six legislative texts it renders as a hard-coded array: the entry for Loi n° 2008-12 points at a signed object in the Supabase project sppsyrftszniuaicadvk, which still answers HTTP 402 «exceed_cached_egress_quota», and the Internet Archive holds no capture of that object — so the regulator's current document store is unusable from any client, not merely this one. The Commission's previous Drupal site, however, served the Law from its own domain at www.cdp.sn/sites/default/files/protection.pdf, and the Internet Archive holds that file from 21 July 2024: 318,186 bytes, content-type application/pdf, and it is the Commission's own copy, not a third party's. It was extracted and read this run. It opens «LOI n° 2008-12 du 25 janvier 2008 portant sur la Protection des données à caractère personnel», carries no «modifiée» marker, runs from the exposé des motifs to art. 78 with no promulgation clause — exactly the copy this entry has always described — and art. 48 reads verbatim: «Aucune décision de justice impliquant une appréciation sur le comportement d'une personne ne peut avoir pour fondement un traitement automatisé des données à caractère personnel destiné à évaluer certains aspects de sa personnalité», then «Aucune décision produisant des effets juridiques à l'égard d'une personne ne peut être prise sur le seul fondement d'un traitement automatisé des données à caractère personnel destiné à définir le profil de l'intéressé ou à évaluer certains aspects de sa personnalité», then the deeming clause for decisions «prises dans le cadre de la conclusion ou de l'exécution d'un contrat et pour lesquelles la personne concernée a été mise à même de présenter ses observations» and those «satisfaisant les demandes de la personne concernée». Art. 77's two-year and one-year transitional periods and art. 78's identity-card reservation are also present as described. The source_url therefore moves to that archived capture of the regulator's own file, which is the same remedy applied to the Central African Republic in commit bc8ef0f: an archived copy of the publisher's own document beats a live page that contains no document. The supersession check is independently reconfirmed by the same bundle — the array of legislative texts the CDP publishes contains Lois 2008-12, 2008-10, 2008-08, 2008-11, 2008-41 and 2016-29/2016-30, the last two amending the Code pénal and the Code de procédure pénale, and nothing «modifiant» Loi 2008-12. Gazette-level confirmation is still absent for the same reachability reason and confidence stays medium: retried 27 August 2026, jo.gouv.sn still has no A record and www.jo.gouv.sn still times out on TCP over both HTTP/1.1 and HTTPS from this egress. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. Senegal deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 16 August 2016, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. Senegal's deposit is the earliest of the sixteen. Art. 14(5) of the Convention states the same solely-automated-decision bar as art. 48 and admits no exception of any kind — no contract limb, no consent limb, no legal-authorisation limb. Art. 48's first two limbs are at least as strict as the treaty, and the judicial limb is stricter, but its third limb is not: the deeming clause, under which a decision taken in the conclusion or performance of a contract and for which the person was put in a position to present their observations, and a decision satisfying the person's own request, are treated as not taken on the sole foundation of automated processing. That is a route out of the prohibition that art. 14(5) does not open, and the opportunity to present observations — the only safeguard art. 48 names — has no counterpart in the Convention either. The national statute is carried here as the operative rule, because it is the instrument that has a supervisory authority behind it and a penalty attached to it, and the Convention runs behind it as a stricter parallel rule. This is recorded as a divergence rather than resolved: neither instrument repeals or qualifies the other, Senegal has not legislated the Convention into domestic law by a separate instrument, and the domestic reception question — whether art. 14(5) is directly effective in Senegal, as arts. 18 and 144 of the Mozambican and Namibian constitutions respectively make it there — has not been separately verified for Senegal and is not asserted here. A controller relying on an exception the statute grants therefore stands on solid statutory ground and unresolved treaty ground. Watch re-polled 13 September 2026 under AIL-263 and the position is unchanged: Projet de loi n° 25/2026 relatif à la protection des Infrastructures d'Information Critiques et à la sécurité numérique is still not promulgated and its text is still not published anywhere reachable, so the art. 75 referral to Loi n° 2008-11 sur la cybercriminalité, on which this entry's penalty field rests, is not yet disturbed. Three independent official records were read. First, the CDP's legislation index — read this run by fetching the single-page application's own bundle rather than rendering it, because the index is a hard-coded array inside cdp.sn/assets/index-D_qEA75k.js — still carries the same seven legislative texts, the newest of which remains Loi n° 2016-30, and nothing on critical information infrastructure. Second, the Assemblée nationale's own record was enumerated gap-free from 19 August to 12 September 2026 through the Laravel API behind assemblee.sn at api.assemblee.sn: the law appears exactly once, as the adoption announcement of 20 August 2026 (publication 2728), whose updated_at is still 20 August 2026 23:52 UTC, and no later publication mentions it, so no transmission or promulgation notice has been posted. Third, the Conseil des ministres communiqués published by the Gouvernement du Sénégal at primature.sn are current to 10 September 2026, and their «Textes législatifs et réglementaires» section — which does report exactly this class of item, as the 29 July 2026 communiqué shows by adopting the two application decrees for the private-security regulator CRASP — mentions neither the law, nor its promulgation, nor any Autorité nationale de Cybersécurité, three weeks after adoption. Two candidate sources were tested and ruled out rather than left implicit: the gazette substitute at primature.sn/publications/lois-et-reglements/lois-et-decrets ceilings at Décret n° 2024-1982 du 13 septembre 2024 and that host's Drupal search returns no results even for control terms, so neither can carry a negative; and ancs.sn, the obvious guess for the Autorité nationale de Cybersécurité, is the Alliance nationale des Communautés pour la Santé, an unrelated health NGO.

Stated maximum penalty — Senegal is the only row on the tracker whose data-protection statute creates no offences of its own. Art. 75, the whole of Chapitre VI, provides that infringements of the Law's provisions are laid down and punished by the Penal Code and by the law relating to cybercrime — Loi n° 2008-11 du 25 janvier 2008 sur la cybercriminalité, adopted the same day — so no penalty figure can be attributed to art. 48 from the data-protection statute itself, and none is asserted here. The route that reaches art. 48 within the Law is administrative and runs through the Commission de Protection des Données Personnelles. Art. 29 lets the Commission issue a warning to a controller that does not respect the obligations arising under the Law and a formal notice (mise en demeure) to end the failures within a period it fixes. Art. 30 provides that if the controller does not comply with the formal notice the Commission may, after an adversarial procedure, pronounce provisional withdrawal of the authorisation granted for three months, at the expiry of which the withdrawal becomes definitive, and a pecuniary fine of 1,000,000 to 100,000,000 francs CFA, recovered under the legislation on recovery of State debts. Art. 31 adds an urgency power where the implementation of a processing or the exploitation of personal data entails a violation of rights and freedoms: after an adversarial procedure the Commission may order interruption of the processing for a maximum of three months, blocking of certain processed data for a maximum of three months, or temporary or definitive prohibition of a processing contrary to the Law. Art. 32 makes the Commission's sanctions and decisions appealable to the Conseil d'Etat. Arts. 25 to 28 supply the inspection powers, exercisable on professional premises under the Code de Procédure Pénale with the Procureur de la République informed in advance, requiring authorisation from the President of the Regional Court where the occupier objects, and recorded in an adversarial procès-verbal.

In force · 25 Jan 2008 checked 20 Sep 2026 Loi n° 2008-12 art. 48 ↗ medium confidence

São Tomé e Príncipe 1

São Tomé e Príncipe Binding

Lei 3/2016 art. 13.º — the Lusophone prohibition without Angola's regulator escape hatch, and with a right to the reasons

Binds Responsáveis pelo tratamento — controllers — with subcontratantes (processors) bound through art. 17, which forbids anyone acting under the authority of the controller or processor, and the processor itself, from processing personal data without the controller's instructions save under legal obligation. Art. 3(1) applies the Law to processing by wholly or partly automated means and to non-automated processing of personal data contained in or intended for manual files. Art. 3(2) sets four territorial limbs: processing by a controller headquartered in São Tomé e Príncipe; processing in the context of the activities of a controller established in São Tomé e Príncipe even where that controller is not headquartered in national territory; processing outside national territory in a place where São Tomé law applies by force of public or private international law; and processing by a controller not established in São Tomé e Príncipe that resorts, for the processing, to means situated in national territory. Art. 3(3) makes that last limb wide in the same terms Angola uses — a controller is deemed to resort to means in São Tomé territory where the processing operations are carried out with means situated in national territory or where the personal data are hosted on means so situated, the mere use of such means for the collection, recording or transit of personal data in national territory being enough — and art. 3(4) then obliges that controller to designate a representative established in São Tomé e Príncipe. A foreign scoring, credit or hiring-assessment operator that merely hosts on São Tomé infrastructure is therefore inside art. 13 and owes a local representative. Impact tier: all entities — art. 13 carries no employee-count, turnover, sector or high-risk-system threshold, and its named evaluation grounds (professional capacity, credit, trustworthiness, conduct) put hiring and credit-scoring deployers squarely in scope.. Article 13.º of Lei n.º 3/2016 — Lei de Protecção de Dados Pessoais is São Tomé e Príncipe's automated-decision provision, and it is the second Lusophone row on the tracker after Angola. Both descend from Portugal's Lei 67/98 and the operative sentence is close to word-for-word: under art. 13(1), «qualquer pessoa tem o direito de não ficar sujeita a uma decisão que produza efeitos na sua esfera jurídica ou que a afecte de modo significativo, tomada exclusivamente com base num tratamento automatizado de dados destinado a avaliar determinados aspectos da sua personalidade, designadamente a sua capacidade profissional, o seu crédito, a confiança de que é merecedora ou o seu comportamento» — any person has the right not to be subject to a decision producing effects in their legal sphere or significantly affecting them, taken exclusively on the basis of automated processing intended to evaluate certain aspects of their personality, namely their professional capacity, their credit, their trustworthiness or their conduct. Where the two Lusophone rows part company is on the way out and on what the data subject gets to see. São Tomé keeps only the two statutory exceptions of the parent law — art. 13(2)(a), a decision taken in the conclusion or performance of a contract, conditioned on the person's own request having been satisfied or on adequate measures guaranteeing their legitimate interests, expressly their right of representation and expression; and art. 13(2)(b), a decision authorised by a law that lays down measures guaranteeing the data subject's rights and legitimate interests. There is no third route: nothing lets the Agência Nacional de Protecção de Dados Pessoais licence an otherwise-prohibited decision, which is exactly the limb Angola carries as art. 29(3) and Cabo Verde as art. 23(3) — São Tomé is the one member of the Lusophone group that dropped the regulator-licence route of art. 13(3) of Portugal's Lei 67/98. In the other direction São Tomé is the more generous of the pair, because art. 11(1)(c) gives the data subject the right to obtain from the controller «o conhecimento das razões subjacentes ao tratamento automatizado dos dados que lhe digam respeito» — knowledge of the reasons underlying the automated processing of data concerning them. The parent Portuguese provision speaks of the lógica subjacente, the underlying logic; São Tomé's drafters wrote razões, reasons, which on its face asks for the grounds of the processing rather than the mechanics of the model, and it is drafted as an access right exercisable on request rather than as a notice duty — the art. 10 information list carries no automated-decision item at all. Angola's Lei 22/11 has no equivalent of either. So among the three African rows added this month the shape is: São Tomé prohibits the decision and lets the data subject ask why the machine processed them, Angola prohibits the decision and never lets them ask, and the Democratic Republic of the Congo never prohibits it but compels disclosure of the underlying logic three times over. Impact tier: all entities.

Force. The Law was approved by the Assembleia Nacional in São Tomé on 15 February 2016, promulgated by President Manuel do Espírito Santo Pinto da Costa on 18 March 2016, and published in the Diário da República n.º 39 de 10 de Maio de 2016 at pp. 285-299 — the gazette number and date run in the running head of every page of the text read. The date carried here is that publication date, and it is the one point in the entry that is not exact to the day: art. 47.º (Entrada em vigor) says only «a presente lei entra em vigor nos termos legais», deferring to the general rule on the entry into force of diplomas rather than fixing a date or a vacatio period on its face, so the operative date is the publication date or a small number of days after it. Applying Deadline Specificity strictly, that residual is stated rather than papered over: no primary text of the São Tomé rule on entry into force of diplomas was located in this pass, secondary accounts point to the five-day PALOP vacatio inherited from Base LXXIX of Lei 5/72, and that account has not been verified against primary text and is not relied on here. Ten years on, nothing on the tracker turns on the difference. Art. 45 sets the only transition and it does not touch art. 13: processing existing in manual files at entry into force was given two years for conformity with arts. 7, 8, 10 and 11. Supersession: none — no successor or amending law was found, and no AI-specific statute is in force in São Tomé e Príncipe. Text read in full in the copy of the Diário da República pages published by the Red Iberoamericana de Protección de Datos, the network of Ibero-American data-protection authorities of which the São Tomé Agência Nacional de Protecção de Dados Pessoais is a member; the file is the gazette typesetting itself, carrying the DR running heads, page numbers 285-299 and the closing signature block, not a re-keyed edition. Coverage of the read: arts. 2 principles, 3 scope and 4 definitions; the whole of Capítulo III on data-subject rights, arts. 10 information, 11 access, 12 opposition, 13 automated individual decisions and 14 compensation, verbatim; arts. 16-18 on sensitive-data authorisations, processors and professional secrecy; the whole enforcement chain — arts. 30-35 administrative infractions and their fines, arts. 36-41 the criminal section, arts. 42-43 accessory penalties; art. 44 on the Agência; and arts. 45-47 the transitional and final provisions. Confidence high on the substance: art. 13 and art. 11(1)(c) were read verbatim in the gazette text and the fine attaching to art. 13 was traced to the enumerated list in art. 32(1) rather than assumed. The Agência Nacional de Protecção de Dados Pessoais, whose organic law art. 44 leaves to the Assembleia Nacional, does exist and is operational — it is a listed member of the African Network of Data Protection Authorities and of the Rede Lusófona de Protecção de Dados, where it leads the video-surveillance working group — so unlike Equatorial Guinea's never-created Órgano Rector, the enforcement route in art. 35 has an addressee. Revisited 31 Aug 2026 to identify the rule behind art. 47.º's «nos termos legais», and the residual is now named rather than left open, though the date is not moved. The applicable instrument is not the pre-independence Base LXXIX of Lei n.º 5/72 recorded above as an unverified account, but Decreto n.º 51/77, a post-independence São-tomense instrument which fixes entry into force «em São Tomé no 5.º [dia], após a sua publicação no Diário da República; no Príncipe no 8.º dia, após a sua publicação no Diário da República». Two things follow. First, the construction is the same named-day form found in Cabo Verde's Lei n.º 87/VII/2011 and in the Spanish Código Civil art. 2.1, not the elapsed-term form that moved Paraguay, so there is no midnight question. Second, entry into force in São Tomé e Príncipe is split by island: on that text, publication on 10 May 2016 puts Lei n.º 3/2016 in force on 15 May 2016 in São Tomé and on 18 May 2016 in Príncipe. Those dates are recorded as the better-sourced reading and are not adopted into the date field, because the wording of Decreto n.º 51/77 was read in the LegisPalop database of PALOP legislation rather than in the Diário da República itself, and a decade-old lifecycle-force row should not trade a labelled imprecision for an unverified precision. The date carried remains the publication date of 10 May 2016. If the text of Decreto n.º 51/77 is ever read in the gazette, this row moves to 15 May 2016 and the Príncipe date belongs in the note. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. São Tomé e Príncipe deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 15 February 2024, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. The date needs care on this row, because São Tomé's deposit is the only one of the sixteen that post-dates the Convention's own entry into force on 8 June 2023. Art. 36 fixes the collective date and adds no per-State entry-into-force clause, so the day from which the Convention binds São Tomé is not derivable from the instrument itself; on the earliest defensible reading it is the deposit of 15 February 2024, and no more precise date is asserted here. On substance, art. 14(5) states the same bar as art. 13.º and admits no exception of any kind, where São Tomé keeps the parent law's two: art. 13.º(2)(a), a decision taken in the conclusion or performance of a contract, conditioned on the person's own request having been satisfied or on adequate measures guaranteeing their legitimate interests, expressly the right of representation and expression; and art. 13.º(2)(b), a decision authorised by a law laying down safeguard measures. Both are routes the Convention does not open. The national statute is carried here as the operative rule, because it is the instrument that has a supervisory authority behind it and a penalty attached to it, and the Convention runs behind it as a stricter parallel rule. This is recorded as a divergence rather than resolved: neither instrument repeals or qualifies the other, São Tomé e Príncipe has not legislated the Convention into domestic law by a separate instrument, and the domestic reception question — whether art. 14(5) is directly effective in São Tomé e Príncipe, as arts. 18 and 144 of the Mozambican and Namibian constitutions respectively make it there — has not been separately verified for São Tomé e Príncipe and is not asserted here. A controller relying on an exception the statute grants therefore stands on solid statutory ground and unresolved treaty ground. Source moved off a non-government host, 14 September 2026, closing the last citation in the non-government source_url audit. The citation this row had carried since it was created was the copy published by the Red Iberoamericana de Protección de Datos at redipd.org — a network of data-protection authorities, not a São-tomense publisher — and a binding-status row whose only authority is a third-party copy is the defect the audit was opened to clear. The Law is now cited to the Agência Nacional de Protecção de Dados Pessoais, the supervisory authority art. 44.º of this Law provides for, which published the gazette issue itself on its own host at www.anpdp.st/docs_comprimidos/legislacao_nacional/dr39_lei3_2016_proteccao_de_dados_pessoais.pdf — the filename carries the gazette's own identifier, DR n.º 39. That live official URL, recorded here alongside the archived one, now answers HTTP 404: the ANPDP replaced its PHP site with a single-page application some time after 26 June 2024, and the whole docs_comprimidos tree went with it, including the English version at legislacao_nacional/law3_2016.pdf; the replacement serves a 1,070-byte Vite shell whose bundle exposes only authentication and form-platform routes and no legislation route at all. The source_url therefore points at the Internet Archive's capture of the regulator's own file, which is the remedy already applied to the Central African Republic in commit bc8ef0f and to Senegal on this tracker. Two captures of that file exist, 22 May 2022 and 21 April 2024; they are byte-identical (MD5 6a9237ebf02893ba3e995bffac97bd64, 283,230 bytes), so the ANPDP served one stable file for at least the two years to its last capture, and the 2024 capture is the one cited. The file is the gazette typesetting, not a re-keyed edition, and it was read end to end this run: page 1 is the Diário da República cover for «Terça feira, 10 de Maio de 2016 Número 39», with the Assembleia Nacional summary line for Lei n.º 03/2016, and every subsequent page carries the running head «N.º 39 – 10 de Maio de 2016 SÃO TOMÉ E PRÍNCIPE - DIÁRIO DA REPÚBLICA» over page numbers running 285 to 299, sixteen pages in all. Every load-bearing claim in this row was re-verified against it: art. 13.º(1) verbatim as quoted above; the two exceptions in art. 13.º(2)(a) and (b) verbatim; art. 32.º(1) enumerating arts. 5.º, 10.º, 11.º, 12.º, 13.º, 16.º, 17.º and 25.º n.º 3 at the 25.000.000,00 to 50.000.000,00 dobra band, so the fine reaching art. 13 is enumerated rather than inferred; art. 35.º(1) placing the application of those fines with the ANPDP; art. 44.º reserving the ANPDP's organic law and staff table to the Assembleia Nacional; art. 45.º giving manual files two years for arts. 7.º, 8.º, 10.º and 11.º; and art. 47.º reading only «A presente Lei entra em vigor nos termos legais», above the Assembleia Nacional's approval at São Tomé on 15 February 2016 under President José da Graça Diogo and the promulgation of 18 March 2016 by President Manuel do Espírito Santo Pinto da Costa. Nothing in the substance of this row moved: the retired redipd.org file extracts to exactly the same 52,884 characters over the same sixteen pages as the ANPDP file, so the two are the same gazette scan re-saved, and what was defective was the provenance of the citation rather than the text behind it. One thing is upgraded rather than merely re-verified. The existence and operation of the Agência, recorded above from its membership of the African Network of Data Protection Authorities and of the Rede Lusófona de Protecção de Dados, now rests on primary text: the same ANPDP legislation directory holds Diário da República n.º 40 de 6 de Abril de 2017, pp. 650-660, carrying Lei n.º 7/2017 — Organização e Funcionamento da Agência Nacional de Protecção de Dados Pessoais, approved by the Assembleia Nacional on 15 February 2017 and promulgated on 22 March 2017 by President Evaristo do Espírito Santo Carvalho — which is the art. 44.º organic law, enacted. It was read this run and it corroborates the supersession finding from the other direction: it amends and repeals nothing in Lei n.º 3/2016, and instead cites it as the law in force throughout, referring to its arts. 5.º, 9.º, 11.º, 16.º, 18.º, 20.º, 21.º, 22.º, 23.º and 25.º by number, while art. 4.º(1)(h) empowers the ANPDP to fix, by sector, the maximum periods for compliance with the controller obligations arising under arts. 11.º to 13.º — a procedural power over the timing of art. 13, not a power over its content. Ruled out this run, so that an archived citation is not mistaken for a search that was not run: no live São-tomense host publishes this Law. parlamento.st and www.parlamento.st refuse TCP, and the Internet Archive's holdings for the Assembleia Nacional stop in 2009, seven years before this Law; diario.gov.st, the obvious gazette host, refuses TCP, and dre.gov.st — the Diário da República electronic address the government portal itself links — has no A record; gov.st answers but is a news portal with no legislation section; stp.gov.st, the Governo portal, exposes a Strapi document API at backstp.gov.st whose entire corpus is seven documents across four types (Decreto-Lei, Comunicado, Programa, Decreto), none of them this Law; financas.gov.st answers 403 to every client; inic.gov.st, which serves national ICT strategy documents, returns HTTP 500 on every path including its own viewdoc.php; the Banco Central's legislation page at bcstp.st carries three financial statutes only; the Tribunal de Contas' legislation page carries no law files; and presidencia.st and ager.st publish no legislation at all.

Stated maximum penalty — 25,000,000 to 50,000,000 dobras, and the notable point is that the fine reaches art. 13 directly. Art. 32(1) enumerates by article number the provisions whose breach is an administrative infraction at that band — arts. 5, 10, 11, 12, 13, 16, 17 and 25(3) — so both the automated-decision prohibition in art. 13 and the right to know the reasons underlying automated processing in art. 11 are inside the sanctioned list. That is the opposite of Angola, where art. 29 appears in neither art. 51 contravention list and enforcement has to run through a complaint, a judicial reparation claim or the crime of qualified disobedience. Art. 32(2) sets a higher band, 45,000,000 to 90,000,000 dobras, for breach of arts. 6, 7, 8, 9, 19 and 20. Art. 31 sets the notification-failure band — 50,000,000 to 120,000,000 dobras for a natural person, 100,000,000 to 200,000,000 for a group without legal personality, and 250,000,000 to 500,000,000 for a legal person — doubled under art. 31(2) where the data are subject to prior control, and art. 34(1) makes negligence always punishable there. All amounts are as written in the 2016 text and are nominal dobras of that date; São Tomé e Príncipe redenominated its currency after the Law was passed, so the figures need conversion before they are quoted as a present-day exposure, and no conversion is asserted here because none was verified against primary text in this pass. Art. 35 gives the application of the fines to the Agência Nacional de Protecção de Dados Pessoais and makes its decision an enforceable title where it is not challenged in the legal period. Alongside the fines, art. 42 allows accessory penalties — temporary or definitive prohibition of the processing, blocking, erasure or total or partial destruction of the data, publicity of the conviction under art. 43 at the convicted party's expense in a widely circulated Portuguese-language periodical for not less than 30 days, and public warning or censure of the controller by the Agência. The criminal section sits behind that: art. 36 punishes intentional failure to notify or to seek authorisation, false information in a notification, diversion or use of personal data incompatibly with the purpose determining their collection, and unlawful interconnection, with up to one year's imprisonment or a fine up to 120 days; art. 37 punishes undue access and art. 38 the vitiation or destruction of data with up to two years; art. 39 makes it qualified disobedience to fail, after notification, to interrupt, cease or block processing, or to refuse the Agência the cooperation demanded of one; art. 40 punishes breach of professional secrecy with up to two years, aggravated by half where the agent is a public official or acted for gain; and art. 41 makes attempt always punishable. Under art. 33(1), where the same act is both a crime and an administrative infraction, the agent is always punished as for the crime.

In force · 10 May 2016 checked 14 Sep 2026 Lei 3/2016 art. 13.º ↗ high confidence

Togo 1

Togo Binding

Loi 2019-014 art. 27 — a judicial limb, a legal-effects limb and a contract carve-out: the Directive 95/46 shape, not the wider ECOWAS one

Binds Responsables du traitement within the scope of art. 2, which subjects to the Law any collection, processing, transmission, storage and use of personal data by a natural person, the State, local authorities or legal persons of public or private law; any processing, automated or not, of data contained in or intended to form part of a file; any processing implemented by a controller on Togolese territory or anywhere Togolese law applies; any processing by a controller established or not in Togo that resorts to means of processing situated on Togolese territory other than for mere transit; and any processing concerning public security, defence, investigation and prosecution of criminal offences or State security, subject to the Law's own derogations. Art. 3 excludes processing by a natural person in the exclusive course of personal or domestic activities where the data are not intended for systematic communication to third parties or dissemination, and temporary copies made in the technical activities of transmission and network access. The formalities are graduated: art. 5 dispenses some processing entirely, art. 6 makes declaration to the Instance de protection the default and provides that only receipt of the récépissé confers the right to implement the processing, art. 7 lets the Instance publish simplified or exempting norms, art. 8 requires prior authorisation for six categories — genetic data and health research, offence and conviction data, file interconnection, national identification numbers, biometric data and public-interest processing — and art. 9 requires a reasoned opinion before regulatory acts for State, public-establishment and public-service processing. Profiling and automated decision-making appear in none of the art. 8 authorisation categories, so unlike Burkina Faso and Niger, Togo imposes no ex ante gate on the processing art. 27 governs. The art. 27 bar binds the courts under its first limb and every decision-maker taking a decision producing legal effects under its second, irrespective of size or sector. Impact tier: all entities.. Article 27 of Loi n° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel is Togo's operative automated-decision rule. It is headed "Du fondement d'une décision de justice" and sits in Chapitre III on the rights of the data subject, between the art. 26 direct-marketing prohibition and the art. 28 cross-border-transfer article, in three unnumbered paragraphs. The first: no judicial decision involving an appraisal of a person's conduct may have as its sole foundation an automated processing of personal data intended to evaluate certain aspects of their personality. The second: no decision producing legal effects with respect to a person may be taken on the sole foundation of an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third is a deeming carve-out: decisions taken in the context of the conclusion or the performance of a contract, and for which the data subject has been put in a position to present their observations, and decisions satisfying the data subject's requests, are not taken on the sole foundation of an automated processing. Two features place Togo away from its Francophone West African neighbours and alongside Morocco and Algeria. First, the second limb is drafted on the Directive 95/46/EC art. 15 model — its trigger is a decision producing legal effects — and not on the wider ECOWAS Supplementary Act model used by Côte d'Ivoire, Burkina Faso and Niger, whose second limb reaches any administrative or private decision appraising human conduct whatever its effects. Second, the judicial limb carries the word "seul": unlike Côte d'Ivoire's art. 25, Burkina Faso's art. 15 and Guinea's art. 27, a Togolese judicial decision is barred only where the automated processing is its sole foundation. Togo does supply the exception clause that Côte d'Ivoire, Mali and Burkina Faso omit, and it is the Moroccan and Algerian one: contract decisions with an opportunity to present observations, plus decisions satisfying the data subject's own requests. The Law creates no right to know the logic of an automated processing — the art. 39 access right runs to information enabling the data subject to know and to contest the processing, confirmation, communication of the data and their origin, purposes, categories, recipients and envisaged transfers, and nothing more — and no right to obtain human intervention or a fresh non-automated decision. The Law carries no definition of profiling.

Art. 97, the final article, is a bare execution clause — "La présente loi est exécutée comme loi de l'Etat" — and the Law contains no commencement article and defers nothing. The date recorded here, 29 October 2019, is the date carried in the Law's own title and citation and is also the date of the Journal officiel de la République togolaise, 64e année, n° 26 ter, in which it was published. Confidence is medium, and the reason is specific and is recorded here rather than smoothed over: the signature block of the enacted text reads "Fait à Lomé, le 30 octobre 2019" over the signatures of President Faure Essozimna Gnassingbé and Prime Minister Selom Komi Klassou, one day AFTER the date of the gazette issue that carries it. The discrepancy is on the face of the gazette itself and is consistent with the Togolese practice of numbered "ter" special issues, but it means the promulgation date and the publication date cannot both be right as printed, and the Togolese general publication-to-force rule was not read against a primary source either, so it could not be confirmed whether force attaches on publication or after a jour franc. Anyone relying on a one-day margin around 29-30 October 2019 should read the gazette page directly. Art. 96 abrogates all prior contrary provisions but names no statute, so no predecessor is superseded on the tracker. Art. 95 is transitional and is not a deferral of art. 27: from entry into force, processing for the State, a public establishment, a local authority or a private legal person managing a public service had two years to conform and all other processing had one year, periods that closed in 2021 and 2020 respectively; art. 94 additionally reduced pre-existing public-sector processing to a declaration under art. 6. Coverage symmetry against the Francophone rows already tracked: Togo is the seventh member of the Directive 95/46/EC art. 15 family on the tracker and it splits that family further. Morocco's art. 11, Algeria's art. 11 and now Togo's art. 27 take the narrow legal-effects trigger with a contract carve-out; Côte d'Ivoire's art. 25, Mali's art. 2, Burkina Faso's art. 15 and Niger's art. 52 take the wider ECOWAS trigger reaching any administrative or private decision appraising human conduct. Togo is a founding ECOWAS member and its Law postdates the ECOWAS Supplementary Act A/SA.1/01/10 by nine years, yet it did not take the Supplementary Act's wider drafting — which is why each statute in this block is read article by article rather than inferred from membership. Text read page by page in the Journal officiel de la République togolaise of 29 October 2019 as published by the Government of Togo's own gazette service, including arts. 2, 3, 5 to 9, 26 to 28, 38 to 41, 70 to 73, 79 to 93 and 94 to 97. Malabo Convention overlay, added 13 September 2026 under the per-country structure decision on AIL-240. Togo deposited its instrument of ratification of the African Union Convention on Cyber Security and Personal Data Protection (adopted at Malabo, 27 June 2014) on 19 October 2021, and the Convention entered into force on 8 June 2023 under its art. 36 — thirty days after Mauritania's deposit, the fifteenth. Art. 14(5) of the Convention states the same bar as art. 27 and admits no exception of any kind, where art. 27 carries the Moroccan and Algerian deeming carve-out: a decision taken in the context of the conclusion or the performance of a contract and for which the data subject has been put in a position to present their observations, and a decision satisfying the data subject's own requests, are deemed not taken on the sole foundation of automated processing. Togo therefore supplies the exception clause that Côte d'Ivoire and Guinea omit, and it is precisely that clause the Convention does not open. The observations proviso is also the only safeguard art. 27 names, and art. 14(5) carries no safeguard at all — no human intervention, no contest, no logic. The national statute is carried here as the operative rule, because it is the instrument that has a supervisory authority behind it and a penalty attached to it, and the Convention runs behind it as a stricter parallel rule. This is recorded as a divergence rather than resolved: neither instrument repeals or qualifies the other, Togo has not legislated the Convention into domestic law by a separate instrument, and the domestic reception question — whether art. 14(5) is directly effective in Togo, as arts. 18 and 144 of the Mozambican and Namibian constitutions respectively make it there — has not been separately verified for Togo and is not asserted here. A controller relying on an exception the statute grants therefore stands on solid statutory ground and unresolved treaty ground.

Stated maximum penalty — No criminal offence attaches to art. 27. The Law's penal chapter is arts. 79 to 93 and every one of its fifteen offences names its own conduct — failure to observe the prior formalities, disregard of a provisional withdrawal of authorisation, disregard of simplified or exempting norms, unauthorised processing of identification data, failure of security measures, fraudulent processing, disregard of the right to object, unlawful processing of sensitive data, of offence data and of health-research data, breach of the retention period, processing of data kept beyond it, diversion of purpose, unauthorised disclosure, and obstruction of the Instance de protection — and none of them reaches an automated decision. Those offences run from three months to five years' imprisonment and from 100,000 to 25,000,000 francs CFA, or one of the two penalties. The route that does reach art. 27 is administrative. Art. 70 lets the Instance de protection des données à caractère personnel issue a warning to a controller not respecting the obligations arising under the Law and a mise en demeure to cease the failures within a period it fixes. Art. 71 provides that where the controller does not comply with that mise en demeure the Instance may, after an adversarial procedure, pronounce a provisional withdrawal of the authorisation for three months which becomes definitive if no corrective measures follow, and a fine which may not exceed 100,000,000 francs CFA, recovered under the legislation on the recovery of State debts. Art. 72 adds urgent measures where implementation of a processing entails a violation of rights and freedoms: interruption of the processing for up to three months, blocking of certain data for up to three months, an injunction to bring the processing into conformity which may carry an astreinte of up to 5,000,000 francs CFA per day except where the State is the controller, and a formal reprimand. Art. 73 adds conservatory measures where a processing is implemented without the prior formalities, including the affixing of seals by a huissier at the controller's expense.

In force · 29 Oct 2019 checked 20 Sep 2026 Loi n° 2019-014 art. 27 ↗ medium confidence

Thailand 1

Thailand Binding

Royal Decree on Digital Platform Service Businesses Sec. 17 — publication of the main parameters of ranking, advertising and review algorithms

Binds Operators of digital platform services subject to prior notification under Sec. 8 — a service with annual revenue from the platform earned in Thailand above THB 1.8 million for a natural person or above THB 50 million for a juristic person, or with more than 5,000 average monthly users. The Sec. 17 disclosure duty applies to the services listed in Sec. 16: platforms provided for remuneration that act as an intermediary in offering goods or services to consumers under contractual relationships with business users, and online search engines. Sec. 3 and the deeming rules extend the Decree to foreign operators serving users in Thailand, indicated by Thai-language display, a Thailand-signifying domain, Thai baht payment, Thai governing law or forum, or paid search placement for Thai users. The heavier Secs. 19 to 21 duties bind only large platforms — above THB 300 million annual revenue per service type, above THB 1 billion across all types, or users exceeding 10 per cent of the Thai population — and designated specified platforms. Impact tier: SME and enterprise.. The Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification, B.E. 2565 (2022), issued under Secs. 32 and 33 of the Electronic Transactions Act B.E. 2544, requires the platform operators identified in Sec. 16 to publish their terms and conditions of service clearly and appropriately, before or at the time the service is used. Section 17 fixes the minimum content of that publication and three of its limbs are algorithmic disclosure duties: the main parameters of the algorithms or of the criteria the operator uses to rank or recommend the list of goods or services to users; the main parameters of the algorithms or criteria used to present advertisements of goods or services to users; and the main parameters of the algorithms or criteria used to collect, moderate and publish user reviews. The same section also requires disclosure of service suspension or termination and remuneration terms, access to and use of data received from the service, support channels, the internal complaint-handling system and dispute resolution with time frames, and the rating of goods, services or content. Separately, operators designated as large or specified digital platform services under Sec. 18 must conduct risk assessments and implement mitigation measures, maintain system security, carry out crisis management, appoint compliance officers and undergo external audit (Secs. 19 to 21), and report annually on that compliance to the Electronic Transactions Development Agency (Sec. 22).

Commencement is computed from the face of the instrument: Sec. 2 provides that the Royal Decree comes into force after the expiration of 240 days from the date of its publication in the Government Gazette, and the publication footnote records Government Gazette Vol. 139, Part 78a, page 17, dated 23 December 2022. Two hundred and forty days from 23 December 2022 expire on 20 August 2023, so the Decree is in force from 21 August 2023. The Sec. 43 transitional rule gave operators already trading on the day before commencement ninety days from that date to file the prior notification, a window that closed on 19 November 2023, and Sec. 44 gave the Sec. 8 paragraph four operators one year. This is Thailand's first entry on the tracker. It is the ASEAN counterpart of cn-algo-recommendation and of the EU ranking-transparency model rather than of the data-protection line: it reaches ranking, advertising and review-moderation algorithms as a platform-transparency duty owed to users, not a right of an individual data subject against a decision. Thailand's Personal Data Protection Act B.E. 2562 contains no equivalent of GDPR Art. 22, so no solely-automated-decision right is tracked for Thailand. Text read in the official English translation published by the Electronic Transactions Development Agency, the supervising authority named in the Decree; ratchakitcha.soc.go.th returns HTTP 403 on its legacy document paths, so the ETDA publication is cited.

Stated maximum penalty — The Decree carries administrative rather than monetary sanctions. Under Sec. 33, where an operator contravenes or fails to comply with the rules, procedures or conditions in Chapter II — which contains Sec. 17 — or with Notifications of the Commission or the Agency, the competent official shall order the operator to stop providing the digital platform service until the rules have been correctly and fully complied with; if the operator fails to comply with that order within ninety days of its issuance, the competent official shall revoke the acknowledgement of its notification from the notification registry, notify it in writing and publish the revocation publicly through the Sec. 14 channel. Revocation removes the operator's lawful basis to trade in Thailand, since Sec. 8 makes prior notification a condition of operation.

In force · 21 Aug 2023 checked 19 Sep 2026 Royal Decree on Digital Platform Service Businesses B.E. 2565 Sec. 17 ↗ high confidence

Türkiye 1

Türkiye Binding

KVKK art. 11(g) — a right to object with no offence of its own to enforce it

Binds Every data controller processing personal data in Türkiye, with no size, sector or turnover threshold — the right is asserted against «the data controller» without qualification, so enterprise, SME and public body alike. Art. 2 applies the Law to natural persons whose personal data are processed and to natural or legal persons processing personal data wholly or partly by automated means, or by non-automated means provided the processing forms part of a data filing system. The exemptions in arts. 28(1) and 28(2) are the boundary to check before assuming coverage, and the second of them matters here: art. 28(2) disapplies certain articles — but not the Law as a whole — where processing is, among other cases, necessary for preventive, protective and intelligence activities by public institutions charged with national defence, national security, public security or the economic security of the State, or is carried out for investigation, prosecution, trial or execution proceedings by judicial authorities. Hiring, credit scoring and insurance underwriting all fall inside the ordinary scope. Two practical features shape who is exposed. First, VERBİS: art. 16 requires controllers to enrol in the Data Controllers' Registry before beginning to process, subject to exemptions the Board sets by criteria including the number of employees, annual balance sheet total and the nature of the business, so the population of registered controllers is enumerated and the Authority knows where to look. Second, the representative rule — a controller not resident in Türkiye must appoint a representative there and enrol through it — so an offshore scoring engine reaching Turkish data subjects is not outside the frame. The limit to state plainly is the one in the text: art. 11(g) attaches to a result produced by analysing data processed «solely» through automated systems, and the Law offers no guidance on what degree of human involvement defeats that, nor has the Board issued a decision defining it.. Türkiye's automated-decision rule is a single sub-paragraph of a rights article, and it is drafted as an objection right rather than as a prohibition. Article 11 of Law No. 6698 on the Protection of Personal Data lists what a data subject may demand of a controller, and limb (g) gives the right «to object to the occurrence of a result against the person himself/herself by analyzing the data processed solely through automated systems». Read against GDPR art. 22 the differences are structural rather than cosmetic. There is no bar on taking the decision: the controller may make it, and the data subject's remedy is to object after the fact. There is no exception architecture, because a right to object needs none — no contract limb, no explicit-consent limb, no authorised-by-law limb, and so nothing corresponding to GDPR art. 22(2) or to the three ways out in s. 62(2) of Zambia's Act. There is no right to obtain human intervention and no right to contest as a distinct step, so the safeguard triad that Zambia carries in full is absent here. And there is no explanation limb anywhere: art. 11 runs (a) to (ğ) and none of its limbs is a logic-disclosure item, while the art. 10 duty to inform at the point of collection covers the controller's identity, the purpose of processing, to whom and for what purpose processed data may be transferred, the method and legal reason of collection, and the art. 11 rights themselves — it does not require a controller to volunteer that a decision was automated. The trigger wording is also narrower than the European one in a way worth preserving: «a result against the person» (kişinin kendisi aleyhine bir sonucun ortaya çıkması) requires an adverse outcome, where GDPR art. 22 catches legal or similarly significant effects whether adverse or not, and where the Swiss art. 21(1) reaches a decision with a legal consequence even absent adversity. A favourable automated decision produces no art. 11(g) right. The 2024 amendment to the Law, made by Law No. 7499 of 12 March 2024, rewrote art. 6 on special categories of personal data and art. 9 on transfers abroad and added the standard-contract notification duty now penalised in art. 18; it did not touch art. 11.

In force since 7 October 2016, and the publication date of the Law is not the operative date for this article. Law No. 6698 was published in the Official Gazette of 7 April 2016, No. 29677, and art. 32 splits commencement: most of the Law entered into force on publication, but arts. 8, 9, 11, 13, 14, 15, 16, 17 and 18 «shall enter into force after six months as of the date of its publication», which brings art. 11 — and with it limb (g) — to 7 October 2016. The 7 April 2016 date carried by most secondary accounts is the Law's date, not this obligation's, and the six-month tranche is easy to miss because it is stated once in the final article rather than in the rights article itself. The grouping is also informative: the same tranche carries art. 13 (application to the controller), art. 14 (complaint to the Board), art. 15 (examination by the Board) and art. 18 (misdemeanours), so the right and its entire enforcement route commenced together on one date, by design. Nothing since has moved it. Law No. 7499 of 12 March 2024, published 12 March 2024, amended arts. 6 and 9 and added a limb to art. 18 with its own 1 June 2024 commencement for the transfer regime, and left art. 11 untouched. Türkiye signed Convention 108+ on 10 October 2018 but has not ratified it, and the Convention itself is not in force, so art. 9(1)(a) of that instrument supplies no independent Turkish rule of the kind the Malabo Convention supplies for Namibia. A live watch, recorded rather than published: a draft AI law modelled on the EU AI Act was submitted to the Grand National Assembly in June 2024 and referred to committee, and successive drafts have circulated since; none has been enacted, so Türkiye has no AI-specific statute in force and art. 11(g) remains the operative automated-decision rule.

Stated maximum penalty — No fine attaches to art. 11(g) directly, and finding that out means reading art. 18 limb by limb rather than quoting the headline range. Art. 18(1) penalises exactly five things: failure to fulfil the art. 10 duty to inform; failure to fulfil the art. 12 data-security obligations; failure to comply with decisions issued by the Board under art. 15; breach of the art. 16 registry obligations; and, since Law No. 7499, failure to make the art. 9(5) standard-contract notification. Breach of a data subject's art. 11 rights is not among them. The enforcement route is therefore indirect and sequential, and it is the route the Law commenced alongside the right itself. Art. 13 requires the data subject to apply to the controller first, and the controller to conclude the request within thirty days at the latest. Art. 14 allows a complaint to the Personal Data Protection Board where the application is rejected, the reply is insufficient, or no reply arrives in time — within thirty days of learning the reply and in any case within sixty days of the application. Art. 15(5) then provides that where an infringement is established the Board «shall decide that the identified infringements shall be remedied by the relevant data controller», and that decision must be implemented without delay and within thirty days at the latest. Only if the controller fails to implement it does a fine become available, and it becomes available under art. 18(1)(c) — non-compliance with a Board decision — rather than under anything about art. 11. The statutory band for that limb is 25,000 to 1,000,000 Turkish lira as printed in the 2016 text, and the printed figures are not the payable ones: art. 18 fines are uprated for every calendar year under art. 17(7) of the Misdemeanour Law No. 5326 read with repeated art. 298 of the Tax Procedure Law No. 213, using the annual revaluation rate, so a decade of compounding sits between the statutory numbers and the current ones. The revalued figures are not published in this row because the Authority's own annual announcement was not retrieved for this check; the statutory band and the revaluation mechanism are recorded instead, and the current-year table should be read from the Authority before any figure is quoted. Two further routes exist alongside: art. 11(ğ) preserves a right to claim compensation for damage through the ordinary courts, and arts. 135 to 140 of the Turkish Penal Code No. 5237 create separate imprisonment offences for unlawful recording, transfer and non-deletion of personal data — none of which is an automated-decision offence. Impact tier: all entities.

In force · 7 Oct 2016 checked 19 Sep 2026 KVKK art. 11(g) ↗ high confidence

Tanzania 1

Tanzania Binding

Personal Data Protection Act s. 36 — rights in relation to automated decision making, with a duty to notify and reconsider

Binds Data controllers and data processors within the scope of s. 22(1): any collection and processing of personal data performed wholly or partly by manual or automated means; processing carried out in the performance of the activities of a controller domiciled in the United Republic or in a territory where its laws apply by virtue of international public law; and processing by a controller or processor not domiciled in the United Republic where the processing is in the United Republic and is not for mere transit of personal data through Tanzania to another country. Section 2 applies the Act to Mainland Tanzania as well as to Tanzania Zanzibar, save that in Zanzibar it does not apply to non-union matters, so a purely Zanzibari matter falls outside it. Registration with the Personal Data Protection Commission under ss. 14 to 16 is a precondition of acting as a controller or processor, and s. 21 deems public institutions that collect and process personal data registered from commencement. The s. 36(2) notify-and-reconsider duty binds any controller that takes a solely-automated decision significantly affecting a data subject, irrespective of size. Impact tier: all entities.. Section 36 of the Personal Data Protection Act, 2022 (Act No. 11 of 2022, Chapter 44) carries Tanzania's operative automated-decision rule, in Part VI (rights of data subjects). Subsection (1) lets a data subject, through the procedures prescribed in the regulations, require the data controller to ensure that any decision taken by or on behalf of the controller which significantly affects the data subject shall not be based solely on processing by automatic means. Subsection (2) operates without prejudice to that request and bites of its own force: where a decision which significantly affects a data subject is based solely on automated processing, the controller shall as soon as practicable notify the data subject that the decision was taken on that basis, and the data subject may require the controller to reconsider the decision. Subsection (3) disapplies the section where the decision is necessary for entering into or performance of a contract between the data subject and a data controller, is authorised by any written law, or is based on the data subject's explicit consent. Section 37 separately entitles a data subject who suffers damage by reason of any contravention of the Act to compensation from the controller or processor.

Commencement was deferred to a ministerial instrument and that instrument is identified on the face of the published Act: the Chapter 44 text as republished in the Special Gazette prints “[1st May, 2023]” together with “[GN. NO. 326 of 2023]” immediately above Part I, so Government Notice No. 326 of 2023 appointed 1 May 2023 as the date on which the Act, including s. 36, came into operation. The Act itself is Act No. 11 of 2022; the text relied on here is the Chapter 44 republication issued as Government Notice No. 395B in Special Supplement No. 21 to the Special Gazette of the United Republic of Tanzania No. 15 Vol. 104 of 13 June 2023, printed by the Government Printer, Dodoma. Section 36(1) is not self-executing — the data subject's requirement runs “through the procedures prescribed in the regulations”, which are the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 — but s. 36(2) is, because it applies “without prejudice to subsection (1)” and imposes the notification duty directly on the controller. The copy of those 2023 Regulations published by the Personal Data Protection Commission is a scanned image with no text layer, so the prescribed procedure could not be read and no claim about its content is made here; the entry rests on the statute. Coverage symmetry against the four African rows already tracked: s. 36 is drawn from the same UK Data Protection Act 1998 s. 12 lineage as gh-dpa-s41 rather than from GDPR art. 22, and the two are the closest pair on the tracker — both pair a request-based right with an automatic notify-and-reconsider duty. The difference is the clock: Ghana fixes hard twenty-one-day periods in both directions, while Tanzania says only “as soon as practicable” for the notification and sets no period at all for the controller's response, so Ghana remains the only African row with hard deadlines. Tanzania's carve-out in s. 36(3) is narrower than Ghana's s. 41(4) because it does not exclude pre-contractual consideration, and unlike ke-dpa-s35 it gives no right to demand a fresh non-automated decision — only reconsideration of the existing one. Text read in the copy of the Act published by the Personal Data Protection Commission, the supervisory authority established by s. 6 of the Act.

Stated maximum penalty — Enforcement is administrative and runs through Part VII. The Commission investigates complaints under ss. 39 to 42, may serve a notice of enforcement under s. 45 and a notice of penalty under s. 46, and s. 46 lists the factors bearing on the amount, including the nature, gravity and duration of the failure, compliance with previous enforcement or penalty notices, adherence to codes of ethics, and financial benefits gained or losses suffered. Section 47 caps the amount: the maximum penalty that may be imposed by the Commission in a penalty notice in relation to a contravention of the provisions of the Act is one hundred million Tanzanian shillings. Section 48 allows the Commission to review its own decision and s. 49 gives a person aggrieved by the administrative action, including directions in an enforcement notice or a penalty imposed, a right of appeal. Section 37 gives the data subject a separate entitlement to compensation from the controller or processor for damage suffered by reason of any contravention of the Act, and s. 50 governs payment of that compensation. The criminal offences in ss. 60 to 62 address unlawful disclosure and unlawful destruction, deletion, concealment or alteration of personal data and do not attach to s. 36.

In force · 1 May 2023 checked 10 Sep 2026 Personal Data Protection Act s. 36 (Act No. 11 of 2022) ↗ high confidence

Ukraine 1

Ukraine Binding

Personal Data Law art. 8 — protection from automated decisions, and a right to know the mechanism

Binds Володільці та розпорядники персональних даних — the owner and the processor of personal data under Law No. 2297-VI, with no size, sector or turnover threshold, so enterprise, SME and public body alike. Art. 1 extends the Law to processing carried out wholly or partly by automated means and to personal data held in or destined for a card index by non-automated means. Art. 25 excludes processing by a natural person exclusively for personal or household needs and processing exclusively for journalistic and creative purposes subject to a balancing test.. Ukraine's automated-decision rule is the oldest in this tracker's CIS set — binding since December 2012, thirteen years before Kazakhstan, Uzbekistan and Kyrgyzstan legislated. Art. 8(2)(13) gives a right to protection from an automated decision having legal consequences, with no 'solely automated' qualifier and no exceptions of any kind, and art. 8(2)(12) gives a standing right to know the mechanism of automatic processing — a logic-transparency right its neighbours withhold. There is no procedure, no deadline and no human-review right attached, and the only penalty route reaches natural persons alone.

In force since 20 December 2012 and unamended since. Points 12 and 13 were added to part two of art. 8 of the Law of Ukraine No. 2297-VI of 1 June 2010 «Про захист персональних даних» by Law No. 5491-VI of 20 November 2012, whose Final Provisions give it effect on the day after publication; the Rada record card for 5491-VI records first official publication in «Голос України» No. 241 of 19 December 2012 and the commencement event as 20 December 2012, and gives the act's state as Чинний. Neither point carries an «виключено» annotation in the consolidated text of 2297-VI (also Чинний, amended by 28 acts), so both are live. Two rights, and the drafting is unlike every peer this tracker carries. Point 13 gives the subject the right «на захист від автоматизованого рішення, яке має для нього правові наслідки» — protection from an automated decision that has legal consequences for them. There is NO exclusivity qualifier: the text says «автоматизованого рішення», not a decision based SOLELY on automated processing, so unlike GDPR art. 22, Kazakhstan's art. 19-1, Uzbekistan's art. 24 and Russia's 152-ФЗ art. 16 the trigger does not require the human to be out of the loop. It is also drafted as a bare right with NO exceptions at all — no consent exit, no contract exit, no «cases provided by law» exit — which is the widest trigger and the narrowest set of defences in the set. Against that, the effects threshold is the narrowest: «правові наслідки» only, with no «similarly significantly affects» limb and no Russian-style «иным образом затрагивающих» catch-all. Point 12 gives the subject the right «знати механізм автоматичної обробки персональних даних» — to know the MECHANISM of automatic processing. That is a standing logic-transparency right, and it is the thing the neighbouring regimes expressly do not give: the Uzbek and Kazakh entries both record that no right to disclosure of the logic exists there. What Ukraine lacks is machinery. Art. 8 attaches no procedure to either point — no objection mechanism, no time limit to answer (against Kazakhstan's three working days, Uzbekistan's ten and Russia's thirty), no duty to explain the individual decision, and no right to human intervention or re-decision. Art. 8(2)(6) supplies only the general access right and art. 16 the general access procedure with a thirty-day answer, neither specific to automated decisions. The right is enforced through the Verkhovna Rada Commissioner for Human Rights (art. 23) rather than by a dedicated supervisory authority. No AI-specific statute has been enacted in Ukraine; art. 8 is the binding hook.

Stated maximum penalty — KUpAP art. 188-39 part four — failure to observe the statutory personal-data protection procedure where it led to unlawful access to the data OR to violation of the data subject's rights — is the limb that reaches a breach of art. 8(2)(12)-(13): 100 to 500 НМДГ for citizens and 300 to 1,000 НМДГ for officials and citizens who are business entities. Part five doubles that for a repeat within a year, to 1,000-2,000 НМДГ. At 17 UAH per НМДГ (Tax Code s. XX, subdivision 1, point 5 — the carve-out to the tax social benefit is expressly limited to the QUALIFICATION of offences, not to the size of the sanction) that is roughly 1,700-8,500 UAH, 5,100-17,000 UAH and 17,000-34,000 UAH respectively, so the ceiling is about 34,000 UAH or 700 euro. The structural point matters more than the figure: the KUpAP addresses natural persons only — громадяни, посадові особи and громадяни — суб'єкти підприємницької діяльності — so a company that breaches art. 8 cannot itself be fined; only its officials can be, and there is no corporate administrative liability for personal-data breaches in Ukraine at all.

In force · 20 Dec 2012 checked 19 Sep 2026 UA Personal Data Law art. 8 ↗ high confidence

Uganda 1

Uganda Binding

Data Protection and Privacy Act s. 27 — notice-based right against solely-automated decisions, an automatic duty to notify and reconsider on a twenty-one-day clock, and a fourteen-day route to the regulator

Binds Data controllers within the scope of s. 1, which applies the Act to a person, institution or public body collecting, processing, holding or using personal data within Uganda, and to a person outside Uganda who collects, processes, holds or uses personal data relating to Ugandan citizens. “Authority” in s. 27(5) is the National Information Technology Authority — Uganda (NITA-U); the Personal Data Protection Office established by s. 4 sits within it and is charged by s. 5 with overseeing implementation and enforcement of the Act. Registration is a standing precondition of processing: s. 29 requires the Authority to register every person, institution or public body collecting or processing personal data in the data protection register. The s. 27 duties bind any controller that takes a solely-automated decision significantly affecting a data subject, irrespective of size or sector. Impact tier: all entities.. Section 27 of the Data Protection and Privacy Act, 2019 (Act 9 of 2019), headed “Rights in relation to automated decision-taking”, is Uganda's operative automated-decision rule and sits in the Part V block of data-subject rights at ss. 23 to 28. Subsection (1) lets a data subject, by notice in writing to a data controller, require the controller to ensure that any decision taken by or on behalf of the controller which significantly affects that data subject is not based solely on the processing by automatic means of personal data in respect of that data subject. Subsection (2) operates without prejudice to subsection (1) and therefore bites even where no such notice has been served: where a decision which significantly affects a data subject is based solely on automated processing, (a) the data controller shall as soon as reasonably practicable notify the data subject that the decision was taken on that basis, and (b) the data subject is entitled, by notice in writing, to require the controller to reconsider the decision within twenty-one days after receipt of that notification. Subsection (3) then gives the controller twenty-one days after receipt of that notice to inform the data subject in writing of the steps the controller has taken in compliance with it. Subsection (4) disapplies the section entirely where the decision is made in the course of considering whether to enter into a contract with the data subject, with a view to entering into the contract, in the course of the performance of the contract, or for a purpose authorised or required by or under any law. Subsection (5) adds an escalation the Ghanaian and Tanzanian analogues do not have: where the data subject is not satisfied with the controller's subsection (3) response, the data subject shall complain in writing to the Authority within fourteen days.

The Act carries no commencement clause of its own, so the default rule supplies the date: s. 14(1) of the Acts of Parliament Act (Chapter 2, Act 16 of 2000) provides that the commencement of an Act shall be such date as is provided in or under the Act, or where no date is provided, the date of its publication as notified in the Gazette, and s. 14(2) deems every Act to come into force at the first moment of the day of commencement. The Act was published in Uganda Gazette no. 21 of 3 May 2019, so s. 27 has been in force since 3 May 2019. The enacted text relied on here is the copy of Act 9 of 2019 published by the Ministry of ICT and National Guidance, which reproduces the printed impression certified by the Clerk to Parliament as a true copy of the bill on 04/02/2019 and the President's assent page dated 25/2/2019; the Clerk's authentication and assent pages were read directly, as was s. 27 in full. Section 39 lets the Minister, after consultation with the Authority, make regulations by statutory instrument; no statutory instrument text could be retrieved from an official host this run, so nothing is claimed here about subsidiary rules, and the entry rests on the statute alone. Coverage symmetry against the seven African rows already tracked: s. 27 belongs to the UK Data Protection Act 1998 s. 12 lineage rather than to GDPR art. 22, and it is a near-verbatim sibling of Ghana's gh-dpa-s41 and a closer sibling still of Tanzania's tz-pdpa-s36 — all three pair a notice-based right with an automatic notify-and-reconsider duty. Uganda now joins Ghana as the only African rows with hard deadlines, and it is the stricter of the two on the data subject's own side: Ghana's twenty-one-day clocks run to reconsideration and to the controller's answer, and Uganda replicates both in s. 27(2)(b) and s. 27(3), but Uganda alone then fixes a further fourteen-day period in s. 27(5) for complaining to the Authority if the answer does not satisfy. Its carve-out in s. 27(4) is as wide as Ghana's — pre-contractual consideration, contract formation and contract performance are all excluded outright, with no compensating safeguards required — and therefore wider than the GDPR-shaped exceptions in ke-dpa-s35, ng-ndpa-s37 and rw-law058-2021-art21. Unlike Kenya, it gives no right to demand a fresh non-automated decision, only reconsideration of the existing one. Two drafting wrinkles in the gazetted text: the printed s. 27(3) duplicates a verb, reading “the steps that the data controller has taken to take …”, and s. 27(5) refers to “sub clause (3)” rather than subsection (3).

Stated maximum penalty — Section 27 non-compliance is not itself an offence: Part VIII creates only three offences — unlawfully obtaining or disclosing personal data (s. 35, fine not exceeding two hundred and forty currency points or imprisonment for ten years or both), unlawfully destroying, deleting, concealing or altering personal data (s. 36, fine not less than two hundred and forty currency points or imprisonment not exceeding ten years or both) and sale of personal data (s. 37, fine not exceeding two hundred and forty five currency points or imprisonment not exceeding ten years or both) — and none of them reaches a solely-automated decision. The Schedule values one currency point at twenty thousand shillings, so the s. 35 to s. 37 ceilings are UGX 4,800,000, UGX 4,800,000 and UGX 4,900,000. Where an offence under ss. 35, 36 or 37 is committed by a corporation, s. 38(1) makes the corporation and every officer who knowingly and willfully authorised or permitted the contravention liable, and s. 38(2) lets the convicting court additionally order the corporation to pay a fine not exceeding two percent of its annual gross turnover. The route to a sanction for s. 27 is administrative and runs through the regulator: s. 27(5) requires the dissatisfied data subject to complain in writing to the Authority within fourteen days, s. 31 lets any person who believes a data collector, processor or controller is infringing their rights or violating the Act complain to the Authority in the prescribed manner, and s. 32 obliges the Authority to investigate every complaint and lets it direct the party to remedy the breach or take such action as the Authority specifies to restore the rights of the data subject. The Act attaches no fine to disobeying such a direction.

In force · 3 May 2019 checked 2 Sep 2026 Data Protection and Privacy Act s. 27 (Act 9 of 2019) ↗ high confidence

United Kingdom 2

UK Binding

UK DUAA 2025 — Automated Decision-Making reform (Arts. 22A–22D)

Binds UK controllers making significant automated decisions with legal or similarly significant effects on data subjects. Replaces UK GDPR Art. 22 default prohibition on significant automated decisions. Controllers may now make such decisions using any lawful basis (incl. legitimate interests), but must: notify data subjects pre-decision, allow representations, provide meaningful human review, and enable contest rights. Special category data remains more restricted.

In force February 5, 2026 per SI 2026/82 (Commencement No. 6). Replaces and substantively restructures UK GDPR Art. 22: removes default prohibition; adds mandatory pre-decision notification, representations, human review, and contest rights. Secondary legislation: UK GDPR (Amendment) Regulations 2026.

Stated maximum penalty — UK GDPR penalties (up to £17.5M or 4% global annual turnover — whichever higher); ICO enforcement

In force · 5 Feb 2026 checked 7 Sep 2026 DUAA 2025, ss.22A–22D (UK GDPR replacement for Art. 22) ↗ high confidence
UK Binding

UK SI 2026/425 — mandatory ICO code of practice on AI and automated decision-making

Binds Information Commissioner (duty to prepare the code); indirectly all UK controllers and processors developing or using AI or making automated decisions under the UK GDPR and DPA 2018 (except Part 4, intelligence services). Requires the Information Commissioner to prepare a statutory code of practice on good practice in processing personal data for (a) developing and using AI and (b) automated decision-making under Arts. 22C(1) UK GDPR / s.50C(1) DPA 2018. The code must include guidance on children's personal data. Once issued, the code is admissible in evidence and regulators and courts must take it into account, so it will set the compliance benchmark for UK controllers developing or deploying AI.

Made 16 April 2026, laid before Parliament 21 April 2026, in force 12 May 2026 (reg. 1(2): 21 days after laying). Powers: DPA 2018 ss.124A(1)-(2) and 124B(11), inserted by Data (Use and Access) Act 2025 ss.92(2) and 93. Reg. 3 modifies the s.124B panel requirement so the panel must not consider or report on any aspect of the code relating to national security. The code itself has NOT yet been issued or consulted on — no publication date is set in the instrument, so the code's own commencement is date TBD; the ICO lists 'Code of Practice on AI and Automated Decision Making' among its current AI work areas. The Explanatory Note states no significant sector impact from the instrument itself; the impact falls when the ICO produces the code (for which the ICO must produce its own impact assessment). Extends to England and Wales, Scotland and Northern Ireland. Companion to uk-duaa-adm.

Stated maximum penalty — No penalty in the instrument itself; the resulting code is enforced through UK GDPR/DPA 2018 powers (up to £17.5M or 4% of global annual turnover, whichever is higher)

In force · 12 May 2026 checked 7 Sep 2026 SI 2026/425 (DPA 2018 AI & ADM Code of Practice Regs) ↗ high confidence

United States 29

US · NY Binding

AI Companion Models Law (GBL Art. 47)

Binds Operators of AI companion models serving New York users (excludes customer-service / internal-productivity-only systems). AI-identity disclosure at session start + every 3h and suicide/self-harm crisis referral (988) for AI companion operators; NY AG enforces.

Stated maximum penalty — Up to $15,000/day per violation (AG only; no private right of action)

In force · 5 Nov 2025 checked 15 Sep 2026 NY GBL Art. 47 ↗ high confidence
US · CA Binding

AB 2013 — GenAI training-data transparency

Binds Developers of generative AI systems made available to Californians. Public dataset-summary disclosure for generative AI offered to Californians.

Stated maximum penalty — Civil enforcement

In force · 1 Jan 2026 checked 15 Sep 2026 AB 2013 ↗ high confidence
US · CA Binding

California companion-chatbot safeguards (SB 243)

Binds Operators of companion-chatbot platforms available in California. AI-status disclosure + self-harm protocols.

Stated maximum penalty — Private right of action

In force · 1 Jan 2026 checked 15 Sep 2026 SB 243 ↗ high confidence
US · TN Binding

Tennessee AI regulation study mandate (SB 1700 / PC 1082, "CHAT Act")

Binds Tennessee Advisory Commission on Intergovernmental Relations (TACIR) — study mandate only; imposes no compliance duties on AI operators. As enacted, SB 1700 does not impose chatbot safety requirements on operators. Senate amendments stripped the original companion-chatbot restrictions and replaced them with a directive for TACIR to study potential AI/chatbot regulation (federal law, other states' approaches, constitutional issues, minor/mental-health safeguards, economic impact); no report deadline is specified.

Effective 2026-05-22, the date carried in the "Effective date(s)" field of the Tennessee General Assembly bill-status record; Section 4 of Public Chapter 1082 reads "This act takes effect upon becoming a law, the public welfare requiring it" (publications.tnsosfiles.com/acts/114/pub/pc1082.pdf), so there is no deferred application. The same record lists the governor's signature action on 2026-05-27; the enrolled chapter's approval stamp is a handwritten scan and is not machine-readable, so the 05/22 effective date is taken from the legislature's own field rather than reconstructed from the signature. Bill was substantially amended (Senate amendments adopted 2026-04-14) before passage, removing the original chatbot-safety restrictions.

Stated maximum penalty — None — study mandate only; no compliance obligation imposed on AI operators

In force · 22 May 2026 checked 15 Sep 2026 SB 1700 / PC 1082 ↗ high confidence
US · NY Binding

New York Synthetic Performer Disclosure Law (S.8420-A / Ch. 617)

Binds Persons, firms, or corporations engaged in commerce who produce or create advertisements using synthetic performers with actual knowledge of their use in New York. Requires conspicuous disclosure when AI-generated synthetic performers (digitally created human assets not recognizable as any identifiable real person) appear in advertisements in any medium — newspapers, magazines, radio, TV, streaming, billboards, and transit. Advertisers must have actual knowledge of synthetic performer use. Exempts expressive works, audio-only ads, and language-translation uses.

Stated maximum penalty — $1,000 first violation; $5,000 subsequent violations (civil penalties)

In force · 9 Jun 2026 checked 15 Sep 2026 S.8420-A / Ch. 617 (2025) ↗ high confidence
US · WA Binding

Washington Prior Authorization AI Transparency Act (SB 5395)

Binds Private health carriers and public employee health plans using AI in prior authorization in Washington. AI cannot be sole basis for denying health care services; human clinical review required for AI-generated denials.

Annual reporting to OIC on AI-generated prior auth statistics required.

Stated maximum penalty — OIC enforcement (civil penalties; license actions)

In force · 11 Jun 2026 checked 15 Sep 2026 SB 5395 ↗ high confidence
US · RI Binding

Rhode Island Healthcare AI Documentation Act (H 7538)

Binds Healthcare providers (physicians, PAs, dentists, RNs, LPNs, APRNs, nursing assistants, other DOH-licensed professionals) and healthcare facilities (§ 23-17-2) in Rhode Island. R.I. Gen. Laws ch. 23-106. Healthcare providers and healthcare facilities that employ AI to document in-person or telehealth visits must notify patients of that use and must review the AI-generated documentation for accuracy after the visit (§ 23-106-3).

Enacted as Substitute A (LC004720/SUB A) creating R.I. Gen. Laws ch. 23-106; signed 22 June 2026; effective upon passage. Verified against the enacted Sub A text 2026-08-10.

Stated maximum penalty — RI healthcare licensing enforcement

In force · 22 Jun 2026 checked 15 Sep 2026 H 7538 ↗ high confidence
US · IA Binding

Iowa Conversational AI Safety Act (SF 2417)

Binds Operators of conversational AI services serving Iowa consumers. Disclosure and safeguard obligations for conversational AI operators serving Iowa users; compliance applicable 2027-07-01.

Law in force 2026-07-01; compliance obligations applicable from July 1, 2027.

Stated maximum penalty — Civil enforcement by Iowa AG (amount TBD)

In force · 1 Jul 2026 checked 15 Sep 2026 SF 2417 ↗ high confidence
US · HI Binding

Hawaii AI Disclosure and Safety Act (SB 3001 / Act 248)

Binds Operators of conversational AI services accessible in Hawaii. AI-identity disclosure, minor safeguards, and suicide-prevention protocols for conversational AI operators.

Annual crisis-intervention referral reports to Behavioral Health Administration beginning 2028-01-01.

Stated maximum penalty — $1,000/violation up to $1,000,000/operator

In force · 14 Jul 2026 checked 15 Sep 2026 SB 3001 / Act 248 ↗ high confidence
US · CA Binding

California AI Transparency Act (SB 942)

Binds Covered GenAI providers with >1M monthly users accessible in California. AI-detection tool + content provenance for >1M-user providers.

Operative 2 August 2026 under Bus. & Prof. Code s 22757.6 as amended by AB 853, which pushed the original 1 January 2026 start date back. Covers the s 22757.3 covered-provider duties: a free public AI-detection tool, latent disclosures in AI-generated image, video and audio output, and an optional manifest disclosure. A covered provider is one whose GenAI system has over 1,000,000 monthly visitors or users and is publicly accessible within California (s 22757.1(d)). AB 853's later tranches are tracked as us-ca-ab853 (1 January 2027) and us-ca-ab853-capture-device (1 January 2028).

Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)

In force · 2 Aug 2026 checked 15 Sep 2026 SB 942 (amd. AB 853) ↗ high confidence
US · CO Binding

Colorado Psychotherapy AI Restrictions (HB 26-1195)

Binds Regulated psychotherapy professionals in Colorado using AI; any entity misrepresenting AI as professional-equivalent. AI cannot deliver psychotherapy without licensed professional's real-time involvement; disclosure and written consent required.

Signed 3 Jun 2026 by Gov. Polis; enacted without a safety clause, so the general post-session effective date applies. IN FORCE since 12 Aug 2026 — the Colorado General Assembly bill record (leg.colorado.gov/bills/hb26-1195) lists the session law as Chapter 358 with Effective Date 08/12/2026, re-confirmed on the day of entry into force. No amendments or delays. Unaffected by the stipulated enforcement stay in X. AI LLC v. Weiser, which reaches only SB 24-205 and its in-session replacement SB 26-189; no injunction has issued in that case. AG holds exclusive enforcement; $20,000 per violation; 60-day cure period.

Stated maximum penalty — Unfair trade practice (CO Consumer Protection Act; AG enforcement); $20,000 per violation

In force · 12 Aug 2026 checked 15 Sep 2026 HB 26-1195 ↗ high confidence
US · AL Binding

Alabama AI Health Insurance Transparency Act (SB 63)

Binds Health insurers using AI in coverage determinations in Alabama. AI may not be sole basis for coverage denial; health insurers must disclose AI use and file annual certification with Alabama DOI.

Annual certification to Alabama DOI required.

Stated maximum penalty — Alabama DOI disciplinary action (license revocation/suspension)

Applies 1 Oct 2026 checked 22 Sep 2026 SB 63 ↗ high confidence
US · CT Binding

Connecticut PA 26-15 (SB 5) tranche 1 — subscription AI, frontier models, synthetic content, state agencies

Binds Subscription-based AI providers, frontier developers, generative AI providers with >1,000,000 monthly users publicly accessible for personal use, and CT state agencies. Subscription-based AI providers give consumer disclosures; frontier developers publish safety frameworks; large generative providers embed provenance data; state agencies gated on OPM/DAS AI policies.

Public Act No. 26-15, signed by the Governor 27 May 2026. This row carries the 1 Oct 2026 tranche: s 2 (frontier developer duties), s 15 (covered provider provenance/detectability of synthetic digital content, >1,000,000 monthly users), s 38 (state agency AI use and procurement). Public Act No. 26-100 (companion HB 5222, signed 2 June 2026) s 67 repealed PA 26-15 s 1 effective from passage and replaced the subscription-based provider disclosure duty with a narrower rule at PA 26-100 s 46, still effective 1 Oct 2026 and still applying to subscription-based providers of generative AI systems with >1,000,000 monthly users publicly accessible for personal use, enforced solely by the AG under CUTPA. The Act's later tranches are carried as separate rows: AI companions 1 Jan 2027 (us-ct-sb5-companion), automated employment-related decision technology 1 Oct 2027 (us-ct-sb5-aedt), covered-platform minors 1 Jan 2028 (us-ct-sb5-minors). Sections 17, 18, 31 (AI Academy, working group, higher-education alliance) took effect 1 Jul 2026 but create state-programme duties only, not private-sector obligations. Bill status page: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&bill_num=SB5&which_year=2026

Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)

Applies 1 Oct 2026 checked 22 Sep 2026 CT PA 26-15 (SB 5) ↗ high confidence
US · CA Binding

California AI Transparency Act — AB 853 large online platform & GenAI hosting platform duties

Binds Large online platforms (public-facing social media, file-sharing, mass messaging or stand-alone search) exceeding 2,000,000 unique monthly users over the preceding 12 months; and GenAI hosting platforms offering model weights or source code for download. Large online platforms must detect, display and preserve content provenance data; GenAI hosting platforms may not offer models that omit AI disclosures.

AB 853 (approved by the Governor 13 October 2025) adds three tranches to the California AI Transparency Act. The covered-provider regime under Bus. & Prof. Code s 22757.3 became operative 2 August 2026 and is tracked separately as us-ca-sb942. This entry covers the second tranche: s 22757.3.1 (large online platform provenance detection, a provenance user interface, user inspection/download, and a bar on knowingly stripping provenance data or digital signatures) and s 22757.3.2 (GenAI hosting platforms may not knowingly make available a GenAI system that omits s 22757.3 disclosures). Both carry an express operative date of 1 January 2027 (s 22757.3.1(c), s 22757.3.2(b)). The capture-device manufacturer tranche starts 1 January 2028 and is tracked as us-ca-ab853-capture-device. Threshold correction 2026-08-12: the large online platform test is 2,000,000 unique monthly users (s 22757.1(h)(1)), not the 1,000,000 figure that governs covered providers; broadband internet access service and telecommunications service are excluded. Note a drafting inconsistency in the enacted text: s 22757.3.2 uses 'GenAI system hosting platform' while the defined term at s 22757.1(g) is 'GenAI hosting platform'.

Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)

Applies 1 Jan 2027 checked 20 Sep 2026 AB 853 (amds. SB 942) ↗ high confidence
US · CO Binding

Colorado Conversational AI Safety Act (HB 26-1263)

Binds Conversational AI operators serving Colorado users. Safety, disclosure, and minor protection obligations for conversational AI operators in Colorado.

Signed 2026-05-29; legal effective date 2026-08-12; compliance obligations from 2027-01-01. Implementing rules are in progress: the Colorado Department of Law filed proposed ADMT & Conversational AI Service rules (4 CCR 904-6) covering both this act and SB 26-189 with the Secretary of State on 11 Aug 2026, with comments open 11 Aug–26 Oct 2026 (4 Sep 2026 for comments feeding the revised draft) and a rulemaking hearing on 26 Oct 2026; the rules are slated to take effect 1 Jan 2027. This act is outside the X. AI LLC v. Weiser enforcement stay, which reaches only SB 24-205 and its in-session replacement SB 26-189.

Stated maximum penalty — CO AG enforcement

Applies 1 Jan 2027 checked 20 Sep 2026 HB 26-1263 ↗ high confidence
US · DE Binding

Delaware DPDPA Amendment — Employment-Data Exemption Narrowed for Profiling and Reports (HB 380)

Binds Controllers conducting business in Delaware, or targeting products or services to Delaware residents, that processed the personal data of at least 10,000 consumers in the preceding calendar year (or 5,000 with >20% of gross revenue from selling personal data) — including employers and HR-technology vendors profiling applicants, employees, agents or independent contractors, and third parties receiving reports used in employment decisions. HB 380 amends the Delaware Personal Data Privacy Act (6 Del. C. ch. 12D) so that the employment-context exemption at § 12D-103(c)(14) no longer covers "personal data processed in connection with profiling and reports under § 12D-106(f)" — bringing AI resume screeners, interview-scoring tools and workforce-analytics reports used for hiring, promotion, discipline and termination inside the Act for applicants, employees, agents and independent contractors. New § 12D-106(f) requires a controller that discloses a "report" to a third party for use in a decision producing legal or similarly significant effects to contract for adverse-action notice, a description of the personal data relied on, and human review of the adverse action where technically feasible; and, on a resident's request, to supply within 30 days the personal data held, the source of the data used in profiling, the identity of every third party that received a report in the previous 24 months, and a chance to correct it. "Report" is newly defined to include "automated decisions based on personal data or profiling", and the § 12D-104(a)(6)c profiling opt-out is broadened from "solely-automated" to "automated" decisions. Applicability drops from 35,000 to 10,000 consumers (§ 12D-103(a)(1)) and the data-protection-assessment trigger from 100,000 to 50,000 (§ 12D-108(a)). § 12D-106(g) carves out scores, models and algorithms furnished as FCRA consumer reports.

Signed by Gov. Matt Meyer on 2 September 2026 alongside HB 381. Section 2 of the enrolled Act reads in full "This Act is effective January 1, 2027." — a single effective date with no staggered or delayed provisions; the word "effective" appears nowhere else in the Act in a commencement sense. The Delaware General Assembly BillDetail page still displayed "Status: Passed 6/16/26 / Ready for Governor for action" with a blank Effective Date field when checked on 3 September 2026, and no session-law chapter document had yet been attached — a known publication lag on that site, not a contradiction: the signature is confirmed by the Governor's own press release of 2 September 2026 on news.delaware.gov.

Stated maximum penalty — No bespoke penalty. Under § 12D-111(e) a violation "shall be deemed an unlawful practice under § 2513 of this title and a violation of subchapter II of Chapter 25 of this title, and shall be enforced solely by the Department of Justice"; 6 Del. C. § 2522(b) sets a civil penalty of not more than $10,000 for each wilful violation, with cease-and-desist, restitution, rescission and asset-freeze relief available under § 2522(c). No private right of action. Since 1 January 2026 the 60-day cure period is discretionary rather than mandatory (§ 12D-111(c)).

Applies 1 Jan 2027 checked 20 Sep 2026 DE HB 380 (DPDPA amendment) ↗ high confidence
US · IL Binding

Illinois AI Teacher Evaluation Restrictions (SB 2909 / PA 104-0565)

Binds Public school evaluators and teachers subject to Illinois teacher evaluation requirements. Prohibits evaluators from using AI to assign numerical scores or qualitative ratings in teacher performance evaluations; prohibits teachers from using AI to generate evaluation evidence. AI may still assist with administrative tasks. Teachers must disclose AI tool name and purpose if used for support.

Signed 2026-07-10 by Governor Pritzker; effective 2027-01-01.

Stated maximum penalty — Administrative enforcement; no direct monetary penalty specified

Applies 1 Jan 2027 checked 21 Sep 2026 SB 2909 / PA 104-0565 ↗ high confidence
US · OR Binding

Oregon AI Companion Act (SB 1546 / Ch.85)

Binds AI companion and chatbot platform operators serving Oregon users. AI disclosure, self-harm protocols, and minor protections; first chatbot law with private right of action and per-violation statutory damages.

Stated maximum penalty — Greater of actual damages or $1,000 per violation; private right of action; attorney fees

Applies 1 Jan 2027 checked 20 Sep 2026 SB 1546 / Ch.85 ↗ high confidence
US · RI Binding

Rhode Island AI Chatbot Safety Act (S 2195)

Binds Chatbot and companion AI operators serving Rhode Island users. Chatbot/companion AI operators must include suicidal-ideation protocols and crisis referrals; annual reporting to AG from 2027-07-01.

Signed 2026-06-22 by Governor McKee; general effective date 2027-01-01. Annual reports to RI AG beginning July 1, 2027.

Stated maximum penalty — RI AG enforcement

Applies 1 Jan 2027 checked 20 Sep 2026 S 2195 ↗ high confidence
US · UT Binding

Utah AI Prior Authorization Disclosure Act (SB 319)

Binds Health insurers operating in Utah for prior authorization processes. Insurers must disclose AI use in prior authorization reviews; adverse determinations must reflect independent medical judgment.

Stated maximum penalty — Disclosure to Utah Insurance Department required

Applies 1 Jan 2027 checked 20 Sep 2026 SB 319 ↗ high confidence
US · WA Binding

Washington AI Companion Chatbot Safety Act (HB 2225 / Ch.168)

Binds AI companion chatbot operators serving Washington users. Non-human disclosure, minor safeguards, and self-harm protocols for AI companion chatbot operators.

Disclosures every 3 hours (all users) or 1 hour (minor users).

Stated maximum penalty — Actual damages + injunctive relief + attorney fees; WA AG (Consumer Protection Act)

Applies 1 Jan 2027 checked 20 Sep 2026 HB 2225 / Ch.168 ↗ high confidence
US · WA Binding

Washington AI Content Disclosure Act (HB 1170 / Ch.167)

Binds AI content creators and operators serving Washington users. Operators/creators must inform users when content is developed or modified through AI.

Signed 2026-03-24; codified as Chapter 167, Laws of 2026. Enforced exclusively by the WA Attorney General under the Consumer Protection Act (ch. 19.86 RCW).

Stated maximum penalty — Civil penalty up to $100,000 per covered provider (WA Consumer Protection Act, ch. 19.86 RCW; AG enforcement only)

Applies 1 Feb 2027 checked 20 Sep 2026 HB 1170 / Ch.167 ↗ high confidence
US · GA Binding

Georgia Conversational AI Safety Act (SB 540)

Binds Operators of conversational AI chatbot services accessible to the Georgia public. Age verification, parental controls, AI-identity disclosure, and crisis protocols for conversational AI chatbot operators.

Stated maximum penalty — Up to $10,000 per knowing violation (GA AG enforcement)

Applies 1 Jul 2027 checked 15 Sep 2026 SB 540 ↗ high confidence
US · ID Binding

Idaho Conversational AI Safety Act (SB 1297)

Binds Consumer-facing conversational AI service operators serving Idaho users (excludes B2B, internal, customer-service bots). AI identity disclosure, crisis referral protocols, and minor safeguards for consumer-facing conversational AI operators.

Modeled on Nebraska LB 525. Signed 2026-03-31 (Idaho Legislature bill-status page; corrected from a prior 2026-04-01 note).

Stated maximum penalty — Idaho AG enforcement (amount TBD)

Applies 1 Jul 2027 checked 15 Sep 2026 SB 1297 ↗ high confidence
US · NE Binding

Nebraska Conversational Artificial Intelligence Safety Act (LB 525)

Binds Conversational AI service operators serving Nebraska users. Operators of consumer-facing conversational AI services must disclose AI nature, apply enhanced safeguards for minors, avoid claiming to provide professional mental health care, and provide crisis intervention referrals.

Signed April 14, 2026; operative July 1, 2027 (sections 12–18).

Stated maximum penalty — $1,000 per violation; up to $500,000 per operator per enforcement action; Nebraska AG enforcement only

Applies 1 Jul 2027 checked 15 Sep 2026 LB 525 ↗ high confidence
US · CT Binding

Connecticut PA 26-15 (SB 5) tranche 3 — automated employment-related decision technology

Binds Developers and deployers of automated employment-related decision technology deployed in Connecticut on or after 1 Oct 2027. Developers and deployers have until 1 Oct 2027, when the duties attach to any automated employment-related decision technology deployed in Connecticut on or after that date.

Public Act No. 26-15 ss 7-12. Date nuance: the sections themselves are '(Effective October 1, 2026)', but the operative duties in ss 8, 9 and 10 each attach only to technology 'deployed in the state on or after October 1, 2027', so 1 Oct 2027 is the date on which the obligations bite. s 8 is the developer-to-deployer disclosure; ss 9-10 are the deployer notice duties; s 11 carries the trade-secret carve-out; s 12 makes violations of ss 8-11 unfair or deceptive trade practices enforced solely by the Attorney General.

Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)

Applies 1 Oct 2027 checked 15 Sep 2026 CT PA 26-15 (SB 5) ss 7-12 ↗ high confidence
US · CA Binding

California AI Transparency Act — AB 853 capture device latent disclosures

Binds Capture device manufacturers, for any capture device first produced for sale in California on or after 1 January 2028 (cameras, mobile phones with built-in cameras or microphones, voice recorders); no user threshold applies. Camera, phone and recorder makers must offer, and switch on by default, latent provenance disclosures in captured content.

Bus. & Prof. Code s 22757.3.3, added by AB 853 (approved 13 October 2025). A capture device manufacturer must (1) give the user the option to include a latent disclosure in content captured by the device and (2) embed latent disclosures by default, in each case only to the extent technically feasible and consistent with widely adopted specifications from an established standards-setting body. The duty attaches to devices first produced for sale in the state on or after 1 January 2028, and s 22757.3.3(c) sets the same operative date. Unlike the covered-provider (1,000,000 monthly users) and large online platform (2,000,000 unique monthly users) tranches, this one has no size threshold: s 22757.1(c)(1) defines a capture device manufacturer simply as a person who produces a capture device for sale in the state. Added 2026-08-12 to close a coverage gap; the 2028 date previously appeared in no entry.

Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)

Applies 1 Jan 2028 checked 15 Sep 2026 AB 853 (amds. SB 942) ↗ high confidence
US · CT Binding

Connecticut PA 26-15 (SB 5) tranche 4 — covered-platform restrictions for minors

Binds Covered operators of covered platforms serving Connecticut users who are under eighteen. Covered platform operators have until 1 Jan 2028 before personalised feed and related restrictions apply to users under 18.

Public Act No. 26-15 s 39, expressly '(Effective January 1, 2028)'. Bars a covered operator from serving a covered minor a personalised recommendation feed based on information associated with the user or the user's device unless one of the listed conditions is met, including commercially reasonable and technically feasible age determination or verifiable parental consent. s 39(g) deems violations of subsections (b)-(e) unfair or deceptive trade practices under Conn. Gen. Stat. s 42-110b(a).

Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)

Applies 1 Jan 2028 checked 15 Sep 2026 CT PA 26-15 (SB 5) s 39 ↗ high confidence

Uruguay 1

Uruguay Binding

Ley 18.331 art. 16 — an automated-decision right that started out automation-blind, and the only one that makes the program itself explainable

Binds Responsables de bases de datos and encargados de tratamiento — the controller and processor analogues — plus, in the words of art. 35, «demás sujetos alcanzados por el régimen legal». Art. 3 applies the Law to personal data recorded on any medium that makes them susceptible of processing, and art. 16 para. 2 names administrative acts and private decisions side by side, so the rule reaches the State and the private sector alike with no sectoral carve-out. Art. 2 extends the data-protection right by analogy to legal persons «en cuanto corresponda», which is unusual: most of the atlas protects natural persons only. Art. 46 gave existing databases one year from entry into force to comply. Impact tier: all entities.. Art. 16 of Ley Nº 18.331 de Protección de Datos Personales y Acción de «Habeas Data» (promulgated 11 August 2008, Diario Oficial of 18 August 2008, Registro Nacional de Leyes y Decretos 2008 t. 1 s. 2 p. 378) is Uruguay's automated-decision right, and it is the only entry in the atlas whose automation trigger was put there by amendment rather than by the original drafter. As enacted in 2008 the article read «que se base en un tratamiento automatizado o no de datos» — a processing of data, automated OR NOT. Art. 152 of Ley Nº 18.719 of 27 December 2010, the National Budget Act, struck the words «o no». Uruguay therefore began where Armenia still is, with a decision rule indifferent to whether a machine was involved, and legislated its way to the Directive 95/46 art. 15 shape; every other narrowing in the atlas runs from a European template outward, not the reverse. The current text has three paragraphs and each does distinct work. Para. 1 is the right proper: «Las personas tienen derecho a no verse sometidas a una decisión con efectos jurídicos que les afecte de manera significativa, que se base en un tratamiento automatizado de datos destinado a evaluar determinados aspectos de su personalidad, como su rendimiento laboral, crédito, fiabilidad, conducta, entre otros» — a right not to be subjected to a decision with legal effects significantly affecting the person, based on automated processing intended to evaluate certain aspects of their personality, such as work performance, credit, reliability or conduct. The list is open («entre otros»), and the trigger is cumulative in a way GDPR art. 22 is not: the decision must have legal effects AND affect the person significantly, where GDPR art. 22(1) offers legal effects OR similarly significant effect as alternatives. Para. 2 is a challenge right rather than an abstention right, and it is where the «solely» test sits: the affected person may contest «los actos administrativos o decisiones privadas» — administrative acts and private decisions — implying an assessment of their conduct «cuyo único fundamento sea un tratamiento de datos personales que ofrezca una definición de sus características o personalidad». Public and private decisions are named in the same breath, so there is no public-sector carve-out. Para. 3 is the finding. On challenging, the person is entitled to information from the controller «tanto sobre los criterios de valoración como sobre el programa utilizado en el tratamiento que sirvió para adoptar la decisión manifestada en el acto» — both the valuation criteria and THE PROGRAM used in the processing that served to adopt the decision. Only one other instrument in the atlas names the software itself in an explanation duty — art. 20(c) of Ecuador's LOPDP, which entitles the challenger to «los criterios de valoración sobre el programa automatizado», the criteria bearing on the program — and Uruguay goes a step further by making the program itself, and not only the criteria about it, part of what is disclosed. GDPR art. 15(1)(h) and its transpositions ask for meaningful information about the logic involved, which is deliberately one abstraction level above the program. Uruguay drafted it a level below, in 2008, and kept it through the 2010 recast. What the 2010 recast did remove, besides «o no», was a fourth paragraph with no counterpart anywhere in the atlas: «La valoración sobre el comportamiento de las personas, basada en un tratamiento de datos, únicamente podrá tener valor probatorio a petición del afectado» — an assessment of a person's conduct based on data processing could have evidentiary value only at the request of the affected person. That was an evidence rule, not a data-protection rule, and it is gone. There are no exits. Art. 16 states no contract, consent or authorising-law exception of the GDPR art. 22(2) kind, and no special-categories bar of the art. 22(4) kind. There is no express right to human intervention either: the remedy is impugnación plus the information duty in para. 3, backed by the habeas data action in arts. 37 to 45 and by the Unidad Reguladora y de Control de Datos Personales. The word «perfilado» does not appear in the Law; the concept is carried by the phrase «una definición de sus características o personalidad».

In force. Ley 18.331 contains no vigencia clause, so the default in art. 1 of the Código Civil applies — promulgation «se reputará sabida diez días después de verificada en la Capital» — which puts the Law, published in the Diario Oficial of 18 August 2008, in force on 28 August 2008; the date is computed from the statute rather than stated by it. The wording tracked here is not the 2008 wording: art. 152 of Ley 18.719 (promulgated 27 December 2010, published 5 January 2011, and carrying no special vigencia note for that article, so in force 15 January 2011 on the same ten-day rule) recast arts. 9, 14, 15, 16, 21, 22, 28 and 35 together. Both texts were read on IMPO, the official normative documentation service — the consolidated article at /bases/leyes/18331-2008/16 and the enacted article at /bases/leyes-originales/18331-2008/16 — and they differ in exactly two places in para. 1 and in the deletion of the original para. 4. IMPO records no later amendment to art. 16; Ley 19.670 (2018) and Ley 19.924 (2020) added arts. 37 to 40 on the data protection officer, impact assessment, breach notification and extraterritorial reach without touching it. No AI-specific statute imposes obligations: arts. 74 and 75 of Ley Nº 20.212 of 6 November 2023 are mandates addressed to AGESIC — to design a national data and AI strategy jointly with the URCDP wherever personal data are involved, to report to the Legislature within 180 days with recommendations for legal regulation, and to run controlled testing environments cleared by a technical committee — not duties on regulated entities, so they are not tracked as an obligation.

Stated maximum penalty — Up to 500,000 UI (unidades indexadas) under art. 35(3), on a five-rung ladder that runs observation, warning, fine, five-day suspension of the database and closure of the database, graduated by gravity, repetition and recidivism. The UI is an inflation-indexed unit, so the ceiling floats rather than eroding — the mechanism Uruguay uses instead of the GDPR's turnover percentage, and the reason the 2008 figure has not been overtaken. There is no turnover-linked band, no separate corporate tier and no minimum. Unlike Montenegro's art. 74 and Kosovo's art. 92, art. 35 does not enumerate offences by article number: it reaches any case «que se violen las normas de la presente ley», so art. 16 carries the full ceiling with no interpretive step. Art. 35 was itself recast by art. 152 of Ley 18.719, and its closure rung by art. 83 of Ley 19.355 of 19 December 2015. Final monetary resolutions of the URCDP are directly enforceable as título ejecutivo.

In force · 28 Aug 2008 checked 16 Sep 2026 Ley 18.331 art. 16 ↗ high confidence

Uzbekistan 1

Uzbekistan Binding

Personal Data Law art. 24 — solely automated decisions

Binds Owners and operators of personal data (собственник и (или) оператор) processing personal data under Law ЗРУ-547. Right not to be subject to a decision based solely on automated processing, with three exits, plus duties to explain the decision, accept an objection and answer it within ten days.

Art. 24 of Law No. ЗРУ-547 of 2 July 2019 'On Personal Data'. Date is not derived: art. 36 of the Law states it enters into force on 1 October 2019. Art. 24 is ORIGINAL text — the 01.10.2019 redaction on lex.uz and the current 25.07.2026 redaction are word-for-word identical, so none of the five subsequent amendment rounds touched it. Structure is close to GDPR 22 and, unlike Russia's 152-FZ art. 16 (ru-152fz-art16), it DOES have a contract limb: a solely automated decision affecting the subject's rights and legitimate interests and producing legal consequences is barred unless (a) the subject consented in writing, including by electronic document, (b) the decision is taken in performance of a contract between owner and subject or to fulfil the conditions of a previously concluded contract, or (c) legislation provides for it. Part three then imposes three affirmative duties on the owner/operator — explain how the decision is taken and its possible legal consequences, give the subject the opportunity to object, and explain how the subject may defend their rights — and part four requires the objection to be considered and the outcome notified to the subject in WRITING WITHIN TEN DAYS, a third of Russia's thirty. What the article does not give: no right to disclosure of the logic, and no right to have the decision changed or re-taken by a human. On penalties, no KoAO article names art. 24; art. 46² part one reaches unlawful use of personal data generally (7 BRV for citizens, 50 BRV for officials), and since 21 Jan 2026 part two reaches unlawful AI processing coupled with dissemination (uz-koao-46-2-ai).

Stated maximum penalty — No article names art. 24; KoAO art. 46²(1) reaches unlawful processing generally (7 BRV citizens / 50 BRV officials)

In force · 1 Oct 2019 checked 10 Sep 2026 Law ЗРУ-547 art. 24 ↗ high confidence

Vietnam 2

Vietnam Comprehensive

AI-content labelling & interaction disclosure

Binds Providers / deployers of generative AI and user-facing AI systems. Machine-readable labels on AI media; disclose when users interact with AI; deceptive deepfakes banned.

Stated maximum penalty — Admin fines (decree-set)

In force · 1 Mar 2026 checked 18 Sep 2026 Law 134/2025/QH15 ↗ high confidence
Vietnam Comprehensive

Vietnam Decision 33 — 46 High-Risk AI Systems List

Binds Operators and providers of the 46 designated high-risk AI systems in Vietnam. Designates 46 specific AI systems as high-risk; new deployments require pre-deployment conformity assessment from Aug 15 2026.

In force from 15 August 2026. Day-of verification (15 Aug 2026): the Government legal-document portal record for Decision 33/2026/QD-TTg lists Ngay ban hanh (issued) 30-06-2026 and Ngay co hieu luc (effective) 15-08-2026. Existing systems have a transition period: 1 March 2027 (most sectors) or 1 September 2027 (healthcare, education, finance); new deployments of the 46 designated systems require pre-deployment conformity assessment from today. MoST (mst.gov.vn) published explainer content on the 6 covered sectors and both transition deadlines on 3 Jul 2026 (https://mst.gov.vn/46-he-thong-ai-duoc-xep-vao-nhom-rui-ro-cao-phai-quan-ly-nghiem-ngat-197260703152945179.htm), with a further notice on 8 Jul 2026 — contextual guidance, not a new binding regulation.

Stated maximum penalty — Enforcement under Vietnam AI Law 134/2025 / Decree 142

In force · 15 Aug 2026 checked 18 Sep 2026 Decision 33/2026/QD-TTg ↗ high confidence

Kosovo 1

Kosovo Binding

Law 06/L-082 art. 21 — GDPR art. 22 with the words «legal» and «significantly» missing from the trigger, and no fine attached to the right itself

Binds Art. 21 binds data controllers. Art. 2(1) applies the Law to the processing of personal data by public and private bodies alike and excludes processing carried out for purely personal purposes; art. 2(2) extends it to Kosovo's diplomatic and consular offices and other official representations abroad. Art. 2(3) reaches controllers not established in the Republic of Kosovo that use automated or other equipment in Kosovo for processing purposes, unless the equipment is used only for transit through Kosovo territory — an equipment-based extraterritorial test of the Directive 95/46 art. 4(1)(c) kind rather than GDPR art. 3(2)'s targeting-and-monitoring test — and requires such controllers to designate a representative registered in Kosovo. Supervision sits with the Agjencia për Informim dhe Privatësi. Impact tier: all entities.. Art. 21 of Ligji Nr. 06/L-082 për Mbrojtjen e të Dhënave Personale (Gazeta Zyrtare e Republikës së Kosovës, Nr. 6, 25 shkurt 2019) is Kosovo's automated-decision rule, and it has been binding since the Law entered into force on 12 March 2019. Art. 1(2) says the Law is aligned with Regulation (EU) 2016/679, and art. 21 follows GDPR art. 22 closely — with one divergence in the operative sentence that runs the other way from every other Western Balkans transposition. Art. 21(1): «Subjekti i të dhënave ka të drejtën të mos i nënshtrohet një vendimi të bazuar vetëm në një përpunim automatik, duke përfshirë profilizimin që prodhon efekte në lidhje me të ose e ndikon në mënyrë të ngjashme atë» — a decision that produces EFFECTS concerning the data subject or similarly affects them. The two qualifiers the GDPR uses to narrow the trigger are absent: «ligjore» (legal), before effects, and «ndjeshëm» / «në masë të konsiderueshme» (significantly), before affects. On its face the threshold is any effect, not a legal effect or a similarly significant one. That the omission is textual rather than an artefact of drafting shorthand is visible inside the same statute: art. 35(3.1), the impact-assessment trigger, carries the full GDPR phrase — «vendimet që prodhojnë efekte ligjore në lidhje me personat fizikë ose ndikojnë në masë të ngjashme personin fizik» — so the drafter had the complete formula to hand and did not use it in art. 21(1). The repealed 2010 Law had it too. Everything else tracks GDPR art. 22. Art. 21(2) gives the same three exits: necessary for entering into or performing a contract between the data subject and a controller (2.1), authorised by a specific law applying to the controller which itself lays down suitable safeguards (2.2), or based on the data subject's explicit consent (2.3). Art. 21(3) attaches safeguards to the contract and consent exits and names all three GDPR limbs — the right to obtain human intervention on the part of the controller, to express one's point of view and to contest the decision. Art. 21(4) bars such decisions from resting on the special categories in art. 8(1) unless art. 8(2.1) (explicit consent) or art. 8(2.7) (substantial public interest) applies, landing exactly where GDPR art. 22(4) lands via art. 9(2)(a) and (g). «Profilizim» is defined at art. 3(1.5) in GDPR terms. Transparency is proactive and triple-anchored on art. 21(1) and (4): arts. 12(2.6) and 13(2.7) require the existence of automated decision-making, profiling included, to be disclosed at collection, and art. 14(1.8) repeats it in the right of access — each with meaningful information about the logic involved and the significance and envisaged consequences. The enforcement picture is the finding. Art. 92, the general misdemeanour article, lists the finable breaches by article number — arts. 4, 5, 6, 7, 8, 10, 12, 14, 29, 30, 32, 46 and 49 and art. 86(3) — and art. 21 is not among them, so the substantive right carries no article-specific fine. Its transparency limbs do: acting contrary to art. 12 is art. 92(1.4) and (1.7), and acting contrary to art. 14 is art. 92(1.12), both at €20,000–€40,000 for a legal person. The same asymmetry existed under the predecessor Law: art. 8 of Ligji Nr. 03/L-172 was likewise absent from the art. 79 misdemeanour list, so an automated-decision breach has never carried a fine of its own in Kosovo, across both statutes. What can reach art. 21 is art. 105, a severity-based catch-all outside the article-by-article scheme. Kosovo has no Law Enforcement Directive counterpart: 06/L-082 applies to public and private bodies alike under art. 2(1), there is no competent-authority Part, and law-enforcement processing is handled through the art. 22 restrictions clause rather than through a separate regime — the North Macedonia and Montenegro pattern rather than the Serbian, Albanian or Bosnian one. Kosovo has no AI-specific statute and no adopted national AI strategy.

In force since 12 March 2019. The Law was adopted by the Assembly on 30 January 2019, promulgated by Presidential decree Nr. DL-59-2019 of 14 February 2019 and published in the Gazeta Zyrtare, Nr. 6, of 25 February 2019; art. 111 sets entry into force at fifteen days after publication, which is 12 March 2019, and the Official Gazette's act record lists no amendment to it. The date is computed from the statutory text because neither the gazette record nor the Agency states an entry-into-force date, and secondary sources diverge — one commercial survey reports 13 February 2019, which conflates the decree, and another reports 11 March 2019, an off-by-one on the same fifteen-day period. Nothing in this entry turns on the one-day question and the primary computation is used. Art. 110 repealed Ligji Nr. 03/L-172 (published 31 May 2010) on entry into force. Its art. 8 was the predecessor rule and is recorded here for the comparison: a Directive 95/46 art. 15 permission clause addressed to the processing rather than a right held by the data subject — automated decision-making capable of producing legal effects or having a significant impact, based solely on automatic processing intended to evaluate certain personal aspects, was permitted only if taken on conclusion or performance of a contract with safeguards such as arrangements allowing the data subject to contest the decision or express a view, or provided for by a law laying down safeguards including a remedy against such decisions. No profiling concept, no consent exit, and no express right to human intervention — the same generation as Montenegro's art. 15a. The atlas carried no Kosovo row under the old Law, so this is an addition rather than a supersession edit. Art. 21 was verified against two independent primary renderings of the same gazette text — the Official Gazette's own HTML of act 18616 and the PDF the Information and Privacy Agency publishes of Gazeta Zyrtare Nr. 6/2019 — which agree word for word, so the omission of «ligjore» and «ndjeshëm» in art. 21(1) is in the text and not in the extraction. Only the Albanian text was read; the gazette's Serbian and English tabs are ASP.NET postbacks that refused a scripted request, and the Albanian text is authentic in any event. Kosovo has no AI statute, no AI bill before the Assembly and no adopted national AI strategy as of this check. AIL-300 computation check (2026-08-31): 12 March 2019 verified against a second primary source. Art. 111 reads verbatim «Ky ligj hyn në fuqi pesëmbëdhjetë (15) ditë pas publikimit në Gazetën Zyrtare të Republikës së Kosovës» (Gazeta Zyrtare act record, ActID 18616) — the same fifteen-day formula the Constitution sets as the default in art. 80(4). The nearest Kosovan rule on reckoning statutory terms is art. 81 of Law No. 05/L-031 on General Administrative Procedure, whose para. 2 provides «Kur afati përcaktohet në ditë, në llogaritjen e tij përjashtohet dita kur ka ndodhur ngjarja nga e cila fillon të ecën afati» — where a term is set in days, the day the triggering event occurred is excluded. Excluding publication day 25 February 2019 puts day 1 at 26 February and day 15 at 12 March 2019, which is the date carried. Art. 81(4) defers a term whose last day is a Saturday, Sunday or public holiday; 12 March 2019 was a Tuesday, so it does not bite. Two residual caveats are recorded rather than papered over: art. 81 sits in the administrative-procedure statute and governs procedural terms, so it is persuasive for a vacatio rather than the universal rule Paraguay's Código Civil art. 342 supplies; and para. 2 fixes only where a day-term starts, not whether it must expire before the effect arises, so a reading of «pas» that requires the fifteen days to have run would give 13 March 2019. 12 March 2019 is retained as the computation on the face of the rule and matches the off-by-one-free reading; the earlier note already records the two divergent secondary accounts (13 February and 11 March 2019), both of which remain wrong.

Stated maximum penalty — €20,000 to €40,000 for a legal person or a person carrying on an independent activity, but not for a breach of art. 21 itself. Art. 92(1) enumerates the general misdemeanours by article number and art. 21 is absent from the list, so the substantive automated-decision right has no article-specific penalty attached to it; the same was true of art. 8 under the repealed 2010 Law, whose art. 79 list also omitted it, so the rule has never been directly finable in Kosovo. The neighbouring duties are finable at that band: failing to inform the data subject under art. 12 — which is where art. 12(2.6) requires disclosure of automated decision-making under art. 21(1) and (4) — is art. 92(1.4) and (1.7), and acting contrary to art. 14, the right of access carrying the same disclosure at art. 14(1.8), is art. 92(1.12). Responsible-person and individual exposure runs alongside at €1,000–€2,000 for the responsible person of a state body and €400–€1,000 for an individual (art. 92(3) and (4)). Reaching art. 21 requires art. 105, which sits outside the article-by-article scheme: where the Agency finds a serious and large-scale breach of personal data it may impose €20,000–€40,000 or, for a company or undertaking, 2% to 4% of total annual turnover of the preceding financial year, the article citing Regulation (EU) 2016/679 for the measure. That band is worth reading closely — the GDPR sets 2% and 4% as ceilings, while art. 105 states 2% as a floor and 4% as the ceiling, so the Kosovo provision has a percentage minimum the GDPR does not have. Art. 91(2) caps the total for multiple related breaches at twice the highest single fine in the Law. Art. 106 preserves civil liability for unlawful processing and criminal liability under the Criminal Code alongside.

In force · 12 Mar 2019 checked 2 Sep 2026 Law 06/L-082 art. 21 ↗ high confidence

South Africa 1

South Africa Binding

POPIA s. 71 — bar on decisions taken solely on automated processing that profiles the data subject

Binds Responsible parties as defined in s. 1, that is public or private bodies or any other person which alone or in conjunction with others determines the purpose of and means for processing personal information. Section 3(1) applies the Act to processing entered in a record by or for a responsible party by automated or non-automated means where the responsible party is domiciled in the Republic, or is not domiciled in the Republic but makes use of automated or non-automated means in the Republic other than merely to forward information through it. Data subjects include juristic persons, so the section reaches automated credit and supplier scoring of companies as well as of natural persons. Impact tier: all entities.. Section 71 of the Protection of Personal Information Act 4 of 2013 carries South Africa's operative automated-decision rule, in Chapter 8 (rights of data subjects regarding direct marketing by unsolicited electronic communications, directories and automated decision making). Subsection (1) provides that a data subject may not be subject to a decision which results in legal consequences for him, her or it, or which affects him, her or it to a substantial degree, which is based solely on the basis of the automated processing of personal information intended to provide a profile of such person, including his or her performance at work, or his, her or its creditworthiness, reliability, location, health, personal preferences or conduct. Subsection (2) disapplies that bar where the decision has been taken in connection with the conclusion or execution of a contract and either the data subject's request in terms of the contract has been met or appropriate measures have been taken to protect the data subject's legitimate interests, or where the decision is governed by a law or code of conduct in which appropriate measures are specified for protecting the legitimate interests of data subjects. Subsection (3) fixes what those appropriate measures must do: provide an opportunity for the data subject to make representations about the decision, and require the responsible party to provide the data subject with sufficient information about the underlying logic of the automated processing of the information relating to him or her to enable him or her to make those representations. The profiling limb is broader than the GDPR Art. 22 analogue in one respect — it names performance at work, creditworthiness, reliability, location, health, personal preferences and conduct on the face of the statute.

Commencement is fixed by proclamation, not by the Act: s. 115(1) provides that POPIA commences on a date determined by the President by proclamation in the Gazette, and s. 115(2) allows different dates for different provisions. Proclamation No. R. 21 of 2020, signed at Hyde Park on 17 June 2020 and published in Government Gazette No. 43461 (Regulation Gazette No. 11136) of 22 June 2020, determined 1 July 2020 as the date on which ss. 2 to 38, ss. 55 to 109, s. 111 and s. 114(1), (2) and (3) commence, and 30 June 2021 as the date for ss. 110 and 114(4). Section 71 falls inside the 55-to-109 block, so it has been in force since 1 July 2020. Section 114(1), which commenced on the same day, required all processing of personal information to be made to conform to the Act within one year, so that transitional window closed on 1 July 2021, the date the market treats as the compliance deadline. The Regulator's Chapter 10 enforcement powers (ss. 73 to 99) and the administrative-fine machinery in s. 109 also commenced on 1 July 2020. South Africa is the tracker's first African jurisdiction. Compared with the Kenyan analogue ke-dpa-s35, POPIA gives no express right to demand a fresh non-automated decision; its remedy is a right to make representations plus disclosure of the underlying logic, and only where the contract exception is relied on. Text read in the enacted Act as published in Government Gazette No. 37067 of 26 November 2013 on gov.za, and the commencement dates read in the proclamation as published by the Information Regulator, the statutory supervisory authority.

Stated maximum penalty — Enforcement runs through Chapter 10: a breach of s. 71 is interference with the protection of personal information under s. 73, which the Information Regulator may pursue by enforcement notice under s. 95. Failure to comply with an enforcement notice is an offence under s. 103(1), punishable under s. 107(a) by a fine or imprisonment for a period not exceeding 10 years, or both. Under s. 109(2)(c) the Regulator may instead serve an infringement notice specifying an administrative fine, which may not exceed R10 million. Section 99 preserves a separate civil action for damages by the data subject, or by the Regulator on the data subject's behalf, irrespective of intent or negligence.

In force · 1 Jul 2020 checked 7 Sep 2026 POPIA s. 71 (Act 4 of 2013) ↗ high confidence

Zambia 1

Zambia Binding

Data Protection Act 2021 s. 62 — the GDPR-shaped automated-decision bar that no offence backs

Binds Every data controller processing personal data in Zambia. Section 3(1) applies the Act «to the processing of personal data performed wholly or partly by automated means and to any processing otherwise than by electronic means», and s. 3(2) carves out only processing by an individual for personal use — there is no small-entity threshold, no turnover floor and no public/private split, so the bar reaches enterprise, SME and public body alike. Two structural features widen the practical reach well beyond the text of s. 62. First, s. 19(1) makes it an offence to control or process personal data at all without registering as a data controller or data processor, so the population subject to s. 62 is a registered and enumerated one. Second, s. 70(1) requires a data controller to process and store personal data on a server or data centre located in the Republic, with ministerial carve-outs under s. 70(2) and a hard localisation rule for sensitive personal data under s. 70(3) — which means an automated decision about a Zambian data subject is, as a matter of the same statute, expected to be computed on infrastructure inside Zambia. The hiring case is squarely in scope: the s. 2 definition of profiling names «performance at work» first among the aspects it covers, and an automated sift producing a hiring outcome is a decision that at least «similarly affects» the candidate. Credit and insurance scoring fall the same way. What is not in scope is a decision with a human materially in the loop — s. 62(1) catches only decisions «based solely on» automated processing, and the Act supplies no gloss on what degree of human review defeats that.. Section 62(1) of the Data Protection Act, 2021 (Act No. 3 of 2021) provides that «a data subject shall not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning that data subject or similarly affects that data subject». The drafting is GDPR art. 22 read through a Commonwealth pen: it is framed as a prohibition on the outcome rather than as a right the data subject must assert, and its three ways out at s. 62(2) are the familiar ones — (a) necessary for entering into, or performance of, a contract between the data subject and a data controller; (b) authorised by any written law; (c) based on the data subject's explicit consent. Where an exception is used, s. 62(3) requires the controller to implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, «including the right to obtain human intervention on the part of the data controller for purposes of enabling the data subject to express the data subject's point of view and contest the decision» — so Zambia carries the full human-intervention, point-of-view and contest triad that the Malabo Convention itself omits. Section 62(4) then adds a separate rule that has no GDPR counterpart in that position: automated data processing shall not be undertaken where the processing involves sensitive personal data unless the data subject has expressly consented, the processing is in the public interest, or it is permitted by any written law with suitable safeguards in place. «Profiling» is defined in s. 2 in GDPR terms — any form of automated processing consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, including analysis or prediction of performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. The explanation limb is reactive rather than proactive. Section 58(2)(d) gives a data subject who is already being processed the right to access «information about the basic logic involved in any automatic processing of data relating to the data in case of automated decision making» — but the s. 64 duty to inform at the point of direct collection runs (a) to (f) and carries no automated-decision item at all, so a Zambian controller must explain the logic when asked and need not volunteer that the decision is automated in the first place. Section 57 is the sleeper: a data controller or data processor «shall notify the Data Protection Commissioner of any third party agreement that allows the third party to trade on the profile of a data subject» — a registration duty on profile-trading that sits in Part VIII and is separate from the s. 62 bar.

In force since 1 April 2021, and the date comes from the commencement instrument rather than from the Act. Section 1 of the Act is a bare enabling clause — «This Act may be cited as the Data Protection Act, 2021, and shall come into operation on the date appointed by the Minister by statutory instrument» — so the assent date of 24 March 2021 that appears on the face of Act No. 3 of 2021 is not the operative date and must not be carried as one. The appointing instrument is Statutory Instrument No. 22 of 2021, the Data Protection Act (Commencement) Order, 2021, made under s. 1 by M. L. Kafwaya, Minister of Transport and Communication, signed at Lusaka on 31 March 2021 and reference MTC.64/9/35. Its para. 2 reads: «The Data Protection Act, 2021, shall come into operation on the date of publication of this Order». The Order was published in the Statutory Instruments of 1st April, 2021 — the date printed in the running head of the gazette pages carrying it — so the whole Act, s. 62 included, has been in force since 1 April 2021. There is no phased or sectioned commencement: SI 22 of 2021 appoints one date for the entire Act, unlike the Mauritian scheme next door, where s. 58(2) of the Data Protection Act 2017 expressly allows different dates for different sections. Zambia deposited its instrument of ratification of the Malabo Convention on 24 March 2021, three months after ratifying on 15 December 2020, so from 8 June 2023 the country is bound both by its own s. 62 and by art. 14(5) of the Convention. The two do not say the same thing, and where they diverge the national statute is the operative rule while the treaty runs behind it: s. 62(2) permits a solely automated decision on the contract, written-law and explicit-consent limbs, and art. 14(5) permits none of the three. Nothing in the Act repeals or qualifies the Convention, and Zambia has not legislated the Convention into domestic law by a separate instrument, so a controller relying on a s. 62(2) exception is in a position that is lawful under the statute and unresolved under the treaty. That tension is recorded rather than resolved here.

Stated maximum penalty — None attaches to s. 62 itself, and tracing that took reading the offence architecture rather than the summaries. The Act penalises by Part, not globally: s. 18(1) makes a body corporate that contravenes Part IV liable to a fine not exceeding one hundred million penalty units or two per cent of annual turnover of the preceding financial year, whichever is higher, and s. 55(1) does the same for Part VIII at two per cent of turnover or two million penalty units, whichever is higher, with s. 55(2) putting a natural person at up to one million penalty units or ten years. Section 62 sits in Part IX (Rights of the Data Subject), and Part IX has no equivalent clause — no section in the Act declares a contravention of Part IX an offence. Section 77, the general penalty, reaches only «a person who commits an offence under this Act for which a specified penalty is not provided», so it presupposes an offence and cannot manufacture one; the widely repeated figure of a fine plus up to three years' imprisonment for automated-decision breaches is s. 77 misapplied. What a data subject actually has is civil and administrative: s. 68, a complaint to the Data Protection Commissioner, whose functions under s. 4(2)(i) include receiving and investigating complaints; s. 69, an appeal to the High Court within thirty days of the Commissioner's decision; and s. 72, compensation from the controller or processor as determined by a court of competent jurisdiction for damage suffered from an infringement of a right under the Act. A profile-trading agreement not notified under s. 57 is likewise unpenalised on its own terms. Impact tier: all entities.

In force · 1 Apr 2021 checked 15 Sep 2026 Data Protection Act 2021 s. 62 ↗ high confidence

Paraguay 1

Paraguay Binding

Ley 7593/2025 art. 33 — an LGPD-style right to REQUEST REVIEW, not a prohibition, and the only ADM rule in the atlas whose trade-secret carve-out protects the data subject's own secrets

Binds Responsables and encargados del tratamiento — controllers and processors, natural or legal persons, public or private. Art. 2 fixes an extraterritorial reach on the GDPR art. 3 pattern and says so expressly, applying «independientemente del medio, país de su sede o el país donde se encuentren los datos»: (a) any controller or processor established in Paraguay, even where the processing happens abroad; and (b) a controller or processor NOT established in the national territory where it processes data of natural persons situated in Paraguayan territory (except for transit purposes), where its processing activities relate to the offering of goods or services directed at residents of Paraguay, or where they relate to monitoring the behaviour of natural persons to the extent that behaviour takes place in Paraguay. The first non-establishment limb is broader than GDPR art. 3(2), which requires an offering or monitoring nexus; Paraguay's limb (b)(i) catches mere processing of data of people located in the country. The Law covers only data of personas físicas (art. 1). Out of scope: purely household or family activity with no disclosure or commercial purpose, and processing for public security, migration, defence, national security and criminal matters, investigation and law enforcement — the last subject to a proportionality and fundamental-rights proviso rather than a clean carve-out.. Art. 33 of Ley N° 7593/2025 «De Protección de Datos Personales en la República del Paraguay» (promulgated and published 27 November 2025) is headed «Derechos ante decisiones individuales automatizadas o semiautomatizadas» and reads: «El titular de datos tiene derecho a solicitar la revisión de las decisiones tomadas sobre la base del tratamiento automatizado de datos personales, que afecten negativamente a sus intereses o produzcan efectos jurídicos, incluidas las decisiones encaminadas a definir sus aspectos personales, profesionales, de consumo, de crédito, de su personalidad. Asimismo, derecho a expresar su punto de vista y a impugnar la decisión.» The shape is Brazilian LGPD art. 20, not GDPR art. 22. There is no prohibition and no «solely» — nothing is forbidden ex ante, so a controller may lawfully run a fully automated decision and the subject's remedy is an ex post request for review. Widely circulated secondary summaries describe Paraguay as importing «the right not to be subject to automated decisions» on the GDPR model; the enacted text does not say that, and the difference is the whole substance of the article. Two further widenings follow from dropping the GDPR frame. The heading and the operative words reach «semiautomatizadas» decisions, so partial automation with a human in the loop is inside the article rather than outside it — the opposite of the «únicamente» escape that Panama, Uruguay and every Directive 95/46 descendant rely on. And the trigger is disjunctive and asymmetric: decisions that «afecten negativamente a sus intereses» OR that «produzcan efectos jurídicos». The first limb is a bare adverse-interest test with no significance threshold at all, materially lower than GDPR art. 22's «le afecte significativamente de modo similar»; the second is unqualified legal effect, so unlike Panama's art. 19 a favourable legal effect still engages the right. The illustrative list — «aspectos personales, profesionales, de consumo, de crédito, de su personalidad» — is LGPD art. 20's list with «de consumo» added. The second paragraph is the explanation duty: on request the controller must give «información clara, completa y adecuada sobre los criterios y procedimientos utilizados para la decisión automatizada», qualified by «con observancia del respeto por secretos comerciales e industriales del titular o que el titular se vea obligado por ley o por contrato a guardar». That carve-out is unique in the atlas. LGPD art. 20 §1 reserves the CONTROLLER's commercial and industrial secrets, and that reservation is what has made the Brazilian provision hard to enforce; Paraguay's text instead attaches the secrets to «el titular», which the Law's own art. 3 definition fixes as the data subject. Read literally the controller may withhold the logic only to protect the SUBJECT's trade secrets or the subject's own confidentiality duties — a carve-out that would almost never bite and that inverts the protection it was copied from. The row is published on the enacted wording; whether this is a drafting slip to be cured by the reglamento is not something the gazette text answers, and no reglamento exists yet. There is no exhaustive-consent-or-contract exit list of the GDPR art. 22(2) kind, and no bar on automated decisions over sensitive data. The third paragraph adds a general duty to «adoptar las medidas adecuadas para salvaguardar los derechos del titular» and a non-exclusivity clause. Profiling is defined at art. 3 («Elaboración de perfiles») in GDPR art. 4(4) terms and covers processing carried out «de forma automatizada y semi automatizada», but art. 33 never mentions profiling; the link is made instead by art. 27, the information duty, which requires disclosure of «la existencia de decisiones automatizadas, incluida la elaboración de perfiles y, al menos en tales casos, información significativa sobre la lógica aplicada, sin que ello afecte derechos intelectuales del responsable del tratamiento» — GDPR art. 13(2)(f) with an intellectual-property carve-out that, unlike art. 33's, does run in the controller's favour. Art. 14 requires a data-protection impact assessment for «evaluación sistemática y completa de aspectos personales de titulares de datos basada en tratamiento de datos automatizado, incluyendo la elaboración de perfiles, y sobre cuya base se adopten decisiones que produzcan efectos jurídicos para las personas físicas o afectación significativa de modo similar» — note that the DPIA trigger keeps the GDPR significance threshold that art. 33 discards, so the article that creates the right is broader than the article that requires the risk assessment.

Enacted but not yet applicable. The Law was approved by the Cámara de Diputados on 14 October 2025 and by the Cámara de Senadores on 5 November 2025 and so «queda sancionado, de conformidad con lo dispuesto en el artículo 207 numeral 2) de la Constitución» (art. 61); the Biblioteca y Archivo del Congreso Nacional record for Ley N° 7593/2025 carries «Promulgación: 27-11-2025» and «Publicación: 27-11-2025». Art. 57 is the whole vigencia clause — «La presente ley entrará en vigor luego de transcurridos veinticuatro meses de su publicación oficial» — and it names no date, so the first day of application is computed rather than read off. The computation is governed by the Código Civil (Ley N° 1183/1985), whose art. 342 makes arts. 337 to 341 applicable to «todos los plazos señalados por las leyes, por los jueces, o por las partes en los actos jurídicos, siempre que en las leyes o en esos actos no se disponga de otro modo», and Ley 7593 disposes nothing else. Art. 339 fixes the terminal day — «El plazo establecido por meses o por años concluirá al transcurrir el día del último mes que tenga el mismo número que aquél en que comenzó a correr el plazo» — and art. 341 adds that «todos los plazos serán contínuos y completos, debiendo siempre terminar en la media noche del último día». Twenty-four months from the publication of 27 November 2025 therefore run out at the midnight ending 27 November 2027, and because art. 57 makes the Law effective only «luego de transcurridos» — once the twenty-four months have ELAPSED — the first day on which it applies is 28 November 2027. That is the date carried in this row. It was previously carried as 27 November 2027; that date is not supported by arts. 339 and 341, under which 27 November 2027 is a day the plazo is still running. A stricter alternative would have the plazo begin to run on 28 November 2025 rather than on the day of publication, by analogy with art. 338 («si el plazo está señalado por días a contar desde uno determinado, quedará éste excluido del cómputo») and with art. 1 of the same Code, under which laws bind «desde el día siguiente al de su publicación»; on that reading art. 339's same-numbered day is 28 November 2027 and the first day of application is 29 November 2027. Art. 338's dies a quo rule is on its face confined to plazos «señalado por días», so this row takes 28 November 2027 and records the 29 November 2027 alternative rather than resolving it. No reading of the Code yields 27 November 2027. This is a computation question inside a single primary source, not a conflict between two primary sources. Nothing in the atlas applies to Paraguay before that date. The only data-protection statute currently in force, Ley N° 6534/2020 «De Protección de Datos Personales Crediticios», is credit-data only and contains no automated-decision rule; Ley 7593 does not repeal it but amends it, derogating arts. 3(a), 3(b), 4, 20(b) and 21(x) (art. 59) and redirecting every reference in it from the Secretaría de Defensa del Consumidor y el Usuario to the new regulator (art. 58). Art. 34 creates that regulator, the Agencia Nacional de Protección de Datos Personales, as a deconcentrated unit inside the Ministerio de Tecnologías de la Información y Comunicación with the rank of Dirección Nacional and functional autonomy — so the enforcement body does not exist yet either. Art. 60 requires the Poder Ejecutivo to issue the reglamento within twenty-four months of publication in the gaceta oficial, i.e. by the same November 2027 mark at which the Law bites, leaving open the possibility that the Law becomes applicable with the implementing rules only just made or not made at all. Re-check at the reglamento and at the constitution of the Agencia; either could change the art. 33 reading, particularly the «secretos comerciales e industriales del titular» carve-out. Re-checked on 31 August 2026 against the Biblioteca y Archivo del Congreso Nacional record for Ley N° 7593/2025: the enacted text of arts. 33, 57 and 60 is unchanged, the record still carries «Fecha de Promulgación: 27-11-2025» and «Fecha de Publicación: 27-11-2025», and it records no corrigendum, amending law or implementing decree. No reglamento under art. 60 and no instrument constituting the Agencia Nacional de Protección de Datos Personales had been published as of that date.

Stated maximum penalty — 20 to 2,500 jornales mínimos «para actividades diversas no especificadas», rising to 5,000 jornales where the infraction concerns sensitive data and to 10,000 jornales where it concerns sensitive data of children and adolescents (art. 46). At the jornal mínimo of G. 117.077 fixed by Resolución MTESS N° 670/2026 with effect from 1 July 2026, that is roughly G. 2,34 million to G. 293 million (about USD 320 to USD 40,000), G. 585 million (about USD 80,000) for sensitive data and G. 1.171 million (about USD 160,000) for children's sensitive data — indicative only, since the jornal is re-fixed by the Executive and will have moved before the Law applies in November 2027. There is no turnover-based alternative. Art. 46 also allows an apercibimiento with a deadline for corrective measures and suspension of processing activities, cumulatively or separately, and art. 42 gives the Agencia corrective measures (cessation or suspension of processing, deletion of the data, imposition of technical, legal or organisational measures) whose appeal has no suspensive effect. A breach of art. 33 is fineable only through a residual catch-all, which is the same structural gap Panama's art. 19 has. Art. 43 classifies faltas as leves or graves only, and both enumerations reach the ARCO-plus-portability set while omitting the automated-decision right: art. 44 lists failures to honour «los derechos de acceso, rectificación, supresión, limitación del tratamiento o a la portabilidad» and art. 45 the reiterated obstruction of «acceso, rectificación, supresión o a la portabilidad». The words «decisión automatizada» and «revisión» appear nowhere in arts. 44 to 45. The route in is therefore the final item of art. 44 — «El incumplimiento de las obligaciones legales o reglamentarias, siempre y cuando las mismas no hayan sido catalogadas como faltas graves» — so refusing a review under art. 33 is a falta LEVE, prescribing in one year (art. 44) rather than two (art. 45). Art. 46 states its 20–2,500 band without splitting it between leves and graves, so the ceiling is not formally reduced by the classification; art. 47 supplies the graduation criteria. Art. 41 preserves the constitutional hábeas data guarantee and a separate judicial action for damages.

Applies 28 Nov 2027 checked 10 Sep 2026 Ley 7593/2025 art. 33 ↗ high confidence

El Salvador 3

El Salvador Comprehensive

Ley de Fomento a Inteligencia Artificial y Tecnologías art. 18 — the ADM right sits in the AI statute, not in the data-protection law

Binds Any natural or legal person using AI commercially or to grant access to rights or services in El Salvador (art. 3 scope: development, research and application of AI, autonomous learning and generative models, and the collection, storage and processing of data for those activities). Anyone using AI commercially, or to give access to rights or services in El Salvador, must tell the user whether the decision was taken by the AI or driven by it, explain it comprehensibly, and provide a route to contest it before a competent natural person.

Decreto Legislativo N.° 234 of 26 February 2025, published in Diario Oficial N.° 43, Tomo 446, of 3 March 2025, reformed by Decreto Legislativo N.° 363 of 16 July 2025 (D.O. N.° 134, Tomo 448, 18 July 2025 — institutional only: ANIA becomes a decentralised body with its own budget). Art. 18 reads: «Cuando se utilice la IA comercialmente o para acceder a derechos o servicios dentro de la República, se estará en la obligación de informar al usuario de si la decisión fue adoptada directamente por la IA o fue impulsada por esta. La notificación de la decisión deberá contener las explicaciones comprensibles y transparentes del proceso para su adopción. Asimismo, deberán establecer mecanismos para impugnar dichas decisiones ante una persona natural competente para confirmar, modificar o revocar la misma.» Three things make this row unlike almost every other automated-decision rule in the atlas. First, the duty lives in an AI-promotion statute, not in the data-protection law: El Salvador's Ley para la Protección de Datos Personales (D.L. N.° 144, D.O. 15 November 2024) contains no GDPR art. 22 analogue at all — its only adjacent provision is the art. 12 right to oppose profiling for commercial or direct-marketing purposes — so art. 18 is the country's automated-decision rule. Second, there is no «solely» and no significant-effects threshold: the trigger is commercial use or access to rights or services, and it catches AI-driven as well as AI-taken decisions, which is wider than GDPR art. 22 on both limbs. Third, art. 18's own sanction is the loss of a benefit rather than a fine: its final sentence makes compliance «un requisito indispensable para gozar de las salvaguardas otorgadas por la presente Ley» — the art. 19 safeguards, which include the bar on liability for third-party misuse and the protection of open-domain training data. The Law creates no fine of its own; art. 8(a) has ANIA refer non-compliance to whichever regulator supervises the sector, and where personal data is involved art. 22 routes the matter to the Ley para la Protección de Datos Personales, whose art. 57 bands run from 1 to 40 monthly minimum wages of the commerce sector. Commencement chain, verified against the counting rule and not computed arithmetically: art. 29 of Decreto Legislativo N.° 234 reads «El presente decreto entrará en vigencia ocho días después de su publicación en el Diario Oficial», and art. 140 Cn. requires that «deberán transcurrir por lo menos ocho días después de su publicación», i.e. an elapsed term rather than a named day. Código Civil art. 46 makes every statutory plazo complete and runs it «hasta la medianoche del último día del plazo», and art. 47 provides that where a period must elapse for rights to arise, they «no nacen … sino después de la medianoche en que termine el último día». Publication 3 March 2025 therefore puts the eighth complete day at 11 March and force at 12 March 2025. The alternative reading, treating the clause as designating the eighth day itself, gives 11 March 2025; it is recorded here and does not change any duty.

Stated maximum penalty — No fine in the AI Law itself — breach forfeits the art. 19 safeguards; referral to the sector regulator (art. 8(a)), and via art. 22 the data-protection bands of 1–40 monthly commerce-sector minimum wages (LPDP art. 57)

In force · 12 Mar 2025 checked 19 Sep 2026 Ley de Fomento a IA art. 18 ↗ high confidence
El Salvador Comprehensive

ANIA Resolución 0001/2025 art. 24 — notification duty for adverse automated decisions, owed whether or not the entity is registered

Binds Any entity using an AI system to take decisions affecting people in El Salvador — expressly «independientemente de si la entidad está sujeta a registro». Where an AI system decides without meaningful human review and adversely affects a person's rights or economic situation in seven listed areas, the entity must notify them that AI was involved, explain its role and give them a way to challenge the decision.

Art. 24 of ANIA Resolución N.° 0001/2025 (D.O. 25 August 2025, Tomo 448, N.° 158, pp. 59–73, Registro No. F34829) is the regulation-level counterpart of art. 18 of the Law and is deliberately wider in one respect: it binds every entity using AI to decide about people in El Salvador, registered or not. Notification is compulsory where the decision was taken by an AI system «sin una revisión humana significativa» and adversely affects the person's rights or economic situation in health and medical treatment; financial services including credit and insurance; employment opportunities; education services; government benefits and services; housing and accommodation; or transport and mobility — two areas, housing and transport, that the Law's own art. 18 does not name. The notice must be clear and comprehensible and must state at a minimum that an AI took part, explain the role it played, and give the person a mechanism to contest the decision; ANIA is to publish non-binding templates. Art. 25 carves out seven cases: fraud detection, prevention or investigation; cybersecurity and vulnerability assessment; law enforcement, regulatory compliance and national security support; circumvention of legitimate security controls; detection of terms-of-service violations, illegal content or harmful behaviour; content recommendation, search results and ad optimisation; and basic productivity features such as spelling and grammar assistance. Note the sixth: recommender and ad-ranking systems are exempt from notification here, which is the opposite of the direction the EU and several Latin American drafts have taken. Art. 26 is a deliberate non-obligation and is recorded so it is not misread as a right to human review: it lets ANIA issue sector guidance on designing meaningful human review «donde dicha revisión sea ofrecida o requerida por esta ley», and states that any service-level target or procedural recommendation is illustrative only and creates no duty under the Disposiciones. The enforceable route to a human is therefore the contest mechanism in art. 18 of the Law and in this article, not art. 26. Same commencement chain as the Law: art. 30 of the Resolución gives eight days after publication, publication was 25 August 2025, the eighth complete day is 2 September and force is 3 September 2025 (alternative reading 2 September 2025).

Stated maximum penalty — No fine — art. 28 escalation only; art. 18 of the Law additionally conditions the art. 19 safeguards on compliance

In force · 3 Sep 2025 checked 19 Sep 2026 ANIA Res. 0001/2025 art. 24 ↗ high confidence
El Salvador Comprehensive

ANIA Resolución 0001/2025 arts. 11–15 — mandatory registration and algorithmic impact assessment for consequential-decision AI; legacy systems must comply by 3 September 2026

Binds Operators (not developers, unless they deploy) whose AI system is the controlling factor in a consequential decision in health; finance and insurance; real-time biometrics in publicly accessible spaces; public powers or access to government services and benefits; employment; or education and professional licensing. Operators whose AI is the controlling factor in consequential decisions in six named sectors must register with ANIA, run an algorithmic impact assessment and pick a compliance route; systems already running when the rules took effect have twelve months, expiring 3 September 2026.

Resolución N.° 0001/2025 of the Agencia Nacional de Inteligencia Artificial, «Disposiciones relativas a la implementación de la Inteligencia Artificial y Tecnologías», published in the Diario Oficial of 25 August 2025, Tomo 448, N.° 158, at pp. 59–73 (Registro No. F34829), issued under arts. 7, 8, 11, 16 and 17 of the Law. It is the implementing instrument the Law's art. 27 required within ninety days of commencement. Art. 11 splits registration in two: voluntary registration to obtain the art. 19 safeguards, and mandatory registration wherever an AI system meets the art. 4(e) definition of a Consequential Decision — the AI acting as «factor controlante», materially affecting a person's legal status, rights or access to essential goods, services or opportunities — in six deployments: primary diagnostic, treatment or emergency determinations in health; creditworthiness, loan approval or denial, and pricing and eligibility for credit or insurance products for natural persons; real-time or near-real-time biometric identification or categorisation in publicly accessible spaces (device unlocking excluded); the exercise of public powers or the grant, denial or revocation of government services or benefits; hiring, dismissal, promotion or compensation without meaningful human supervision; and admission, grading at scale, academic progression, or professional licensing and certification. The obligation falls on the operator; developers register only if they deploy. Foreign entities may register without incorporating locally by naming a Designated Representative. Art. 12 excludes general-purpose model, API and cloud providers as such, infrastructure and MLOps tooling, research and strictly personal use, the training phase where its outputs are not used to decide about individuals, and consumer productivity software with auxiliary AI features — but an excluded entity that later deploys for an art. 11 use must register before deployment. Art. 15 requires registered systems to run an algorithmic impact assessment covering risk identification, likelihood and severity, mitigation, monitoring and bias and fairness testing; art. 16 lets an operator demonstrate compliance by annual self-certification against ANIA-recognised standards, by third-party certification valid for up to three years, or by joining the supervised sandbox, which under art. 23 carries a twelve-month grace period from enforcement. Certification under ISO/IEC 42001, 23053, 23894 or 38507, the NIST AI RMF 1.0, or IEEE 7000, 7001 or 7010 raises a rebuttable presumption of conformity (arts. 21–22). The date on this row is the art. 29 transitional deadline, not the commencement date. The Disposiciones themselves took effect on 3 September 2025; art. 29 gives AI systems that were already operating lawfully before that date twelve months to meet the mandatory-registration requirements. Código Civil art. 46 ends a plazo of months on the same-numbered day, so the twelve months run out at midnight ending 3 September 2026; on the alternative commencement reading the deadline is 2 September 2026. Systems first deployed after 3 September 2025 have had no grace period at all. Same commencement chain as the Law: art. 30 of the Resolución gives eight days after publication, publication was 25 August 2025, the eighth complete day is 2 September and force is 3 September 2025 (alternative reading 2 September 2025). Enforcement carries no fine. Art. 28 makes ANIA proceed in steps — educational guidance with at least sixty days to remediate, then formal notice with technical assistance, then a compliance order with proportionate deadlines, and referral to other competent authorities only for serious and repeated violations — with emergency measures reserved for a clear and imminent risk of serious harm. Art. 19 forbids ANIA from demanding source code, model architecture, weights or raw training data. Re-polled 3 September 2026, the art. 29 expiry day itself, twice: against the Centro de Documentación Judicial legislative corpus (jurisprudencia.gob.sv) and, independently, against the Diario Oficial itself via the Imprenta Nacional download API (POST https://www.diariooficial.gob.sv/api/v1/diarios-disponibles, form fields year and month; issues fetched at https://www.diariooficial.gob.sv/seleccion/{Id}). No instrument extends, defers, suspends or amends the art. 29 transitional period. The gazette sweep is the firmer of the two. Every Diario Oficial issue from 12 to 21 August 2026 was downloaded and read in full — eight issues, 1,240 pages, 5.86 million characters of extracted text — and contains no occurrence of «inteligencia artificial», «ANIA», «robótica» or «algoritm-» anywhere, in either the sumario or the body; the only hits for «automatizad-» are land-registry «folio real automatizado» boilerplate. Extraction was validated against controls («diario oficial» 253–516 hits per issue, «decreto», «ministerio», «órgano ejecutivo» all present; a nonsense control string returns zero), so the negative is a real absence and not a silent extraction failure. This firms the previous CDJ-corpus negative, which was indexed only through 11 August 2026, forward to 21 August 2026 and narrows the provisional window from twenty-three days to thirteen. That window was closed only in part, and the ceiling that appeared to block it has since moved. Re-polled 6 September 2026: the Diario Oficial availability API now returns fifteen August issues, the highest being issue id 31829 of 27 August 2026, where on 3–4 September the highest that existed was id 31825 of 21 August 2026. The ceiling is therefore LAGGING rather than frozen — ids that returned HTTP 307 on the expiry-day poll later returned documents — but it does NOT advance on a steady daily cadence; see the 7 September 2026 note below, which withdraws the «roughly one publication day per calendar day» rate stated here. The four issues published since the last poll — 24, 25, 26 and 27 August 2026 (ids 31826–31829) — were downloaded and read, and none extends, defers, suspends or amends the art. 29 transitional period. The unverifiable window is thereby narrowed from thirteen days to seven, 28 August – 3 September 2026, and it is closable on a later poll rather than permanently unfalsifiable. Method note for the next poller, learned this heartbeat: ANIA instruments are published in the Diario Oficial as JPEG-2000 scanned inserts with no text layer. Pages 59–73 of Tomo 448 N.° 158 extract as running headers only (91–197 characters per page) and do not render even with a full pdf.js and canvas pipeline. The sumario, however, is real text and does name «AGENCIA NACIONAL DE INTELIGENCIA ARTIFICIAL / Resolución No. 1/2025» — which is how this publication was located. Grep the sumario, not the body; a body-only grep will produce a false negative on any ANIA instrument. Two presentational discrepancies, both recorded rather than escalated because the article structure is identical and nothing substantive turns on either. The gazette sumario styles the instrument «Resolución No. 1/2025 — Disposiciones Relativas a la Implementación de la Inteligencia Artificial y Tecnologías», whereas ANIA's own site serves the same fifteen-article text as the «Reglamento para la Aplicación de la Ley de Fomento a Inteligencia Artificial y Tecnologías» (https://ania.gob.sv/wp-content/themes/ania/assets/docs/reglamento-ley-ia.pdf); the page count, the art. 29 twelve-month grace, the art. 11 registration trigger, the arts. 21–22 standards regime and the art. 30 eight-day commencement clause all match. The atlas uid says 0001/2025 and the gazette says 1/2025. On the two open implementing gaps: the art. 21 list of recognised standards is not in fact outstanding — it was gazetted with the Resolución itself and names ISO/IEC 42001, 23053, 23894 and 38507, the NIST AI RMF 1.0 and IEEE 7000, 7001 and 7010, with art. 22 supplying only the process for ANIA to add further standards. The art. 24 notification templates remain unpublished, as does the overdue Ley de Tecnologías Robóticas art. 20 framework. The registry is no longer purely notional: ania.gob.sv now runs a live «Registro Nacional de IA» intake, though the site itself cautions that «esta recepción no sustituye la constancia oficial cuando el proceso esté formalizado» and no registry instrument has been gazetted. Código Civil art. 46 runs the twelve months to midnight ending 3 September 2026, so on the primary reading the row is still «dateset» today and begins to bite on 4 September 2026; on the alternative 2 September reading it is already biting. It moves to «force» on the first check after 3 September 2026, absent any extension. Flipped to «force» on 4 September 2026, El Salvador local time (04:13 CST), the first check after the art. 29 twelve-month transitional period ran out at midnight ending 3 September 2026. No extension, deferral, suspension or amendment was found in any source. The flip is confirmed and strengthened on the 6 September 2026 re-poll described above, which read four further gazette issues to 27 August 2026; the earlier statement that the corpus ceiling was frozen and that no further source attempt was warranted was wrong and is withdrawn — the ceiling merely lags publication by about ten days. The row rests on a firm no-extension negative through 27 August 2026, with only 28 August – 3 September 2026 outstanding. Legacy AI systems in the six art. 11 sectors that were already operating before 3 September 2025 are now subject to the mandatory registration, algorithmic-impact-assessment and compliance-route requirements in full, with no grace period remaining for any operator; art. 28 escalation, not a fine, is the enforcement route. Still outstanding and unaffected by this flip: the art. 24 notification templates and the overdue Ley de Tecnologías Robóticas art. 20 framework. Method note added 6 September 2026, and the reason an earlier poll wrongly called the corpus ceiling frozen: every Diario Oficial PDF is encrypted with the PDF standard security handler (V4, R4, AESV2 — AES-128-CBC) under an EMPTY user password, so a naive text extractor returns about one character per page across every issue and every control string comes back zero. That is a broken read, not an absence, and on this corpus it is indistinguishable from a clean negative unless controls are checked. The file key is derived by Algorithm 2 from /O, /P and the first /ID string and must be validated against the stored /U by Algorithm 5 before any negative is trusted; each stream then takes a per-object key of MD5(key + objnum[3 LE] + gen[2 LE] + 'sAlT') and is AES-CBC decrypted with its own first sixteen bytes as the IV. Two further traps: the object-number regex must be anchored on whitespace or it captures the tail of a preceding number and derives the wrong per-object key; and the gazette's typesetting injects spaces between the letters of headline words, so «Decreto» occurs as «D e c r e t o» and a stem search must be run against an accent-stripped, fully DE-SPACED copy of the text, not merely a punctuation-collapsed one. Read this way, issues 31826, 31828 and 31829 extract at 1.0–1.8 million characters with healthy controls («republica» 174/53/48, «ministerio» 87/42/30) and issue 31827 decodes cleanly in the sumario, which is the part that indexes ANIA instruments. Across all four: zero occurrences of «inteligencia artificial», «agencia nacional», «algoritm-», «robotic-», «tecnologias roboticas», «datos personales» or «biometr-»; the only «automatizad-» hits are land-registry «folio real automatizado» boilerplate, and every apparent «ania» hit is a substring of Betania, Estefanía or compañía. Still outstanding on the 6 September 2026 check, both re-verified against ania.gob.sv, which serves exactly three documents (ley-fomento-ia.pdf, reglamento-ley-ia.pdf, estrategia-nacional-ia-2026.pdf) and no others: the art. 24 notification templates, and the overdue Ley de Tecnologías Robóticas art. 20 minimum-regulations framework. Re-polled 7 September 2026. The Diario Oficial availability API (POST /api/v1/diarios-disponibles, year=2026 month=8) returns the same fifteen August issues as on 6 September, the highest still being id 31829 of 27 August 2026; year=2026 month=9 returns HTTP 200 with an empty body, i.e. no September issue exists. Ids 31830–31834 were probed directly and every one redirects to the site landing page rather than serving a PDF, whereas 31829 serves a 1.97 MB encrypted PDF — so the ceiling is a real absence, not an access failure. The ceiling therefore did NOT advance at all across a full calendar day. The rate stated on 6 September, that the corpus advances by about one publication day per calendar day, is withdrawn: on this evidence the ceiling moves in irregular bursts, and no date can be predicted for when the outstanding window will close. The unverifiable window accordingly remains 28 August – 3 September 2026, unchanged and NOT narrowed this heartbeat. Two independent corroborating checks were run instead. First, ANIA's own site was re-inventoried and still serves exactly three documents (ley-fomento-ia.pdf, reglamento-ley-ia.pdf, estrategia-nacional-ia-2026.pdf) with no occurrence of «plantilla», «notificaci-», «acuerdo» or «resoluci-» anywhere on the page: no registry acuerdo, no art. 24 templates, no robotics framework. Second, the Centro de Documentación Judicial bóveda was probed by month directory, which turns out to be a one-request existence test: a populated month returns HTTP 403 (directory listing forbidden) and an absent month returns HTTP 404. Calibrated against 2025/08, 2026/06, 2026/07 and 2026/08, all 403, and against 2026/10 as a future-month negative control, 404 — the directory for 2026/09 returns 404, so no instrument dated September 2026 has been deposited to the corpus at all. That is a corroborating negative and not a proof, because the CDJ corpus lags publication just as the gazette does; it is recorded as consistent with, not as independent confirmation of, the no-extension finding. Net effect on the row: none. The «force» lifecycle and the 3 September 2026 date stand on the firm no-extension negative through 27 August 2026. Nothing found on 7 September 2026 extends, defers, suspends or amends the art. 29 transitional period, and the art. 24 notification templates and the overdue Ley de Tecnologías Robóticas art. 20 framework both remain unpublished. Re-polled 11 September 2026. Nothing has moved on any of the three open Salvadoran items, and the significant finding this heartbeat is about the SOURCES rather than the law: both primary corpora are now stalled, so the outstanding 28 August – 3 September 2026 window is not closable on any predictable schedule and daily polling has no yield. First, the Diario Oficial availability API (POST /api/v1/diarios-disponibles) returns for year=2026 month=8 the same fifteen August issues as on 6 and 7 September, the highest still being id 31829 of 27 August 2026; year=2026 month=9 returns HTTP 200 with an empty body. Ids 31830–31835 were probed directly and every one 307-redirects to the site landing page, while 31829 still serves a 1.97 MB PDF — a real absence, not an access failure. The ceiling has therefore been frozen at 27 August 2026 for five consecutive calendar days (6–11 September). Second, the Centro de Documentación Judicial legislative corpus (baseDatos=2) has a watermark of 11 August 2026 on generic control terms («Ministerio» newest hit 11/08/2026; «Presidente de la República» 07/08/2026), unchanged since the early-September polls — roughly a 31-day lag. Third, the bóveda month-directory existence test was re-run and is unchanged: 2025/08, 2026/06, 2026/07 and 2026/08 all return HTTP 403 (populated, listing forbidden), 2026/09 returns 404 and the 2026/10 future-month control also returns 404 — so no instrument dated September 2026 has been deposited. Substantively the subject search is unchanged and confirms the row. The CDJ corpus returns exactly three AI/robotics instruments — Resolución 0001/2025 (D.O. 25 August 2025, Tomo 448), the Ley de Tecnologías Robóticas D.L. 340 (D.O. 21 July 2025, Tomo 448) and the Ley de Fomento a Inteligencia Artificial y Tecnologías D.L. 234 (D.O. 3 March 2025, Tomo 446) — and each is flagged «Vigencia: Vigente». Resolución 0001/2025 is therefore still in force and unamended as indexed; nothing extends, defers, suspends or amends the art. 29 transitional period. The «force» lifecycle and the 3 September 2026 date stand unchanged on the firm no-extension negative through 27 August 2026. The art. 24 notification templates and the overdue Ley de Tecnologías Robóticas art. 20 minimum-regulations framework both remain unpublished. Polling guidance revised for the next poller: with both corpora static, the cheap check is the two-request pair — the availability API for a ceiling past id 31829 / 27 August 2026, and the bóveda 2026/09 directory for a 403 — and it is worth running weekly rather than per-heartbeat. Only a ceiling advance past 27 August 2026 can close the outstanding window. Re-polled 13 September 2026, and the finding reverses the source verdict recorded on 11 September. Both corpora have MOVED. The Diario Oficial availability API (POST /api/v1/diarios-disponibles, year=2026 month=8) now returns seventeen August issues, the highest being id 31832 of 31 August 2026, where on 6, 7 and 11 September the highest that existed was id 31829 of 27 August 2026; and the Centro de Documentación Judicial legislative corpus (baseDatos=2) now indexes to 18 August 2026, against the 11 August 2026 watermark recorded on 11 September. The statement that the ceiling was «frozen at 27 August 2026» and that the outstanding window was «not closable on any predictable schedule» was therefore wrong and is withdrawn; this is the second time a frozen verdict has been written into this row and then disproved by simply re-polling, and the correct reading of this corpus remains that it lags publication in irregular bursts rather than that it stops. The two newly available issues, id 31830 of 28 August 2026 and id 31832 of 31 August 2026, were downloaded and read in full under the AES-128 decryption path described above: 1.99 million and 1.41 million characters of extracted text respectively, with healthy controls («diario oficial» 211 and 158 hits, «republica» 162 and 57, «ministerio» 96 and 22), so the reads are real. Across both issues there are zero occurrences of «inteligencia artificial», «agencia nacional», «robotic-», «tecnologias roboticas» or «registro de sistemas». Id 31831 does not exist as a served issue — it, and ids 31833 and 31834, redirect to the site landing page while 31830 and 31832 serve PDFs — and 29 and 30 August 2026 were a Saturday and Sunday, so 28 and 31 August 2026 complete the business-day coverage of that stretch. The outstanding unverifiable window accordingly narrows from seven calendar days (28 August – 3 September 2026) to the three business days 1–3 September 2026. Nothing found extends, defers, suspends or amends the art. 29 transitional period, so the «force» lifecycle and the 3 September 2026 date stand unchanged. The art. 24 notification templates and the overdue Ley de Tecnologías Robóticas art. 20 minimum-regulations framework both remain unpublished; the subject search still returns exactly three AI/robotics instruments (D.L. 234, D.L. 340, Resolución 0001/2025), each «Vigencia: Vigente». The bóveda month-directory existence test is unchanged — 2025/08, 2026/06, 2026/07 and 2026/08 all return HTTP 403 (populated), 2026/09 returns 404 and the 2026/10 future-month control also returns 404 — so no instrument dated September 2026 has been deposited. Polling guidance for the next poller, superseding the «both corpora static» guidance below it: the ceiling DOES advance, so keep the weekly cadence but expect it to move roughly four publication days per week. The cheap two-request pair is unchanged — the availability API for a ceiling past id 31832 / 31 August 2026, and the bóveda 2026/09 directory for a 403. Only a ceiling advance past 3 September 2026 can close the outstanding window.

Stated maximum penalty — No fine — art. 28 escalation only (guidance with ≥60 days to remediate, formal notice, compliance order, referral to the competent sector authority for serious and repeated violations)

In force · 3 Sep 2026 checked 19 Sep 2026 ANIA Res. 0001/2025 arts. 11–15 ↗ high confidence

Jamaica 1

Jamaica Binding

Data Protection Act, 2020 s. 12 — the UK-1998 opt-out, plus a proactive duty to tell the individual the decision was automated

Binds Every data controller in Jamaica taking a decision that significantly affects a data subject, with no sectoral, size or turnover threshold — enterprise, SME and public body alike. The rule is outcome-scoped rather than sector-scoped: the statutory examples in ss. 6(2)(d) and 12(2) are performance at work, creditworthiness, reliability and conduct, so automated hiring sifts, automated credit and insurance decisions, and automated conduct or disciplinary determinations are squarely inside it. A decision with a human materially in the loop is outside it — s. 12(2) reaches only decisions «based solely on» automatic processing, and the Act supplies no gloss on how much human review defeats that. Two structural points widen the practical reach. First, the s. 12(3) disclosure duty runs by default: it is not conditional on the data subject knowing that automation was used, so a controller that never receives a notice still owes the notification. Second, s. 68(1) provides that where a body corporate commits an offence under the Act, the body corporate is liable, «notwithstanding any other penalty specified in this Act», to a fine not exceeding four per cent of its annual gross worldwide turnover for the preceding year of assessment computed in accordance with the Income Tax Act — a GDPR-scale turnover ceiling grafted onto a 1998-shaped rights regime.. Jamaica does not follow the GDPR art. 22 pattern its Caribbean neighbours use. Section 12 of the Data Protection Act, 2020 (Act 7 of 2020) is drafted on the United Kingdom's Data Protection Act 1998 s. 12 and is a notice-based right rather than a standing prohibition. Section 12(1) fixes the trigger: the section «applies to a decision, other than an exempt decision, taken by or on behalf of a data controller and which significantly affects a data subject». Section 12(2) then gives the individual the entitlement «at any time, by notice in writing to the data controller, to require the data controller to ensure that no decision to which this section applies is based solely on the processing, by automatic means, of personal data in respect of the data subject for the purpose of evaluating matters relating to the data subject (for example, the individual's performance at work, creditworthiness, reliability, or conduct)». Nothing bars the decision until that notice is served. What lifts Jamaica above the 1998 model is s. 12(3), which bites where no notice has been served. Where a controller who has not received a s. 12(2) notice takes a decision to which the section applies, the controller «shall, as soon as is reasonably practicable, inform the individual that the decision was made on the basis described in subsection (2)», and the individual is then entitled, within thirty days of receiving that information, to require the controller by written notice «to reconsider the decision or make a new decision otherwise than on that basis». Section 12(4) gives the controller thirty days from that notice to supply a written statement of the steps it intends to take. This is an unconditional, controller-side disclosure duty attaching to every solely-automated significant decision — the Jamaican Act volunteers the fact of automation, which the Zambian and Mauritian statutes do not. The exemptions sit at s. 12(7)-(8) and are narrower than GDPR art. 22(2) because both limbs must be met. An «exempt decision» is one authorised or required by or under any enactment, or made in the course of steps taken to consider entering into or to perform a contract with the data subject — and, cumulatively, either the effect of the decision is to grant a request of the data subject, or steps have been taken to safeguard the data subject's legitimate interest, «for example, by allowing the data subject to make representations». There is no consent limb at all: consent is not a route out of s. 12 in Jamaica. The logic limb is separate and reactive. Section 6(2)(d) entitles an individual, where processing by automatic means of his personal data «is for the purpose of evaluating matters relating to that individual (such as, for example, the individual's performance at work, creditworthiness, reliability, or conduct)» and «has constituted or is likely to constitute the sole basis for any decision significantly affecting the individual», «to be informed by the data controller, upon payment of the prescribed fee, of the logic involved in that decision-taking». Note the fee: Jamaica is one of the few jurisdictions on this tracker where the explanation right is expressly chargeable. Section 6(7)(a) lets the Commissioner require the logic information to be produced for inspection when adjudicating a s. 6(6) application, but s. 6(7)(b) bars disclosure to the applicant pending determination in the applicant's favour.

Commencement is phased, the phasing matters, and both Appointed Day Notices have now been read in full. Section 1(1) provides that the Act «shall come into operation on a day appointed by the Minister by notice published in the Gazette, and different days may be appointed in respect of different provisions of this Act». Exactly two such notices have been made; the Office of the Information Commissioner's own gazette register lists no third. The first — the Data Protection Act, 2020 (Sections 2, 4, 56, 57, 60, 66, 74 and 77 and First Schedule) (Appointed Day) Notice, 2021, No. 221, Jamaica Gazette Supplement Vol. CXLIV No. 160, dated 30 November 2021 — appointed 1 December 2021 for ss. 2, 4, 56, 57, 60, 66, 74 and 77 and the First Schedule only, which are the Information Commissioner's own constitutive provisions. **Section 12 was not among them**, so the automated-decision right was not in force in 2021, and any source dating this obligation to 1 December 2021 is reading the wrong notice. The operative instrument is the second: the Data Protection Act, 2020 (Additional Specified Provisions) (Appointed Day) Notice, 2023, No. 437A, Jamaica Gazette Supplement (Proclamations, Rules and Regulations) Vol. CXLVI No. 364A, Friday 1 December 2023, at pp. 2928A-2928B, dated 30 November 2023 and signed by Andrew Holness, Prime Minister. Its paragraph 2 appoints 1 December 2023 as the day on which «(a) sections 1 and 3; (b) Part II; (c) sections 14, 15, 16, 17, 19 and 20; (d) sections 21(1), (3), (4) and (5); (e) sections 22, 23, 24, 25, 26, 27, 28, 29, 30 and 31; (f) Part V; (g) sections 58, 59, 61, 63, 64, 65, 67, 68, 69, 71, 72, 73, 75 and 76; and (h) the Second and Fourth Schedules» shall come into operation. **Section 12 is not named individually — it arrives inside limb (b).** The Act's arrangement of sections puts Part II («Rights of Data Subjects and Others») at ss. 5 to 13, s. 12 being «Rights in relation to automated decision-taking» and s. 13 «Rectification of inaccuracies, etc.», and Part III opens at s. 14, which is why limb (c) starts there. Appointing Part II therefore commences ss. 5-13 as a block, bringing s. 12 and the s. 6(2)(d) logic-explanation right into force together on 1 December 2023. The reading checks out internally: within the ranges the 2023 notice otherwise covers, the sections it skips are 2, 56, 57, 60, 66, 74 and 77 — precisely those already commenced by the 2021 notice. **The date is now confirmed against the enumerated section list rather than inferred from the section 76 transition period.** Section 76(1)'s two-year compliance term, running from the earliest appointed day of 1 December 2021, independently expires on the same date, and s. 76(2) bars proceedings for good-faith processing during it. ⚠️ What the same notice leaves out is material, and the penalty field reflects it: **the whole of Part VI (Enforcement, ss. 44-55) is absent from the list**, as are s. 18 (the Part III registration offences), s. 21(2), s. 62 (the Commissioner's fixed-penalty power), s. 70 (Appeals) and the Third Schedule. Section 12 is in force while the general enforcement machinery that would ordinarily back it is not. Note also that s. 45, the data protection impact assessment duty, sits in Part VI and is likewise uncommenced. Provenance: the 2023 notice is published only as a two-page mixed-raster scan with no text layer (pdf.js returns 16 characters per page); the section list was recovered by decoding the file's JBIG2 mask layer to an image and reading it directly, and the 2021 notice, which does carry a text layer, was used as the control.

Stated maximum penalty — No offence attaches to s. 12 directly, and — the point that matters most here — much of the enforcement architecture that would ordinarily back it has never been commenced. The 2023 Appointed Day Notice omits the whole of Part VI (ss. 44-55), so the enforcement notice (s. 44), the data protection impact assessment duty (s. 45), requests for assessment (s. 46), assessment notices (s. 47), information notices (s. 49), the offence of failing to comply with a notice (s. 52, which carries the fine not exceeding one million Jamaican dollars on conviction in a Parish Court), the rights of appeal (ss. 53-54) and the powers of entry and inspection (s. 55) are all enacted but not in operation. Section 62, the Commissioner's fixed-penalty power, is likewise uncommenced, as is s. 18, the Part III registration offence. Any statement that a s. 12 breach exposes a controller to the JMD 1,000,000 s. 52 fine is describing Jamaican law that is not yet in force. What is operative is narrower and sits inside the section itself. Section 12(5), in force with the rest of Part II since 1 December 2023, provides that where the Commissioner is satisfied on a data subject's application that a controller has failed to comply with a notice under s. 12(2) or s. 12(3)(b), the Commissioner «may order the data controller to reconsider the decision, or to take a new decision, that is not based solely on such processing as is described in subsection (2)», and s. 12(6) confines the order's effect to the data subject and the controller. Alongside it s. 69 (Liability for damage) is in force and supplies a civil compensation route, and ss. 61, 67, 68 and 75 are in force. Section 68(1) makes a body corporate that commits any offence under the Act liable, notwithstanding any other penalty specified in the Act, to a fine not exceeding four per cent of annual gross worldwide turnover for the preceding year of assessment, with s. 68(2) listing the quantum factors and s. 68(3) extending liability to a consenting or conniving director, manager or secretary. That four per cent ceiling is itself in force, but it is parasitic — it amplifies an offence under the Act rather than creating one, and the offence provisions it would attach to in this context, ss. 18 and 52, are precisely the ones not yet commenced. In practice the live exposure for an automated-decision failure in Jamaica today is a s. 12(5) reconsideration order plus s. 69 damages, not a fine. Section 75 lets the Minister amend any monetary or fixed penalty by affirmative-resolution order. Impact tier: all entities.

In force · 1 Dec 2023 checked 9 Sep 2026 Data Protection Act 2020 s. 12 ↗ high confidence

Barbados 1

Barbados Binding

Data Protection Act, 2019-29 s. 18 — a GDPR art. 22 transplant that is stricter than the original on sensitive data

Binds Every data controller and data processor within the Act's territorial reach, with no size, turnover or sector threshold — enterprise, SME and public body alike. The hiring, credit and insurance cases are the paradigm: the s. 2 profiling definition covers evaluation of personal aspects relating to a natural person, and an automated sift or score producing a hiring, lending or underwriting outcome both «produces legal effects» or at least «similarly significantly affects» the individual within s. 18(1). Two features are worth separating from the European original. First, s. 18(4) makes the sensitive-personal-data case categorically harder than under the GDPR, because the consent route is removed rather than tightened — a controller running automated health, biometric, trade-union or similar profiling in Barbados needs a public-interest justification, not a signature. Second, the s. 19/20 disclosure duty is drafted as a collection-time obligation rather than as an access right, so it binds a controller that has never received a data-subject request; the trigger is obtaining the data, not being asked about it. A decision with a human materially in the loop is outside s. 18 entirely — the section reaches only decisions «based solely on» automated processing.. Section 18 of the Data Protection Act, 2019-29 is headed «Automated individual decision-making, including profiling» and reproduces GDPR art. 22 almost word for word. Section 18(1): «The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or similarly significantly affects him.» Section 18(2) disapplies that where the automated processing or profiling is (a) «necessary for entering into, or performance of, a contract between the data subject and a data controller»; (b) «authorised by any enactment to which the data controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests»; or (c) «based on the data subject's consent». Section 18(3) then requires that in the (a) and (c) cases — contract and consent, not the statutory-authorisation case, which carries its own safeguards on the face of (b) — the controller «shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests». Section 18(4) is where Barbados departs from the European text and goes further: «Subsection (2) shall not apply to sensitive personal data unless it is in the public interest and suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place.» GDPR art. 22(4) permits solely-automated processing of special-category data on explicit consent or substantial public interest; the Barbadian provision drops the consent route entirely, so no amount of consent will license a solely-automated significant decision on sensitive personal data in Barbados. Read with s. 18(2)(c), the result is that consent unlocks automation for ordinary personal data and never for sensitive personal data. The transparency limb is proactive and cross-referenced, unlike the reactive access-only limb in Zambia. Both s. 19 (information to be provided where personal data is collected from the data subject) and s. 20 (where it has not been so obtained) require the controller to give «the existence of automated decision-making, including profiling, referred to in section 18 and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject» — at the time the data is obtained, without a request and without a fee. Section 19(3) extends the duty to further processing for a new purpose. «Profiling» is defined in s. 2 in GDPR terms as any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.

Section 100 of the Act is a bare enabling clause — «This Act comes into operation on a date to be fixed by proclamation» — and the face of the Act carries only «[Commencement: by Proclamation]», so the 12 August 2019 assent printed in Official Gazette No. 66 is not the operative date and must not be carried as one. The Act was proclaimed in late March 2021 and brought into operation on 31 March 2021, excepting the controller/processor registration provisions at ss. 50, 51, 52, 55, 56 and 57, which were held back. **The proclamation instrument itself has not been read on this box**: the Barbados Official Gazette issue carrying it is not exposed on `oag.gov.bb`, `gisbarbados.gov.bb` or `barbadosparliament.com` in a form reachable from here, and the 31 March 2021 date and the excepted-section list come from consistent secondary reporting rather than from the gazette. Confidence is held at medium on that ground alone; the text of s. 18 is verified verbatim against the Act as published by the Office of the Attorney General and is not in doubt. The exception list is not idle detail — it interacts directly with the penalty position. Section 95(1) confines the Commissioner's administrative penalty to contraventions of s. 52(1), s. 57(1) and ss. 60 to 67, and two of those three named sections (52 and 57) are among the provisions withheld from the proclamation, which narrows the administrative route further still. Section 18 is not in the withheld list and has been in operation since 31 March 2021. To close the gap, obtain the March 2021 Barbados Official Gazette proclamation and confirm the excepted sections by number; that would move confidence to high without changing the date.

Stated maximum penalty — No offence and no administrative penalty attaches to s. 18 itself, and the reason is structural. Section 95(1) empowers the Commissioner, after a hearing and where he considers it in the public interest, to order a person who «has contravened section 52(1), section 57(1) and sections 60 to 67» to pay the Crown a penalty not exceeding BBD 50,000, with the s. 95(2) quantum factors (nature, gravity and duration; intent or negligence; mitigation; previous contraventions; cooperation; categories of data affected; self-notification) tracking GDPR art. 83(2). Section 18 is outside that enumerated list, so the administrative fine cannot reach it. The operative route is the enforcement notice. Section 75(1) lets the Commissioner, where satisfied that a controller or processor «has contravened or is contravening this Act» — the whole Act, not a subset — serve a notice requiring specified steps to be taken or refrained from, or requiring the person to stop processing altogether; s. 75(2) requires him to consider whether the contravention has caused or is likely to cause damage or distress, and s. 75(3) requires the notice to state the provision contravened and the s. 91 appeal right. Disobedience is then an offence: s. 83(1) provides that a person who fails to comply with an enforcement notice, an information notice or a special information notice is guilty of an offence and liable on summary conviction to a fine of BBD 15,000 or to imprisonment for 6 months, with a due-diligence defence at s. 83(3); a knowing or reckless false statement in purported compliance with an information notice carries BBD 500,000 or 3 years under s. 83(2). A data subject also has a free-standing civil claim under s. 93 (right to compensation and liability) and an appeal to the Data Protection Tribunal established under s. 90. Impact tier: all entities.

In force · 31 Mar 2021 checked 20 Sep 2026 Data Protection Act 2019-29 s. 18 ↗ medium confidence

Questions & answers

From the data

When must a chatbot disclose that it is AI?

Several laws now require it. The EU AI Act’s Article 50, California’s SB 243 companion-chatbot rules, South Korea’s AI Basic Act and Vietnam’s Law on AI all require users to be told that they are dealing with an AI system rather than a human.

What is training-data transparency?

A duty to publish a summary of the data used to train a model. California’s AB 2013 requires generative-AI developers to post a dataset summary; the EU AI Act requires GPAI providers to publish a sufficiently detailed summary of training content.

Which AI transparency rules apply to automated decisions?

Quebec’s Law 25 gives individuals a right to be informed of, and to understand the main factors behind, an automated decision made about them using personal information; Colorado’s AI Act adds consumer notice and appeal rights for consequential automated decisions.

Which jurisdictions does AI Law Radar track for transparency & disclosure?

We currently track transparency & disclosure obligations across 75 jurisdictions: Albania, Angola, Australia, Azerbaijan, Bosnia and Herzegovina, Burkina Faso, Burundi, Benin, Brazil, Canada, Democratic Republic of the Congo, Central African Republic, Republic of the Congo, Switzerland, Côte d'Ivoire, Chile, Cameroon, China, Cabo Verde, Germany, Algeria, Ecuador, Egypt, European Union, Gabon, Georgia, Ghana, Guinea, Equatorial Guinea, Indonesia, India, Japan, Kenya, Kyrgyzstan, South Korea, Kazakhstan, Morocco, Moldova, Montenegro, Madagascar, North Macedonia, Mali, Mauritania, Mauritius, Mexico, Mozambique, Namibia, Niger, Nigeria, Panama, Philippines, Serbia, Russia, Rwanda, Singapore, Senegal, São Tomé e Príncipe, Togo, Thailand, Türkiye, Tanzania, Ukraine, Uganda, United Kingdom, United States, Uruguay, Uzbekistan, Vietnam, Kosovo, South Africa, Zambia, Paraguay, El Salvador, Jamaica and Barbados. Each is dated and linked to its primary source on this page.