Loi N° 025-2018/AN du 31 mai 2018 portant Code pénal (Penal Code of Burkina Faso, substantive cybercrime offences, Book VII)
bf-cyber-2018 · Act
Burkina Faso criminalises cyber offences principally through its Penal Code, enacted by Law No. 025-2018/AN of 31 May 2018, whose Book VII sets out an extensive catalogue of computer- and technology-related offences. The reform followed a March 2018 Council of Europe mission and was designed to bring Burkinabè law into line with the Budapest Convention while respecting fundamental rights; the agreed provisions were then incorporated into the wider revision of the Penal Code and the Code of Criminal Procedure. On the substantive side, Book VII and related provisions criminalise illegal access to and interference with information systems and computer data, computer-related forgery and fraud, and a range of cyber-enabled conduct. Notable specific offences include online child pornography (art. 533-37); obtaining computer data by extortion (art. 611-28), by threat (art. 611-29) or by fraud (art. 613-1); misappropriation and concealment of computer data (arts. 613-3 and 614-1); malicious use of cryptographic means (art. 216-10); and the manufacture, import, possession, offer, hire or sale of devices designed to breach the privacy of others (art. 524-10). Procedurally, the framework is completed by the Code of Criminal Procedure (Law No. 040-2019/AN of 29 May 2019), which created investigation measures specific to computer data to facilitate digital enquiry (arts. 515-26 to 515-42). In addition, the earlier Law No. 040-2017/AN of 29 June 2017 had already introduced special investigation techniques relevant to cybercrime suppression, including interception of telecommunications, infiltration, pseudonymous online investigation, and seizure of computer data. Enforcement institutions include ANSSI (the national information-systems security agency, established 2013, which manages the CIRT-BF), the Brigade Centrale de Lutte Contre la Cybercriminalité (BCLCC), ARCEP as electronic-communications regulator, and the Commission de l'Informatique et des Libertés for data protection. Burkina Faso has no single dedicated cybercrime statute; the framework is split between the Penal Code (substantive) and the Code of Criminal Procedure (procedural). A National Strategy to Combat Cybercrime 2025-2029 was validated in November 2024 and a law on the protection of information systems was adopted in July 2024. International cooperation currently rests on bilateral treaties and the Niamey Accord, with Budapest Convention accession pending. Source language: French.
- Book VII of the 2018 Penal Code establishes a comprehensive catalogue of cyber-dependent and cyber-enabled offences, including illegal access to and interference with information systems and data
- Specific offences: online child pornography (art. 533-37); obtaining computer data by extortion (art. 611-28), threat (art. 611-29) or fraud (art. 613-1); misappropriation and concealment of computer data (arts. 613-3, 614-1)
- Malicious use of cryptographic means (art. 216-10) and manufacture, import, possession, offer, hire or sale of devices enabling breaches of privacy (art. 524-10)
- Procedural investigation measures specific to computer data in the Code of Criminal Procedure (Law No. 040-2019/AN of 29 May 2019, arts. 515-26 to 515-42)
- Earlier Law No. 040-2017/AN of 29 June 2017 introduced special investigation techniques (interception, infiltration, pseudonymous online investigation, seizure of computer data)
- Enforcement by ANSSI / CIRT-BF, the Brigade Centrale de Lutte Contre la Cybercriminalité (BCLCC) and ARCEP; reform aligned to the Budapest Convention following a 2018 Council of Europe mission
- Cross-border cooperation rests on bilateral treaties and the Niamey Accord (G5 Sahel); Budapest Convention accession pending