Loi N° 001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel (Burkina Faso Personal Data Protection Act 2021)
bf-dp-2021 · Act
Law No. 001-2021/AN of 30 March 2021 is Burkina Faso's current primary data protection statute, replacing the earlier Law No. 010-2004/AN of 20 April 2004. Promulgated by Presidential Decree No. 2021-0276, it represents a comprehensive modernisation of the country's data protection regime, drawing on the EU General Data Protection Regulation (GDPR) and the updated Council of Europe Convention 108+. The law applies to any automated processing of personal data, as well as non-automated processing in structured filing systems, carried out by public authorities and private entities. It has extra-territorial reach, applying to processing by controllers and processors not established in Burkina Faso where the processing relates to data subjects located in the country. Building on the foundation of the 2004 law, the 2021 Act expands data subject rights to include explicit provisions on the right to data portability, the right to erasure (sometimes described as the right to be forgotten), and the right to restriction of processing, alongside the established rights of access, rectification, and objection. Controllers are required to maintain records of processing activities and to embed data protection considerations into system design (privacy by design and by default). The law introduces a mandatory Data Protection Officer (DPO) requirement for controllers whose core activities involve large-scale systematic monitoring of data subjects, or large-scale processing of sensitive data. DPOs may be internal staff or external service providers. A significant departure from the 2004 regime is mandatory breach notification. In the event of a personal data breach, controllers must notify the Commission de l'Informatique et des Libertés (CIL) within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to individuals' rights and freedoms, affected data subjects must also be notified without undue delay. Cross-border transfers of personal data are permitted only where an adequacy determination has been made, appropriate safeguards are in place (including standard contractual clauses or binding corporate rules), or specific derogations apply. The CIL retains its status as the competent supervisory authority. The 2021 law significantly enhances the CIL's enforcement arsenal by introducing administrative fines for infringements, in addition to the criminal sanctions retained from the earlier law. Source language: French.
- Controllers must notify the CIL of personal data breaches within 72 hours of discovery; high-risk breaches must also be communicated directly to affected data subjects without undue delay.
- Data subjects have rights of access, rectification, erasure, portability, restriction, and objection enforceable against controllers and processors.
- Controllers and processors must maintain records of processing activities and implement privacy by design and by default.
- DPO appointment is mandatory where processing involves large-scale systematic monitoring or sensitive data processing at scale.
- Cross-border transfers require an adequacy determination, appropriate safeguards (e.g. standard contractual clauses or binding corporate rules), or a specific derogation.
- The CIL may impose administrative sanctions in addition to referring criminal violations; sanctions regime is enhanced relative to the 2004 law.
- Processing of sensitive data (health, biometrics, criminal convictions, political opinions) requires additional safeguards and prior CIL authorisation.
- The law applies extra-territorially to controllers outside Burkina Faso who process personal data of individuals located in the country.