Loi N° L/2016/037/AN du 28 juillet 2016 relative à la cybersécurité et à la protection des données à caractère personnel (Guinea Cybersecurity and Personal Data Protection Act 2016)
gn-csdp-2016 · Act
Law No. L/2016/037/AN of 28 July 2016 is Guinea's principal statute governing both cybersecurity and the protection of personal data, consolidating two regulatory domains into a single instrument. Adopted by the National Assembly and promulgated in 2016, the law reflects an approach common in states at early stages of digital regulation, addressing computer crime, electronic transactions, and personal data protection within a unified legal framework. In relation to personal data protection, the law establishes foundational principles consistent with the ECOWAS regional framework, including purpose limitation, data minimisation, accuracy, security, and lawful processing. It defines the categories of personal data, distinguishes between ordinary and sensitive personal data, and sets out the conditions under which processing is permissible. Sensitive data, including health information, racial or ethnic origin, political opinions, religious beliefs, and sexual orientation, is subject to stricter processing conditions. The law envisages the creation of a dedicated personal data protection authority by regulatory means, but as of the date of drafting, a standalone data protection authority has not been formally operationalised. Supervisory functions are exercised in practice by the Autorité de Régulation des Postes et Télécommunications (ARPT), which hosts the law on its website and operates a personal data protection section. The Agence Nationale de Sécurité des Systèmes d'Information (ANSSI) also hosts the law and exercises cybersecurity functions. Data subjects are granted rights of access, rectification, and opposition. The law establishes criminal penalties for a range of offences, including unauthorised access to computer systems (1 to 5 years' imprisonment plus fines of 60 to 130 million GNF), obstruction of computer systems (3 to 6 years' imprisonment plus fines of 100 to 500 million GNF), and fraudulent data interception (5 to 10 years' imprisonment plus fines of 500 million to 1 billion GNF). Cross-border data transfers are regulated under the law, which restricts transfers to countries that do not ensure an adequate level of protection. The law also addresses cybercrime offences including hacking, phishing, and electronic fraud. Note: some sources cite the enacted date as 26 July 2016; 28 July 2016 is used here on the basis of the ARPT official publication but flagged for reviewer verification. The absence of a formally established standalone data protection authority is a significant implementation gap that reviewers should note. Source language: French.
- The law combines cybersecurity regulation and personal data protection in a single instrument; data protection provisions establish principles of purpose limitation, data minimisation, accuracy, and security.
- Sensitive data (health, ethnic origin, political opinions, sexual orientation) is subject to additional processing restrictions and may require prior authorisation.
- Data subjects have rights of access, rectification, and opposition enforceable against data controllers.
- Cross-border transfers of personal data are restricted to countries ensuring an adequate level of protection.
- A dedicated personal data protection authority is envisaged by the law but has not been formally established by regulation as of the date of drafting; ARPT exercises de facto supervisory functions.
- Criminal sanctions for cybercrime offences range from 1 to 10 years' imprisonment and fines from 60 million to 1 billion GNF, depending on the offence.
- Mandatory cybersecurity incident reporting (72-hour window) has been operationalised through a 2024 implementing decree applying to electronic transaction systems.
- The Agence Nationale de Sécurité des Systèmes d'Information (ANSSI) exercises cybersecurity functions alongside ARPT under the same legislative framework.