Loi n° 2014-006 du 17 juillet 2014 sur la lutte contre la cybercriminalité
mg-cyber-2014 · Act
Law No. 2014-006 of 17 July 2014 on combating cybercrime is Madagascar's principal dedicated cybercrime statute. Adopted because the existing Penal Code could not address offences committed in cyberspace, it comprises 41 articles across three chapters and was subsequently amended and supplemented by Law No. 2016-031 of 23 August 2016. Chapter I ('Offences relating to information systems', arts 1-15) defines core technical terms and criminalises fraudulent access to or remaining within an information system, the fraudulent input, alteration, deletion or suppression of computer data, computer-related forgery (producing inauthentic data for legal use), interference with and obstruction of system functioning, illegal interception of non-public data transmissions, the misuse of devices, access codes and passwords designed to commit these offences, and computer-related fraud causing patrimonial loss. Participation in an organised group formed to commit these offences and attempt are punished as the substantive offence, and recidivism attracts doubled penalties. Chapter II ('Offences against natural persons committed through an information system', arts 16-25) addresses online threats, identity usurpation intended to disturb a person's peace or harm their honour, online insult and defamation (including of constituted bodies and public officials), denial or trivialisation of genocide and crimes against humanity, child pornography (defined for under-18s, including realistic or computer-generated images), online solicitation of minors, and the dissemination of violent, pornographic, racist or xenophobic material. Chapter III (arts 26-41) regulates telecommunications and electronic-communications operators and service providers: it imposes obligations to erase or anonymise traffic data, permits deferral of erasure for up to one year for judicial purposes (data preservation and retention), restricts retained data to identification, technical characteristics and terminal location rather than content, and obliges operators to block reported stolen handsets. Article 35 introduced corporate criminal liability into Malagasy law for operator breaches, and Article 40 criminalises refusal to surrender a decryption key to the judicial authorities. Enforcement runs through the ordinary criminal courts and judicial police; the law does not establish a dedicated cybercrime agency. The statute has been criticised for the breadth of its speech-related offences.
- System offences (arts 3-14): fraudulent access or remaining, data interference, computer forgery, system interference, illegal interception and misuse of devices
- Computer-related fraud causing patrimonial loss (art 15)
- Offences against persons (arts 16-25): online threats, identity usurpation, online insult and defamation, child pornography (incl. realistic or computer-generated images) and solicitation of minors
- Organised-group participation and attempt punished as the substantive offence, with doubled penalties for recidivism (arts 10, 37, 38)
- Operator and ISP duties to erase or anonymise traffic data, with judicial deferral (data preservation) of up to one year (arts 26-27)
- Corporate criminal liability for operator breaches (art 35)
- Mandatory disclosure of decryption keys to the judicial authorities (art 40)
- Amended and supplemented by Law No. 2016-031 of 23 August 2016