Loi n° 2014-038 sur la protection des données à caractère personnel
mg-dp-2014 · Act
Law No. 2014-038 on the Protection of Personal Data is Madagascar's primary legislative framework governing the collection, processing, and storage of personal data. Adopted by the National Assembly in December 2014 and promulgated on 9 January 2015, the law draws substantially from the EU Data Protection Directive 95/46/EC and reflects the principles of the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention). It entered into force upon publication in the Official Gazette on 9 June 2015. The law applies to any automated or manual processing of personal data carried out on Malagasy territory by a public body or private organisation, and also extends to processing outside Madagascar where a data controller uses means located in the country. It covers both automated processing and manual filing systems where data is organised by reference to individuals. Data controllers must register with the Commission de l’Informatique et des Libertés (CIL) before undertaking any processing of personal data. Processing must rest on a lawful basis: consent, contractual necessity, legal obligation, protection of vital interests, or public interest. Sensitive data categories, including health, biometric, political opinion, religious belief, and racial origin, are subject to heightened restrictions and generally require express consent or a derogation authorised by the CIL. Data subjects have the right to be informed of the purposes and legal basis for processing, the right of access to their personal data, the right to rectification of inaccurate or incomplete data, and the right to object to processing for direct marketing or other legitimate-interest purposes. The law also provides a right to refuse automated decision-making where such decisions produce significant legal or similar effects on the individual. Data controllers must implement appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. The law does not prescribe an explicit breach notification timeline, but failure to maintain adequate security constitutes an enforceable violation. Cross-border transfers of personal data are permissible only to countries providing an adequate level of protection, or where the CIL has authorised a transfer on the basis of contractual guarantees, binding corporate rules, or the data subject’s explicit consent. Transfers to jurisdictions without one of these conditions are prohibited. Violations attract administrative sanctions including suspension of data processing activities, as well as criminal penalties. Fines range from MGA 200,000 to MGA 10,000,000 depending on the nature and gravity of the infringement; more serious offences, such as unlawful processing of sensitive data, may result in terms of imprisonment. The Commission Malagasy de l’Informatique et des Libertés (CMIL), formally established by Decree 2023-1541 in December 2023 and operationalised in August 2025, is the independent supervisory authority. Prior to its formal constitution, the law’s reference to a CIL body was unrealised in practice, significantly limiting enforcement capacity in the years since the law entered into force.
- All data controllers must register with the Commission de l’Informatique et des Libertés (CIL) before commencing any processing of personal data
- Data subjects have rights of access, rectification, and objection to processing carried out for direct marketing or legitimate-interest purposes
- Processing of sensitive data categories (health, biometric, political, religious, racial) requires express consent or a derogation authorised by the CIL
- Cross-border transfers are permitted only to countries providing adequate protection or where the CIL grants specific authorisation on the basis of contractual guarantees, binding corporate rules, or consent
- No explicit breach notification timeline is prescribed; failure to maintain adequate security measures constitutes an enforceable violation
- Criminal penalties include terms of imprisonment for serious offences such as unlawful processing of sensitive data
- Fines range from MGA 200,000 to MGA 10,000,000 depending on the nature and gravity of the infringement