Loi N° 2013-015 du 21 mai 2013 portant protection des données à caractère personnel en République du Mali (Mali Personal Data Protection Act 2013)
ml-dp-2013 · Act
Law No. 2013-015 of 21 May 2013 is Mali's primary personal data protection statute. Adopted as part of a broader regional wave of data protection legislation aligned with the ECOWAS Supplementary Act A/SA.1/01/10 of 2010, the law establishes a comprehensive framework for the protection of personal data and fundamental freedoms in the context of digital processing. The law applies to all automated processing of personal data, as well as non-automated processing in structured filing systems, carried out by natural or legal persons, whether public or private, established in Mali. Controllers outside Mali are also subject to the law where they use processing equipment located in Mali. The law is built around core data quality principles: personal data must be collected for specified, explicit and legitimate purposes; must be adequate, relevant and not excessive relative to those purposes; must be accurate and kept up to date; and must not be retained for longer than necessary. Data controllers must implement appropriate technical and organisational security measures to protect data against accidental or unlawful loss, alteration, or unauthorised access. A prior notification or authorisation regime applies before processing commences. Simple processing activities are declared to the Autorité de Protection des Données à caractère Personnel (APDP); processing involving sensitive data or data posing heightened risks requires prior authorisation. The APDP was established by Article 20 of the law as an independent administrative authority and became operational in 2016. Data subjects are granted enforceable rights of access, rectification, erasure, and opposition, including the right to oppose processing for direct marketing purposes without giving reasons. Automated individual decision-making producing significant legal effects requires specific safeguards. Cross-border transfers of personal data are prohibited unless the recipient country ensures an adequate level of protection, or specific safeguards or derogations apply. The law was amended by Law No. 2017-070 of 18 December 2017, which revised provisions relating to the composition and functioning of the APDP. Penalties include fines and imprisonment, with aggravated sanctions for processing sensitive data without authorisation. Source language: French.
- Processing must be declared to or authorised by the APDP before commencing, depending on the nature of the data and the processing activities involved.
- Sensitive data (health, ethnic origin, political opinions, religious beliefs, biometrics, sexual life, criminal convictions) requires prior APDP authorisation; processing without authorisation is a criminal offence.
- Data subjects have enforceable rights of access, rectification, erasure, and opposition, including opposition to direct marketing processing without reasons.
- Cross-border transfers are prohibited unless the recipient country ensures adequate protection or appropriate safeguards are in place.
- The APDP is the independent supervisory authority established by Article 20 of the law; it receives notifications and authorisation requests, conducts investigations, and enforces compliance.
- Automated individual decision-making producing significant legal effects requires specific safeguards and data subject notification.
- Law No. 2017-070 of 18 December 2017 amended provisions on the composition and operation of the APDP; reviewer should confirm whether further amendments have been enacted.
- Penalties include fines and imprisonment; aggravated sanctions apply for unauthorised sensitive-data processing and obstruction of APDP investigations.