NigerIn ForceData Protection

Loi N° 2022-59 du 16 décembre 2022 relative à la protection des données à caractère personnel (Niger Personal Data Protection Act 2022)

ne-dp-2022 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Law No. 2022-59 of 16 December 2022 is Niger's current primary personal data protection statute, replacing the earlier legislative framework established by Law No. 2017-28 of 3 May 2017 (as amended by Law No. 2019-71 of 24 December 2019). The 2022 law represents a comprehensive update reflecting rapid technological evolution and Niger's commitment to alignment with international data protection standards, including the ECOWAS regional framework and Convention 108+. The law applies to any collection, processing, preservation, or use of personal data, whether by automated or manual means in structured filing systems. Personal data is defined broadly to include any information of any nature whatsoever, regardless of its medium, relating to an identified or identifiable natural person, whether directly or indirectly through reference to identification numbers or specific physical, psychological, genetic, cultural, social or economic elements. The law aims to guarantee confidentiality, security, and responsible use of personal information, while strengthening trust in digital services and electronic transactions within Niger. It establishes obligations for data controllers relating to lawfulness of processing, purpose limitation, data minimisation, accuracy, security, and accountability. Data subjects are granted enforceable rights consistent with modern data protection frameworks, including rights of access, rectification, erasure, and objection. The law also addresses the processing of sensitive personal data, which is subject to stricter conditions and may require prior authorisation from the supervisory authority. Cross-border transfers are regulated, with restrictions on transfers to countries that do not ensure an adequate level of protection for personal data. The Haute Autorité de la Protection des Données à Caractère Personnel (HAPDP) is the supervisory authority. Established by the 2017 law and officially launched on 5 August 2020, the HAPDP has continued under the 2022 framework. The law has been further modified by Law No. 2023-31 of 4 July 2023 and by Ordinances Nos. 2024-16 of 26 April 2024 and 2024-29 of 24 June 2024. Reviewer should confirm whether these modifications affect any of the key provisions described above. Source language: French.

Key provisions
  1. Processing must comply with principles of lawfulness, purpose limitation, data minimisation, accuracy, security, and accountability; the HAPDP supervises conformity.
  2. Data subjects have rights of access, rectification, erasure, and objection enforceable against data controllers.
  3. Sensitive personal data requires additional safeguards and may require prior HAPDP authorisation.
  4. Cross-border transfers of personal data are restricted to countries ensuring adequate protection or meeting specific safeguard conditions.
  5. The HAPDP is the independent supervisory authority; it receives declarations and authorisations, investigates complaints, and enforces compliance.
  6. Law No. 2022-59 repealed Laws Nos. 2017-28 and 2019-71; it has been further modified by Law No. 2023-31 of 4 July 2023 and Ordinances 2024-16 and 2024-29.
  7. Reviewer action required: confirm final consolidated text, verify modifications by 2023 and 2024 instruments, and confirm current effective provisions.
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from HAPDP official website text; note: this law repealed earlier Laws No. 2017-28 and No. 2019-71; further modified by Law No. 2023-31 of 4 July 2023 and Ordinances 2024-16 and 2024-29