ChadIn ForceData Protection

Law No. 007/PR/2015 on the Protection of Personal Data (Chad)

td-pdpl-2015 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Law No. 007/PR/2015 on the protection of personal data is Chad's comprehensive data protection statute, enacted in 2015. It establishes a legal framework covering the collection, processing, transmission, and storage of private and professional data. The law requires that the collection, processing, storage, recording, and transmission of personal data be carried out lawfully, fairly, and non-fraudulently, and that personal data be collected only for explicit, specific, and legitimate purposes. Data subjects are granted the right to be informed about the processing of their personal data, the right to require the correction of their data, the right to request its deletion, and the right to object, on legitimate grounds, to the processing of their personal data. Controllers and processors are subject to corresponding obligations around lawful processing and security. Institutionally, the supervisory function is housed in the Agence Nationale de Sécurité Informatique et de Certification Électronique (ANSICE), an authority established by the companion Law No. 006/PR/2015 in the same year, which became fully operational in 2020. Penalties for non-compliance range from CFA 1 million to CFA 10 million (approximately USD 1,700 to USD 17,300), and offenders may face imprisonment of three months to one year. This entry was created from a June 2026 verification search rather than from a pre-existing ATLPF research file. The exact enactment date within 2015, cross-border transfer rules, sensitive-data provisions, and any subsequent amendments should be confirmed against the official text and a primary-source URL added. Note that ANSICE is primarily an IT-security and electronic-certification body, so the strength of its dedicated data protection enforcement is uncertain. Source language: French.

Key provisions
  1. Chad's comprehensive data protection statute, enacted 2015, covering collection, processing, transmission, and storage of personal data.
  2. Requires lawful, fair, and non-fraudulent processing for explicit, specific, and legitimate purposes.
  3. Data subjects have rights to information, correction, deletion, and objection on legitimate grounds.
  4. Supervisory authority is ANSICE, established by Law No. 006/PR/2015 and operational from 2020.
  5. Penalties: fines of CFA 1 million to 10 million and imprisonment of three months to one year.
  6. Reviewer action: confirm exact enactment date, transfer and sensitive-data provisions, and amendments against the official text; add primary-source URL.