CF

Central African Republic

Central Africa

0Instruments
0Cases
0Regulators
0%Coverage
Overview

The Central African Republic has no comprehensive personal data protection law. A June 2026 verification search confirmed that the country lacks dedicated data protection legislation and, more broadly, comprehensive cyber-law infrastructure; ATLPF holds no Instrument or Regulator record for the jurisdiction, consistent with that finding. No supervisory authority exists, and no advanced or publicly confirmed draft data protection bill was identified. Such data-governance activity as exists is sectoral and incidental, for example, references to data-security measures in the context of public-health institution-building, rather than a general personal data protection regime. Against the backdrop of the country's wider security and institutional challenges, data protection has not been a legislative priority. For anyone assessing data-handling obligations in the Central African Republic, the practical position is that there is no statutory data protection regime, no registration or breach-notification requirements, and no supervisory enforcement; any privacy protection would rest on general constitutional or international human-rights commitments rather than a dedicated framework.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection00
AI Governance00
Fintech00
Cybercrime00
Digital Rights00
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Notable gaps

The gap is the absence of any comprehensive data protection law, supervisory authority, or advanced draft bill. The country also lacks broader cyber-law infrastructure that might otherwise carry incidental data protection provisions.