Guinea
West Africa
Guinea regulates personal data through Law No. L/2016/037/AN of 28 July 2016 on cybersecurity and the protection of personal data, which consolidates several regulatory domains, computer crime, electronic transactions, and personal data protection, within a single instrument, an approach common in states at an early stage of digital regulation. On data protection, the law establishes ECOWAS-aligned principles (purpose limitation, minimisation, accuracy, security), distinguishes ordinary from sensitive data (subject to stricter conditions and sometimes prior authorisation), and grants data subjects rights of access, rectification, and opposition. Cross-border transfers are restricted to countries ensuring adequate protection, and the law carries heavy criminal penalties for cybercrime offences (from 1 to 10 years' imprisonment and substantial fines). The decisive weakness is institutional. The law envisages a dedicated personal data protection authority to be created by regulation, but as of drafting that authority has not been formally operationalised. In practice, supervisory functions are exercised by the Autorité de Régulation des Postes et Télécommunications (ARPT), which hosts the law and runs a data protection section, while the Agence Nationale de Sécurité des Systèmes d'Information (ANSSI) exercises cybersecurity functions under the same framework. A 2024 implementing decree operationalised a 72-hour cybersecurity incident-reporting window for electronic-transaction systems. ATLPF holds the instrument and a Regulator record for ARPT (whose mandate is confirmed), but because the dedicated data protection authority contemplated by the 2016 law remains unestablished, enforcement of the data protection provisions specifically is weaker than in single-statute peers with a purpose-built regulator, which is why Guinea sits just below the standard single-instrument-plus-regulator score.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 1 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 1 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 0 | 0 | ○ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Loi L/2017/031/AN relative aux institutions financières inclusives en République de Guinée (Law L/2017/031/AN on Inclusive Financial Institutions in the Republic of Guinea)
Enacted 1 Jan 2017
Feuille de route nationale de l'intelligence artificielle 2026-2035 (Guinea National Artificial Intelligence Roadmap 2026-2035)
Enacted 20 Dec 2025
Loi N° L/2016/037/AN du 28 juillet 2016 relative à la cybersécurité et à la protection des données à caractère personnel (Guinea Cybersecurity and Personal Data Protection Act 2016)
Enacted 28 Jul 2016
The dedicated data protection authority envisaged by the 2016 law has not been operationalised; ARPT acts only as a de facto supervisor, leaving specific data protection enforcement uncertain. The combined cyber/data-protection structure subordinates privacy to a broader security agenda, and an enacted-date discrepancy (26 vs 28 July 2016) is flagged on file.