MG

Madagascar

East Africa

6Instruments
0Cases
3Regulators
65%Coverage
Overview

Madagascar has a comprehensive standalone data protection statute, Law No. 2014-038 on the protection of personal data, adopted by the National Assembly in December 2014, promulgated on 9 January 2015, and in force on publication in the Official Gazette in June 2015. The law draws on the EU Data Protection Directive 95/46/EC and reflects the principles of the African Union (Malabo) Convention. It applies to automated or manual processing carried out on Malagasy territory by public bodies or private organisations, and reaches processing outside Madagascar where a controller uses means located in the country. Controllers must register with the supervisory commission before processing, and processing must rest on a lawful basis, consent, contractual necessity, legal obligation, vital interests, or public interest. Sensitive categories (health, biometric, political opinion, religious belief, racial origin) attract heightened restrictions and generally require express consent or an authorised derogation. Data subjects have rights to be informed, to access, to rectify, to object (including to direct marketing), and to refuse automated decision-making with significant effects. The law does not prescribe an explicit breach-notification timeline, but inadequate security is an enforceable violation. Cross-border transfers are permitted only to countries with adequate protection or where the commission authorises a transfer on the basis of contractual guarantees, binding corporate rules, or consent. Penalties combine administrative suspension of processing with criminal fines of MGA 200,000 to MGA 10,000,000 and, for serious offences such as unlawful sensitive-data processing, imprisonment. Institutionally, Madagascar's framework was hampered for years by the absence of a functioning regulator. The Commission Malagasy de l'Informatique et des Libertés (CMIL) was only formally constituted by Decree 2023-1541 in December 2023 and operationalised in August 2025; before then, the law's reference to a supervisory body went unrealised, significantly limiting enforcement. With the CMIL now operational, the regime has moved from law-on-paper toward active supervision, though it remains early in that transition.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection20
AI Governance00
Fintech30
Cybercrime10
Digital Rights20
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
mg-const-privacy·Act

Constitution of the Fourth Republic of Madagascar, 2010, Article 13 (Inviolability of the person, the home and secrecy of correspondence)

MadagascarDigital RightsData ProtectionIn Force
Verified

Enacted 17 Nov 2010

mg-cyber-2014·Act

Loi n° 2014-006 du 17 juillet 2014 sur la lutte contre la cybercriminalité

MadagascarCybercrimeDigital RightsIn Force
Verified

Enacted 17 Jul 2014

mg-csbf-instr002-2017·Guidance

CSBF Instruction n° 002/2017 relative à l'agrément des établissements de monnaie électronique (Instruction on the Licensing of Electronic Money Establishments)

MadagascarFintechIn Force
Verified

Enacted 1 Jan 2017

mg-csbf-instr003-2017·Guidance

CSBF Instruction n° 003/2017 relative au fonctionnement des comptes de cantonnement (Instruction on the Operation of Trust Accounts)

MadagascarFintechIn Force
Verified

Enacted 1 Jan 2017

mg-emoney-2017·Act

Loi n° 2016-056 du 02 février 2017 sur la Monnaie Électronique et les Établissements de Monnaie Électronique (Law No. 2016-056 on Electronic Money and Electronic Money Establishments)

MadagascarFintechIn Force
Verified

Enacted 2 Feb 2017

mg-dp-2014·Act

Loi n° 2014-038 sur la protection des données à caractère personnel

MadagascarData ProtectionIn Force
Verified

Enacted 9 Jan 2015

Notable gaps

No explicit statutory breach-notification deadline. The supervisory authority (CMIL) only became operational in August 2025, so there is no track record of enforcement, and a decade-long enforcement vacuum preceded it. The 2014 law also predates the GDPR accountability model (no general DPO mandate or portability right on file).