Madagascar
East Africa
Madagascar has a comprehensive standalone data protection statute, Law No. 2014-038 on the protection of personal data, adopted by the National Assembly in December 2014, promulgated on 9 January 2015, and in force on publication in the Official Gazette in June 2015. The law draws on the EU Data Protection Directive 95/46/EC and reflects the principles of the African Union (Malabo) Convention. It applies to automated or manual processing carried out on Malagasy territory by public bodies or private organisations, and reaches processing outside Madagascar where a controller uses means located in the country. Controllers must register with the supervisory commission before processing, and processing must rest on a lawful basis, consent, contractual necessity, legal obligation, vital interests, or public interest. Sensitive categories (health, biometric, political opinion, religious belief, racial origin) attract heightened restrictions and generally require express consent or an authorised derogation. Data subjects have rights to be informed, to access, to rectify, to object (including to direct marketing), and to refuse automated decision-making with significant effects. The law does not prescribe an explicit breach-notification timeline, but inadequate security is an enforceable violation. Cross-border transfers are permitted only to countries with adequate protection or where the commission authorises a transfer on the basis of contractual guarantees, binding corporate rules, or consent. Penalties combine administrative suspension of processing with criminal fines of MGA 200,000 to MGA 10,000,000 and, for serious offences such as unlawful sensitive-data processing, imprisonment. Institutionally, Madagascar's framework was hampered for years by the absence of a functioning regulator. The Commission Malagasy de l'Informatique et des Libertés (CMIL) was only formally constituted by Decree 2023-1541 in December 2023 and operationalised in August 2025; before then, the law's reference to a supervisory body went unrealised, significantly limiting enforcement. With the CMIL now operational, the regime has moved from law-on-paper toward active supervision, though it remains early in that transition.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 2 | 0 | ◐ |
| AI Governance | 0 | 0 | ○ |
| Fintech | 3 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 2 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Constitution of the Fourth Republic of Madagascar, 2010, Article 13 (Inviolability of the person, the home and secrecy of correspondence)
Enacted 17 Nov 2010
Loi n° 2014-006 du 17 juillet 2014 sur la lutte contre la cybercriminalité
Enacted 17 Jul 2014
CSBF Instruction n° 002/2017 relative à l'agrément des établissements de monnaie électronique (Instruction on the Licensing of Electronic Money Establishments)
Enacted 1 Jan 2017
CSBF Instruction n° 003/2017 relative au fonctionnement des comptes de cantonnement (Instruction on the Operation of Trust Accounts)
Enacted 1 Jan 2017
Loi n° 2016-056 du 02 février 2017 sur la Monnaie Électronique et les Établissements de Monnaie Électronique (Law No. 2016-056 on Electronic Money and Electronic Money Establishments)
Enacted 2 Feb 2017
Loi n° 2014-038 sur la protection des données à caractère personnel
Enacted 9 Jan 2015
No explicit statutory breach-notification deadline. The supervisory authority (CMIL) only became operational in August 2025, so there is no track record of enforcement, and a decade-long enforcement vacuum preceded it. The 2014 law also predates the GDPR accountability model (no general DPO mandate or portability right on file).