Mali
West Africa
Mali has a comprehensive standalone data protection regime. Its primary instrument is Law No. 2013-015 of 21 May 2013 on the protection of personal data, adopted as part of the regional wave of legislation aligned with the ECOWAS Supplementary Act A/SA.1/01/10 of 2010. The law applies to automated processing and to non-automated processing held in structured filing systems, carried out by public or private controllers established in Mali, and reaches controllers outside Mali that use processing equipment located in the country. It is built on the standard data-quality principles, purpose limitation, adequacy and relevance, accuracy, and time-limited retention, and requires controllers to implement appropriate technical and organisational security measures. Processing operates under a prior notification or authorisation regime: ordinary processing is declared to the supervisory authority, while sensitive data (health, ethnic origin, political opinions, religious beliefs, biometrics, sexual life, criminal convictions) may only be processed with prior authorisation, and doing so without authorisation is a criminal offence. Data subjects hold enforceable rights of access, rectification, erasure, and opposition, including opposition to direct-marketing processing without giving reasons; solely automated decisions producing significant legal effects require specific safeguards. Cross-border transfers are prohibited unless the recipient country ensures adequate protection or appropriate safeguards apply. The framework was refined by Law No. 2017-070 of 18 December 2017, which revised the composition and functioning of the supervisory authority. Enforcement sits with the Autorité de Protection des Données à caractère Personnel (APDP), the independent administrative authority established by Article 20 of the 2013 law and operational since 2016. The APDP receives declarations and authorisation requests, investigates complaints, conducts on-site inspections, issues recommendations and opinions, and refers matters for criminal prosecution; penalties include fines and imprisonment, with aggravated sanctions for unauthorised sensitive-data processing and obstruction of its investigations. With a law in force for over a decade, an operational regulator, and a 2017 amending statute, Mali sits among the more settled francophone West African regimes, though it has not yet modernised to the full GDPR-style accountability model adopted by some neighbours.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 1 | 0 | ◐ |
| AI Governance | 0 | 0 | ○ |
| Fintech | 0 | 0 | ○ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 1 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Loi N° 2019-056 du 5 décembre 2019 portant répression de la cybercriminalité (Law on the Suppression of Cybercrime) (Mali)
Enacted 5 Dec 2019
Loi N° 2013-015 du 21 mai 2013 portant protection des données à caractère personnel en République du Mali (Mali Personal Data Protection Act 2013)
Enacted 21 May 2013
The 2013 law predates the post-GDPR accountability model and does not specify a fixed breach-notification deadline or a standalone DPO mandate. ATLPF holds no record of implementing regulations beyond the 2017 amendment, and no confirmation of whether further modernising amendments have been enacted.