AI LAW RADAR · Daily Last verified 22 Aug 2026

Topic dossier

High-risk & high-impact AI obligations

How the major risk-based regimes define high-risk or high-impact AI, and the assessments, oversight and documentation that classification triggers. 43 obligations across 36 jurisdictions — 35 in force, 2 proposed. Next dated deadline: 1 Jan 2027.

Risk-tiering is the architecture of most comprehensive AI laws: a system classified as high-risk — or high-impact — attracts the heaviest duties, typically a pre-deployment assessment, human oversight, risk management, technical documentation and sometimes registration. The EU AI Act’s Annex III is the reference model; South Korea, Vietnam, Peru, Brazil and the DIFC each run their own variant. The obligations below are the high-risk tier of each regime.

The Register

43 obligations · 36 jurisdictions

United Arab Emirates 1

UAE Binding

DIFC Data Protection Regulation 10

Binds Controllers / operators deploying autonomous or AI systems processing personal data in the DIFC. Binding rules for autonomous / AI systems processing personal data in the DIFC; high-risk needs certification or an Autonomous Systems Officer.

DIFC free-zone scope; enforcement from early 2026. General certification guidance still pending. Proposed amendments to Regulation 10 (plus new Regulation 11 on accreditation) were under 30-day public consultation (Consultation Paper No. 3 of 2026); comment period closed 18 Jul 2026. Final amended regulations pending.

Stated maximum penalty — DIFC data-protection fines

In force · 1 Jan 2026 checked 22 Aug 2026 DIFC Regulation 10 ↗ high confidence

Burkina Faso 1

Burkina Faso Binding

Loi 001-2021/AN art. 15 — a two-limb bar with no exception, backed by art. 19's reasoning and artificial-intelligence disclosure right and by art. 31's prior authorisation for predictive-AI decision support

Binds Responsables du traitement and sous-traitants within the scope of the Law, whose art. 6 states that information and communication technologies are at the service of the human person and must not harm human identity, private life, individual and collective freedoms or human rights generally. Art. 4 excludes temporary copies made for technical transmission and access purposes, which must be erased once their purpose is achieved, and processing for purely literary, artistic or journalistic purposes carried out in accordance with the ethical rules of those professions, the security measures protecting journalistic sources and the moderation rules applicable to discussion forums operated by news publishers. Prior formalities are a standing precondition: art. 30 sets the declaration regime and art. 31 the prior-authorisation regime, which covers offence and conviction data in the private sector, interconnection of files in either sector, national-identification-number processing in either sector, biometric processing in the private sector, public-interest processing including for historical, statistical or scientific purposes, decision-support processing involving an appraisal of human conduct or profiling or resting on predictive artificial-intelligence techniques, and transfers abroad. The first limb of art. 15 binds the courts themselves; the second binds every administrative and private decision-maker, irrespective of size or sector. Art. 78 makes the sanctions in arts. 63 to 75 applicable to all files, automated or not, whose use does not fall exclusively within the exercise of the right to private life. Impact tier: all entities.. Article 15 of Loi n° 001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel is Burkina Faso's operative automated-decision rule, closing Chapitre 1 of Titre II on fundamental principles immediately before the chapter on the rights of the data subject. Its first limb bars any judicial decision involving an appraisal of human conduct from having as its foundation an automated processing of information giving a definition of the profile or the personality of the person concerned and intended to evaluate certain aspects of their personality. Its second bars any administrative or private decision involving an appraisal of human conduct from having as its sole foundation an automated processing of information giving a definition of the profile or the personality of the person concerned. Like Côte d'Ivoire's art. 25 and Mali's art. 2, the Law states no exception whatever — no contract carve-out, no consent exception, no legal-authorisation exception and no opportunity to present observations. Two neighbouring provisions do the work that the exception clause does elsewhere. Article 19 gives every person the right to know and to contest the information and the reasoning used in processing, automated or not, whose results are relied on against them, and adds that where that processing falls within artificial intelligence the criteria and the nature of the personal data founding it must be indicated to the person from the point of collection. Article 31 goes further than any other row on the tracker by putting the technology itself behind a licence: processing that assists administrative or private decision-making, involves an appraisal of human conduct, gives a definition of the profile or the personality of the person concerned, or rests on artificial-intelligence techniques for predictive purposes, may not be implemented without prior authorisation from the Commission de l'informatique et des libertés. That is a permissioning gate on predictive AI, not merely a constraint on the resulting decision. There is no right to obtain human intervention or a fresh non-automated decision, and the art. 16 information list stops at identity, purposes, categories, whether answers are compulsory, recipients, access, rectification, suppression and objection rights, retention period, foreign transfers and the means of giving or withdrawing consent.

Supersession: art. 82 abrogates Loi n° 010-2004/AN du 20 avril 2004 portant protection des données à caractère personnel, the statute this sweep originally targeted, which is therefore no longer operative and is not tracked. Art. 83 is a bare execution clause — "La présente loi sera exécutée comme loi de l'Etat" — and there is no commencement article and no deferral of art. 15. The date recorded is the date printed at the foot of the enacted text, "Ainsi fait et délibéré en séance publique à Ouagadougou, le 30 mars 2021", the Assemblée nationale having deliberated in its sitting of that day. Confidence is medium and the reason is specific to Burkina Faso: laws there are promulgated by presidential decree, and neither the promulgation decree for Loi n° 001-2021/AN nor the date of the Journal officiel carrying it could be established from any official host this run — cil.bf serves a maintenance page on every path, legiburkina.bf, jo.gov.bf and sgg.gov.bf do not resolve, and the CIL's own document tree returns 404 live. Entry into force can therefore only be 30 March 2021 or later. Art. 81 is transitional and not a deferral of art. 15: processing already created and governed by art. 30 is subject only to declaration, the CIL may by special decision apply art. 31 to it subject to a prorogation of not more than one year granted by decree in Council of Ministers on the supervisory authority's opinion, and from the date of entry into force all processing had one year to meet the Law's prescriptions, failing which it is deemed implemented without the corresponding declaration or authorisation. Art. 80 preserves the mandates of CIL members already appointed. Source: the enacted text as published by the CIL itself, retrieved from the Internet Archive capture of 10 July 2025 of the CIL's own document store, the live path having 404'd during the site's maintenance outage; an archived copy of a document served by the official host satisfies Primary Source First on the same basis as ng-ndpa-s37. Coverage symmetry against the fifteen African rows already tracked: art. 15 takes the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting shared with Côte d'Ivoire's art. 25 and Niger's art. 52 — the second limb is tied to an appraisal of human conduct rather than to legal or significant effects — and, like Côte d'Ivoire and Mali, states no exception at all. Its art. 19 is materially identical to the third and fourth paragraphs of Niger's art. 52, including the artificial-intelligence disclosure duty at collection; since Burkina Faso's Law predates Niger's by twenty months, Burkina Faso is the source of that drafting on the tracker and Niger the follower. Two rows therefore carry an express artificial-intelligence clause, not one. Burkina Faso goes one step beyond Niger in art. 31 by making predictive-AI decision-support processing subject to prior authorisation, which is the only ex ante licensing gate on artificial intelligence in any data-protection statute on the tracker. The four-way African lineage picture: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, sn-loi200812-art48, ci-loi2013450-art25, ne-loi202259-art52, bj-code-num-art401, ml-loi2013015-art2 and now bf-loi0012021-art15; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — Art. 79 is the entire criminal chapter and creates no offence of its own: breaches of the Law are punished by the Penal Code in its provisions dealing with offences in computing matters and by means of information and communication technologies, so no criminal figure is attributed to art. 15 here. Everything operative is administrative and belongs to the CIL. Art. 63 lets the CIL, following the verification and inspection missions under art. 57 and without prejudice to criminal proceedings, impose a warning, a mise en demeure, an injunction to cease the processing carried out, blocking of certain personal data, a flat-rate fine, or withdrawal of the authorisation. Art. 65 fixes the flat-rate fine by reference to turnover rather than to a currency ceiling, which is unique among the Francophone rows: proportionate to the gravity of the failures and the advantages drawn from them, it is one per cent of pre-tax turnover for the last closed financial year on a first failure and five per cent on recidivism, recovered as a debt due to the State. Arts. 67 to 75 then set specific CIL fines: 5,000,000 to 10,000,000 francs CFA for obstructing the CIL's action in three specified ways; 5,000,000 to 20,000,000 francs CFA for processing without the prior formalities prescribed by the Law, which is the provision that reaches a failure to obtain the art. 31 prior authorisation for decision-support or predictive-artificial-intelligence processing; 5,000,000 to 20,000,000 francs CFA for processing without the precautions needed to preserve data security and 1,000,000 to 10,000,000 francs CFA for communicating data to unauthorised third parties or intentionally accessing files without authorisation; 5,000,000 to 100,000,000 francs CFA for purpose diversion; 5,000,000 to 100,000,000 francs CFA for fraudulent, unfair or unlawful collection, and for health-research processing in breach of art. 36; 2,000,000 to 5,000,000 francs CFA for processing despite a legitimately founded objection; 10,000,000 to 100,000,000 francs CFA for keeping sensitive data in computerised memory without express agreement, and for offence, conviction or security-measure data outside the permitted cases; 5,000,000 to 20,000,000 francs CFA for retaining identifiable data beyond the declared or authorised period, except for State processing; and 5,000,000 to 20,000,000 francs CFA for unauthorised divulgation harming honour, consideration or the intimacy of private life, reduced to 2,000,000 to 5,000,000 francs CFA where committed by imprudence or negligence. Art. 15 is named in none of them, so the route to it is the art. 63 general list including the art. 65 turnover-based flat-rate fine. Art. 76 lets the CIL order confiscation of the material media carrying the data or their erasure, even where the media do not belong to the sanctioned person, and, where it sanctions under arts. 67 to 75, ban the controller from managing any processing personally or through an intermediary for up to two years. Art. 77 lets it order publication of the decision or extracts in one or more newspapers at the sanctioned person's expense. Art. 64 requires sanctions to rest on a report by a CIL member designated by the President, notified to the controller, who may file observations and be represented or assisted at a hearing, requires decisions to be reasoned and notified, and makes sanction decisions appealable to the competent administrative court. Art. 66 lets the President of the CIL, or the person whose rights and freedoms are violated, apply in référé for any measure necessary to safeguard those rights, under astreinte, where the infringement of the Chapitre 2 rights is serious and immediate, and preserves compensation for moral or material damage.

In force · 30 Mar 2021 checked 17 Aug 2026 Loi n° 001-2021/AN art. 15 ↗ medium confidence

Benin 1

Benin Binding

Code du numérique art. 401 — a Directive-shaped bar widened to significant effects, with profiling named, mandatory safeguards inside the exception and a full logic-disclosure right

Binds Responsables du traitement within the scope of Livre cinquième, whose art. 379 states that the Livre's provisions establish a legal framework for the protection of private and professional life consequent on the collection, processing, transmission, storage and use of personal data, and that any processing, in whatever form, must respect the fundamental rights and freedoms of natural persons whatever their nationality or residence, while taking account of the prerogatives of the State, the rights of local authorities and the purposes for which undertakings were created. Prior formalities under Chapitre III of Titre II are a standing precondition, and Chapitre IV imposes the controller obligations, including the arts. 415 and 416 information duties that carry the automated-decision disclosure. The Autorité de Protection des Données à caractère Personnel established by Titre III supervises. The first paragraph of art. 401 binds the courts themselves; the second binds any decision-maker whose decision produces legal effects or significantly affects the person, irrespective of size or sector. Impact tier: all entities.. Article 401 of Loi n° 2017-20 du 20 avril 2018 portant code du numérique en République du Bénin, headed "Fondement d'une décision de justice — Aspects de la personnalité d'une personne physique", is Benin's operative automated-decision rule. It sits in Livre cinquième (protection of personal data), Titre II, Chapitre IV, immediately after the direct-marketing prohibition in art. 400. Its first paragraph bars any judicial decision involving an appraisal of the conduct of a natural person from having as its foundation an automated processing — expressly including profiling — of personal data intended to evaluate certain aspects of that person's personality. Its second paragraph bars any decision producing legal effects with regard to a person, or significantly affecting them, from being taken on the sole basis of an automated processing of data intended to evaluate certain aspects of their personality: the significant-effects limb is what separates Benin from Senegal, Morocco and Algeria, whose second limb stops at legal effects. Its third paragraph is the exception, and it is conditional rather than absolute — the prohibition does not apply where the decision is taken in the context of a contract or is founded on a provision laid down by or under the provisions of the Livre, a decree or an ordinance, but that contract or provision must contain appropriate measures safeguarding the legitimate interests of the person concerned, and the person must at least be permitted to put their point of view usefully. Benin is unusual among the Francophone rows in defining profiling: art. 1 defines it as any form of automated processing of personal data consisting in using those data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict elements concerning work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Unlike Senegal, Côte d'Ivoire, Morocco and Algeria, Benin also carries a full logic-disclosure right modelled on the GDPR: arts. 415 and 416 require the controller to inform the data subject, at collection and where data are obtained indirectly, of the existence of automated decision-making including profiling within the meaning of art. 401 and, at least in such cases, of useful information about the underlying logic and about the significance and the envisaged consequences of that processing for the data subject, and the access right repeats the same entitlement, with a copy of the information to be supplied without delay and at the latest within sixty days of the request. Art. 401 processing is also a named data protection impact assessment trigger: a systematic and extensive evaluation of personal aspects based on automated processing including profiling, on the basis of which decisions producing legal effects or similarly significantly affecting a natural person are taken, requires a prior impact assessment. There is no right to obtain human intervention or a fresh non-automated decision; the safeguard the Law names is the opportunity to put one's point of view usefully, and it exists only inside the exception.

The Code carries no commencement article: its final provision abrogates earlier texts, naming among them Loi n° 2009-09 du 24 mai 2009 portant protection des données à caractère personnel en République du Bénin, and ends with a bare execution clause, "La présente loi sera exécutée comme loi de l'État". The date recorded is the date the Law bears, 20 April 2018, which is also the date printed in the running head of every page of the enacted text. Confidence is medium for the same reason as the other Francophone rows: the Beninese general publication-to-force rule was not read against a primary source, and the date of the Journal officiel de la République du Bénin carrying the Code could not be established from an official host this run, so entry into force can only be that date or later. Supersession is settled on the face of the text: Loi n° 2009-09 of 2009 is abrogated and is not tracked. Note the Law's own numbering oddity, which is not an error in this entry — the instrument is numbered 2017-20 but dated 20 April 2018, because it was voted by the Assemblée nationale in 2017 and promulgated in 2018. One drafting defect is recorded for candour: art. 461, which fixes the penalties, refers to "les infractions visées à l'article 445" where the offence list is in fact art. 460, and the same article then refers correctly to "l'article 460" twice in its later paragraphs, so the cross-reference in the first sentence is a slip. Text read in the edition of the Code printed by the Autorité de Protection des Données à caractère Personnel, the supervisory authority established by Titre III of Livre cinquième, which carries the Assemblée nationale imprint; art. 401 and its heading, arts. 415 and 416, the impact-assessment article, the arts. 452 to 459 administrative chapter and the arts. 460 and 461 penal chapter were each read in full. Coverage symmetry against the thirteen African rows already tracked: art. 401 is the hybrid of the Francophone group. Its shape is the Directive 95/46/EC art. 15 shape — a judicial limb, a general limb, an exception — but three features are imported from the GDPR: the significant-effects alternative in the second limb, the express naming of profiling as a defined term, and the logic-disclosure and impact-assessment machinery. That makes Benin the bridge between the two African lineages rather than a member of either. Within the Francophone family the split is now three ways: Senegal, Morocco and Algeria keep the Directive drafting with a legal-effects threshold and a deeming clause; Côte d'Ivoire and Niger take the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting in which any administrative or private decision appraising human conduct is caught; Benin keeps the Directive skeleton and grafts GDPR flesh onto it. Benin's exception is also the strongest-conditioned of the Francophone rows: where Senegal, Morocco and Algeria simply deem contract decisions with an opportunity to present observations outside the bar, and Niger admits consent, contract and legal authorisation outright, Benin requires the contract or the enabling provision itself to contain appropriate measures safeguarding the person's legitimate interests, with the right to put one's point of view usefully as an express minimum. The four-way African lineage picture: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, sn-loi200812-art48, ci-loi2013450-art25, ne-loi202259-art52 and now bj-code-num-art401 as its GDPR-inflected outlier; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — No offence reaches art. 401 directly. Art. 460 enumerates fifteen offences under Livre cinquième — obstructing the Autorité in three specified ways, processing without the prescribed prior formalities, knowingly using data collected by a fraudulent process, processing sensitive, offence-related or national-identification-number data outside the permitted conditions, processing without implementing the prescribed measures, collecting data by fraudulent, unfair or unlawful means, diverting or manipulating data held for registration, classification, transmission or other processing, transferring data to a third State without satisfying the transfer requirements, using violence, threats, gifts or promises to compel a person to hand over information obtained under art. 436 or to consent to processing, processing despite a well-founded rectification request or objection, failing to respect the Livre's provisions on informing data subjects, failing to respect its provisions on access rights, retaining data beyond the declared period outside historical, statistical or scientific purposes, unauthorised divulgation harming the person's consideration or the intimacy of their private life, and participating in an association or agreement formed to commit any of those offences — and the automated-decision bar is not among them. Two of the fifteen do reach the disclosure duties that art. 401 feeds: the failure to respect the Livre's provisions on informing data subjects and the failure to respect its provisions on access rights both catch a controller that withholds the art. 415, 416 and access-right information about the existence of automated decision-making including profiling, the underlying logic, and its significance and envisaged consequences. Art. 461 punishes those offences with imprisonment of six months to ten years and a fine of 10,000,000 to 50,000,000 francs CFA, or one of those penalties only, with complicity and attempt punished identically; where the formalities offence is committed by simple negligence only a fine of 5,000,000 to 50,000,000 francs CFA may be imposed. The court may order erasure of all or part of the data processed, may pronounce complementary penalties including confiscation of the material media carrying the data, excluding computers, and final convictions are published in the Journal officiel de la République du Bénin and on an electronic medium at the convicted person's expense. The route that reaches art. 401 itself is administrative. Art. 452 lets the Autorité issue a warning to a controller that does not respect the obligations arising under the Livre and a formal notice to end the observed failure within a period not exceeding eight days. Art. 453 defines grave failures — unfair collection, communication to an unauthorised third party, unlawful collection of sensitive, offence-related or national-identifier data, collection or use causing serious harm to fundamental rights or to the intimacy of private life, and obstruction of an on-site inspection. Art. 454 lets the Autorité, respecting the adversarial principle, impose a pecuniary sanction (except where the processing is implemented by the State), an injunction to cease the processing, definitive or temporary withdrawal of the authorisation, or blocking of certain data. Art. 455 fixes the amount: proportionate to the gravity of the failures and the advantages drawn from them, not exceeding 50,000,000 francs CFA on a first failure and, on a repeated failure within five years from the date the previous pecuniary sanction became definitive, not exceeding 100,000,000 francs CFA or, for an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of 100,000,000 francs CFA; where the Autorité's pecuniary sanction becomes definitive before the criminal court rules on the same or connected facts, that court may set the sanction off against its fine. Art. 456 lets any sanction be coupled with an injunction to make any useful modification or deletion in the operation of the processing within a period not exceeding eight days; art. 457 requires a report notified to the controller, who has fifteen days to make written or oral observations and may attend or be represented; art. 458 makes sanction decisions appealable to the competent administrative court; and art. 459 lets the Autorité publish the sanctions imposed.

In force · 20 Apr 2018 checked 22 Aug 2026 Code du numérique art. 401 (Loi n° 2017-20) ↗ medium confidence

Brazil 1

Brazil Proposed

AI Act bill (PL 2338/2023) advancing

Binds Would bind AI providers / deployers once enacted. Risk-based, EU-style framework; Senate-approved Dec 2024, now before the Chamber of Deputies.

Senate-approved Dec 2024; before the Chamber of Deputies Special Committee. Rapporteur Dep. Aguinaldo Ribeiro (PP-PB) has not yet presented opinion ("parecer"); no plenary vote scheduled as of Jul 28, 2026. 35 related bills consolidated. Plenary vote not expected before late 2026.

Stated maximum penalty — Bill: up to R$50M / 2% revenue

Proposed checked 12 Aug 2026 PL 2338/2023 ↗ high confidence

Republic of the Congo 1

Republic of the Congo Binding

Loi n° 29-2019 art. 13 — the Directive-shaped bar whose fine arrives only if the controller defies the formal notice

Binds Responsables de traitement and, through art. 12, anyone acting under their authority with access to personal data. The prior-formality regime runs through arts. 32 to 40: art. 32 and art. 33 carry the dispensations from formalities that art. 93 later cross-refers to, arts. 33 to 36 set the declaration regime, and art. 40 governs processing authorised by regulatory act, for which art. 94 requires the Commission to inform the Government so that it may take measures to end an established violation, the Government having fifteen days to report back on the action taken. Neither profiling nor automated decision-making is listed as a category attracting prior authorisation, so Congo imposes no ex ante gate on the processing art. 13 governs. Art. 82 provides for prior consultation of the Commission and arts. 90 and 91 for a data protection officer who must have due regard, in performing their tasks, to the risk associated with processing operations having regard to their nature, scope, context and purposes. The art. 13 bar binds the courts under its first limb and, under its second, every decision-maker whose decision produces legal effects in regard to a natural person, with no size or sector threshold. Impact tier: all entities.. Article 13 of Loi n° 29-2019 du 10 octobre 2019 portant protection des données à caractère personnel is the Republic of the Congo's operative automated-decision rule. It closes Chapitre 1 of Titre II on the principles governing processing, immediately after art. 12, which provides that a person acting under the authority of the controller and having access to personal data may process them only on the controller's instruction, and immediately before art. 14, which governs sensitive data. It has three unnumbered paragraphs and follows the Directive 95/46/EC art. 15 template closely. The first: no judicial decision involving an appraisal of the conduct of a natural person may have as its foundation an automated processing of personal data intended to evaluate certain aspects of their personality. The second: no decision producing legal effects in regard to a natural person may be taken on the sole foundation of an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third is a deeming clause rather than a true exception: decisions taken in the context of the conclusion or performance of a contract, and for which the person concerned was put in a position to present their observations, and decisions satisfying the requests of the person concerned, are not regarded as taken on the sole foundation of an automated processing. As in Guinea, Madagascar and Gabon, the judicial limb omits the word "seul" that the second limb carries, so a Congolese court appraising conduct may not rest on such a processing at all. The second limb takes the narrow Directive trigger confined to decisions producing legal effects, which places Congo with Gabon, Togo, Senegal, Morocco and Algeria rather than with the wide-trigger group. What distinguishes this row from every other Francophone entry is the thinness of what surrounds it. The Law creates no right to know the logic underlying an automated processing — the words logique, raisonnement and profilage appear nowhere in it — no human-review right, no right to a fresh non-automated decision, and no definition of profiling. Art. 13 is a bare prohibition with a deeming clause and nothing else.

The Law carries no commencement article. Art. 101, its final provision, is a bare publication and execution clause — the present Law shall be published in the Journal officiel de la République du Congo and executed as a law of the State — and nothing in the text defers art. 13. The date recorded here is the date of publication of the gazette in which the Law appears: Journal officiel de la République du Congo n° 45-2019, whose issue date, printed on the running heads of the issue, is Thursday 7 November 2019. The Law itself is dated 10 October 2019 at Brazzaville, over the signatures of President Denis Sassou-Nguesso, Prime Minister Clément Mouamba, the Minister of Justice Aimé Ange Wilfrid Bininga and the Minister of Posts, Telecommunications and the Digital Economy Léon Juste Ibombo, and it is by that promulgation date that it is universally cited. The gazette date is preferred here over the promulgation date because art. 101 attaches publication rather than promulgation, which is the same choice made for Togo. Confidence is medium because the Congolese general publication-to-force rule was not verified against a primary source: if force runs from promulgation rather than from publication the operative date is 10 October 2019, four weeks earlier, and if the general rule adds a clear-days delay after publication it is later. Both candidate dates are long past, so the lifecycle of this row is unaffected either way. Art. 100 is transitional and is not a deferral of art. 13, which is a prohibition rather than a conformance duty: from entry into force, all data processing had to meet the Law's prescriptions within two years where operated for the State, a public establishment, a decentralised administrative entity or a private-law legal person managing a public service, and within one year for everyone else, so the outer conformance window closed in November 2021 on the date recorded here. Art. 99 subjects already-created public-sector processing to a declaration only. The Law abrogates nothing expressly and names no predecessor statute, so nothing is superseded on the tracker. Text read in the Journal officiel itself, published by the Secrétariat général du Gouvernement, covering the whole of the Law from art. 1 to the signature block, including the definitions, the arts. 12 to 14 principles, the arts. 32 to 40 formalities, the arts. 90 and 91 data-protection-officer provisions and the arts. 92 to 101 sanctions and final chapters. No AI-specific statute or guidance is in force in the Republic of the Congo.

Stated maximum penalty — The route to art. 13 is administrative, it is two-step, and the fine is not available for the breach itself. Art. 92 gives the Commission a catch-all first step: it may pronounce a warning against a controller not respecting the obligations flowing from the present Law, and a mise en demeure to cause the breaches concerned to cease within the time limit it fixes. Because that is drafted against the Law's obligations generally rather than against an enumerated list, it reaches art. 13. Art. 93 then supplies the teeth, but only conditionally: if the controller does not comply with the mise en demeure addressed to them, the Commission may, after a contradictory procedure, pronounce a provisional withdrawal of the authorisation granted or a provisional prohibition of processing not exceeding three months, a definitive withdrawal of the authorisation or a definitive prohibition of processing, an injunction to cease the processing where it falls under the declaration regime or benefits from the arts. 32 and 33 dispensations, and a pecuniary fine of one million to one hundred million francs CFA, recovered in accordance with the legislation on the recovery of State debts. A controller that breaches art. 13 and then complies with the resulting mise en demeure is therefore exposed to no fine at all. Art. 94 supplies an urgency track independent of that sequence: where the implementation of a processing or the exploitation of personal data entails a violation of rights and liberties, the Commission may, after a contradictory procedure, decide the interruption of the processing for a maximum of three months, the locking of certain data for a maximum of three months, or the temporary or definitive prohibition of a processing contrary to the Law. Art. 95 requires sanctions to rest on a report by a designated member, notified to the controller, who may file observations and be represented or assisted; art. 96 allows sanctions to be made public and inserted in publications at the sanctioned person's expense; art. 97 opens recourse against the Commission's sanctions and decisions to the Cour suprême. On the penal side the Law creates no offence of its own: art. 98 provides simply that infringements of the provisions of the present Law are provided for and repressed by the Penal Code and by the law on combating cybercrime, which places Congo with Senegal and Burkina Faso as a statute that refers all criminal enforcement out to other instruments.

In force · 7 Nov 2019 checked 21 Aug 2026 Loi n° 29-2019 art. 13 ↗ medium confidence

Côte d'Ivoire 1

Côte d'Ivoire Binding

Loi 2013-450 art. 25 — no judicial, administrative or private decision appraising human conduct may rest on automated profiling, with no carve-out at all

Binds Responsables du traitement within the scope of art. 3, which subjects to the Law any collection, processing, transmission, storage and use of personal data by a natural person, the State, local authorities or legal persons of public or private law; any processing, automated or not, of data contained in or intended to form part of a file; any processing implemented on national territory; and any processing concerning public security, defence, investigation and prosecution of criminal offences or State security, subject to derogations fixed by other legislation in force. Art. 4 excludes processing by a natural person in the exclusive course of personal or domestic activities where the data are not intended for systematic communication to third parties or for dissemination, and temporary copies made for technical transmission and access purposes. Prior declaration to the Autorité de protection is a standing precondition under art. 5, with prior authorisation required under art. 7 for genetic, medical and research data, offence and conviction data, national identification numbers, biometric data, public-interest processing and transfers to third countries, and art. 13 requiring a decree for processing on behalf of the State. The art. 25 bar binds courts under its first limb and every administrative or private decision-maker under its second, irrespective of size or sector. Impact tier: all entities.. Article 25 of Loi n° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel is Côte d'Ivoire's operative automated-decision rule. It sits at the end of Chapitre 4 (principes-directeurs du traitement des données à caractère personnel), immediately before the cross-border-transfer article, and has two limbs in two unnumbered paragraphs. The first is addressed to the courts: no judicial decision involving an appraisal of the conduct of a natural person may have as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality. The second reaches beyond the courts and is drafted more widely than any comparable African provision: no administrative or private decision involving an appraisal of human conduct may have as its sole foundation an automated processing of personal data giving a definition of the profile or of the personality of the person concerned. Two features distinguish it. First, the second limb is not confined to decisions producing legal effects and carries no significant-effect threshold either — the trigger is an appraisal of human conduct, whoever takes the decision and whatever its effects, so it is wider on its face than Morocco's and Algeria's art. 11. Second, and unusually, the Law supplies no carve-out whatever: there is no contract-formation or contract-performance deeming clause, no consent exception, no legal-authorisation exception and no opportunity-to-present-observations proviso. The Law also creates no right to know the logic underlying an automated processing — the art. 29 access right runs to information enabling the data subject to know and to contest the processing, the confirmation that data are processed, communication of the data and of any available information as to their origin, and information on purposes, categories and recipients — and no right to obtain human intervention or a fresh non-automated decision. The Law carries no definition of profiling; art. 25 speaks of an automated processing giving a definition of the profile or the personality of the person concerned.

Art. 54, the final article, is a bare publication clause — the Law "sera publiée au Journal officiel de la République de Côte d'Ivoire et exécutée comme loi de l'Etat" — and the Law contains no commencement article and defers nothing. The text was adopted by the Assemblée nationale, promulgated by the President at Abidjan on 19 June 2013 and published in the Journal officiel de la République de Côte d'Ivoire of 8 August 2013 at pp. 474 to 482, which is the date recorded here; the promulgation date of 19 June 2013 appears in the title and above the presidential signature. Confidence is medium for the same reason as Morocco's and Algeria's art. 11: the Ivorian general publication-to-force rule was not itself read against a primary source, so it could not be confirmed whether force attaches on the day the Journal officiel is published or after the customary jour franc. Art. 53 is transitional and not a deferral of art. 25: controllers already processing personal data had six months from the entry into force of the Law to bring themselves into conformity, a period that closed in 2014. Two typesetting defects in the gazetted text are recorded for candour and neither touches art. 25: the Chapitre 2 heading on p. 476 and the opening of art. 32 on p. 479 both carry a stray line reading "du secrétaire permanent de la Commission nationale du Fonds pour l'Environnement mondial", plainly imported in error from another text in the same issue. Coverage symmetry against the ten African rows already tracked: art. 25 belongs to the Directive 95/46/EC art. 15 line that reaches West Africa through art. 42 of the ECOWAS Supplementary Act A/SA.1/01/10 on personal data protection, and it is the third member of the Directive family on the tracker alongside ma-loi0908-art11 and dz-loi1807-art11. The African picture is now four-way: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37 and rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36 and ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11 and now ci-loi2013450-art25; and a Directive-family statute from which the automated-decision article is simply absent = Tunisia's Loi organique 2004-63, which is why each Francophone statute is read article by article rather than assumed. Within the Directive family Côte d'Ivoire is the outlier in both directions: it is the widest, because its second limb reaches any administrative or private decision appraising human conduct rather than only decisions producing legal effects, and it is the barest, because Morocco and Algeria both deem contract decisions with an opportunity to present observations outside the bar while Côte d'Ivoire states no exception at all. Like Morocco and Algeria it grants no human-review right; unlike Morocco, which has the art. 7(c) right to know the logic of an automated processing, Côte d'Ivoire has no logic-disclosure right at all. Text read page by page in the Journal officiel de la République de Côte d'Ivoire of 8 August 2013 as published by the Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire, which art. 46 designates as the Autorité de protection.

Stated maximum penalty — No criminal offence attaches to art. 25. The Law's three penal provisions each name their own conduct and none of them reaches an automated decision: art. 21 punishes the collection and processing of data revealing racial, ethnic or regional origin, filiation, political opinions, religious or philosophical convictions, trade-union membership, sexual life, genetic data or health with ten to twenty years' imprisonment and a fine of 20,000,000 to 40,000,000 francs CFA; art. 22 punishes direct marketing by any means of communication using the personal data of a natural person who has not given prior consent with one to five years' imprisonment and a fine of 1,000,000 to 10,000,000 francs CFA; and art. 45 punishes obstruction of the Autorité de protection with one month to two years' imprisonment and a fine of 1,000,000 to 10,000,000 francs CFA. The route that does reach art. 25 is administrative. Art. 49 lets the Autorité de protection issue a warning to a controller that does not respect the obligations arising under the Law and a formal notice (mise en demeure) to cease the failures observed within a period it fixes. Art. 50 lets it decide, after an adversarial procedure, to interrupt the processing, to block certain data or to prohibit temporarily or definitively a processing contrary to the Law where implementation entails a violation of rights and freedoms. Art. 51 lets it, after hearing a controller or processor that has not complied with the Law and with the formal notice addressed to it, pronounce provisional withdrawal of the authorisation, definitive withdrawal of the authorisation, or a pecuniary sanction proportionate to the gravity of the failures and to the advantages drawn from them; that pecuniary sanction may not exceed 10,000,000 francs CFA, and on a repeated failure within five years from the date on which a previous pecuniary sanction became definitive it may not exceed 100,000,000 francs CFA or, in the case of an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of 500,000,000 francs CFA. Art. 51 adds that these administrative and pecuniary sanctions apply without prejudice to penal sanctions, and art. 52 leaves the modalities of withdrawal and of recovery of the pecuniary sanction to decree.

In force · 8 Aug 2013 checked 20 Aug 2026 Loi n° 2013-450 art. 25 ↗ medium confidence

Cameroon 1

Cameroon Binding

Loi n° 2024/017 art. 44 — the first GDPR-shaped bar in Francophone Africa, in the only African statute that makes profiling itself a crime

Binds Responsables de traitement and sous-traitants, who art. 20 makes subject to the same obligations in respect of processing activity. The art. 2 scope is unusually wide: the Law governs any processing of personal data carried out by the State, decentralised territorial collectivities or any other natural or legal person; any processing of the personal data of any person established, resident or in transit in Cameroon; any processing carried out by a controller or processor established in Cameroon; and any processing carried out in a territory where Cameroonian law applies by virtue of international law or duly ratified conventions. The transit limb is worth noting — it reaches the data of travellers passing through. Art. 3 excludes purely personal or domestic processing not intended for systematic communication to a third party or for dissemination, temporary technical copies made in transmission and access provision, and processing for literary, artistic, public-interest archival, scientific or historical research, statistical or journalistic purposes. Cameroon is also the only jurisdiction in the African block that gates processing generally rather than by category: art. 19(1) subjects the processing of personal data to the prior obtention of an authorisation delivered by the Autorité de protection des données à caractère personnel, and art. 19(2) adds a separate prior authorisation for any interconnection or interoperability process involving sensitive data files relating to minors, with the modalities of delivery left to regulation. Automated decision-making and profiling are not singled out for their own ex ante gate because everything already needs one. Art. 29 requires a processing register, art. 27(2) an annual security report to the Authority, and art. 25 a risk evaluation on criteria and validation modalities fixed by regulation. The art. 44 right binds every controller taking a decision based exclusively on automated processing, with no size, sector or legal-effects threshold — Cameroon states no requirement that the decision produce legal effects or significantly affect the person, which makes its trigger wider than the GDPR's. Impact tier: all entities.. Article 44 of Loi n° 2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun is Cameroon's operative automated-decision rule, and it is the first entry in the Francophone African block that is built on the GDPR rather than on Directive 95/46/EC. It sits in Titre III, Des droits de la personne concernée, which opens at art. 37 and runs through erasure and digital oblivion (arts. 37 and 38), access (art. 39), objection (art. 40), direct-marketing consent (art. 41), rectification (art. 42) and portability (art. 43). Art. 44(1) gives the data subject the right to object to any decision based exclusively on the automated processing of their personal data, including profiling. Art. 44(2) admits two exceptions and no more: where the data subject has been informed of the use of the automated decision-making system and has given prior, explicit and informed consent; and where the processing is authorised by law, provided that law lays down appropriate measures safeguarding the rights, freedoms and legitimate interests of the data subject. There is no contract limb — the carve-out that Directive-derived statutes such as Congo, Gabon, Togo and Senegal all carry for decisions taken in the conclusion or performance of a contract is simply absent, so a Cameroonian controller cannot excuse an automated decision by pointing to a contract. Art. 44(3) then supplies the safeguard package: the data subject also has the right to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision founded on the automated processing. Cameroon therefore joins the GDPR-lineage group of Kenya, Nigeria and Rwanda as its first Francophone member, and it states all three limbs of the art. 22(3) safeguard against a shorter exception list than the GDPR itself carries. The transparency side is carried by art. 21, the controller's information duty, which must be discharged at the latest at collection and which lists, among the rights whose existence must be disclosed, the right not to be subject to an individual automated decision, including profiling, and a distinct right to information on the taking of an automated decision, the underlying logic and the envisaged consequences of the processing. Profilage is defined in the definitions article as automated processing of personal data consisting in using them to evaluate certain personal aspects relating to a natural person, notably their health, preferences, location and economic situation. Art. 33 requires a prior data-protection impact assessment for any type of processing liable to engender a high risk to the rights and freedoms of natural persons.

Force. The Law carries no commencement article: art. 75, its final provision, says that the present Law, which abrogates all prior contrary provisions, shall be registered, published according to the urgency procedure, then inserted in the Journal Officiel in French and in English. The date recorded here is the promulgation date printed on the face of the Law over the signature of President Paul Biya at Yaoundé, 23 December 2024, which is also the date from which the Law's own transitional clock runs. Confidence is medium for the same reason as Morocco, Congo-Brazzaville and Gabon: the Cameroonian general publication-to-force rule was not verified against a primary source, so if force runs from insertion in the Journal Officiel rather than from promulgation the operative date is somewhat later. Nothing turns on the difference for the lifecycle of this row, because the date that actually matters to duty-holders has now passed on either reading. That date is 23 June 2026: art. 73 gives natural and legal persons in charge of the processing of personal data a period of eighteen (18) months from the date of promulgation of the present Law to conform to its provisions. Eighteen months from 23 December 2024 expired on 23 June 2026, so the conformance window closed roughly two months before this entry was written and art. 44 is fully operative against existing controllers. Art. 73 is a transitional conformance window on the Indonesian and Rwandan pattern, not a deferred commencement — it does not postpone the Law itself, which is why the row is dated from promulgation rather than from the end of the window. Two further caveats. First, art. 74 provides that particular texts shall specify, as needed, the modalities of application of the Law, and several provisions expressly await regulation: the art. 19(3) authorisation modalities, the art. 25(1) risk-evaluation criteria, the art. 32(3) transfer-authorisation modalities and the art. 35 monitoring and control modalities. Art. 44 is not among them — it is self-executing on its own terms and needs no implementing text. Second, the Autorité de protection des données à caractère personnel that the Law creates and that arts. 54 to 61 arm with the administrative sanctions had not been verified as operational when this entry was written, which affects who can enforce art. 44 administratively but not whether the duty exists; the arts. 62 to 71 civil and penal routes do not depend on the Authority existing. Supersession: the Law abrogates all prior contrary provisions without naming a predecessor data-protection statute, because there was none — before 23 December 2024 Cameroon was one of the last African states with no dedicated personal data protection law, its nearest instruments being Loi n° 2010/012 du 21 décembre 2010 on cybersecurity and cybercriminality and Loi n° 2010/013 on electronic communications, neither of which carries an automated-decision rule. Nothing on the tracker is superseded by this row. No AI-specific statute is in force in Cameroon and the Law does not define artificial intelligence; Gabon remains the only Francophone African data-protection statute that does. Text read page by page in the certified true copy published by the Presidency of the Republic (Secrétariat général, Service du fichier législatif et réglementaire), covering the arts. 1 to 5 scope and definitions, the arts. 6 to 18 principles, the art. 19 prior-formalities chapter, the arts. 20 to 35 controller obligations, the art. 36 interconnection chapter, the arts. 37 to 46 rights chapter, and the arts. 54 to 75 sanctions and final chapters.

Stated maximum penalty — Cameroon carries the heaviest enforcement apparatus of any African row on the tracker, and it is the only one in which profiling is itself a crime. Art. 65 punishes with three (03) to ten (10) years' imprisonment and a fine of one million (1,000,000) to twenty million (20,000,000) francs CFA, or one of those two penalties only, the controller or processor who carries out or causes to be carried out a processing of personal data for profiling purposes. That is a free-standing offence attaching to the act of profiling rather than to any breach of the art. 44 right, and it has no analogue anywhere else in the African block: in Ghana, Uganda, Madagascar, Congo-Brazzaville, Gabon, Morocco and Algeria no penal article reaches the automated-decision provision at all. Read with the art. 5 definition of profilage — automated processing used to evaluate personal aspects relating to a natural person, notably health, preferences, location and economic situation — art. 65 exposes ordinary commercial scoring, segmentation and recommendation practice to a custodial sentence, and it is not qualified by any of the art. 44(2) exceptions, which are drafted against art. 44(1) and not against the offence. Art. 71 lifts the ceiling for legal persons: notwithstanding the criminal liability of their directors, legal persons may be declared criminally liable and sentenced to a fine of fifty million (50,000,000) to one billion (1,000,000,000) francs CFA where the offences provided for by the Law have been committed by the persons responsible for them. Art. 64(1) supplies the route aimed at art. 44 itself: one (01) to three (03) years' imprisonment and a fine of fifty thousand (50,000) to one million (1,000,000) francs CFA, or one of those two only, for the controller or processor who carries out or causes to be carried out a processing despite the objection of the data subject, where the processing responds to direct-marketing purposes or where the objection is founded on grounds provided for by law — and an art. 44(1) objection is founded on grounds provided for by law. Art. 63 punishes fraudulent, unfair or unlawful collection or access with two to five years and 200,000 to 5,000,000 francs CFA, doubled where accompanied by locking or encryption; art. 67 punishes purpose diversion and incompatible further processing with six months to two years and 500,000 to 5,000,000 francs CFA; art. 69 punishes unlawful international transfer with three to ten years and 2,000,000 to 20,000,000 francs CFA. On the administrative side, art. 54 gives the Authority a ten (10) day mise en demeure, an injunction to bring the processing into conformity under a penalty payment not exceeding one hundred thousand (100,000) francs CFA per day of delay, and, on non-compliance, suspension of the activity covered by the authorisation, withdrawal of the authorisation, or prohibition of any personal-data processing activity. Art. 55 exposes processing without prior authorisation to 5,000,000 to 50,000,000 francs CFA; art. 56 exposes refusal to make requested information available to the data subject to 1,000,000 to 10,000,000 francs CFA, which is the administrative route reaching an art. 21 or art. 39 failure; art. 57 exposes breach of the Authority's référentiel to 5,000,000 to 20,000,000 francs CFA; art. 61 exposes breach of a cahier des charges obligation to 10,000,000 to 100,000,000 francs CFA. Art. 62 preserves the civil route: on a serious infringement of the rights mentioned in the Law the data subject may ask the competent court, ruling under the urgency procedure, to order any measure necessary to safeguard their rights, if need be under a penalty payment, and may separately seek reparation.

In force · 23 Dec 2024 checked 20 Aug 2026 Loi n° 2024/017 art. 44 ↗ medium confidence

China 1

China Binding

China AI Agents Implementation Opinions (CAC/NDRC/MIIT)

Binds Developers and deployers of AI agent services in China; mandatory compliance for healthcare, transportation, media, and public safety sectors; guidance-level for others. First national policy framework for AI agents. Mandatory for 19 priority sectors (healthcare, transport, media, public safety): filing, compliance testing, product recall provisions. Establishes three-tier decision authority model. AI-generated content labeling required. Enforceable via existing CSL/DSL/PIPL frameworks.

Published and operative from May 8, 2026 (jointly issued by CAC, NDRC, MIIT). Three-tier decision authority model: decisions requiring human-only authority; decisions requiring user approval; decisions agent may handle autonomously. High-risk sector filing and testing obligations enforceable under Cybersecurity Law, Data Security Law, PIPL. No standalone penalty regime; enforcement via existing frameworks.

Stated maximum penalty — Enforcement via CSL/DSL/PIPL (no standalone penalties specified)

In force · 8 May 2026 checked 17 Aug 2026 CAC/NDRC/MIIT AI Agents Implementation Opinions (May 2026) ↗ high confidence

Germany 1

DE Binding

Germany AI Market Surveillance Act (KI-MIG)

Binds AI providers, importers, distributors, and deployers of AI systems operating in Germany under EU AI Act scope (Reg. EU 2024/1689). Designates Bundesnetzagentur (BNetzA) as Germany's lead AI authority; establishes enforcement architecture for EU AI Act in Germany, including AI regulatory sandboxes (KI-Reallabore) and domestic penalty regime.

National implementing law for EU AI Act. EU phased obligations still apply: Art.50 transparency in force Aug 2, 2026; high-risk Annex I AI → Aug 2, 2028 (per the Digital Omnibus, Reg. (EU) 2026/1744); full high-risk Annex III → Dec 2, 2027.

Stated maximum penalty — €35M or 7% global turnover (prohibited AI practices); €15M or 3% (high-risk violations); €50K for domestic procedural violations (KI-MIG §§15–17)

In force · 29 Jul 2026 checked 22 Aug 2026 KI-MIG ↗ high confidence

Algeria 1

Algeria Binding

Loi 18-07 art. 11 — no decision with legal effects may rest on the sole basis of automated profiling or personality evaluation, and no court may found an appraisal of conduct on one at all

Binds Responsables du traitement within the territorial scope of art. 4: processing carried out by a natural or legal person whose controller is established on Algerian territory (a controller carrying on an activity in Algeria through an installation, whatever its legal form, is treated as established there) or on the territory of a State whose legislation is recognised as equivalent; and processing by a controller not established in Algeria that resorts, for the purposes of processing, to automated or non-automated means situated on Algerian territory, excluding means used only for transit. In that second case the controller must notify the national authority of the identity of its representative installed in Algeria, who substitutes for it in all rights and obligations under the Law. The first limb of art. 11 binds the courts themselves. Art. 6 excludes from the Law data processed by a natural person in the exclusive course of personal or domestic activities and not destined for communication to third parties or dissemination, data collected and processed in the interest of national defence and security, and data collected and processed for the prevention, prosecution and punishment of offences and held in judicial databases.. Article 11 of Loi n° 18-07 du 25 Ramadhan 1439 correspondant au 10 juin 2018 relative à la protection des personnes physiques dans le traitement des données à caractère personnel is Algeria's operative automated-decision rule. It sits in Titre II, Chapitre I (fundamental principles), immediately before the declaration and authorisation machinery of art. 12, and has two limbs. The first is absolute and is addressed to the courts: no judicial decision involving an appraisal of a person's conduct may be founded on an automated processing of personal data intended to evaluate certain aspects of that person's personality — there is no consent, contract or safeguards exception to this limb. The second is the general rule: no other decision producing legal effects with respect to a person may be taken on the sole basis of an automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third paragraph supplies the only carve-out, and it operates by deeming rather than by exemption: decisions taken in the course of the conclusion or performance of a contract for which the person concerned has been put in a position to present their observations, and decisions satisfying the requests of the person concerned, are not regarded as taken on the sole basis of an automated processing. The Law carries no profiling definition, no right to an explanation of the logic involved and no human-review right; the opportunity to present observations exists only inside the contractual deeming clause.

Art. 76, the final article, is a bare publication clause — "La présente loi sera publiée au Journal officiel de la République algérienne démocratique et populaire" — and the Law contains no commencement article and no deferral for art. 11. The date used here is therefore the date of the Journal officiel that carries the Law: JO n° 34 of 25 Ramadhan 1439 corresponding to 10 June 2018, whose masthead and per-page footers were read directly in the JORADP French edition. Confidence is medium for the same reason as Morocco's art. 11: the Algerian general publication-to-force rule (art. 4 of the Code civil, Ordonnance n° 75-58) was not primary-source verified — the 1975 Journal officiel volumes on JORADP are image scans with no recoverable text layer, and Loi n° 05-10 of 20 June 2005, which amended the Code civil, was read in full and does not touch art. 4 — so it could not be confirmed whether force attaches on the day of publication or the day after. Art. 75 is a transitional provision, not a deferral of art. 11: persons already carrying on a processing activity at the date of promulgation must bring themselves into conformity within a maximum of one year from the date of installation of the national authority, on pain of the art. 56 penalties. Art. 11 itself is self-executing and is not conditioned on the authority existing; the art. 46 administrative route that enforces it is.

Stated maximum penalty — No criminal offence attaches to art. 11. The penal chapter (arts. 56 to 74) enumerates the articles it punishes — art. 12 processing without declaration or authorisation, sensitive data without express consent, purpose deviation, fraudulent collection, unauthorised access, obstruction of the national authority, the art. 28 national register, the art. 32, 34, 35 and 36 data-subject rights, arts. 38 and 39 security, art. 43 breach notification and art. 44 cross-border transfer — and art. 11 appears in none of them. Art. 47's fixed fine of 500,000 DA is likewise confined to arts. 32, 34, 35, 36 and to the notifications under arts. 4, 14 and 16. The route that does reach art. 11 is art. 46, under which non-observance of the provisions of the Law by the responsable du traitement leads the national authority to take administrative measures against them: a warning, a formal notice (mise en demeure), provisional withdrawal for a period not exceeding one year or definitive withdrawal of the declaration receipt or the authorisation, and a fine — with no amount fixed for it in the text. Decisions of the national authority are open to appeal before the Conseil d'Etat. Art. 70 refers offences by legal persons to the Penal Code and art. 74 doubles the penalties of the penal chapter on recidivism, but neither enlarges the reach of art. 11.

In force · 10 Jun 2018 checked 17 Aug 2026 Loi n° 18-07 art. 11 ↗ medium confidence

European Union 3

EU Comprehensive

High-risk AI obligations (Annex III)

Binds Providers & deployers of Annex III high-risk AI (employment, credit, education, biometrics, law enforcement, migration). Omnibus (Reg. EU 2026/1744, OJ L 2026/1744 published 24 Jul 2026) defers high-risk obligations for standalone Annex III systems from 2 Aug 2026 to 2 Dec 2027.

Regulation (EU) 2026/1744 (Digital Omnibus) published in the Official Journal; application of the Annex III high-risk obligations is deferred to 2 December 2027.

Stated maximum penalty — Up to 3% turnover or €15M

Applies 2 Dec 2027 checked 22 Aug 2026 EU AI Act (Digital Omnibus) ↗ high confidence
EU Comprehensive

EU AI Act high-risk obligations (Annex I — product-embedded)

Binds Providers and deployers of AI systems embedded in regulated products listed in Annex I (medical devices, general product safety, machinery, toys, aviation, automotive, railway). Omnibus (Reg. EU 2026/1744, OJ L 2026/1744 published 24 Jul 2026) defers high-risk obligations for AI embedded in Annex I regulated products (medical devices, machinery, toys, aviation) from 2 Aug 2026 to 2 Aug 2028.

Regulation (EU) 2026/1744 (Digital Omnibus) published in the Official Journal; application of the Annex I product-embedded high-risk obligations is deferred to 2 August 2028.

Stated maximum penalty — Up to 3% global turnover or €15M

Applies 2 Aug 2028 checked 17 Aug 2026 EU AI Act (Digital Omnibus amendment) ↗ high confidence
EU Comprehensive

High-risk AI intended for public authorities — legacy-system compliance deadline

Binds Providers and deployers of high-risk AI systems intended to be used by public authorities. Providers and deployers of high-risk AI systems intended to be used by public authorities have until 2 Aug 2030 to bring those systems into line with the AI Act, regardless of the general legacy-system grace period for systems placed on the market before the high-risk rules apply.

Article 111(2) of Regulation (EU) 2024/1689 as replaced by the Digital Omnibus on AI, Regulation (EU) 2026/1744, Article 1(39)(a) (OJ L, 24.7.2026). Distinct from the main high-risk application dates (Annex III standalone systems, 2 Dec 2027; Annex I product-embedded systems, 2 Aug 2028): this is the backstop retrofit date for legacy systems that would otherwise sit in the grace period indefinitely. Recital (39) of the Digital Omnibus clarifies that the Article 111(2) grace period operates at type-and-model level: where at least one individual unit was lawfully placed on the market or put into service before the cut-off, other units of the same type and model stay within the grace period as long as the design remains unchanged, while a significant change in design ends it. Breaches fall in the Article 99(4) tier, points (a) for provider obligations under Article 16 and (e) for deployer obligations under Article 26.

Stated maximum penalty — Up to 3% turnover or €15M

Applies 2 Aug 2030 checked 17 Aug 2026 EU AI Act Art. 111(2) (Digital Omnibus) ↗ high confidence

Gabon 1

Gabon Binding

Loi n° 025/2023 art. 77 — the recast that carries the Francophone family's only statutory definition of artificial intelligence

Binds Responsables de traitement, on the terms of the art. 4 scope: the Law applies to any collection, processing, transmission, storage and use of personal data by a natural person or by public-law or private-law legal persons, and to any processing, automated or not, of personal data contained or intended to be contained in a file. Art. 78 subjects automated processing to a declaration to the APDPVP, excepting the processing mentioned in arts. 80, 81 and 82 or in art. 111; art. 79 requires the declaration to carry an undertaking that the processing satisfies the Law's requirements, to be addressed by any means leaving a trace, and requires the controller to notify data breaches likely to seriously affect fundamental rights and freedoms to the competent supervisory authority without excessive delay. Neither profiling nor automated decision-making is listed as a category attracting prior authorisation, so Gabon imposes no ex ante gate on the processing art. 77 governs. Art. 206 and art. 207 distinguish controllers holding a récépissé or an authorisation from de facto controllers holding neither. The art. 77 bar binds the courts under its first limb and, under its second, every decision-maker whose decision produces legal effects in regard to a person, with no size or sector threshold. Impact tier: all entities.. Article 77 of Loi n° 025/2023 du 12 juillet 2023 portant modification de la loi n° 001/2011 du 25 septembre 2011 relative à la protection des données à caractère personnel is Gabon's operative automated-decision rule. Like its predecessor it is not a free-standing article: the automated-decision paragraphs are appended to the article governing data relating to offences, convictions and security measures, which reserves such processing to public and judicial authorities and legal persons managing a public service acting within their legal remit, and to auxiliaires de justice for the strict needs of the missions the law confers on them. Three unnumbered paragraphs follow. The first: no judicial decision involving an appraisal of a person's conduct may have as its foundation a computerised processing of data intended to evaluate certain aspects of their personality. The second: no other decision producing legal effects in regard to a person may be taken on the sole foundation of an automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third deems decisions taken in the context of the conclusion or performance of a contract, and for which the person concerned was put in a position to present their observations, and those satisfying the requests of the person concerned, not to be issued from an automated processing. As in Guinea, Madagascar and Congo, the judicial limb omits the word "seul" that the second limb carries. The second limb takes the narrow Directive 95/46/EC trigger confined to decisions producing legal effects. What sets Gabon apart from every other Francophone row on the tracker is the surrounding apparatus, which is GDPR-grade and, uniquely, AI-aware on the face of the statute. The definitions article defines Intelligence Artificielle as a logical and automated process generally resting on an algorithm which is able to carry out well-defined tasks, adding that any tool used by a machine constitutes an artificial intelligence; it separately defines raw data in the field of artificial intelligence as data having undergone no transformation since its initial observation, input data in the field of artificial intelligence as data used for machine learning or for the decision-making of the system, and the artificial neuron by reference to whether it should be activated. It also defines Profilage as a processing using an individual's personal data with a view to analysing and predicting their characteristics, and Portabilité. Art. 43, the access right, carries the full GDPR transparency package: the existence of automated decision-making, including profiling, and at least in such cases meaningful information about the underlying logic as well as the significance and the envisaged consequences of that processing for the person concerned, together with a distinct right for the data subject to obtain on request knowledge of the reasoning underlying the processing of the data where the results of that processing are applied to them. Gabon is therefore the one jurisdiction in this block where the automated-decision bar sits alongside both a logic-disclosure right and a reasoning right.

Supersession: this row replaces, and does not duplicate, the automated-decision provision of Loi n° 001/2011 du 25 septembre 2011, which carried the same rule at its art. 50 in the same unusual placement, appended to the article on offence and conviction data. Loi n° 025/2023 is styled a modification of the 2011 Law but is in substance a full recast, running to 221 articles against the predecessor's shorter frame and renumbering throughout; its art. 221 provides that the present Law, which abrogates all prior contrary provisions, notably certain provisions of Loi n° 001/2011, shall be registered, published in the Journal Officiel and executed as a law of the Republic. Because the abrogation is of contrary provisions rather than of the 2011 Law as a whole, and because the recast reproduces the automated-decision rule rather than repealing it, the obligation is continuous from 2011; only the article number, the wording and the enforcement apparatus changed. The wording changes are small but real: the 2011 judicial limb read "traitement automatisé" where the 2023 text reads "traitement informatisé", and the 2011 deeming clause read that such decisions are not regarded as taken on the sole foundation of an automated processing, where the 2023 clause reads that they are not considered as issued from an automated processing. The institutional change is larger: the Commission nationale pour la protection des données à caractère personnel created by the 2011 Law is replaced by the Autorité pour la Protection des Données Personnelles et de la Vie Privée, the APDPVP, which is the body named throughout the enforcement chapter. The Law carries no commencement article and art. 221 is a bare registration, publication and execution clause, so nothing is deferred. The date recorded here is the date of the gazette in which the Law was promulgated and published: Journal Officiel de la République Gabonaise n° 218 Bis of 15 July 2023, printed on the running head of every page of the issue. The Law itself is dated 12 July 2023 at Libreville, and the promulgating decree in the same issue bears the same date. Confidence is medium because the Gabonese general publication-to-force rule was not verified against a primary source: if force runs from promulgation the operative date is 12 July 2023, three days earlier. Both candidate dates are long past, so the lifecycle of this row is unaffected either way. On sourcing: the official gazette host journal-officiel.ga returned HTTP 503 on every path when checked for this entry, so the text was read in the scan of Journal Officiel n° 218 Bis published by the AFAPDP, the association of Francophone data-protection authorities of which Gabon's regulator is a member. That file is a reproduction of the official gazette, carrying its running heads, pagination and the other laws promulgated in the same issue, and is treated as primary on the same basis as the archived official texts used for Burkina Faso and Nigeria. Care is needed with that issue: it also carries Loi n° 027/2023 on cybersecurity and cybercrime, whose own arts. 49 to 66 create heavy imprisonment and fine penalties that have nothing to do with the data-protection Law and must not be attributed to it. Text read across the whole of Loi n° 025/2023, including the definitions, the arts. 4 to 6 scope, the art. 43 access right, arts. 77 to 79, and the arts. 199 to 221 recourse, control, sanctions and final chapters. No AI-specific statute is in force in Gabon, but the definitions article of this Law is the only place in the Francophone African block where artificial intelligence is defined in a binding data-protection statute.

Stated maximum penalty — Art. 77 is reached by the administrative catch-all in art. 203, which provides that the Authority appraises and pronounces, without graduation, according to the breach of the present Law established, a warning against a controller not respecting the obligations flowing from the Law, a mise en demeure to cause the established breaches to cease within the time limit it fixes, and a pecuniary sanction. The phrase "sans graduation" matters: unlike Congo, where the fine becomes available only once a mise en demeure has been defied, the Gabonese Authority is expressly freed from any obligation to escalate through the list in order. Art. 204 sets the pecuniary regime. Where the controller does not comply with the mise en demeure addressed to them they may be summoned to a hearing, and after contradictory debate the APDPVP may pronounce a provisional suspension of the collection and processing of personal data for three months, becoming definitive on expiry, and a fine of one million to one hundred million francs CFA. The amount must be proportionate to the gravity of the breaches and to the advantages derived from them. On a first breach it may not exceed ninety-eight million four hundred thousand francs CFA. On recidivism it may not exceed three hundred million francs CFA or, in the case of an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of one hundred and ninety-six million francs CFA. That absolute ceiling on the percentage limb is distinctive and is worth reading carefully: because the 5 per cent figure is itself capped at one hundred and ninety-six million francs CFA, the turnover limb binds only undertakings with pre-tax turnover below roughly 3.9 billion francs CFA, and above that threshold the percentage ceases to have any effect — the opposite of how the equivalent ceilings work in Guinea, Côte d'Ivoire, Niger and Burkina Faso, where the percentage is the escalating term. Where the APDPVP has pronounced a pecuniary sanction that has become definitive before the criminal court has finally ruled on the same or connected facts, the court may order the pecuniary sanction to be set off against the fine it pronounces. Art. 205 allows warnings to be made public and, where the controller is in bad faith, the insertion of sanctions in publications at the sanctioned person's expense. Art. 206 exposes a controller holding a récépissé or authorisation who does not respect the Law's obligations, after mise en demeure, to suspension of the récépissé or authorisation for up to two months, definitive withdrawal on expiry of the suspension, and a fine of one million to one hundred million francs CFA. Art. 207 treats a controller holding neither as a de facto controller, exposed to a fine of one million to one hundred million francs CFA together with a mise en demeure to regularise. Art. 208 supplies emergency powers, including interruption of the processing for a maximum of three months, where implementation of a processing or exploitation of data entails a violation of rights and liberties. On the penal side art. 213 punishes obstruction of the APDPVP with six months to one year's imprisonment and a fine of one million to ten million francs CFA; no penal article of this Law reaches art. 77.

In force · 15 Jul 2023 checked 22 Aug 2026 Loi n° 025/2023 art. 77 ↗ medium confidence

Ghana 1

Ghana Binding

Data Protection Act s. 41 — notice-based right against solely-automated decisions, plus an automatic duty to notify and reconsider

Binds Data controllers within the scope of s. 45(1): those established in Ghana processing data in Ghana; those not established in Ghana but using equipment or a data processor carrying on business in Ghana to process the data; and processing in respect of information originating partly or wholly from Ghana. Section 45(3) treats as established in Ghana an individual ordinarily resident there, a body incorporated under Ghanaian law, a partnership or person registered under the Registration of Business Names Act, 1962 (Act 151) or the Trustees Incorporation Act, 1962 (Act 106), an unincorporated joint venture or association operating in part or in whole in Ghana, and any other person maintaining an office, branch or agency there; s. 45(2) requires a controller not incorporated in Ghana to register as an external company. Registration with the Data Protection Commission is a standing precondition of processing: s. 53 prohibits processing personal data without registration and s. 56 makes failure to register an offence. The s. 41 duties bind any controller that takes a solely-automated decision significantly affecting an individual, irrespective of size. Impact tier: all entities.. Section 41 of the Data Protection Act, 2012 (Act 843), headed “Rights in relation to automated decision-taking”, carries Ghana's operative automated-decision rule, in the block of data-subject rights at ss. 35 to 44. Subsection (1) entitles an individual at any time, by notice in writing to a data controller, to require the controller to ensure that any decision taken by or on behalf of the controller which significantly affects that individual is not based solely on the processing by automatic means of personal data in respect of which that individual is the data subject. Subsection (2) then operates despite the absence of such a notice: where a decision which significantly affects an individual is based solely on that processing, the controller shall as soon as reasonably practicable notify the individual that the decision was taken on that basis, and the individual is entitled, by notice in writing, to require the controller to reconsider the decision within twenty-one days after receipt of the notification. Subsection (3) gives the controller twenty-one days after receipt of that notice to inform the individual in writing of the steps it intends to take in compliance with that notice. Subsection (4) disapplies the section where the decision is made in the course of considering whether to enter into a contract with the data subject, with a view to entering into the contract, in the course of performance of the contract, for a purpose authorised or required by or under an enactment, or in other circumstances prescribed by the Minister. Subsection (5) lets the Commission, if satisfied on a complaint by a data subject that a person taking a decision has not complied, order the controller into compliance; subsection (6) preserves the rights of third parties. Section 43 separately gives a data subject who suffers damage or distress through a controller's contravention of a requirement of the Act a right to compensation from that controller.

Commencement is not stated on the face of the Act. Section 99 provides that the Minister shall specify the date when the Act comes into force by publication in the Gazette, and the enacted text records only a Date of Gazette notification of 18 May 2012, which is the publication of the Act itself and not the appointed commencement. The Data Protection Commission — the statutory supervisory authority established by s. 1 of this Act, so the body whose own existence dates from the appointed day — states on its Who We Are page that the Commission “was established by the Data Protection Act 2012 (Act 843) which came into force 16th October 2012”. That regulator statement is the date recorded here. The underlying ministerial commencement instrument itself could not be retrieved: the Commission publishes no commencement or Executive Instrument in its media library, and Ghana has no online official gazette that serves the instrument. The date is therefore taken from the supervisory authority's own publication rather than from the gazette notice, and should be revisited if the instrument surfaces. Section 41 carries no separate or deferred commencement of its own. Act 843 remains the principal Act: it has no amendment on the Commission's records and the Commission has published no automated-decision or AI guidance under it, so the statutory text is the whole of the binding rule. Ghana is the tracker's fourth African jurisdiction, after South Africa, Kenya and Nigeria. Its drafting is the oldest of the four and is modelled on the UK Data Protection Act 1998 s. 12 rather than on GDPR Art. 22: the right is exercised by written notice rather than existing as a standing prohibition, and the contract carve-out in s. 41(4) is wider than the GDPR-style exceptions in ke-dpa-s35 and ng-ndpa-s37 because it excludes pre-contractual consideration and contract performance outright, without requiring compensating safeguards. Against that, s. 41(2) is stronger than all three peers on one axis: the duty to notify and the right to demand reconsideration bite automatically whenever a solely-automated significant decision is taken, without the data subject having served any prior notice, and both legs run on a hard twenty-one-day clock, where ke-dpa-s35 says only “within a reasonable period” and za-popia-s71 and ng-ndpa-s37 set no deadline at all. Text read in the copy of the Act published by the Data Protection Commission, the supervisory authority established under it.

Stated maximum penalty — Section 41 non-compliance is not itself an offence. The route to a sanction runs through the Commission: on a complaint by a data subject under s. 41(5) the Commission may order the controller to comply, and where the Commission is satisfied that a controller has contravened or is contravening any of the data protection principles it shall serve an enforcement notice under s. 75 requiring specified steps or a halt to specified processing. Failure to comply with an enforcement notice or an information notice is an offence under s. 80(1), punishable on summary conviction by a fine of not more than one hundred and fifty penalty units or a term of imprisonment of not more than one year, or both. Section 95 sets a general penalty, for an offence under the Act for which no penalty is specified, of a fine of not more than five thousand penalty units or imprisonment of not more than ten years, or both, and s. 94(2) applies the same five-thousand-penalty-unit ceiling to offences under Regulations made under the Act. Section 43 gives the data subject a separate civil claim for compensation for damage or distress caused by a failure to comply with a requirement of the Act. Penalty units are valued under the Fines (Penalty Units) Act, 2000 (Act 572), which is not part of Act 843.

In force · 16 Oct 2012 checked 17 Aug 2026 Data Protection Act s. 41 (Act 843) ↗ high confidence

Guinea 1

Guinea Binding

Loi L/2016/037/AN art. 27 — the strictest Francophone automated-decision bar, with no exception of any kind and a general penalty running to 7% of turnover

Binds Responsables du traitement and their sous-traitants, subordonnés and préposés. The prior formalities are set out in Chapitres V and VI: art. 7 subjects six categories to prior authorisation before any implementation — genetic and medical data and scientific research in those fields, data on offences, convictions or security measures pronounced by the courts, national identification numbers or identifiers of the same nature including telephone numbers, biometric data, public-interest processing including for historical, statistical or scientific purposes, and transfers to a third country — while art. 8 lets the Authority establish norms simplifying or exempting the declaration duty for the most common categories, and art. 6 exempts processing for which a data protection correspondent has been designated except where a third-country transfer is envisaged. Art. 9 fixes the minimum contents of a request for opinion, a declaration or an authorisation request, art. 11 the channels for filing, and art. 12 gives the Authority two months, extendable once by two months on a reasoned decision, to accept or refuse — with the notable rule that silence beyond those periods amounts to implicit acceptance of the declaration or a tacit authorisation, and that an appeal against a refusal is not suspensive. Profiling and automated decision-making appear in none of the art. 7 authorisation categories, so Guinea, like Togo and unlike Burkina Faso and Niger, imposes no ex ante gate on the processing art. 27 governs. Art. 17 requires a reasoned opinion of the Authority before processing on behalf of the State, a public-law legal person or a private-law legal person managing a public service is authorised by regulation, in the fields of State security, national defence or public security, the prevention, investigation, establishment or prosecution of criminal offences or the execution of criminal convictions or security measures, the population census, and the processing of salaries, pensions, taxes, duties and other settlements. The art. 27 bar binds the courts under its first limb and every administrative or private decision-maker appraising human conduct under its second, irrespective of size or sector. Impact tier: all entities.. Article 27 of Loi n° L/2016/037/AN du 28 juillet 2016 relative à la cybersécurité et la protection des données à caractère personnel is Guinea's operative automated-decision rule. It sits in Chapitre VIII on the guiding principles of personal-data processing, between the art. 26 press-and-Penal-Code saving and the art. 28 cross-border-transfer article, in two unnumbered paragraphs. The first: no judicial decision involving an appraisal of the conduct of a natural person may have as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality. The second: no administrative or private decision involving an appraisal of human conduct may have as its sole foundation an automated processing of personal data giving a definition of the profile or of the personality of the person concerned. Two things make this the strictest formulation in the Francophone family tracked. First, the judicial limb does not contain the word "seul", so it bars any judicial decision appraising conduct from resting on such a processing at all, whatever else the court also relies on, while the qualifier is present in the second limb of the same article. That asymmetry is not unique to Guinea, and an earlier version of this entry wrongly said it was: Madagascar's art. 3, Congo-Brazzaville's art. 13, Gabon's art. 77 and Algeria's art. 11 all drop the qualifier from the judicial limb and keep it in the other, which makes the pattern a shared inheritance of the Francophone family rather than a Guinean innovation. What Guinea combines with it is what no other row does: its wide second limb reaches any administrative or private decision appraising human conduct, not merely decisions producing legal effects as in Congo, Gabon, Togo, Morocco and Algeria. Second, and like Côte d'Ivoire, Mali and Burkina Faso, the Law supplies no carve-out whatever — no contract exception, no consent exception, no legal-authorisation exception and no opportunity to present observations. The Law creates no right to know the logic underlying an automated processing: art. 30 lists what must be given at collection and art. 31 the access right, which runs to information enabling the data subject to know and to contest the processing, confirmation, communication of the data and their origin, and purposes, categories and recipients. There is no human-review right and no right to a fresh non-automated decision, and the Law carries no definition of profiling. What the rights chapter does carry, unusually for a 2016 Francophone statute and evidently drawn from the then-new GDPR rather than from the Directive, is a right to erasure and digital oblivion in arts. 35 to 39 and a right to data portability in art. 40.

Unusually for this block, the commencement rule is express and needs no inference. Art. 65, the final article, reads that the present Law, which abrogates all prior contrary provisions and enters into force from the date of its promulgation, shall be registered and published in the Journal Officiel de la République de Guinée and executed as a law of the State. The date stamped in the signature block over the signature of President Prof. Alpha Condé at Conakry is 28 July 2016, and 28 July 2016 is therefore the date recorded here. This resolves a discrepancy that runs through the secondary record: several repositories, including the copy indexed by the Cour Suprême, cite the Law as "du 26 juillet 2016", while the National Assembly's own page and the copy published by ANSSI Guinée carry 28 July. The enacted text read for this entry carries 28 July, and because art. 65 attaches force to promulgation rather than to publication, the Journal Officiel date does not need to be established for the date on this row to be sound. Confidence is medium rather than high for one reason only: the promulgation date is a rubber stamp impressed into a blank on the signature page of a scanned document rather than typeset, and the Journal Officiel citation for the Law could not be established from a primary source, so the two-day margin around 26-28 July 2016 cannot be closed by a second official instrument. Art. 63 is transitional and is not a deferral of art. 27: controllers had a maximum of one year from promulgation to bring themselves into conformity, a period that closed on 28 July 2017. Art. 64 leaves unspecified application modalities to decrees, orders and decisions. The abrogation in art. 65 names no statute, so no predecessor is superseded on the tracker. Guinea is not an ECOWAS outlier by accident: it is a founding member, and its art. 27 takes the wider ECOWAS Supplementary Act A/SA.1/01/10 drafting in its second limb — any administrative or private decision appraising human conduct — placing it with Côte d'Ivoire, Burkina Faso, Niger and Mali rather than with Togo, Morocco and Algeria, whose second limb is confined to decisions producing legal effects. Within that ECOWAS group Guinea is the strictest, because its judicial limb alone omits the word "seul". The Law is a combined instrument: cybersecurity and cybercrime occupy roughly its first two thirds and personal data protection the last, with the data-protection part restarting its own definitions at p. 34 of the enacted text and running from art. 1 to art. 65. Text read page by page in the copy published by the Agence Nationale de la Sécurité des Systèmes d'Information, the Guinean State agency, including the definitions, arts. 7 to 13, 14 to 17, 18 to 29, 30 to 40, 41 to 43 and 55 to 65. The pages were read as page images because the file is a scan with no text layer.

Stated maximum penalty — Guinea is the one jurisdiction in this block where the automated-decision bar is directly and heavily enforceable, and the reason is that art. 56 is a general catch-all rather than a list of named offences. Art. 56 provides that any controller, or their processor, subordinate or agent, who does not respect the provisions of the present Law shall be punished by a fine of 50,000,000 to 150,000,000 Guinean francs. On recidivism within the five years following the date on which that fine became definitive, the fine is raised to an amount which may not exceed 1,500,000,000 Guinean francs and, where an undertaking is concerned, to an amount which may not exceed 7 per cent of pre-tax turnover for the last closed financial year. Because art. 56 is drafted against "les dispositions de la présente loi" without enumeration, it reaches art. 27 on its face — no other Francophone row on the tracker has a penalty that reaches its automated-decision article directly, and the 7 per cent turnover ceiling is the highest in the block, against 5 per cent in Côte d'Ivoire, Niger and Burkina Faso. Art. 55 separately punishes obstruction of the Authority in charge of Personal Data Protection, or failure to comply with its decisions and injunctions, with six months to three years' imprisonment and a fine of 20,000,000 to 150,000,000 Guinean francs, with accomplices liable to the same penalties and the Procureur de la République or competent judge to be informed without delay. Art. 57 leaves the modalities of recovery of the Authority's pecuniary sanctions to regulation. Art. 58 allows administrative and penal sanctions to be aggravated on recidivism at the discretion of the Authority or the competent judicial authority, with imprisonment doubled and fines doubled for a natural person and doubled to quintupled for a legal person. Art. 59 allows additional sanctions of the same nature as those in the cybercrime law. Art. 60 requires that sanctions be published at least in the Journal Officiel, on the Authority's website and on the CERT's, in a newspaper or legal-notices journal and at the registry of the competent court, the last two at the convicted person's expense. Art. 61 preserves the sanctions available under the cybercrime law, and art. 62 aligns limitation periods with the Penal Code and the Code of Criminal Procedure.

In force · 28 Jul 2016 checked 21 Aug 2026 Loi n° L/2016/037/AN art. 27 ↗ medium confidence

Indonesia 1

Indonesia Binding

UU 27/2022 (PDP Law) Arts. 10 and 34 — objection to solely-automated decisions and mandatory impact assessment

Binds Personal-data controllers ('Pengendali Data Pribadi') within the scope of Art. 2: any person, public body or international organisation acting inside Indonesian jurisdiction, and those outside it whose acts have legal effect in Indonesia or affect Indonesian data subjects abroad. Processing by a natural person for purely personal or household activity is excluded. Impact tier: all entities.. Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi is Indonesia's general data-protection statute. Art. 10(1) gives the data subject the right to object to a decision taken solely on the basis of automated processing, including profiling, that produces legal effects or has a significant impact on them; Art. 10(2) leaves the procedure for lodging that objection to a Government Regulation (Peraturan Pemerintah). Art. 34(1) separately obliges the personal-data controller to carry out a personal-data-protection impact assessment where processing carries a high potential risk to the data subject, and Art. 34(2)(a) lists automated decision-making with legal effect or significant impact on the data subject as the first such high-risk category — alongside large-scale processing, systematic evaluation, scoring or monitoring, data matching or combination, and the use of new technologies. The elucidation of Art. 10(1) defines 'pemrofilan' as electronically identifying a person by reference to matters including employment history, economic condition, health, personal preferences, interests, reliability, behaviour, location or movements.

Enacted and promulgated in Jakarta on 17 October 2022; Lembaran Negara 2022 No. 196, Tambahan Lembaran Negara No. 6820. Art. 76 provides that the Act enters into force on the date of promulgation, so 17 October 2022 is the in-force date. Art. 74 is a transitional rule, not a deferred commencement: controllers, processors and other parties involved in personal-data processing were given at most two years from promulgation to align their processing with the Act, so the adjustment window closed on 17 October 2024 and the duties are now fully exigible. Two implementation caveats, both verified rather than assumed. First, no Government Regulation implementing the Act has been issued: a search of the Sekretariat Negara legal database returns no PP under UU 27/2022, and the Komdigi JDIH record for the Act carries an empty 'Peraturan Pelaksanaan' section. The Art. 10(2) objection procedure and the Art. 34(3) impact-assessment procedure therefore still lack their detailed rules. Second, Art. 57(1) lists the provisions carrying administrative sanctions and Art. 34(1) is on that list while Art. 10 is not — the sanctioned duty is the impact assessment, while the Art. 10 right is exercised through the supervisory body and the dispute-resolution route of Chapter XIII. Indonesia's peer of br-lgpd-art20, cn-pipl-art24, kr-pipa-art37-2-adm, ar-ley25326-art20 and cl-ley21719-art8bis: like Brazil and Argentina it is already in force, and like Chile it pairs the objection right with a mandatory impact assessment, but unlike Korea it grants no express right to an explanation or to human re-processing. Text read in the full statutory text published by the JDIH of the Kementerian Komunikasi dan Digital, the ministry of record for the Act; the Sekretariat Negara salinan (LN 2022/196) is a scanned image and carries no text layer, and peraturan.bpk.go.id returned HTTP 403 to every request.

Stated maximum penalty — Administrative sanctions under Art. 57 for breach of the Art. 34(1) impact-assessment duty: written warning, temporary suspension of processing, erasure or destruction of the personal data, and/or an administrative fine of at most 2 per cent of annual revenue or annual receipts measured against the variable of the violation, imposed by the supervisory body. Art. 57(5) leaves the procedure for imposing those fines to a Government Regulation that has not yet been issued.

In force · 17 Oct 2022 checked 21 Aug 2026 UU 27/2022 Arts. 10, 34 (LN 2022/196) ↗ high confidence

Kenya 1

Kenya Binding

Data Protection Act s. 35 — right against solely-automated decisions, with written notification and a right to reconsideration

Binds Data controllers and data processors within the scope of s. 4, that is those established or ordinarily resident in Kenya and processing personal data while in Kenya, and those not so established or resident but processing personal data of data subjects located in Kenya. Registration with the Office of the Data Protection Commissioner under ss. 18 and 19 is a precondition of acting as a controller or processor, subject to the thresholds set by the Data Protection (Registration of Data Controllers and Data Processors) Regulations. The s. 35 duties bind any controller or processor that takes a solely-automated decision with legal or significant effect. Impact tier: all entities.. Section 35 of the Data Protection Act No. 24 of 2019 gives every data subject a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning or significantly affects the data subject (s. 35(1)). The right does not apply where the decision is necessary for entering into or performing a contract between the data subject and a data controller, is authorised by a law to which the controller is subject and which lays down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, or is based on the data subject's consent (s. 35(2)). Where a controller or processor does take such a decision, s. 35(3) imposes two duties: it must as soon as reasonably practicable notify the data subject in writing that a decision has been taken based solely on automated processing, and the data subject may then, after a reasonable period from receipt of that notification, request the controller or processor to reconsider the decision or to take a new decision that is not based solely on automated processing. On receipt of such a request the controller or processor must within a reasonable period consider the request including any relevant information the data subject provides, comply with it, and inform the data subject in writing of the steps taken in compliance and of the outcome (s. 35(4)). Section 35(5) empowers the Cabinet Secretary to make further provision by Regulations. Section 31 separately makes a data protection impact assessment mandatory where a processing operation is likely to result in high risk to the rights and freedoms of a data subject.

Commencement is stated on the face of the published Act: the gazetted text of the Data Protection Act No. 24 of 2019 records a Date of Assent of 8 November 2019 and a Date of Commencement of 25 November 2019, and s. 35 carries no deferred or separately-appointed commencement. The Office of the Data Protection Commissioner was constituted in November 2020 and has exercised its enforcement powers since; the section itself has been operative from 25 November 2019. Kenya is the tracker's second African jurisdiction, added in the same sweep as za-popia-s71. Section 35 follows the GDPR Art. 22 shape more closely than the South African provision does: it grants an express right to demand a new decision that is not based solely on automated processing, which POPIA s. 71 does not, and it attaches an affirmative written-notification duty on the controller rather than leaving disclosure to a request. It stops short of the Korean kr-pipa-art37-2-adm model in that it confers no standalone right to an explanation of the criteria used. Text read in the official copy of the Act published by the Office of the Data Protection Commissioner, the supervisory authority established by Part II of the Act; new.kenyalaw.org and kenyalaw.org return HTTP 403 to non-browser clients, so the ODPC copy is cited.

Stated maximum penalty — Section 63 caps the administrative penalty the Data Commissioner may impose by penalty notice, in relation to an infringement of a provision of the Act, at five million Kenyan shillings, or in the case of an undertaking one per centum of its annual turnover of the preceding financial year, whichever is lower; s. 62 governs the penalty notice and s. 58 the enforcement notice that ordinarily precedes it. Section 65 gives a person who suffers damage by reason of a contravention a right to compensation from the controller or processor. Section 73 provides a general penalty, for offences under the Act for which no specific penalty is prescribed, of a fine not exceeding three million shillings or imprisonment for a term not exceeding ten years, or both. Appeals against administrative action lie to the High Court under s. 64.

In force · 25 Nov 2019 checked 16 Aug 2026 Data Protection Act s. 35 (No. 24 of 2019) ↗ high confidence

Kyrgyzstan 2

Kyrgyzstan Binding

Digital Code arts. 191-193 - every AI system used in the country must be danger-assessed, and both the method and the result must be published

Binds Владельцы систем искусственного интеллекта - the owners of AI systems applied in the Kyrgyz Republic, with the art. 192(3) risk-minimisation duty extending to users as well. Resolution No. 770 para. 2 spells the scope out: owners of AI systems applied in Kyrgyzstan 'irrespective of organisational-legal form, departmental (sectoral) affiliation and form of ownership'. There is no turnover, headcount, sector or nationality threshold anywhere in Chapter 23, so a sole trader running one model and a state body running a national platform owe the same assessment and the same publication.. Chapter 23 of the Digital Code of the Kyrgyz Republic (Code No. 178 of 31 July 2025), arts. 191 to 193, is the base layer of Kyrgyzstan's AI regime and it is unusual in applying to every AI system without a risk gate. Art. 191(1) starts from permission: AI systems are designed, developed and applied without restriction except where this Code says otherwise. Art. 191(2) then fixes seven sectoral principles that owners must build to - risk reduction, openness, explainability, human controllability, accuracy, reliability and security - and art. 191(3) makes them the basis on which every requirement for AI systems is set and read. Art. 192(1) limits what those requirements may protect to six enumerated goods (life and health, human and civil rights and freedoms, the environment, defence capability, national security, public order), art. 192(2) prohibits outright the design, development or application of AI systems for the targeted and knowingly unlawful causing of harm to those goods, and art. 192(3) puts a general duty on owners and users of AI systems irrespective of danger level to take all reasonable and necessary measures to minimise the risk of such harm. Art. 193 is the operative obligation: ALL AI systems applied in Kyrgyzstan are subject to a danger assessment, carried out by the system's owner at the design stage, again on completion of development and before application, and again on any unplanned change to the system or its environment of use that could alter the result. The owner writes the methodology itself, but under requirements set by the Cabinet of Ministers, and art. 193(4) requires BOTH the assessment result AND the methodology to be posted on the owner's website in a form simple and intelligible to natural persons and additionally as open data, state secrets excepted. Those Cabinet requirements exist: Resolution No. 770 of 2 December 2025 approved a Requirements-for-the-danger-assessment-methodology annex, so this is a filled slot and not a deferred one.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. The implementing act is Cabinet of Ministers Resolution No. 770 of 2 December 2025, published in «Эркин-Тоо» No. 96 (3753) of 5 December 2025, which approves five annexes under arts. 193 and 194 - the danger-assessment methodology requirements, and requirements for risk management, for system characteristics, for digital data quality and for technical documentation. Its para. 4 commences it 'fifteen days after the entry into force of the Digital Code', which computed from 6 February 2026 puts it at 21 February 2026; the ЦБД record card carries no dateOfEntry for the Resolution, so that single date is arithmetic from the Resolution's own text rather than a stated date. The Resolution's status in ЦБД is «Действует».

Stated maximum penalty — Nothing. There is no administrative offence for failing to run the danger assessment, for using a methodology that does not meet the Resolution No. 770 requirements, or for not publishing the result and the methodology. The only AI-specific offence Kyrgyzstan created is art. 228-10 of the Code of Offences (Code No. 128 of 28 October 2021, article inserted by Law No. 180 of 31 July 2025), and it reaches only the art. 192(2) prohibition: design, development or application of AI systems for the targeted and knowingly unlawful causing of harm to the protected goods, fined at 200 расчетных показателей for natural persons and 650 for legal persons. The расчетный показатель has been 100 som since 1 January 2006 (Law No. 13 of 27 January 2006 art. 2; Jogorku Kenesh Resolution No. 1115-III of 15 June 2006, still «Действует»), so the ceiling is 20,000 som for a natural person and 65,000 som for a legal person - roughly 230 and 745 US dollars. This is the same enforcement gap Kazakhstan has: a fully drafted duty layer sitting on a single narrow offence.

In force · 6 Feb 2026 checked 22 Aug 2026 KG Digital Code arts. 191-193 ↗ high confidence
Kyrgyzstan Binding

Digital Code arts. 194-196 - self-classified high-danger AI needs a signed public declaration of conformity before first use

Binds Владельцы (owners) and пользователи (users) of AI systems that the owner's own danger assessment classifies as high-danger, plus, by art. 126, every provider of a digital wellbeing service that uses AI within the service, without any assessment step. Duties split by role: arts. 194 and 195 fall on the owner, art. 196 on the user, and art. 196(3) moves the owner's set onto a rebrander, repurposer or substantial modifier. No size or sector threshold; Resolution No. 770 para. 2 restates the scope as all owners irrespective of legal form, sectoral affiliation or ownership.. Where the art. 193 danger assessment returns a system whose use raises the risk of harm to the protected goods to a level requiring risk management, art. 194(1) makes it a «система искусственного интеллекта повышенной опасности» - a high-danger AI system - and the Digital Code's substantive regime attaches for the whole life cycle. The classification is comparative and self-executed rather than annex-driven: it asks whether the system raises risk relative to alternative ways of doing the same thing, and art. 194(3) expressly excludes systems whose role in the decision or action is purely auxiliary and does not raise risk. Art. 194(4) hands the Cabinet of Ministers the four requirement families - risk management, system characteristics (openness, explainability, controllability, accuracy, reliability, digital resilience), digital data quality, and technical documentation - and all four now exist as annexes to Resolution No. 770. Art. 194(5) lists seven owner duties: conform to the mandatory requirements; implement and maintain a risk-management system across the whole life cycle; produce proper technical documentation; preserve the system logs while the system is under its control; confirm conformity before first application; remedy identified non-conformities; and, on demand of the competent state body, suspend - and on a final court act terminate - design and development carried on in breach. Art. 195 is the gate: before a high-danger system may be applied, its owner must adopt a declaration of conformity in the form and content approved by the Cabinet of Ministers, cast as a digital document, signed with a qualified digital signature, and posted on the owner's website as a publicly accessible digital record. Art. 196 then binds the user (deployer): operate per the manual, keep the processed data relevant, maintain effective supervision with named responsible persons and allocated resources, notify the owner and suspend use the moment there is ground to believe the manual-compliant use could cause harm, preserve logs, and suspend or terminate on official demand or court act. Art. 196(2) adds an explanation right where the output feeds a decision capable of infringing rights: general information about the system's characteristics and operating principles must be published on the site for consumer-facing systems and supplied in accessible form otherwise, and anyone whose interests the decision touches may demand, free of charge, information letting them understand and check how the result about them was arrived at. Art. 196(3) transfers the owner's duties to whoever puts the system into service under their own name or mark, changes its purpose, makes substantial modifications, or turns it into a high-danger system - the EU AI Act art. 25 pattern - and art. 196(4) releases the original owner in the latter two cases. Art. 196(5) exempts purely personal or family use from most duties, but makes that user and whoever gave them access jointly and severally liable where third-party rights are infringed. One sector is classified by statute rather than by assessment: art. 126 declares AI systems used to deliver digital wellbeing services to be high-danger systems as a matter of law.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. The regime is operable rather than pending: Cabinet of Ministers Resolution No. 770 of 2 December 2025 («Эркин-Тоо» No. 96 (3753) of 5 December 2025) supplies all four art. 194(4) requirement families as annexes 2 to 5, and the art. 195 declaration was completed separately by Cabinet of Ministers Order No. 1181-т of 31 December 2025, which approved the Requirements for the content of the declaration of conformity of high-danger AI systems. Both are «Действует» in ЦБД. Resolution No. 770 commences fifteen days after the Code, i.e. 21 February 2026 on the arithmetic of its own para. 4; the ЦБД card states no dateOfEntry for it.

Stated maximum penalty — Nothing, in administrative terms. The Code of Offences contains no article penalising application of a high-danger AI system without a declaration, non-conformity with the Resolution No. 770 requirements, absence of a risk-management system, loss of logs, or refusal of the art. 196(2) explanation. Art. 228-10, the only AI-specific offence, is confined to the art. 192(2) targeted-unlawful-harm prohibition (200 расчетных показателей for natural persons, 650 for legal persons; the расчетный показатель is 100 som, so 20,000 and 65,000 som). What does bite is non-monetary and, for an operating business, heavier: art. 194(5)(7) and art. 196(1)(7) let the competent state body order suspension of design, development or application on demand, with termination on a final court act. Civil exposure is the other real channel - art. 192(3) makes owners and users liable for harm caused, and for digital wellbeing services art. 127(2) lets the consumer elect a statutory compensation of 100 to 400 расчетных показателей (10,000 to 40,000 som) in place of proving damages, with the burden on the provider to disprove causation.

In force · 6 Feb 2026 checked 22 Aug 2026 KG Digital Code arts. 194-196 ↗ high confidence

South Korea 1

S. Korea Comprehensive

AI Basic Act — high-impact AI duties

Binds Operators of high-impact AI and advanced / high-compute AI. Risk management, human oversight and impact assessment for high-impact / advanced AI (MSIT administrative-fine grace period of at least one year from 22 Jan 2026).

MSIT enforcement grace period of AT LEAST one year from 22 Jan 2026 before administrative fines are imposed — confirmed in an MSIT primary release (see kr-aibasic-transparency, nttSeqNo=1191). Duration is not yet finalised by MSIT, so ~22 Jan 2027 is a floor rather than a confirmed end date, and the release states no carve-out. The 22 Jan 2026 in-force date is primary-sourced.

Stated maximum penalty — Admin fine up to ₩30M

In force · 22 Jan 2026 checked 21 Aug 2026 AI Basic Act ↗ high confidence

Kazakhstan 2

Kazakhstan Binding

AI Law art. 17(3) — seven AI capabilities banned outright, and the owner classifies its own risk tier

Binds Собственники и владельцы систем искусственного интеллекта — the owners and holders of AI systems. The Law states no size, sector, turnover or nationality threshold, so enterprise, SME, sole trader and public body are all covered on the same terms; the administrative fines in KoAP art. 641-1 are the place where size enters, and they are graded across natural persons, small business and non-commercial organisations, medium business and large business.. Law of the Republic of Kazakhstan No. 230-VIII ЗРК of 17 November 2025 «Об искусственном интеллекте» is Kazakhstan's first standalone AI statute and the first in Central Asia, and art. 17 is its structural core. Art. 17(3) forbids, on the territory of Kazakhstan, the creation and operation of AI systems possessing any one of seven functional capabilities: (1) use of subconscious, manipulative or other methods that distort a natural person's behaviour and limit their capacity to take informed decisions, or that push them into decisions capable of causing or threatening harm; (2) exploitation of a person's moral or physical vulnerability arising from age, disability, social position or any other circumstance, with the aim of causing or threatening harm; (3) evaluation and classification of natural persons or groups over a period of time on the basis of their social behaviour or known, assumed or predicted personal characteristics — a social-scoring ban, subject to cases provided by law; (4) collection and processing of personal data in breach of the personal-data legislation; (5) classification of natural persons on the basis of biometric data to infer race, political views, religious affiliation or any other criterion for the purpose of discriminating against them; (6) determination of a person's emotions without their consent, save in cases provided by law; and (7) creation and dissemination of results of AI activity that the laws prohibit. The list is close enough to EU AI Act art. 5 to be read against it, but it is a prohibition on creation and operation rather than on placing on the market, it has no law-enforcement-carve-out architecture, and the emotion-recognition limb is a consent rule rather than a workplace-and-education ban. Art. 17(1) then sets the three risk tiers — minimal, medium and high — and, unlike the EU's annex-driven scheme, assigns the classification to the owner and (or) holder of the system itself, applying the rules on classification of informatisation objects. High-risk systems that are also critically important information-and-communication infrastructure, or that are intended to form state electronic information resources, are treated as state systems for information-security purposes. Art. 17(2) adds a second, orthogonal axis of autonomy — low (a human always makes the final choice), medium (human correction or reversal remains possible) and high (human correction or reversal is wholly excluded or technically impossible) — and defers the rules on creating and operating high-autonomy systems to other laws, which is a real gap rather than a filled slot.

In force since 18 January 2026. Art. 31 commences the Law «по истечении шестидесяти календарных дней после дня его первого официального опубликования», with no article carved out. The А́ділет record card gives first official publication as the newspapers «Егемен Қазақстан» No. 222 (31202) and «Казахстанская правда» No. 222 (30600), both of 18 November 2025, with the Reference Control Bank of NPA in electronic form following on 20 November 2025. The sixty days run from 19 November 2025 and expire at the end of 17 January 2026, so the Law entered into force on 18 January 2026. А́ділет serves the text as «Обновленный» (consolidated and current), database state 19 August 2026, and flags the only pending change — Law No. 326-VIII of 24 June 2026 — as a future «Примечание ИЗПИ» note rather than as applied text.

Stated maximum penalty — The Law itself sets no figure: art. 30 is a bare referral to responsibility «в соответствии с законами Республики Казахстан». The companion Law No. 232-VIII of 17 November 2025 inserted KoAP art. 641-1, but its part one reaches only two things — failure to inform users about misleading synthetic outputs, and failure to manage the risks of a high-risk system where that failure caused harm — so breach of the art. 17(3) prohibitions is NOT itself an enumerated administrative offence. In practice an art. 17(3) capability is reached indirectly: through art. 18(2), which obliges immediate suspension or termination once such a risk is identified and whose breach is penalised by art. 641-1, through art. 20(2)(2), which makes the presence of prohibited capabilities an express object of AI system audit, through the personal-data offences in KoAP art. 79-1 and following where limb (4) is engaged, and through the criminal law, since art. 641-1 applies only «если это действие (бездействие) не содержит признаков уголовно наказуемого деяния». This entry states no figure for art. 17(3) itself rather than importing the art. 641-1 band, which on its face does not cover it.

In force · 18 Jan 2026 checked 21 Aug 2026 KZ AI Law art. 17 ↗ high confidence
Kazakhstan Binding

AI Law art. 18 — lifecycle risk management, refreshed at least yearly, and it is the penalised duty

Binds Собственники и владельцы систем искусственного интеллекта — the owners and holders of AI systems. The Law states no size, sector, turnover or nationality threshold, so enterprise, SME, sole trader and public body are all covered on the same terms; the administrative fines in KoAP art. 641-1 are the place where size enters, and they are graded across natural persons, small business and non-commercial organisations, medium business and large business.. Art. 18 of Law No. 230-VIII is the obligation with teeth. It defines AI risk management as a continuous process, planned and carried out by the owner and (or) holder across the whole lifecycle of the system, comprising four elements: identification and analysis of known and foreseeable risks of the system when used according to its intended purpose; assessment of risks both against the intended purpose and under conditions of foreseeable misuse; adoption of appropriate and targeted risk-management measures designed to prevent and eliminate the risks identified; and — the one hard cadence in the statute — regular updating of the risks not less than once a year. Art. 18(2) adds a trigger duty: where a risk is identified that the circumstances in art. 17(3), the prohibited-capability list, may arise, the owner and holder must take immediate measures to prevent and minimise damage and to protect the rights, freedoms and legitimate interests of natural persons and of society, including by suspending or wholly terminating operation of the system. Two features are worth marking against the EU comparison. The duty as drafted is not confined to high-risk systems — art. 18(1) speaks of the owner and holder of an AI system without qualification — whereas the administrative offence that backs it in KoAP art. 641-1(1)(2) is limited to high-risk systems and additionally requires a consequence, so the duty is broader than its sanction. And the annual refresh is a floor stated in the statute itself, not in delegated rules, which makes it directly checkable in a way EU AI Act art. 9 is not. Art. 19 sits alongside as a voluntary quality route: sectoral state bodies compile and continuously publish lists of trusted high-risk AI systems, and an owner seeking inclusion must have the system audited under art. 20, whose art. 20(2) requires the audit additionally to assess the quality and lawfulness of the data libraries used to train the models and the presence of prohibited functional capabilities.

In force since 18 January 2026. Art. 31 commences the Law «по истечении шестидесяти календарных дней после дня его первого официального опубликования», with no article carved out. The А́ділет record card gives first official publication as the newspapers «Егемен Қазақстан» No. 222 (31202) and «Казахстанская правда» No. 222 (30600), both of 18 November 2025, with the Reference Control Bank of NPA in electronic form following on 20 November 2025. The sixty days run from 19 November 2025 and expire at the end of 17 January 2026, so the Law entered into force on 18 January 2026. А́ділет serves the text as «Обновленный» (consolidated and current), database state 19 August 2026, and flags the only pending change — Law No. 326-VIII of 24 June 2026 — as a future «Примечание ИЗПИ» note rather than as applied text.

Stated maximum penalty — KoAP art. 641-1(1)(2), inserted by Law No. 232-VIII of 17 November 2025 (published «Егемен Қазақстан» and «Казахстанская правда» No. 222, 18 November 2025, so in force on the same 18 January 2026 date), penalises the failure by owners or holders to carry out risk management of HIGH-risk AI systems where that failure caused negative impact on people's health or wellbeing, the creation or dissemination of prohibited or false information, discrimination or violation of human rights, or other harm, and provided the act or omission carries no indicia of a criminal offence. First offence: 15 MRP for natural persons, 20 MRP for small business entities and non-commercial organisations, 30 MRP for medium business entities, 100 MRP for large business entities. Repeat within one year of an administrative penalty being imposed, under art. 641-1(2): 30, 50, 70 and 200 MRP respectively, AND suspension or prohibition of the operation of the AI system — which is the sharpest consequence in the regime, since the monetary ceiling is modest. Jurisdiction sits with the authorised body in the field of artificial intelligence under new KoAP art. 692-3, and cases may be heard and penalties imposed by the head of that body and their deputies. Amounts are stated in the mесячный расчетный показатель (MRP, monthly calculation index), the statutory unit the Code uses; the tenge value of one MRP is reset every year by the republican budget law, so the MRP figures rather than a converted tenge sum are the stable statement of the penalty.

In force · 18 Jan 2026 checked 21 Aug 2026 KZ AI Law art. 18 ↗ high confidence

Morocco 1

Morocco Binding

Loi 09-08 art. 11 — neutrality of the effects of automated processing: bar on decisions grounded solely in automated profiling

Binds Controllers within the scope of art. 2: processing of personal data wholly or partly by automated means, and non-automated processing of personal data contained in or intended to form part of manual files, where the controller is established on Moroccan territory and carries on an activity there, or is not established in Morocco but resorts, for the purposes of processing personal data, to automated or non-automated means situated on Moroccan territory. A controller in the second case must designate a representative established in Morocco who is substituted for it in the rights and obligations arising under the Law. Prior declaration to, or prior authorisation from, the Commission Nationale de contrôle de la protection des Données à caractère Personnel is a standing precondition of processing under arts. 12 and 13, with art. 12 requiring prior authorisation for sensitive-data and other listed processing. The art. 11 bar binds any controller taking a decision with legal effects grounded solely in automated profiling or personality evaluation, irrespective of size, and its first paragraph binds courts. Impact tier: all entities.. Article 11 of Law No. 09-08 relating to the protection of individuals with regard to the processing of personal data, headed “Neutralité des effets d'un traitement automatisé”, carries Morocco's operative automated-decision rule. Its first paragraph provides that no judicial decision involving an appraisal of a person's conduct may be founded on automated processing of personal data intended to evaluate certain aspects of that person's personality. Its second paragraph extends the bar beyond the courts: no other decision producing legal effects in respect of a person may be taken on the sole basis of automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. Its third paragraph sets the carve-out: decisions taken in the course of the conclusion or the performance of a contract, and for which the data subject has been put in a position to make observations, are not regarded as taken on the sole basis of automated processing, and neither are decisions granting a request made by the data subject. Article 7(c) supplies the companion transparency right, entitling the data subject to knowledge of the logic underlying any automated processing of personal data concerning them, alongside the confirmation and communication rights in art. 7(a) and (b). Article 11 is a transposition of art. 15 of Directive 95/46/EC by way of the French model, drafted in 2009 and so predating the GDPR: it speaks of automated processing intended to profile or to evaluate personality rather than of “profiling” as a defined term, and the safeguard it names is an opportunity to make observations rather than human intervention.

Law 09-08 was promulgated by Dahir nº 1-09-15 of 22 safar 1430 (18 February 2009) and published, together with the dahir, in Bulletin Officiel nº 5714 of 7 rabii I 1430 (5 March 2009), the date recorded here. The Law contains no commencement clause and no deferred-commencement mechanism: it ends at art. 67 and the dahir simply orders publication in the Bulletin Officiel. The date is therefore the publication date of the Bulletin Officiel carrying the text, read off the header of the copy published by the CNDP; the general Moroccan rule tying entry into force to that publication has not itself been read against a primary source, which is why confidence is recorded as medium rather than high. Article 67 is transitional only: it gave persons already carrying on processing before publication a maximum of two years, running from the date of the CNDP's installation as recorded by an administrative act published in the Bulletin Officiel, to regularise their declarations and authorisations, and on its own terms it reaches the declaration and authorisation regime rather than the art. 11 bar. Décret nº 2-09-165 was taken for the application of the Law; the CNDP publishes it only in Arabic and no date claim is drawn from it here. Coverage symmetry against the four African rows already tracked: Morocco is the oldest drafting of the five and the only one in the Directive 95/46/EC lineage rather than the GDPR art. 22 or UK DPA 1998 s. 12 lineages. Structurally it is closest to za-popia-s71 — both are prohibitions whose contract exception is conditioned on the data subject having had an opportunity to make representations, and neither grants human intervention or a fresh decision — but Morocco is narrower in two ways and wider in one. It is narrower in that its bar reaches only decisions producing legal effects, with no “substantial degree” or “significant effect” limb as in South Africa, Kenya, Nigeria, Rwanda, Tanzania and Ghana, and in that its disclosure duty sits in art. 7(c) as an access right rather than inside the automated-decision article as in za-popia-s71(3). It is wider in that its first paragraph binds courts directly, which no other row on the tracker does. It carries no deadline. Text read in the copy of the Law published by the CNDP, the supervisory authority instituted by the Law.

Stated maximum penalty — Article 11 has no dedicated penalty: the criminal tier in Chapter VII attaches to named articles and art. 11 is not among them. Article 53 punishes a controller that refuses the access, rectification or objection rights under arts. 7, 8 and 9 with a fine of MAD 20,000 to MAD 200,000 per infringement, which reaches the art. 7(c) right to know the logic underlying automated processing but not the art. 11 bar itself. The nearest general route is art. 63, under which a controller that refuses to apply the decisions of the Commission Nationale is liable to imprisonment of three months to one year and a fine of MAD 10,000 to MAD 100,000, or one of those penalties only; art. 62 punishes obstruction of the Commission's supervisory functions with imprisonment of three to six months and a fine of MAD 10,000 to MAD 50,000, or one of them. Article 64 doubles the fines where the offender is a legal person, without prejudice to penalties on its officers, and allows partial confiscation of assets, confiscation under art. 89 of the Penal Code, and closure of the establishment where the offence was committed; art. 65 doubles the sanctions on repeat offence within a year of a final conviction. Article 66 lets sworn agents of the Commission, alongside judicial police officers, investigate and record infringements by procès-verbal for transmission to the Crown Prosecutor within five days.

In force · 5 Mar 2009 checked 20 Aug 2026 Loi 09-08 art. 11 ↗ medium confidence

Madagascar 1

Madagascar Binding

Loi n° 2014-038 art. 3 — the wide automated-decision bar stated as a founding principle, with no exception and a 5% turnover catch-all behind it

Binds Responsables de traitement, on the terms of the art. 5 scope: the Law applies to any processing of personal data, automated or not, contained or intended to be contained in files, carried out in whole or in part on Malagasy territory, excluding processing for exclusively personal activities and processing for the sole purposes of journalism or literary or artistic expression. Art. 6 fixes the applicable-law rules. The prior-formality regime runs through Chapitre VI: art. 43 sets the declaration channel and art. 44 the categories reserved to a regulatory act, with art. 76 providing that processing governed by art. 44 and already created is subject only to a declaration. Neither profiling nor automated decision-making appears as a category attracting prior authorisation, so Madagascar, like Guinea and Togo and unlike Burkina Faso and Niger, imposes no ex ante gate on the processing art. 3 governs. The art. 3 bar itself binds two distinct classes of decision-maker with no size or sector threshold: under its first limb the courts, and under its second every administrative and private decision-maker appraising human conduct. Art. 52 provides for a délégué à la protection des données who exercises their functions independently, receives no instructions from the controller and may not be sanctioned for exercising them. Impact tier: all entities.. Article 3 of Loi n° 2014-038 du 9 janvier 2015 sur la protection des données à caractère personnel is Madagascar's operative automated-decision rule, and it is placed as a founding principle rather than as an operative duty: it sits in Chapitre premier, Dispositions générales, immediately after art. 2, which declares that data processing must serve every person and respect human identity, human rights, privacy and individual and public liberties, and immediately before art. 4, which creates the Commission Malagasy de l'Informatique et des Libertés. The article has two unnumbered paragraphs. The first: no judicial decision involving an appraisal of human conduct may have as its foundation an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The second: no administrative and private decision involving an appraisal of human conduct may have as its sole foundation an automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. Three features of the drafting matter. The judicial limb does not carry the word "seul", while the second limb of the same article does, so a court appraising conduct may not rest on such a processing at all, whatever else it also relies on. The second limb takes the wide trigger — any administrative and private decision involving an appraisal of human conduct — rather than the narrow Directive 95/46/EC trigger confined to decisions producing legal effects, which is what Congo-Brazzaville, Gabon, Togo, Morocco and Algeria use. And the Law supplies no carve-out whatever: no contract exception, no consent exception, no legal-authorisation exception, and no opportunity to present observations. Madagascar therefore joins Côte d'Ivoire, Mali, Burkina Faso and Guinea in barring the conduct outright rather than deeming some decisions outside it. The Law does create a logic right, but it is narrower than the bar it accompanies: the third indent of the art. 23 access right entitles a data subject to the information enabling them to know and to contest the logic underlying an automated processing where a decision has been taken on its foundation and produces legal effects in their regard. Art. 3's own second limb is not limited to legal effects, so a decision appraising conduct without legal effects is barred by art. 3 while falling outside the art. 23 logic right. There is no human-review right, no right to a fresh non-automated decision, and the Law carries no definition of profiling.

The Law carries no commencement article. Its final provision, art. 78, is a bare publication and execution clause — the present Law shall be published in the Journal Officiel and executed as a law of the State — and nothing in the text defers art. 3 or any other article. The date recorded here, 9 January 2015, is the date of promulgation stamped in the signature block at Antananarivo over the signature of President Rajaonarimampianina Hery Martial, and it is the date by which the Law is universally cited, including in the ILO NATLEX record. The Law is numbered for 2014 and promulgated in 2015 because it was adopted by the National Assembly in 2014 and cleared by the Haute Cour Constitutionnelle first: the preamble recites décision n° 02-HCC/D3 du 07 janvier 2015, two days before promulgation. Confidence is medium for one reason only, and it is the same reason as for Morocco, Algeria and Togo: because art. 78 attaches publication rather than force, the operative date depends on the Malagasy general publication-to-force rule, which was not verified against a primary source, and the Journal Officiel issue and date for the Law could not be established from an official source. If Malagasy law makes force turn on Journal Officiel publication rather than on promulgation, the true date is later than the one recorded here by the length of the publication lag, and the row would need amending. Art. 76 is transitional and is not a deferral of art. 3: all processing implemented before entry into force had one year from publication to conform, on a sectoral timetable fixed by the Commission and published in the Journal Officiel, a period long since closed. Art. 77 leaves application modalities to regulatory texts. The Law abrogates nothing expressly and names no predecessor statute, so nothing is superseded on the tracker. Text read end to end — all 78 articles, from the exposé des motifs to the signature block — in the edition published by the Unité de Gouvernance Digitale, the Malagasy State's digital-governance unit, which serves the full statutory text as HTML and credits CNLEGIS, the State's legislative database, as its source. No AI-specific statute or guidance is in force in Madagascar.

Stated maximum penalty — Art. 3 is not an offence, and none of the penal articles reaches it — but the administrative route does, because art. 55 is a general catch-all. Art. 55 provides that the Commission Malagasy de l'Informatique et des Libertés may pronounce against a controller, in the event of a breach of one or more of the provisions of the present Law and after a contradictory procedure, a warning, a mise en demeure, a pecuniary sanction, and the further measures the article lists, with pecuniary sanctions doubled on recidivism. Because art. 55 is drafted against "une ou plusieurs des dispositions de la présente loi" without enumeration, it reaches art. 3 on its face. Art. 59 caps the pecuniary sanction: its amount must be proportionate to the gravity of the breaches and to the advantages derived from them, and it may not exceed 5 per cent of pre-tax turnover for the last closed financial year — the same ceiling as Côte d'Ivoire, Niger and Burkina Faso, and below Guinea's 7 per cent. Art. 57 allows any sanction decision to be coupled with an injunction to make, within a time limit the Commission sets, any modification or deletion it judges useful. Art. 58 requires the sanction to rest on a report notified to the controller, who may file written and oral observations and be represented or assisted, and provides that sanction decisions may be appealed to the Conseil d'Etat. Art. 60 makes sanction decisions public, allows the identity of natural persons to be anonymised, and lets the Commission order their insertion in publications or newspapers at the sanctioned person's expense. The penal articles, by contrast, are a closed list of named offences and none of them names art. 3: art. 61 punishes obstruction of the Commission with six months to two years' imprisonment and a fine of 800,000 to 8,000,000 Ariary; art. 62 failure to observe prior formalities, six months to two years and 200,000 to 2,000,000 Ariary; art. 63 unlawful processing of sensitive data, offence files or the national identification number by reference to arts. 14, 15, 17 and 18, two to five years and 800,000 to 8,000,000 Ariary; art. 64 breach of the art. 15 security measures; art. 65 unfair collection, two to five years and 1,000,000 to 10,000,000 Ariary; art. 66 misuse of purpose; art. 67 disregard of a founded rectification or objection request; art. 68 breach of the art. 27 information duty; art. 69 breach of the art. 23 access right; art. 70 over-retention; and art. 71 disclosure harming the person's standing or private life, two to five years and 1,000,000 to 10,000,000 Ariary. Art. 72 allows erasure of the data to be ordered in any of those cases and art. 73 requires the Procureur de la République to notify the Commission's president of prosecutions.

In force · 9 Jan 2015 checked 20 Aug 2026 Loi n° 2014-038 art. 3 ↗ medium confidence

Mali 1

Mali Binding

Loi 2013-015 art. 2 — a one-limb bar, stated as a founding principle, on decisions with legal effects resting solely on computerised profiling, with no exception of any kind

Binds Responsables du traitement within the scope of arts. 4 and 5. Art. 4 applies the Law to any processing of personal data carried out wholly or partly on national territory. Art. 5 subjects to the Law any processing of personal data by the State, local authorities, personalised public bodies, natural persons and private-law legal persons; any processing implemented by a controller established on national territory or not, excluding means used only for transit on that territory; and any processing concerning public security, national defence, the investigation and prosecution of criminal offences or State security, even where linked to an important economic or financial interest of the State, subject to the derogations provided by the Law or by other texts. Art. 6 excludes processing by a natural person in the exclusive course of personal or domestic activities where the data are not intended for systematic communication to third parties or for dissemination, and temporary copies made in the course of technical transmission and access activities. Art. 57 makes declaration to the Autorité de Protection des Données à caractère Personnel a standing precondition, and provides that where that formality has been omitted in bad faith the Autorité imposes the appropriate administrative sanction assessed by reference to the gravity of the fault. The art. 2 bar binds any decision-maker whose decision induces legal effects, irrespective of size or sector. Impact tier: all entities.. Mali's automated-decision rule is not in a rights chapter at all: it is the third paragraph of art. 2, in Chapitre I of Loi n° 2013-015 du 21 mai 2013 portant protection des données à caractère personnel en République du Mali, the chapter headed "De l'objet". Article 2 opens with the founding principle that informatics must be at the service of every person and must respect human identity, human rights, private life and public and individual freedoms, states that everyone has a right to the protection of the personal data concerning them, and then provides that no decision inducing legal effects with regard to a person may be taken on the sole basis of a computerised processing intended to define the profile of the person concerned or to evaluate certain aspects of their personality. Three features make it the leanest formulation in the Francophone family. It has one limb only — there is no separate bar addressed to the courts, which every other Francophone row on the tracker carries. It states no exception whatever: there is no contract deeming clause, no consent exception, no legal-authorisation exception and no opportunity to present observations, so on its face it shares that absence with Côte d'Ivoire's art. 25 alone. And it speaks of a "traitement informatique" rather than a "traitement automatisé", which is the older French formula. The companion right sits in art. 12, in Chapitre V on the rights of persons: everyone has the right to obtain from a controller the communication, in an intelligible form, of all the data concerning them together with any available information as to their origin, and — the operative half for automated decisions — the information and the reasoning used in computerised processing whose results are relied on against them. That right is exercised free of charge, on the spot or remotely, must be answered without delay, and a copy of the data conforming to the content of the processing is delivered on request; where there is a risk of concealment or disappearance of the data the Autorité may order any appropriate measure. There is no defined term for profiling and no right to obtain human intervention or a fresh non-automated decision.

The Law contains no commencement article: Chapitre X, headed "Des dispositions finales", consists of art. 69 alone, which provides only that practical implementation matters not covered by the Law are to be supplied by deliberation of the Autorité de Protection des Données à caractère Personnel in conformity with the spirit of the Law, and the text then ends with the promulgation formula "Bamako, le 21 mai 2013" and the signature of the interim President of the Republic, Professor Dioncounda Traoré. The date recorded here is the date of the Journal officiel de la République du Mali that carries the Law: fifty-fourth year, numéro 26 of 28 June 2013, pp. 1002 to 1011, whose masthead, table of contents entry and per-page footers were read directly. That is the same basis used for Morocco, Algeria and Côte d'Ivoire. Confidence is medium for the same reason: the Malian general publication-to-force rule was not itself read against a primary source, so it could not be confirmed whether force attaches on the day of publication of the Journal officiel or after a delay. Art. 68 is transitional and not a deferral of art. 2: public services and natural or legal persons whose activity before the date of promulgation consisted, principally or incidentally, in processing personal data had a maximum of six months to conform, failing which their activities are deemed contrary to the Law and must cease without delay — a period that closed in 2013. The Law was adopted by the Assemblée nationale in its sitting of 9 May 2013. Text read in the Journal officiel itself, which is the official gazette published by the Secrétariat général du Gouvernement. Coverage symmetry against the fourteen African rows already tracked: art. 2 belongs to the Directive 95/46/EC art. 15 line but is the shortest and oldest-sounding member of it, and it is the only automated-decision provision on the tracker that sits inside a purposes-and-principles article rather than in a rights or obligations chapter. Against its neighbours: Senegal's art. 48, Morocco's and Algeria's art. 11 all carry a judicial limb and a contract deeming clause, and Mali has neither; Côte d'Ivoire's art. 25 and Niger's art. 52 carry a judicial limb and, in Côte d'Ivoire's case, no exception, so Mali and Côte d'Ivoire are the only two African rows with no exception at all, and Mali is the barer of the two because it lacks the judicial limb. Mali's art. 12 reasoning-disclosure right is, word for word in substance, the third paragraph of Niger's art. 52 — the right to know and contest the information and the reasoning used in processing whose results are relied on against the person — which puts Mali and Niger together as the only Francophone rows on the tracker with that right, though Niger states it inside the automated-decision article itself and adds an artificial-intelligence clause that Mali has nothing resembling. The four-way African lineage picture is unchanged: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, sn-loi200812-art48, ci-loi2013450-art25, ne-loi202259-art52, bj-code-num-art401 and now ml-loi2013015-art2; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — No offence reaches art. 2. Art. 58 provides that, save where the Law makes special provision in computing matters, the classification of offences and the penalties applicable to them are those defined by the Penal Code, the Code des personnes et de la famille, the electoral law and the other laws creating offences in the field of personal data protection, with procedure governed by the Code de Procédure Pénale. The Law's own two fine articles name their own conduct and neither names an automated decision. Art. 65 punishes with a fine of 5,000,000 to 20,000,000 francs the communication to unauthorised third parties of, or unauthorised or unlawful access to, personal data engaging fundamental rights, individual freedoms or private life; the diversion or any modification of the purpose of a collection or processing without the express and reasoned authorisation of the Autorité; collection by fraudulent, unfair or unlawful means, or processing of nominative information concerning a natural person despite that person's objection where the objection is founded on legitimate reasons connected to their fundamental rights or private life; automated processing of nominative personal data for health research in violation of laws and regulations; and, outside the cases provided by law, placing or keeping in computerised memory nominative data concerning offences, convictions or national security measures, that last offence applying also to non-automated or mechanographic files. Art. 66 punishes with a fine of 2,500,000 to 10,000,000 francs processing nominative information without taking all precautions to preserve its security, in particular against distortion or damage, and placing or keeping in computerised memory, without the prior agreement of the person concerned, nominative data revealing directly or indirectly racial or ethnic origins, political, philosophical or religious opinions or trade-union membership. The route that reaches art. 2 is administrative and is set out in art. 61, which lists the Law's administrative sanctions exhaustively: a warning against any good-faith controller that has not observed the administrative formalities of collection, processing and management laid down by the Law or by the Autorité's regulatory acts; a mise en demeure of the controller at fault to bring itself into conformity; an injunction to cease personal-data processing activities in case of fault; and withdrawal of the agrément where the Autorité finds it necessary. Art. 62 lets the Autorité use every technical means in its possession to secure the automatic execution of its decision; art. 63 requires administrative sanction decisions to be reasoned on pain of nullity and notified to those concerned; art. 59 confirms that the Autorité imposes the administrative and pecuniary sanctions flowing from the Law without prejudice to criminal sanctions and may institute simple-police contraventions by lawfully made regulations; art. 67 lets the Autorité settle any pecuniary sanction by transaction at the offender's request, subject to the scales fixed by law; and art. 56 lets the President of the Autorité denounce any infringing user to the Procureur de la République or bring a complaint before the competent courts. Art. 60 leaves civil actions to the Code de Procédure Civile, Commerciale et Sociale and the Régime Général des Obligations. Notably, art. 61 attaches no fine to a breach of art. 2 — the administrative list stops at withdrawal of agrément.

In force · 28 Jun 2013 checked 17 Aug 2026 Loi n° 2013-015 art. 2 ↗ medium confidence

Niger 1

Niger Binding

Loi 2022-59 art. 52 — automated individual decisions: a two-limb bar, a right to know and contest the reasoning, and an express artificial-intelligence disclosure duty at collection

Binds Responsables du traitement and sous-traitants within the scope of arts. 3 and 4. Art. 3 subjects to the Law any collection, processing, transmission, storage and use of personal data by legal persons of public or private law and by natural persons; any processing, automated or not, of personal data contained in or intended to form part of a file; and any processing concerning public security, defence, investigation and prosecution of criminal offences or State security, subject to derogations defined by the Law or other legislation in force. Art. 4 applies the Law to processing implemented by a controller or processor established on national territory and in any place where national law applies. Prior formalities are a standing precondition: art. 31 requires prior authorisation from the Haute Autorité à la Protection des Données à caractère Personnel for, among others, any processing permitting profiling or behavioural analysis, biometric processing, unique-identifier processing, interconnection of files, and transfers to third countries, and art. 79 requires every private-law legal person acting as a controller to appoint an internal data protection correspondent, with public-sector controllers appointing a point focal in that role. The first limb of art. 52 binds the courts themselves; the second binds every administrative and private decision-maker; the third and fourth paragraphs bind any controller whose results are relied on against a person, and the fourth bites at the moment of collection wherever the processing falls within artificial intelligence. Impact tier: all entities.. Article 52 of Loi n° 2022-59 du 16 décembre 2022 relative à la protection des données à caractère personnel, headed "Décision individuelle basée sur le traitement automatisé", is Niger's operative automated-decision rule and the richest of the Directive-family provisions tracked in Africa. It has five paragraphs. The first bars any judicial decision involving an appraisal of the conduct of a natural person from having as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality. The second bars any administrative or private decision involving an appraisal of human conduct from having as its sole foundation an automated processing of personal data giving a definition of the profile or the personality of the person concerned. The third creates a free-standing right: every person has the right to know and to contest the information and the reasoning used in processing, automated or not, whose results are relied on against them. The fourth is the artificial-intelligence clause, which Niger shares only with art. 19 of Burkina Faso's Loi n° 001-2021/AN and with no other row on the tracker — where that processing falls within artificial intelligence, the criteria and the nature of the personal data on which the processing is founded must be indicated to the person from the point of collection. The fifth supplies the exceptions: an automated individual decision is nevertheless admitted where it is founded on the explicit consent of the person concerned, necessary to the conclusion or performance of a contract between the person concerned and a controller, or authorised by a legislative or regulatory provision. Unlike Morocco, Algeria and Côte d'Ivoire, Niger defines profiling: art. 1 defines it as any automated processing of personal data with a view to evaluating certain personal aspects relating to a natural person, in particular to analyse or predict elements concerning work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Art. 31 separately subjects any processing permitting profiling or behavioural analysis to prior authorisation by the HAPDP. The Law grants no right to obtain human intervention or a fresh non-automated decision.

Supersession: art. 112 of Loi n° 2022-59 abrogates all prior contrary provisions and names in particular Loi n° 2017-28 du 3 mai 2017 relative à la protection des données à caractère personnel as modified by Loi n° 2019-71 du 24 décembre 2019. Loi 2017-28 is therefore no longer the operative Nigerien instrument and is not tracked. Art. 112 combines abrogation and publication in a single article — the Law "est publiée au Journal Officiel de la République du Niger et exécutée comme loi de l'Etat" — and there is no commencement article and no deferral of art. 52. The date recorded here is the date of promulgation printed on the face of the enacted text: "Fait à Niamey, le 16 décembre 2022", signed by the President of the Republic Mohamed Bazoum and countersigned by the Prime Minister Ouhoumoudou Mahamadou, with an ampliation by the Deputy Secretary-General of the Government. Confidence is medium and the reason is narrower than for Morocco, Algeria and Côte d'Ivoire, where the general publication-to-force rule was the only unverified link: here the date of the Journal officiel de la République du Niger that carries the Law could not be established at all, because no Nigerien official-gazette host resolved this run — sgg.gouv.ne, www.sgg.gouv.ne, journal-officiel.ne and assemblee.ne all fail to resolve — so the entry uses the promulgation date, and the true entry into force can only be that date or later. Art. 111, replaced by Ordonnance n° 2024-16 du 26 avril 2024, is transitional and not a deferral of art. 52: already-created processing operations carried out for the State, a public establishment, a local authority or a private-law body managing a public service are notified to the HAPDP, and from the date of entry into force all processing must meet the Law's prescriptions on pain of its sanctions. The text was read twice over: article by article in the enacted, signed forty-six-page copy of Loi n° 2022-59 published by the HAPDP, in which art. 52 was read directly on p. 27, and against the HAPDP's own April 2026 consolidated version, which integrates Loi n° 2023-31 du 4 juillet 2023, Ordonnance n° 2024-16 du 26 avril 2024 and Ordonnance n° 2024-29 du 24 juin 2024 and marks amended articles "(nouveau)". Art. 52 is not so marked and is identical in both, so no amendment has touched it; the consolidation renumbers the enacted art. 112 into arts. 112 and 113. The consolidated document states on its face that it is provided for information only and does not replace the official texts published in the Journal officiel, which is why the enacted copy is cited as the source. Coverage symmetry against the eleven African rows already tracked: art. 52 belongs to the Directive 95/46/EC art. 15 line that reaches West Africa through art. 42 of the ECOWAS Supplementary Act A/SA.1/01/10, which the Law's preamble expressly cites alongside the African Union Convention on Cyber Security and Personal Data Protection. Its first two paragraphs are word-for-word the two limbs of Côte d'Ivoire's art. 25, which makes those two the closest pair in Africa, but Niger then goes considerably further in both directions. It is stronger, because it adds the right to know and contest the information and reasoning relied on — a right Côte d'Ivoire lacks entirely and Morocco has only in the narrower art. 7(c) form — and because it names artificial intelligence and attaches a disclosure duty to it at the point of collection. That artificial-intelligence clause is not unique to Niger: art. 19 of Burkina Faso's Loi n° 001-2021/AN du 30 mars 2021 carries it in materially identical words, and Burkina Faso's Law predates Niger's by twenty months, so Burkina Faso is the source of the drafting and Niger the follower. Burkina Faso goes one step further still, because its art. 31 subjects predictive-artificial-intelligence decision-support processing to prior authorisation, which Niger does not. It is weaker, because Côte d'Ivoire states no exception at all while Niger admits explicit consent, contract and legal authorisation, which is the GDPR art. 22(2) exception set grafted onto a Directive-era bar. The four-way African lineage picture is unchanged: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, ci-loi2013450-art25 and now ne-loi202259-art52; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — Niger is the first Directive-family row on the tracker where a penal article does reach part of the automated-decision provision, and the reach is partial. Art. 102 punishes obstructing without legitimate reason the exercise of a right conferred by the Law in the course of a processing of personal data with imprisonment of three months to two years and a fine of 1,000,000 to 20,000,000 francs CFA, or one of those penalties only. The third paragraph of art. 52 confers a right on the person — to know and contest the information and reasoning used — so art. 102 reaches a refusal of that right. The first two paragraphs of art. 52 are prohibitions on the decision-maker rather than rights of the person, and no offence in Chapitre XIV names them: arts. 95 to 104 are confined to unlawful sensitive-data processing (three months to five years and 5,000,000 to 50,000,000), unconsented direct marketing (three months to three years and 1,000,000 to 10,000,000), obstruction of the HAPDP (three months to two years and 1,000,000 to 10,000,000), failure to take security precautions (three months to two years and 1,000,000 to 10,000,000), purpose deviation (three months to five years and 5,000,000 to 50,000,000), unauthorised communication of or access to files (three months to five years and 5,000,000 to 50,000,000), fraudulent, unfair or unlawful collection (three months to five years and 5,000,000 to 50,000,000), unlawful retention beyond the permitted period (three months to two years and 5,000,000 to 50,000,000) and unauthorised divulgation harming honour or privacy (three months to five years and 5,000,000 to 50,000,000, reduced to a fine of 500,000 to 1,000,000 where committed by imprudence or negligence). Art. 105 applies Penal Code arts. 59 to 61 on recidivism, and art. 106 lets the court order confiscation or erasure of the media carrying the data, ban the convicted controller from managing any processing for up to two years, and order publication of extracts in legal-notice journals at the convicted person's expense. The administrative route reaches the whole of art. 52. Art. 92 lets the HAPDP, after an adversarial procedure, issue a warning and a mise en demeure to end the failures within a period it fixes, and, if the controller does not comply, pronounce provisional or definitive withdrawal of the authorisation or a pecuniary sanction. Art. 93 lets it order interruption of the processing, blocking of certain data, or temporary or definitive prohibition of a processing contrary to the Law. Art. 94 fixes the ceiling: the pecuniary sanction is proportionate to the gravity of the failures and the advantages drawn from them and may not exceed 100,000,000 francs CFA, rising on a repeated failure within two years from the date the previous pecuniary sanction became definitive to 200,000,000 francs CFA or, for an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of 500,000,000 francs CFA, and applies without prejudice to penal sanctions. Art. 108 lets any person who claims to be injured in their private life by a processing, or whose complaint to the controller has gone unanswered, complain to the HAPDP; art. 109 makes the HAPDP's sanctions and decisions appealable to the Conseil d'Etat; and art. 110 preserves an effective judicial remedy, including urgent interim relief under astreinte where the infringement is serious and immediate.

In force · 16 Dec 2022 checked 20 Aug 2026 Loi n° 2022-59 art. 52 ↗ medium confidence

Nigeria 1

Nigeria Binding

Nigeria Data Protection Act s. 37 — right against solely-automated decisions, with a duty to provide human intervention on request

Binds Data controllers and data processors within the scope of s. 2(2): those domiciled in, resident in, or operating in Nigeria; any processing of personal data that occurs within Nigeria; and controllers or processors not domiciled, resident or operating in Nigeria that process personal data of a data subject in Nigeria. Section 2(1) applies the Act to processing whether by automated means or not, and s. 3(1) carves out processing carried out solely for personal or household purposes. The s. 37 right binds any controller taking a solely-automated decision with legal or similar significant effect, irrespective of size. A narrower registration and governance tier sits above it: a data controller or data processor “of major importance” — defined in s. 65 as one domiciled, resident or operating in Nigeria that processes personal data of more than such number of data subjects in Nigeria as the Commission may prescribe, or such other class the Commission may designate as processing data of particular value or significance to the economy, society or security of Nigeria — must register with the Commission under s. 44(1) within six months after the commencement of the Act or on becoming one, and must designate a Data Protection Officer under s. 32(1). Impact tier: all entities.. Section 37 of the Nigeria Data Protection Act, 2023 (Act No. 37 of 2023) carries Nigeria's operative automated-decision rule, in Part VI (rights of a data subject). Subsection (1) gives a data subject the right not to be subject to a decision based solely on automated processing of personal data, including profiling, which produces legal or similar significant effects concerning the data subject. Subsection (2) disapplies that right where the decision is necessary for entering into or the performance of a contract between the data subject and a data controller, is authorised by a written law which establishes suitable measures to safeguard the fundamental rights and freedoms and the interests of the data subject, or is authorised by the consent of the data subject. Subsection (3) is the operative duty on the controller: where an exception is relied on, the data controller shall implement suitable measures to safeguard the data subject's fundamental rights, freedoms and interests, including the rights to obtain human intervention on the part of the data controller, to express the data subject's point of view, and to contest the decision. Section 65 defines “automated decision-making” as a decision based solely on automated processing by automated means, without any human involvement. Section 36(3) separately gives a right to object at any time to processing for direct marketing purposes, which includes profiling to the extent that it is related to such direct marketing, and s. 36(4) requires processing for those purposes to stop on objection.

Commencement is stated on the face of the enacted Act: the gazetted text prints “[12th Day of June, 2023]” immediately above the enacting formula, and s. 37 carries no deferred or separately-appointed commencement, so the section has been in force since 12 June 2023. The Act was published by The Federal Government Printer, Lagos as a supplement to the Federal Republic of Nigeria Official Gazette No. 119, Vol. 110 of 1 July 2023, Government Notice No. 82, as Act No. 37, at pages A719 to A758. Section 37 follows the GDPR Art. 22 shape and is the closest of the tracker's three African provisions to it: unlike the South African za-popia-s71, which offers only representations plus disclosure of the underlying logic, Nigeria expressly grants human intervention, the right to express a point of view and the right to contest the decision; unlike the Kenyan ke-dpa-s35 it imposes no affirmative written-notification duty when a solely-automated decision is taken, and confers no express right to demand a fresh non-automated decision. Source access: the Nigeria Data Protection Commission is the statutory supervisory authority established by s. 4 of the Act and ndpc.gov.ng is the only official host that serves the Act text, but the host returns HTTP 403 (nginx, not a challenge page) to every non-browser client from this network, on the apex domain and on every subdomain except the services portal; nass.gov.ng's publications register does not carry the Act, and nigeriagazette.gov.ng does not resolve. The text cited here was therefore read from the Internet Archive's byte-for-byte capture of the NDPC-hosted gazette PDF at the source_url (capture of 31 May 2025, origin Last-Modified 1 March 2024): https://web.archive.org/web/20250531105744/https://ndpc.gov.ng/wp-content/uploads/2024/03/Nigeria_Data_Protection_Act_2023.pdf. No secondary or NGO copy was relied on. Not yet verified: the NDPC General Application and Implementation Directive 2025 (issued 20 March 2025) may add implementation detail on automated decision-making; every archived capture of it replays 503, so it is excluded from this entry and left for a later check.

Stated maximum penalty — Section 48 governs sanctions. After an investigation under s. 46, the Commission may order the controller or processor to remedy the violation, to compensate a data subject who has suffered injury, loss or harm, to account for the profits realised from the violation, or to pay a penalty or remedial fee (s. 48(2)). Under s. 48(3)–(5) that penalty may be up to the “higher maximum amount” for a data controller or data processor of major importance, being the greater of ₦10,000,000 and 2% of its annual gross revenue in the preceding financial year, or the “standard maximum amount” for one not of major importance, being the greater of ₦2,000,000 and 2% of that revenue. Failure to comply with a compliance order made under s. 47 is a separate offence under s. 49, punishable on conviction by a fine of up to the same higher or standard maximum amount, or imprisonment for a term not more than one year, or both. Section 51 gives a data subject who suffers injury, loss or harm a civil action for damages, and s. 50 allows an application to court for judicial review of a Commission order within 30 days.

In force · 12 Jun 2023 checked 22 Aug 2026 NDPA s. 37 (Act No. 37 of 2023) ↗ high confidence

Peru 1

Peru Comprehensive

AI Law 31814 + Reglamento — risk-based regime

Binds Public and private AI developers / deployers. Prohibited / high-risk / acceptable tiers; high-risk AI needs prior evaluation, human oversight and transparency.

Stated maximum penalty — Referral to data-protection / Indecopi

In force · 22 Jan 2026 checked 20 Aug 2026 Ley 31814 + DS 115-2025-PCM ↗ high confidence

Philippines 1

Philippines Binding

Data Privacy Act IRR Secs. 34 and 48 — automated decision-making: logic disclosure, NPC notification and the consent bar

Binds Personal information controllers and personal information processors within the scope of the Act and Rule II of the IRR, including entities not established in the Philippines that use equipment located in the country or maintain an office, branch or agency here. The Section 48 notification duty binds any controller whose automated processing becomes the sole basis for a decision significantly affecting a data subject; the Section 34 transparency and objection rights bind all controllers. Impact tier: all entities.. The Implementing Rules and Regulations of Republic Act No. 10173 (Data Privacy Act of 2012) carry the Philippines' operative automated-decision regime. Section 34 gives the data subject a right to be informed whether personal data are processed 'including the existence of automated decision-making and profiling', and requires the controller to furnish, before entry of the data into the processing system or at the next practical opportunity, the methods used for automated access together with 'meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject' (Sec. 34(a)(f)); the same section carries a right to object to processing 'including processing for direct marketing, automated processing or profiling', and a right of access to 'information on automated processes where the data will, or is likely to, be made as the sole basis for any decision that significantly affects or will affect the data subject'. Section 48 adds a filing duty and a substantive bar: a controller carrying out wholly or partly automated processing operations must notify the National Privacy Commission once the automated processing becomes the sole basis for making decisions about a data subject and the decision would significantly affect that subject, submitting the purpose of processing, the categories of data and data subjects, the consent forms or manner of obtaining consent, the recipients, the retention period, the 'methods and logic utilized for automated processing', the decisions that would be made on the basis of the processed data or that would significantly affect the rights and freedoms of the data subject, and the name and contact details of the data protection officer; and 'no decision with legal effects concerning a data subject shall be made solely on the basis of automated processing without the consent of the data subject'. Section 16(c)(6) of the Act itself carries the statutory root of the access right.

Commencement is computed from the face of the instrument. IRR Section 72 provides that the Rules take effect fifteen days after publication in the Official Gazette; the Rules were promulgated by the National Privacy Commission on 24 August 2016 and published in the Official Gazette on 25 August 2016, which places entry into force on 9 September 2016. IRR Section 67 gave controllers one year from that date to register their data processing systems or automated processing operations subject to notification, so that window closed on 9 September 2017 and the Section 48 duty is now fully exigible. The parent statute, Republic Act No. 10173, was approved on 15 August 2012 and took effect fifteen days after newspaper publication under its Section 45. Note the division of labour between statute and rules: RA 10173 Sec. 16(c)(6) grants only access to information on automated processes used as the sole basis for a significant decision, while the consent bar on solely-automated decisions with legal effects and the meaningful-information-about-the-logic requirement appear only in the IRR, at Secs. 48 and 34 respectively. Asian peer of cn-pipl-art24, kr-pipa-art37-2-adm and id-uu27-adm: like Indonesia and Korea it is already in force, and like Korea it reaches the logic of the decision, but unlike Korea it grants no express right to human re-processing — the Philippine mechanism is a consent gate plus a regulator filing rather than a post-hoc review right. Text read at the National Privacy Commission's own publication of the IRR and cross-checked against the Supreme Court E-Library copy (elibrary.judiciary.gov.ph/thebookshelf/showdocs/2/70735), which carries the identical Secs. 34, 48, 67 and 72. officialgazette.gov.ph returns HTTP 403 to non-browser clients, so the NPC copy is cited.

Stated maximum penalty — IRR Section 65 subjects violations of the Act, the Rules and Commission issuances to compliance and enforcement orders, cease and desist orders, a temporary or permanent ban on processing, or fines under a schedule published by the Commission. That schedule is NPC Circular No. 2022-01 (Guidelines on Administrative Fines, 8 August 2022): each infraction of a data subject right under Sec. 16 of the DPA affecting more than 1,000 data subjects is a grave infraction carrying 0.5 per cent to 3 per cent of the annual gross income of the preceding year, and 1,000 or fewer affected subjects is a major infraction carrying 0.25 per cent to 2 per cent, with total administrative fines capped at PHP 5,000,000. Criminal liability under Chapter VIII of the Act runs separately for the enumerated offences, for example unauthorised processing of personal information at one to three years' imprisonment and a fine of PHP 500,000 to PHP 2,000,000 under Sec. 25(a).

In force · 9 Sep 2016 checked 21 Aug 2026 DPA of 2012 IRR Secs. 34, 48 (RA 10173) ↗ high confidence

Russia 1

Russia Binding

243-FZ art. 8 — three developer duties that attach only once a model takes sovereign or national status

Binds Russian individual entrepreneurs and legal persons that develop, design, train or modify a large foundational AI model within art. 3(5) and whose model has been granted sovereign and (or) national status under the procedure art. 6(5) leaves to the Government. Developers of large foundational models without that status, and foreign developers, are outside art. 8. The separate power in art. 5(2)(3) for the Government to designate cases in which only sovereign and (or) national models may be applied — for banking and other financial-market spheres in agreement with the Central Bank — is what can make the status commercially necessary rather than optional in a given sector.. Art. 8 is the closest thing Russian law has to a foundation-model developer obligation, and its chapeau is what decides how far it reaches: the duties are imposed on «разработчик суверенной и (или) национальной больших фундаментальных моделей искусственного интеллекта» — the developer of a sovereign and (or) national large foundational model — and not on developers generally. Sovereign and national status is conferred, not assumed: art. 6(5) leaves the Government to set the procedure for recording models and assigning the status, art. 6(2) makes a sovereign model one whose developer is a Russian legal person, whose development and characteristics are determined by that Russian legal person across the whole lifecycle, whose development cycle including training is fully technically reproducible, whose user queries are answered and whose data are stored in data centres located in Russia and belonging to Russian legal persons, and which has passed confirmation of conformity with Russian legislation and with traditional Russian spiritual and moral values in a procedure to be established by the Government; art. 6(3) defines a national model on similar lines but requires only that the Government-specified essential characteristics be determined by the Russian developer and that externally sourced components, including other developers' models, be distributed under an open licence. Art. 6(4) supplies the control test for what counts as a Russian legal person, at more than fifty per cent of the votes. Against that background art. 8 requires the status-holding developer to take organisational and technical measures to secure the model, to define rules of operation setting the limits and conditions of its application, updating and decommissioning, and to keep technical documentation describing the model's key parameters and limitations to the extent needed to assess the safety of its application. The duties are the counterpart of the art. 7 package of state support, access to state data sets for training under art. 5(2)(5) and the art. 10(2) training exception, so in substance this is a conditional regime a developer opts into rather than a horizontal safety obligation of the EU AI Act general-purpose kind. The consequence worth recording is the negative one: a developer of a large foundational model that does not hold either status carries none of the art. 8 duties.

Art. 8 is deferred by art. 13(2) to 1 March 2027, together with art. 9, art. 10, art. 5(2) points 3 to 5 and art. 6 parts 2 to 5, even though art. 13(1) puts the Law itself in force on 1 September 2026. Two further timing points sit on the face of the Law. The conformity-confirmation procedure required by art. 6(2)(5) and art. 6(3)(5) and the status-assignment procedure required by art. 6(5) are both left to Government acts that had not been made as at 21 August 2026, so the gateway to art. 8 is not yet operable. And art. 13(3) grandfathers information systems in which large foundational models were created or operated on the day art. 5(2)(3) commences: until 1 September 2032 the cases where only sovereign or national models may be applied do not extend to them, provided the data are processed and stored in Russia. Adopted 8 July 2026, approved by the Federation Council 17 July 2026, published 26 July 2026 as 0001202607260003, Собрание законодательства РФ 2026 No. 30 item 4089, «Российская газета» of 31 July 2026.

Stated maximum penalty — None is stated in the Law. Art. 11 refers to «законодательство Российской Федерации» without more, and the Code of Administrative Offences carried no article on large foundational AI models as at 21 August 2026. The practical sanction visible on the face of the Law is administrative rather than pecuniary: sovereign and national status is assigned and recorded by the Government under art. 6(5), so the loss of that status, and with it the art. 7 support measures, the art. 5(2)(5) access to state data sets for training and the art. 10(2) training exception, is what a failure of the art. 8 duties puts at risk.

Applies 1 Mar 2027 checked 21 Aug 2026 243-FZ art. 8 ↗ high confidence

Rwanda 1

Rwanda Binding

Law No. 058/2021 art. 21 — right not to be subject to a decision based on automated data processing

Binds Data controllers, data processors and third parties within the scope of art. 2: those established or residing in Rwanda and processing personal data while in Rwanda, and those neither established nor resident in Rwanda that process the personal data of data subjects located in Rwanda. Article 2 reaches processing of personal data by electronic or other means through an automated or non-automated platform. Registration with the supervisory authority is a standing precondition of acting as a controller or processor: arts. 29 to 36 govern registration, the registration certificate, its renewal, modification and cancellation, and the register itself, and operating without a registration certificate is an administrative misconduct under art. 54. The art. 21 right binds any controller taking a solely-automated decision with legal or significant consequences, irrespective of size. The National Cyber Security Authority is the designated supervisory authority. Impact tier: all entities.. Article 21 of Law Nº 058/2021 of 13/10/2021 relating to the protection of personal data and privacy carries Rwanda's operative automated-decision rule, in Chapter III (rights of the data subject). Its first paragraph gives the data subject the right not to be subject to a decision based solely on automated personal data processing, including profiling, which may produce legal consequences or significant consequences to him or her. The second paragraph disapplies that right where the decision is based on the explicit consent of the data subject, is necessary for entering into or performance of a contract between the data subject and the data controller, or is authorised by Laws to which the data controller is subject and which also put in place suitable measures to safeguard the data subject's rights, freedoms and legitimate interests. The third paragraph adds a free-standing limit that binds even inside those exceptions: any automated processing of personal data intended to evaluate certain personal aspects relating to a natural person does not base on sensitive personal data unless one of the grounds in art. 10 is met. Article 3 supplies the definitions that give the rule its reach — item 11° defines profiling as a form of automated processing used to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements; item 8° defines legal consequences as consequences that negatively affect a person's legal status or legal rights; and item 7° defines significant consequences as consequences having an impact as significant as legal effects that negatively affect the behaviour and choices of a data subject. Two adjacent duties attach to the same processing: art. 14 requires the controller to disclose to the data subject the existence of automated decision making, including profiling, together with information about the logic involved and the significance and envisaged consequences of the processing, and art. 45 makes a personal data protection impact assessment mandatory where there is a systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing of personal data, including profiling, on which decisions producing effects concerning such persons are based.

Commencement is stated on the face of the Law and needs no separate instrument: art. 70 provides that the Law comes into force on the date of its publication in the Official Gazette of the Republic of Rwanda, and it was published in Official Gazette nº Special of 15/10/2021, so art. 21 has been in force since 15 October 2021. Article 67 gave a controller or processor already in operation a period not exceeding two years from that publication date to conform its operations to the Law; that transitional window closed on 15 October 2023 and does not defer art. 21 itself. Article 66 lets the competent organ, in collaboration with the supervisory authority, put in place regulations; no regulation specific to automated decision-making has been issued. Coverage symmetry against the four African rows already tracked: art. 21 is a standing prohibition in the GDPR art. 22 shape, like ke-dpa-s35 and ng-ndpa-s37 and unlike the notice-based gh-dpa-s41, but its remedy is the thinnest of the five — where Nigeria's s. 37(3) expressly grants human intervention, the right to express a point of view and the right to contest, and Kenya's s. 35(3)-(4) grants written notification plus reconsideration or a fresh non-automated decision, Rwanda's art. 21 sets out only the right and its exceptions and prescribes no safeguard measures inside the exceptions at all. It carries no hard deadline; the thirty-day and sixty-day clocks in arts. 19, 20 and 22 attach to objection, portability and restriction, not to art. 21. Its distinctive addition is the art. 21 third-paragraph bar on grounding evaluative automated processing in sensitive personal data, which none of the four peers has. Text read in the Official Gazette as published by the National Cyber Security Authority, the supervisory authority designated under the Law; the English, French and Ikinyarwanda columns of the gazette were read together and agree.

Stated maximum penalty — There is no offence specific to art. 21. Enforcement runs through Chapter VIII. Under art. 54 a listed administrative misconduct — including processing personal data contrary to the Law, operating without a registration certificate, failure to designate a personal data protection officer and the breach-notification failures — carries an administrative fine of not less than RWF 2,000,000 and not more than RWF 5,000,000, or one per cent of the global turnover of the preceding financial year, and for a corporate body or legal entity one per cent of that global turnover; the same article lets the supervisory authority make regulations determining further administrative misconducts and sanctions. The criminal tier in arts. 56 to 61 is narrower and does not name automated decision-making: art. 56 punishes accessing, collecting, using, offering, sharing, transferring or disclosing personal data contrary to the Law with one to three years' imprisonment and a fine of RWF 7,000,000 to RWF 10,000,000, or one of those penalties, and art. 60 punishes collecting or processing sensitive personal data contrary to the Law with seven to ten years' imprisonment and a fine of RWF 20,000,000 to RWF 25,000,000, or one of those penalties. Article 62 sets the corporate penalty for any of the arts. 56 to 61 offences at 5% of the annual turnover of the preceding financial year, and art. 63 lets the court order seizure or confiscation of the objects used and the proceeds gained, and permanent or temporary closure of the entity or premises. Article 65 gives a person who suffers serious damage from a controller's or processor's breach a claim for compensation before the competent court.

In force · 15 Oct 2021 checked 20 Aug 2026 Law No. 058/2021 art. 21 ↗ high confidence

Senegal 1

Senegal Binding

Loi 2008-12 art. 48 — no decision with legal effects on the sole basis of automated profiling, and no judicial appraisal of conduct founded on one at all

Binds Responsables du traitement within the scope of art. 2, which subjects to the Law any collection, processing, transmission, storage and use of personal data by a natural person, by the State, by local authorities or by legal persons of public or private law; any processing, automated or not, of data contained in or intended to form part of a file, save the processing excluded by art. 3; any processing implemented by a controller on Senegalese territory or in any place where Senegalese law applies; and any processing implemented by a controller, established in Senegal or not, that resorts to means of processing situated on Senegalese territory, excluding means used only for transit. In that last case the controller must designate a representative established on Senegalese territory, without prejudice to actions that may be brought against the controller itself. Prior formalities are a standing precondition: declaration to the Commission de Protection des Données Personnelles is the default, art. 20 puts health, offence, interconnection, national-identifier, biometric and public-interest processing under prior authorisation, and art. 21 requires a regulatory act taken after the reasoned opinion of the Commission for State, public-establishment, local-authority and public-service processing touching State security, defence, public safety, criminal enforcement, the population census and sensitive data. The first paragraph of art. 48 binds the courts themselves; the second binds any controller taking a decision with legal effects, irrespective of size or sector. Impact tier: all entities.. Article 48 of Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel is Senegal's operative automated-decision rule. It sits in Chapitre III among the substantive processing obligations, between the direct-marketing prohibition in art. 47 and the cross-border-transfer regime in art. 49, and it has three paragraphs. The first is absolute and addressed to the courts: no judicial decision involving an appraisal of a person's conduct may have as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality — there is no consent, contract or safeguards exception to this limb. The second is the general rule: no decision producing legal effects with regard to a person may be taken on the sole basis of an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third supplies the only relief and operates by deeming rather than by exemption: decisions taken in the course of the conclusion or the performance of a contract and for which the person concerned has been put in a position to present their observations, and decisions satisfying the requests of the person concerned, are not regarded as taken on the sole basis of an automated processing. The Law carries no definition of profiling, no right to know the logic underlying an automated processing — the art. 58 information list stops at identity, purposes, categories, recipients, whether answering is compulsory, the right to be removed from the file, the existence of access and rectification rights, the retention period and any envisaged foreign transfers — and no right to obtain human intervention or a fresh non-automated decision. The safeguard it names is an opportunity to present observations, and it exists only inside the contractual deeming clause.

The Law contains no commencement article and, in the copy published by the Commission de Protection des Données Personnelles, no publication clause either: the text runs from the exposé des motifs to art. 78, which reserves the application measures for the digitised national identity card to a separate regulation, and stops there. The date recorded is therefore the date the Law itself bears, 25 January 2008. Confidence is medium, and for a reason one step weaker than Morocco's and Algeria's: not only was the Senegalese general publication-to-force rule not read against a primary source, but the date of the Journal officiel de la République du Sénégal carrying the Law could not be established at all, because no Senegalese gazette host resolved this run — jo.gouv.sn and www.jo.gouv.sn both fail to resolve over http and https. Entry into force can therefore only be that date or later. Art. 77 is transitional and not a deferral of art. 48: from the date of entry into force, processing operations carried out for the State, a public establishment, a local authority or a private-law body managing a public service had two years to conform and all other processing had one year, periods that closed in 2010 and 2009 respectively; art. 76 subjects already-created public-sector processing to declaration only, under art. 18. Décret n° 2008-721 du 30 juin 2008 was taken for the application of the Law; no date claim is drawn from it here. Supersession: the CDP's own legislation index, checked this run, still carries Loi n° 2008-12 as the governing statute, with no amending or replacing instrument listed. Text read end to end in the copy published by the CDP, the independent administrative authority created by art. 5 of the Law; the CDP serves that copy from its own signed document store, and the entry cites the CDP legislation page because the storage link is a time-limited signed URL. Coverage symmetry against the twelve African rows already tracked: art. 48 belongs to the Directive 95/46/EC art. 15 line, and within that family Senegal is the closest match to Morocco's art. 11 and Algeria's art. 11 anywhere in Africa — the three share the same three-paragraph shape, the same absolute judicial limb, the same legal-effects threshold on the second limb, and the same contractual deeming clause conditioned on an opportunity to present observations. That makes the Francophone family split cleanly in two: Senegal, Morocco and Algeria keep the Directive's own drafting, while Côte d'Ivoire's art. 25 and Niger's art. 52 take the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting, in which the second limb reaches any administrative or private decision appraising human conduct and the legal-effects threshold disappears. Senegal predates the Supplementary Act by two years, which is consistent with that split. The four-way African lineage picture is unchanged: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, ci-loi2013450-art25, ne-loi202259-art52 and now sn-loi200812-art48; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — Senegal is the only row on the tracker whose data-protection statute creates no offences of its own. Art. 75, the whole of Chapitre VI, provides that infringements of the Law's provisions are laid down and punished by the Penal Code and by the law relating to cybercrime — Loi n° 2008-11 du 25 janvier 2008 sur la cybercriminalité, adopted the same day — so no penalty figure can be attributed to art. 48 from the data-protection statute itself, and none is asserted here. The route that reaches art. 48 within the Law is administrative and runs through the Commission de Protection des Données Personnelles. Art. 29 lets the Commission issue a warning to a controller that does not respect the obligations arising under the Law and a formal notice (mise en demeure) to end the failures within a period it fixes. Art. 30 provides that if the controller does not comply with the formal notice the Commission may, after an adversarial procedure, pronounce provisional withdrawal of the authorisation granted for three months, at the expiry of which the withdrawal becomes definitive, and a pecuniary fine of 1,000,000 to 100,000,000 francs CFA, recovered under the legislation on recovery of State debts. Art. 31 adds an urgency power where the implementation of a processing or the exploitation of personal data entails a violation of rights and freedoms: after an adversarial procedure the Commission may order interruption of the processing for a maximum of three months, blocking of certain processed data for a maximum of three months, or temporary or definitive prohibition of a processing contrary to the Law. Art. 32 makes the Commission's sanctions and decisions appealable to the Conseil d'Etat. Arts. 25 to 28 supply the inspection powers, exercisable on professional premises under the Code de Procédure Pénale with the Procureur de la République informed in advance, requiring authorisation from the President of the Regional Court where the occupier objects, and recorded in an adversarial procès-verbal.

In force · 25 Jan 2008 checked 20 Aug 2026 Loi n° 2008-12 art. 48 ↗ medium confidence

Togo 1

Togo Binding

Loi 2019-014 art. 27 — a judicial limb, a legal-effects limb and a contract carve-out: the Directive 95/46 shape, not the wider ECOWAS one

Binds Responsables du traitement within the scope of art. 2, which subjects to the Law any collection, processing, transmission, storage and use of personal data by a natural person, the State, local authorities or legal persons of public or private law; any processing, automated or not, of data contained in or intended to form part of a file; any processing implemented by a controller on Togolese territory or anywhere Togolese law applies; any processing by a controller established or not in Togo that resorts to means of processing situated on Togolese territory other than for mere transit; and any processing concerning public security, defence, investigation and prosecution of criminal offences or State security, subject to the Law's own derogations. Art. 3 excludes processing by a natural person in the exclusive course of personal or domestic activities where the data are not intended for systematic communication to third parties or dissemination, and temporary copies made in the technical activities of transmission and network access. The formalities are graduated: art. 5 dispenses some processing entirely, art. 6 makes declaration to the Instance de protection the default and provides that only receipt of the récépissé confers the right to implement the processing, art. 7 lets the Instance publish simplified or exempting norms, art. 8 requires prior authorisation for six categories — genetic data and health research, offence and conviction data, file interconnection, national identification numbers, biometric data and public-interest processing — and art. 9 requires a reasoned opinion before regulatory acts for State, public-establishment and public-service processing. Profiling and automated decision-making appear in none of the art. 8 authorisation categories, so unlike Burkina Faso and Niger, Togo imposes no ex ante gate on the processing art. 27 governs. The art. 27 bar binds the courts under its first limb and every decision-maker taking a decision producing legal effects under its second, irrespective of size or sector. Impact tier: all entities.. Article 27 of Loi n° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel is Togo's operative automated-decision rule. It is headed "Du fondement d'une décision de justice" and sits in Chapitre III on the rights of the data subject, between the art. 26 direct-marketing prohibition and the art. 28 cross-border-transfer article, in three unnumbered paragraphs. The first: no judicial decision involving an appraisal of a person's conduct may have as its sole foundation an automated processing of personal data intended to evaluate certain aspects of their personality. The second: no decision producing legal effects with respect to a person may be taken on the sole foundation of an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third is a deeming carve-out: decisions taken in the context of the conclusion or the performance of a contract, and for which the data subject has been put in a position to present their observations, and decisions satisfying the data subject's requests, are not taken on the sole foundation of an automated processing. Two features place Togo away from its Francophone West African neighbours and alongside Morocco and Algeria. First, the second limb is drafted on the Directive 95/46/EC art. 15 model — its trigger is a decision producing legal effects — and not on the wider ECOWAS Supplementary Act model used by Côte d'Ivoire, Burkina Faso and Niger, whose second limb reaches any administrative or private decision appraising human conduct whatever its effects. Second, the judicial limb carries the word "seul": unlike Côte d'Ivoire's art. 25, Burkina Faso's art. 15 and Guinea's art. 27, a Togolese judicial decision is barred only where the automated processing is its sole foundation. Togo does supply the exception clause that Côte d'Ivoire, Mali and Burkina Faso omit, and it is the Moroccan and Algerian one: contract decisions with an opportunity to present observations, plus decisions satisfying the data subject's own requests. The Law creates no right to know the logic of an automated processing — the art. 39 access right runs to information enabling the data subject to know and to contest the processing, confirmation, communication of the data and their origin, purposes, categories, recipients and envisaged transfers, and nothing more — and no right to obtain human intervention or a fresh non-automated decision. The Law carries no definition of profiling.

Art. 97, the final article, is a bare execution clause — "La présente loi est exécutée comme loi de l'Etat" — and the Law contains no commencement article and defers nothing. The date recorded here, 29 October 2019, is the date carried in the Law's own title and citation and is also the date of the Journal officiel de la République togolaise, 64e année, n° 26 ter, in which it was published. Confidence is medium, and the reason is specific and is recorded here rather than smoothed over: the signature block of the enacted text reads "Fait à Lomé, le 30 octobre 2019" over the signatures of President Faure Essozimna Gnassingbé and Prime Minister Selom Komi Klassou, one day AFTER the date of the gazette issue that carries it. The discrepancy is on the face of the gazette itself and is consistent with the Togolese practice of numbered "ter" special issues, but it means the promulgation date and the publication date cannot both be right as printed, and the Togolese general publication-to-force rule was not read against a primary source either, so it could not be confirmed whether force attaches on publication or after a jour franc. Anyone relying on a one-day margin around 29-30 October 2019 should read the gazette page directly. Art. 96 abrogates all prior contrary provisions but names no statute, so no predecessor is superseded on the tracker. Art. 95 is transitional and is not a deferral of art. 27: from entry into force, processing for the State, a public establishment, a local authority or a private legal person managing a public service had two years to conform and all other processing had one year, periods that closed in 2021 and 2020 respectively; art. 94 additionally reduced pre-existing public-sector processing to a declaration under art. 6. Coverage symmetry against the Francophone rows already tracked: Togo is the seventh member of the Directive 95/46/EC art. 15 family on the tracker and it splits that family further. Morocco's art. 11, Algeria's art. 11 and now Togo's art. 27 take the narrow legal-effects trigger with a contract carve-out; Côte d'Ivoire's art. 25, Mali's art. 2, Burkina Faso's art. 15 and Niger's art. 52 take the wider ECOWAS trigger reaching any administrative or private decision appraising human conduct. Togo is a founding ECOWAS member and its Law postdates the ECOWAS Supplementary Act A/SA.1/01/10 by nine years, yet it did not take the Supplementary Act's wider drafting — which is why each statute in this block is read article by article rather than inferred from membership. Text read page by page in the Journal officiel de la République togolaise of 29 October 2019 as published by the Government of Togo's own gazette service, including arts. 2, 3, 5 to 9, 26 to 28, 38 to 41, 70 to 73, 79 to 93 and 94 to 97.

Stated maximum penalty — No criminal offence attaches to art. 27. The Law's penal chapter is arts. 79 to 93 and every one of its fifteen offences names its own conduct — failure to observe the prior formalities, disregard of a provisional withdrawal of authorisation, disregard of simplified or exempting norms, unauthorised processing of identification data, failure of security measures, fraudulent processing, disregard of the right to object, unlawful processing of sensitive data, of offence data and of health-research data, breach of the retention period, processing of data kept beyond it, diversion of purpose, unauthorised disclosure, and obstruction of the Instance de protection — and none of them reaches an automated decision. Those offences run from three months to five years' imprisonment and from 100,000 to 25,000,000 francs CFA, or one of the two penalties. The route that does reach art. 27 is administrative. Art. 70 lets the Instance de protection des données à caractère personnel issue a warning to a controller not respecting the obligations arising under the Law and a mise en demeure to cease the failures within a period it fixes. Art. 71 provides that where the controller does not comply with that mise en demeure the Instance may, after an adversarial procedure, pronounce a provisional withdrawal of the authorisation for three months which becomes definitive if no corrective measures follow, and a fine which may not exceed 100,000,000 francs CFA, recovered under the legislation on the recovery of State debts. Art. 72 adds urgent measures where implementation of a processing entails a violation of rights and freedoms: interruption of the processing for up to three months, blocking of certain data for up to three months, an injunction to bring the processing into conformity which may carry an astreinte of up to 5,000,000 francs CFA per day except where the State is the controller, and a formal reprimand. Art. 73 adds conservatory measures where a processing is implemented without the prior formalities, including the affixing of seals by a huissier at the controller's expense.

In force · 29 Oct 2019 checked 20 Aug 2026 Loi n° 2019-014 art. 27 ↗ medium confidence

Tanzania 1

Tanzania Binding

Personal Data Protection Act s. 36 — rights in relation to automated decision making, with a duty to notify and reconsider

Binds Data controllers and data processors within the scope of s. 22(1): any collection and processing of personal data performed wholly or partly by manual or automated means; processing carried out in the performance of the activities of a controller domiciled in the United Republic or in a territory where its laws apply by virtue of international public law; and processing by a controller or processor not domiciled in the United Republic where the processing is in the United Republic and is not for mere transit of personal data through Tanzania to another country. Section 2 applies the Act to Mainland Tanzania as well as to Tanzania Zanzibar, save that in Zanzibar it does not apply to non-union matters, so a purely Zanzibari matter falls outside it. Registration with the Personal Data Protection Commission under ss. 14 to 16 is a precondition of acting as a controller or processor, and s. 21 deems public institutions that collect and process personal data registered from commencement. The s. 36(2) notify-and-reconsider duty binds any controller that takes a solely-automated decision significantly affecting a data subject, irrespective of size. Impact tier: all entities.. Section 36 of the Personal Data Protection Act, 2022 (Act No. 11 of 2022, Chapter 44) carries Tanzania's operative automated-decision rule, in Part VI (rights of data subjects). Subsection (1) lets a data subject, through the procedures prescribed in the regulations, require the data controller to ensure that any decision taken by or on behalf of the controller which significantly affects the data subject shall not be based solely on processing by automatic means. Subsection (2) operates without prejudice to that request and bites of its own force: where a decision which significantly affects a data subject is based solely on automated processing, the controller shall as soon as practicable notify the data subject that the decision was taken on that basis, and the data subject may require the controller to reconsider the decision. Subsection (3) disapplies the section where the decision is necessary for entering into or performance of a contract between the data subject and a data controller, is authorised by any written law, or is based on the data subject's explicit consent. Section 37 separately entitles a data subject who suffers damage by reason of any contravention of the Act to compensation from the controller or processor.

Commencement was deferred to a ministerial instrument and that instrument is identified on the face of the published Act: the Chapter 44 text as republished in the Special Gazette prints “[1st May, 2023]” together with “[GN. NO. 326 of 2023]” immediately above Part I, so Government Notice No. 326 of 2023 appointed 1 May 2023 as the date on which the Act, including s. 36, came into operation. The Act itself is Act No. 11 of 2022; the text relied on here is the Chapter 44 republication issued as Government Notice No. 395B in Special Supplement No. 21 to the Special Gazette of the United Republic of Tanzania No. 15 Vol. 104 of 13 June 2023, printed by the Government Printer, Dodoma. Section 36(1) is not self-executing — the data subject's requirement runs “through the procedures prescribed in the regulations”, which are the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 — but s. 36(2) is, because it applies “without prejudice to subsection (1)” and imposes the notification duty directly on the controller. The copy of those 2023 Regulations published by the Personal Data Protection Commission is a scanned image with no text layer, so the prescribed procedure could not be read and no claim about its content is made here; the entry rests on the statute. Coverage symmetry against the four African rows already tracked: s. 36 is drawn from the same UK Data Protection Act 1998 s. 12 lineage as gh-dpa-s41 rather than from GDPR art. 22, and the two are the closest pair on the tracker — both pair a request-based right with an automatic notify-and-reconsider duty. The difference is the clock: Ghana fixes hard twenty-one-day periods in both directions, while Tanzania says only “as soon as practicable” for the notification and sets no period at all for the controller's response, so Ghana remains the only African row with hard deadlines. Tanzania's carve-out in s. 36(3) is narrower than Ghana's s. 41(4) because it does not exclude pre-contractual consideration, and unlike ke-dpa-s35 it gives no right to demand a fresh non-automated decision — only reconsideration of the existing one. Text read in the copy of the Act published by the Personal Data Protection Commission, the supervisory authority established by s. 6 of the Act.

Stated maximum penalty — Enforcement is administrative and runs through Part VII. The Commission investigates complaints under ss. 39 to 42, may serve a notice of enforcement under s. 45 and a notice of penalty under s. 46, and s. 46 lists the factors bearing on the amount, including the nature, gravity and duration of the failure, compliance with previous enforcement or penalty notices, adherence to codes of ethics, and financial benefits gained or losses suffered. Section 47 caps the amount: the maximum penalty that may be imposed by the Commission in a penalty notice in relation to a contravention of the provisions of the Act is one hundred million Tanzanian shillings. Section 48 allows the Commission to review its own decision and s. 49 gives a person aggrieved by the administrative action, including directions in an enforcement notice or a penalty imposed, a right of appeal. Section 37 gives the data subject a separate entitlement to compensation from the controller or processor for damage suffered by reason of any contravention of the Act, and s. 50 governs payment of that compensation. The criminal offences in ss. 60 to 62 address unlawful disclosure and unlawful destruction, deletion, concealment or alteration of personal data and do not attach to s. 36.

In force · 1 May 2023 checked 22 Aug 2026 Personal Data Protection Act s. 36 (Act No. 11 of 2022) ↗ high confidence

Uganda 1

Uganda Binding

Data Protection and Privacy Act s. 27 — notice-based right against solely-automated decisions, an automatic duty to notify and reconsider on a twenty-one-day clock, and a fourteen-day route to the regulator

Binds Data controllers within the scope of s. 1, which applies the Act to a person, institution or public body collecting, processing, holding or using personal data within Uganda, and to a person outside Uganda who collects, processes, holds or uses personal data relating to Ugandan citizens. “Authority” in s. 27(5) is the National Information Technology Authority — Uganda (NITA-U); the Personal Data Protection Office established by s. 4 sits within it and is charged by s. 5 with overseeing implementation and enforcement of the Act. Registration is a standing precondition of processing: s. 29 requires the Authority to register every person, institution or public body collecting or processing personal data in the data protection register. The s. 27 duties bind any controller that takes a solely-automated decision significantly affecting a data subject, irrespective of size or sector. Impact tier: all entities.. Section 27 of the Data Protection and Privacy Act, 2019 (Act 9 of 2019), headed “Rights in relation to automated decision-taking”, is Uganda's operative automated-decision rule and sits in the Part V block of data-subject rights at ss. 23 to 28. Subsection (1) lets a data subject, by notice in writing to a data controller, require the controller to ensure that any decision taken by or on behalf of the controller which significantly affects that data subject is not based solely on the processing by automatic means of personal data in respect of that data subject. Subsection (2) operates without prejudice to subsection (1) and therefore bites even where no such notice has been served: where a decision which significantly affects a data subject is based solely on automated processing, (a) the data controller shall as soon as reasonably practicable notify the data subject that the decision was taken on that basis, and (b) the data subject is entitled, by notice in writing, to require the controller to reconsider the decision within twenty-one days after receipt of that notification. Subsection (3) then gives the controller twenty-one days after receipt of that notice to inform the data subject in writing of the steps the controller has taken in compliance with it. Subsection (4) disapplies the section entirely where the decision is made in the course of considering whether to enter into a contract with the data subject, with a view to entering into the contract, in the course of the performance of the contract, or for a purpose authorised or required by or under any law. Subsection (5) adds an escalation the Ghanaian and Tanzanian analogues do not have: where the data subject is not satisfied with the controller's subsection (3) response, the data subject shall complain in writing to the Authority within fourteen days.

The Act carries no commencement clause of its own, so the default rule supplies the date: s. 14(1) of the Acts of Parliament Act (Chapter 2, Act 16 of 2000) provides that the commencement of an Act shall be such date as is provided in or under the Act, or where no date is provided, the date of its publication as notified in the Gazette, and s. 14(2) deems every Act to come into force at the first moment of the day of commencement. The Act was published in Uganda Gazette no. 21 of 3 May 2019, so s. 27 has been in force since 3 May 2019. The enacted text relied on here is the copy of Act 9 of 2019 published by the Ministry of ICT and National Guidance, which reproduces the printed impression certified by the Clerk to Parliament as a true copy of the bill on 04/02/2019 and the President's assent page dated 25/2/2019; the Clerk's authentication and assent pages were read directly, as was s. 27 in full. Section 39 lets the Minister, after consultation with the Authority, make regulations by statutory instrument; no statutory instrument text could be retrieved from an official host this run, so nothing is claimed here about subsidiary rules, and the entry rests on the statute alone. Coverage symmetry against the seven African rows already tracked: s. 27 belongs to the UK Data Protection Act 1998 s. 12 lineage rather than to GDPR art. 22, and it is a near-verbatim sibling of Ghana's gh-dpa-s41 and a closer sibling still of Tanzania's tz-pdpa-s36 — all three pair a notice-based right with an automatic notify-and-reconsider duty. Uganda now joins Ghana as the only African rows with hard deadlines, and it is the stricter of the two on the data subject's own side: Ghana's twenty-one-day clocks run to reconsideration and to the controller's answer, and Uganda replicates both in s. 27(2)(b) and s. 27(3), but Uganda alone then fixes a further fourteen-day period in s. 27(5) for complaining to the Authority if the answer does not satisfy. Its carve-out in s. 27(4) is as wide as Ghana's — pre-contractual consideration, contract formation and contract performance are all excluded outright, with no compensating safeguards required — and therefore wider than the GDPR-shaped exceptions in ke-dpa-s35, ng-ndpa-s37 and rw-law058-2021-art21. Unlike Kenya, it gives no right to demand a fresh non-automated decision, only reconsideration of the existing one. Two drafting wrinkles in the gazetted text: the printed s. 27(3) duplicates a verb, reading “the steps that the data controller has taken to take …”, and s. 27(5) refers to “sub clause (3)” rather than subsection (3).

Stated maximum penalty — Section 27 non-compliance is not itself an offence: Part VIII creates only three offences — unlawfully obtaining or disclosing personal data (s. 35, fine not exceeding two hundred and forty currency points or imprisonment for ten years or both), unlawfully destroying, deleting, concealing or altering personal data (s. 36, fine not less than two hundred and forty currency points or imprisonment not exceeding ten years or both) and sale of personal data (s. 37, fine not exceeding two hundred and forty five currency points or imprisonment not exceeding ten years or both) — and none of them reaches a solely-automated decision. The Schedule values one currency point at twenty thousand shillings, so the s. 35 to s. 37 ceilings are UGX 4,800,000, UGX 4,800,000 and UGX 4,900,000. Where an offence under ss. 35, 36 or 37 is committed by a corporation, s. 38(1) makes the corporation and every officer who knowingly and willfully authorised or permitted the contravention liable, and s. 38(2) lets the convicting court additionally order the corporation to pay a fine not exceeding two percent of its annual gross turnover. The route to a sanction for s. 27 is administrative and runs through the regulator: s. 27(5) requires the dissatisfied data subject to complain in writing to the Authority within fourteen days, s. 31 lets any person who believes a data collector, processor or controller is infringing their rights or violating the Act complain to the Authority in the prescribed manner, and s. 32 obliges the Authority to investigate every complaint and lets it direct the party to remedy the breach or take such action as the Authority specifies to restore the rights of the data subject. The Act attaches no fine to disobeying such a direction.

In force · 3 May 2019 checked 17 Aug 2026 Data Protection and Privacy Act s. 27 (Act 9 of 2019) ↗ high confidence

United States 3

US · CO Binding

Colorado AI Act (SB 26-189)

Binds Developers & deployers of automated decision-making tech in consequential decisions. ADMT documentation, consumer notice & appeal rights.

ENFORCEMENT STAYED — xAI v. Weiser, No. 1:26-cv-01515 (D. Colo.): On approx. April 27, 2026, a joint consent-based enforcement stay was entered (agreed by xAI LLC, the U.S. DOJ, and the Colorado AG). The original SB 24-205 was repealed and replaced by SB 26-189 (signed May 14, 2026); the stay was extended to SB 26-189. AG cannot initiate enforcement until 14 days after any PI ruling. xAI must file a formal PI motion within 28 days of Colorado finalizing rulemaking under SB 26-189. Law is valid and on the books (effective date unchanged: 2027-01-01), but practical enforcement is suspended pending PI disposition. FEDERAL PREEMPTION PRESSURE (separate from the litigation stay): on 7 July 2026 the FTC published for comment a proposed 'Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems' (docket FTC-2026-0859), asserting that steering AI outputs contrary to consumers' reasonable expectations — in the FTC's words 'including attempted compliance with a State law, such as Colorado's recently revised Artificial Intelligence Act' — may be deceptive under Section 5 of the FTC Act. The comment period closed 31 July 2026 and drew opposing comments, including from a multistate attorney-general coalition. The FTC has not finalised the policy statement and no court has ruled on preemption, so the text, scope and 1 January 2027 effective date of SB 26-189 are unchanged by it.

Stated maximum penalty — AG enforcement; per violation

Applies 1 Jan 2027 checked 22 Aug 2026 SB 26-189 ↗ high confidence
US · CT Binding

Connecticut PA 26-15 (SB 5) tranche 3 — automated employment-related decision technology

Binds Developers and deployers of automated employment-related decision technology deployed in Connecticut on or after 1 Oct 2027. Developers and deployers have until 1 Oct 2027, when the duties attach to any automated employment-related decision technology deployed in Connecticut on or after that date.

Public Act No. 26-15 ss 7-12. Date nuance: the sections themselves are '(Effective October 1, 2026)', but the operative duties in ss 8, 9 and 10 each attach only to technology 'deployed in the state on or after October 1, 2027', so 1 Oct 2027 is the date on which the obligations bite. s 8 is the developer-to-deployer disclosure; ss 9-10 are the deployer notice duties; s 11 carries the trade-secret carve-out; s 12 makes violations of ss 8-11 unfair or deceptive trade practices enforced solely by the Attorney General.

Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)

Applies 1 Oct 2027 checked 12 Aug 2026 CT PA 26-15 (SB 5) ss 7-12 ↗ high confidence
US · Federal Proposed

AI Kill Switch Act (Lieu-Moran)

Binds AI system developers meeting both: $100M+ training compute and $500M+ annual gross AI revenue. Frontier AI developers meeting dual thresholds ($100M dev compute, $500M annual AI revenue) must implement kill-switch capability; 15-day DHS incident reporting; DHS/CISA authority to compel emergency shutdown.

Introduced Jul 23, 2026 by Reps. Lieu (D) and Moran (R) as H.R. 9917; referred to the House Committee on Homeland Security same day; triggered by OpenAI/Hugging Face hack incident. 119th Congress.

Stated maximum penalty — Up to $2M/day (general); up to $20M/day (defying shutdown order)

Proposed checked 13 Aug 2026 AI Kill Switch Act ↗ high confidence

Uzbekistan 1

Uzbekistan Binding

Law on Informatization art. 7¹ — AI must not harm, and no decision on AI output alone

Binds Anyone creating information resources using AI, or operating an information system that runs on AI technologies, in Uzbekistan — and anyone taking a legally significant decision affecting a person's rights and freedoms. Information resources created with AI and information systems running on AI technologies must not harm a person; legally significant decisions affecting rights and freedoms may not rest exclusively on their conclusions.

Art. 7¹ was inserted into the Law 'On Informatization' (No. 560-II of 11 Dec 2003) by Law No. ЎРҚ-1115 of 21 January 2026, an omnibus AI amendment act passed by the Legislative Chamber on 12 Aug 2025 and approved by the Senate on 1 Nov 2025. Art. 4 of ЎРҚ-1115 brings it into force on the day of official publication, and the official Uzbek consolidated text records that publication as National Database of Legislation, 21.01.2026, No. 03/26/1115/0063 — so 21 January 2026 is the in-force date, not a projection. Two duties, both stated flatly and neither limited by sector, size or nationality: (1) AI-created information resources and AI-based information systems must not damage a person, their life, health, freedom, honour or dignity, or violate their other inalienable rights; (2) when taking legally significant decisions affecting a person's rights and freedoms it is not permitted to rely EXCLUSIVELY on the conclusions of such resources and systems. The second limb is a human-in-the-loop mandate on the decision-maker rather than a data-subject right — unlike the objection route in art. 24 of the Personal Data Law (uz-pd-art24), it is not triggered by the person and has no consent or contract exit. Art. 7¹ carries NO penalty of its own: ЎРҚ-1115 attached administrative liability only to unlawful AI processing of personal data (uz-koao-46-2-ai), not to art. 7¹. Verified against the official Uzbek-language consolidated text; the Russian text on lex.uz is marked an unofficial translation.

Stated maximum penalty — None — no penalty attached to art. 7¹

In force · 21 Jan 2026 checked 21 Aug 2026 Law on Informatization art. 7¹ ↗ high confidence

Vietnam 2

Vietnam Comprehensive

Law on AI — risk-tiered obligations

Binds AI developers / providers / deployers / users; extraterritorial (local representative required). Three-tier risk classification; high-risk AI needs conformity assessment + registration (general grace to 1 Mar 2027).

Sector-differentiated grace period: 12 months (to 1 Mar 2027) for most sectors; 18 months (to 1 Sep 2027) for healthcare, education and finance. Implementing Decree 142/2026/ND-CP in force 1 May 2026.

Stated maximum penalty — Admin fines up to ₫2B (decree-set)

In force · 1 Mar 2026 checked 14 Aug 2026 Law 134/2025/QH15 ↗ high confidence
Vietnam Comprehensive

Vietnam Decision 33 — 46 High-Risk AI Systems List

Binds Operators and providers of the 46 designated high-risk AI systems in Vietnam. Designates 46 specific AI systems as high-risk; new deployments require pre-deployment conformity assessment from Aug 15 2026.

In force from 15 August 2026. Day-of verification (15 Aug 2026): the Government legal-document portal record for Decision 33/2026/QD-TTg lists Ngay ban hanh (issued) 30-06-2026 and Ngay co hieu luc (effective) 15-08-2026. Existing systems have a transition period: 1 March 2027 (most sectors) or 1 September 2027 (healthcare, education, finance); new deployments of the 46 designated systems require pre-deployment conformity assessment from today. MoST (mst.gov.vn) published explainer content on the 6 covered sectors and both transition deadlines on 3 Jul 2026 (https://mst.gov.vn/46-he-thong-ai-duoc-xep-vao-nhom-rui-ro-cao-phai-quan-ly-nghiem-ngat-197260703152945179.htm), with a further notice on 8 Jul 2026 — contextual guidance, not a new binding regulation.

Stated maximum penalty — Enforcement under Vietnam AI Law 134/2025 / Decree 142

In force · 15 Aug 2026 checked 15 Aug 2026 Decision 33/2026/QD-TTg ↗ high confidence

South Africa 1

South Africa Binding

POPIA s. 71 — bar on decisions taken solely on automated processing that profiles the data subject

Binds Responsible parties as defined in s. 1, that is public or private bodies or any other person which alone or in conjunction with others determines the purpose of and means for processing personal information. Section 3(1) applies the Act to processing entered in a record by or for a responsible party by automated or non-automated means where the responsible party is domiciled in the Republic, or is not domiciled in the Republic but makes use of automated or non-automated means in the Republic other than merely to forward information through it. Data subjects include juristic persons, so the section reaches automated credit and supplier scoring of companies as well as of natural persons. Impact tier: all entities.. Section 71 of the Protection of Personal Information Act 4 of 2013 carries South Africa's operative automated-decision rule, in Chapter 8 (rights of data subjects regarding direct marketing by unsolicited electronic communications, directories and automated decision making). Subsection (1) provides that a data subject may not be subject to a decision which results in legal consequences for him, her or it, or which affects him, her or it to a substantial degree, which is based solely on the basis of the automated processing of personal information intended to provide a profile of such person, including his or her performance at work, or his, her or its creditworthiness, reliability, location, health, personal preferences or conduct. Subsection (2) disapplies that bar where the decision has been taken in connection with the conclusion or execution of a contract and either the data subject's request in terms of the contract has been met or appropriate measures have been taken to protect the data subject's legitimate interests, or where the decision is governed by a law or code of conduct in which appropriate measures are specified for protecting the legitimate interests of data subjects. Subsection (3) fixes what those appropriate measures must do: provide an opportunity for the data subject to make representations about the decision, and require the responsible party to provide the data subject with sufficient information about the underlying logic of the automated processing of the information relating to him or her to enable him or her to make those representations. The profiling limb is broader than the GDPR Art. 22 analogue in one respect — it names performance at work, creditworthiness, reliability, location, health, personal preferences and conduct on the face of the statute.

Commencement is fixed by proclamation, not by the Act: s. 115(1) provides that POPIA commences on a date determined by the President by proclamation in the Gazette, and s. 115(2) allows different dates for different provisions. Proclamation No. R. 21 of 2020, signed at Hyde Park on 17 June 2020 and published in Government Gazette No. 43461 (Regulation Gazette No. 11136) of 22 June 2020, determined 1 July 2020 as the date on which ss. 2 to 38, ss. 55 to 109, s. 111 and s. 114(1), (2) and (3) commence, and 30 June 2021 as the date for ss. 110 and 114(4). Section 71 falls inside the 55-to-109 block, so it has been in force since 1 July 2020. Section 114(1), which commenced on the same day, required all processing of personal information to be made to conform to the Act within one year, so that transitional window closed on 1 July 2021, the date the market treats as the compliance deadline. The Regulator's Chapter 10 enforcement powers (ss. 73 to 99) and the administrative-fine machinery in s. 109 also commenced on 1 July 2020. South Africa is the tracker's first African jurisdiction. Compared with the Kenyan analogue ke-dpa-s35, POPIA gives no express right to demand a fresh non-automated decision; its remedy is a right to make representations plus disclosure of the underlying logic, and only where the contract exception is relied on. Text read in the enacted Act as published in Government Gazette No. 37067 of 26 November 2013 on gov.za, and the commencement dates read in the proclamation as published by the Information Regulator, the statutory supervisory authority.

Stated maximum penalty — Enforcement runs through Chapter 10: a breach of s. 71 is interference with the protection of personal information under s. 73, which the Information Regulator may pursue by enforcement notice under s. 95. Failure to comply with an enforcement notice is an offence under s. 103(1), punishable under s. 107(a) by a fine or imprisonment for a period not exceeding 10 years, or both. Under s. 109(2)(c) the Regulator may instead serve an infringement notice specifying an administrative fine, which may not exceed R10 million. Section 99 preserves a separate civil action for damages by the data subject, or by the Regulator on the data subject's behalf, irrespective of intent or negligence.

In force · 1 Jul 2020 checked 16 Aug 2026 POPIA s. 71 (Act 4 of 2013) ↗ high confidence

Questions & answers

From the data

What is a high-risk AI system?

A system whose use could materially affect safety or fundamental rights — for example in employment, credit, essential services, biometrics or critical infrastructure. The EU AI Act lists these uses in Annex III; other regimes use comparable high-risk or high-impact categories with their own lists.

What does a high-risk classification require?

Usually a pre-deployment or conformity assessment, human oversight, risk management, technical documentation and sometimes registration. The precise package depends on the instrument — see each row’s primary source.

When do the EU AI Act’s high-risk rules apply?

The Annex III high-risk obligations were set for 2 August 2026. The Digital Omnibus, adopted by the European Parliament on 16 June 2026, proposes deferring them to 2 December 2027; until the Council adopts it and it is published in the Official Journal, the original date legally stands.

Which jurisdictions does AI Law Radar track for high-risk ai systems?

We currently track high-risk ai systems obligations across 36 jurisdictions: United Arab Emirates, Burkina Faso, Benin, Brazil, Republic of the Congo, Côte d'Ivoire, Cameroon, China, Germany, Algeria, European Union, Gabon, Ghana, Guinea, Indonesia, Kenya, Kyrgyzstan, South Korea, Kazakhstan, Morocco, Madagascar, Mali, Niger, Nigeria, Peru, Philippines, Russia, Rwanda, Senegal, Togo, Tanzania, Uganda, United States, Uzbekistan, Vietnam and South Africa. Each is dated and linked to its primary source on this page.