AI LAW RADAR · Daily Last verified 22 Aug 2026

Topic dossier

AI transparency & disclosure requirements

When people have to be told they are dealing with AI, and content has to be marked as model-generated — chatbot disclosure, content labelling and training-data transparency. 99 obligations across 57 jurisdictions — 76 in force. Next dated deadline: 17 Sep 2026.

Transparency is the most common thread running through AI law. Three duties recur: telling a person when they are interacting with an AI system, marking content that an AI generated, and — increasingly — disclosing what data a model was trained on. The instruments below each carry one or more of these duties, tracked to their primary sources.

The Register

99 obligations · 57 jurisdictions

Angola 1

Angola Binding

Lei 22/11 art. 29.º — decisões individuais automatizadas: the only prohibition on the tracker that the data-protection authority can licence

Binds Responsáveis pelo tratamento — controllers — with subcontratados (processors) bound through the art. 23 processor regime. Art. 3(1) makes the scope explicitly tri-sectoral: the Law catches processing carried out by any person or entity of the public, private or cooperative sector. Art. 3(2) sets the territorial reach at four limbs: processing by a controller headquartered in the Republic of Angola; processing in the context of the activities of a controller established in Angola even where that controller is not headquartered in Angolan territory; processing outside Angola where Angolan law applies by virtue of public or private international law; and processing by a controller not established in Angola that resorts, for the processing, to means situated in Angolan territory. Art. 3(3) makes that last limb wide — a controller is deemed to resort to means in Angolan territory where the processing operations are carried out with, or the data are hosted on, means situated in Angola, the mere use of such means for the collection, recording or transit of personal data in the territory being enough. Art. 3(4) then requires any controller caught by the means limb to designate, by communication to the Agência de Protecção de Dados, a representative established in Angola who substitutes for it in all its rights and obligations, without prejudice to the controller's own liability — so a foreign scoring or profiling operator hosting on Angolan infrastructure is both bound by art. 29 and required to stand up a local representative. Art. 4 excludes processing by a natural person in the exercise of exclusively personal or domestic activities, and, without prejudice to special legislation, processing under the legal rules on state secrecy and security and on judicial secrecy, and processing of the personal data of members of the Angolan Armed Forces by military units, establishments and organs. Impact tier: all entities — art. 29 applies to every controller in every sector, with no employee-count, turnover or high-risk-system threshold, and its named evaluation grounds (professional capacity, credit, trustworthiness, conduct) put hiring and credit-scoring deployers squarely in scope.. Article 29.º of Lei n.º 22/11, de 17 de Junho — Lei da Protecção de Dados Pessoais is Angola's automated-decision provision, and it is Portuguese Lei 67/98 lineage rather than the Directive 95/46/EC transposition template that the Francophone African rows carry or the GDPR template that Cameroon carries. Under art. 29(1), qualquer pessoa tem o direito de não ficar sujeita a uma decisão que produza efeitos na sua esfera jurídica ou que a afecte de modo significativo, tomada exclusivamente com base num tratamento automatizado de dados destinado a avaliar determinados aspectos da sua personalidade, designadamente, a sua capacidade profissional, o seu crédito, a confiança de que é merecedora ou o seu comportamento — any person has the right not to be subject to a decision producing effects in their legal sphere or significantly affecting them, taken exclusively on the basis of automated data processing intended to evaluate certain aspects of their personality, namely their professional capacity, their credit, their trustworthiness or their conduct. The trigger is the classical one: solely automated, evaluative, and gated by a legal-effects-or-significant-effect threshold, so it is narrower than Equatorial Guinea's art. 13(b) and narrower than Cameroon's art. 44, neither of which requires a threshold. What makes Angola structurally different is the second route out. Art. 29(2) carries the familiar contract exception — a person may be subject to such a decision where it occurs in the conclusion or performance of a contract and either their request to conclude or perform was satisfied, or adequate measures exist guaranteeing the defence of their legitimate interests, designadamente o seu direito de representação e expressão, namely their right of representation and expression. Art. 29(3) then adds the route that, on the tracker, only one other jurisdiction carries: pode ainda ser permitida a tomada de uma decisão, nos termos do n.º 1 deste artigo, quando a Agência de Protecção de Dados o autorize, definindo medidas de garantia da defesa dos interesses legítimos do titular dos dados — the decision may further be permitted where the Agência de Protecção de Dados authorises it, itself defining the measures that guarantee the defence of the data subject's legitimate interests. Most prohibitions on the tracker admit only exceptions fixed in the statute (consent, contract, or a law laying down safeguards); Angola and Cabo Verde are the two where the supervisory authority can licence an otherwise-forbidden automated decision case by case and write the safeguards for it. The clause is a shared inheritance from art. 13(3) of Portugal's Lei 67/98 rather than an Angolan invention — Cabo Verde carries it as art. 23(3) of the text republished by Lei 121/IX/2021, naming the Comissão Nacional de Proteção de Dados — and São Tomé e Príncipe, from the same lineage, dropped it. The safeguard package is also thinner than the GDPR's. Art. 29(2) gives a right of representation and expression but no right to obtain human intervention in the decision and no right to contest it after the fact, and the Law carries no logic-disclosure duty anywhere: the art. 25 information list runs through purposes, recipients, whether the answer is obligatory, the existence and conditions of access, rectification, updating, elimination and opposition, and the consequences of collection without consent, with no item on the existence of automated decision-making and no item on the logic involved; and the art. 26 access right reaches confirmation, purposes, categories, recipients, the specific data and available information on their origin, but not the logic of any automated processing. So a data subject in Angola may never learn that a machine decided, and if the Agência authorises the decision under art. 29(3) the safeguards they get are whatever that authorisation says. Impact tier: all entities.

Force, and the date is exact. Art. 67.º (Entrada em vigor) provides A presente lei entra em vigor à data da sua publicação — the Law enters into force on the date of its publication — and it was published in the Diário da República, I Série, n.º 114, de 17 de Junho de 2011, at pp. 3185-3202. The instrument was approved by the Assembleia Nacional in Luanda on 24 May 2011 and promulgated by President José Eduardo dos Santos on 8 June 2011; art. 64.º revokes all legislation contrary to it, and art. 63.º gave controllers of pre-existing processing two years from entry into force to notify the Agência de Protecção de Dados. Art. 65.º required the Executive to regulate the Law within 120 days of publication. Supersession: none in force. A revision is live but has not been enacted — the Agência de Protecção de Dados ran a public consultation titled Projecto de Revisão da Lei n.º 22/11, de 17 de Junho - Lei de Protecção de Dados Pessoais on the Government's consultapublica.gov.ao portal from 17 March 2025 to 17 April 2025, and that consultation is recorded as Encerrada (closed). No successor law has appeared in the Diário da República, so Lei 22/11 art. 29 is the operative rule today and the draft is tracked as a watch item, not as a dateset entry; it will only be published as an obligation once the successor is gazetted with an entry-into-force clause. No AI-specific statute is in force in Angola and the Law does not define artificial intelligence — Gabon's Loi 025/2023 remains the only data-protection statute in the African block that does. Text read in full in the official scanned copy of the Diário da República issue published by the Agência de Protecção de Dados itself, the supervisory authority created by the Law, which satisfies Primary Source First on the same basis as the Nigeria, Burkina Faso, Gabon, Chad and Equatorial Guinea copies. The copy is an 18-page image-only scan (RC4-40 encrypted, DCTDecode page streams) with no text layer and was read as page images. Coverage of the read: art. 3 scope and art. 4 exclusions in full; art. 5 definitions; the whole of Secção IV Direitos dos Titulares dos Dados, arts. 25 information, 26 access, 27 opposition, 28 rectification-updating-elimination and 29 automated individual decisions, verbatim; arts. 17-19 and 22-24 on video surveillance, direct marketing, communication of data, processors and interconnection; arts. 44-46 on the Agência; and the whole of Capítulo IV, arts. 47-62 — administrative and judicial protection, civil liability, contraventions and fines, and the criminal section — plus Capítulo V arts. 63-67. Confidence high: the article was read verbatim in the gazette text, the entry-into-force clause is explicit, and the enforcement route was traced through the sanction articles rather than assumed.

Stated maximum penalty — No fine attaches to art. 29 itself — the enforcement route is indirect, and this is the entry's most consequential finding. Art. 51.º(1) enumerates the contraventions exhaustively by article number: alínea a) sets USD 75,000.00 to USD 150,000.00 for breach of the obligations in arts. 14.º, 15.º, 16.º, 17.º, 20.º, 30.º, 31.º and 32.º, for negligent failure to notify the Agência or notification with false information, and for failing to comply with an Agência order to cease access to open transmission networks; alínea b) sets USD 65,000.00 to USD 130,000.00 for breach of the principles in arts. 6.º to 11.º, for processing without the data subject's consent where no dispensation applies, and for breach of arts. 18.º, 19.º and 21.º to 24.º. Art. 29.º appears in neither list. Art. 51.º(2) trebles the respective limits for legal persons, companies and de facto associations — so the ceiling elsewhere in the Law reaches USD 450,000.00 — and art. 51.º(3) makes negligence and attempt punishable; art. 53.º gives the Agência de Protecção de Dados the power to apply the fines, its homologated deliberation constituting an enforceable title if not challenged in the legal period. What a data subject actually has against an unlawful automated decision is three-fold. First, art. 47.º: without prejudice to the right to complain to the Agência, any person may use administrative or judicial means to secure compliance with the data-protection provisions, and decisions of the Agência are themselves subject to contentious administrative appeal. Second, art. 48.º: anyone who has suffered moral or material harm through the undue use of personal data has the right to demand reparation by judicial route, with the judge grading the injury objectively. Third, and the sharpest, art. 58.º (Desobediência qualificada): whoever, having been notified to that effect, fails to interrupt, cease or block the processing of personal data is punished with imprisonment of up to 3 years or a corresponding fine — so once the Agência orders an art. 29 profiling operation stopped, defying the order is a crime. Art. 61.º allows accessory penalties alongside applied fines, including temporary or definitive prohibition of the processing, blocking, erasure or total or partial destruction of the data, publication of the conviction at the convicted party's expense, and public warning or censure of the controller. Separately, art. 55.º(1)(a) makes it a crime punishable with 3 to 18 months' imprisonment or a corresponding fine to omit the request for authorisation to the Agência de Protecção de Dados — a limb that on its face reaches a controller who takes an art. 29(1) decision on the art. 29(3) footing without ever having sought the Agência's authorisation, though the Law does not spell that application out and it has not been tested.

In force · 17 Jun 2011 checked 19 Aug 2026 Lei 22/11 art. 29.º ↗ high confidence

Australia 1

AU Binding

Australia Automated Decision-Making Transparency (Privacy Act APP 1.7–1.9)

Binds All Australian Privacy Principle (APP) entities using automated decision-making affecting individual rights or interests. All APP entities using personal information in ADM that could significantly affect individual rights must disclose this in their privacy policies.

OAIC published the ADM Transparency Issues Paper May 2026; consultation closed 15 June 2026 (https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making). OAIC states it intends to release the guidance by September 2026, ahead of the 10 December 2026 commencement of the ADM obligation. No new OAIC guidance issued as of 2026-08-11.

Stated maximum penalty — Civil penalties up to AUD $50M (OAIC enforcement)

Applies 10 Dec 2026 checked 22 Aug 2026 Privacy & Other Legislation Amendment Act 2024 (Cth) ↗ high confidence

Burkina Faso 1

Burkina Faso Binding

Loi 001-2021/AN art. 15 — a two-limb bar with no exception, backed by art. 19's reasoning and artificial-intelligence disclosure right and by art. 31's prior authorisation for predictive-AI decision support

Binds Responsables du traitement and sous-traitants within the scope of the Law, whose art. 6 states that information and communication technologies are at the service of the human person and must not harm human identity, private life, individual and collective freedoms or human rights generally. Art. 4 excludes temporary copies made for technical transmission and access purposes, which must be erased once their purpose is achieved, and processing for purely literary, artistic or journalistic purposes carried out in accordance with the ethical rules of those professions, the security measures protecting journalistic sources and the moderation rules applicable to discussion forums operated by news publishers. Prior formalities are a standing precondition: art. 30 sets the declaration regime and art. 31 the prior-authorisation regime, which covers offence and conviction data in the private sector, interconnection of files in either sector, national-identification-number processing in either sector, biometric processing in the private sector, public-interest processing including for historical, statistical or scientific purposes, decision-support processing involving an appraisal of human conduct or profiling or resting on predictive artificial-intelligence techniques, and transfers abroad. The first limb of art. 15 binds the courts themselves; the second binds every administrative and private decision-maker, irrespective of size or sector. Art. 78 makes the sanctions in arts. 63 to 75 applicable to all files, automated or not, whose use does not fall exclusively within the exercise of the right to private life. Impact tier: all entities.. Article 15 of Loi n° 001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel is Burkina Faso's operative automated-decision rule, closing Chapitre 1 of Titre II on fundamental principles immediately before the chapter on the rights of the data subject. Its first limb bars any judicial decision involving an appraisal of human conduct from having as its foundation an automated processing of information giving a definition of the profile or the personality of the person concerned and intended to evaluate certain aspects of their personality. Its second bars any administrative or private decision involving an appraisal of human conduct from having as its sole foundation an automated processing of information giving a definition of the profile or the personality of the person concerned. Like Côte d'Ivoire's art. 25 and Mali's art. 2, the Law states no exception whatever — no contract carve-out, no consent exception, no legal-authorisation exception and no opportunity to present observations. Two neighbouring provisions do the work that the exception clause does elsewhere. Article 19 gives every person the right to know and to contest the information and the reasoning used in processing, automated or not, whose results are relied on against them, and adds that where that processing falls within artificial intelligence the criteria and the nature of the personal data founding it must be indicated to the person from the point of collection. Article 31 goes further than any other row on the tracker by putting the technology itself behind a licence: processing that assists administrative or private decision-making, involves an appraisal of human conduct, gives a definition of the profile or the personality of the person concerned, or rests on artificial-intelligence techniques for predictive purposes, may not be implemented without prior authorisation from the Commission de l'informatique et des libertés. That is a permissioning gate on predictive AI, not merely a constraint on the resulting decision. There is no right to obtain human intervention or a fresh non-automated decision, and the art. 16 information list stops at identity, purposes, categories, whether answers are compulsory, recipients, access, rectification, suppression and objection rights, retention period, foreign transfers and the means of giving or withdrawing consent.

Supersession: art. 82 abrogates Loi n° 010-2004/AN du 20 avril 2004 portant protection des données à caractère personnel, the statute this sweep originally targeted, which is therefore no longer operative and is not tracked. Art. 83 is a bare execution clause — "La présente loi sera exécutée comme loi de l'Etat" — and there is no commencement article and no deferral of art. 15. The date recorded is the date printed at the foot of the enacted text, "Ainsi fait et délibéré en séance publique à Ouagadougou, le 30 mars 2021", the Assemblée nationale having deliberated in its sitting of that day. Confidence is medium and the reason is specific to Burkina Faso: laws there are promulgated by presidential decree, and neither the promulgation decree for Loi n° 001-2021/AN nor the date of the Journal officiel carrying it could be established from any official host this run — cil.bf serves a maintenance page on every path, legiburkina.bf, jo.gov.bf and sgg.gov.bf do not resolve, and the CIL's own document tree returns 404 live. Entry into force can therefore only be 30 March 2021 or later. Art. 81 is transitional and not a deferral of art. 15: processing already created and governed by art. 30 is subject only to declaration, the CIL may by special decision apply art. 31 to it subject to a prorogation of not more than one year granted by decree in Council of Ministers on the supervisory authority's opinion, and from the date of entry into force all processing had one year to meet the Law's prescriptions, failing which it is deemed implemented without the corresponding declaration or authorisation. Art. 80 preserves the mandates of CIL members already appointed. Source: the enacted text as published by the CIL itself, retrieved from the Internet Archive capture of 10 July 2025 of the CIL's own document store, the live path having 404'd during the site's maintenance outage; an archived copy of a document served by the official host satisfies Primary Source First on the same basis as ng-ndpa-s37. Coverage symmetry against the fifteen African rows already tracked: art. 15 takes the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting shared with Côte d'Ivoire's art. 25 and Niger's art. 52 — the second limb is tied to an appraisal of human conduct rather than to legal or significant effects — and, like Côte d'Ivoire and Mali, states no exception at all. Its art. 19 is materially identical to the third and fourth paragraphs of Niger's art. 52, including the artificial-intelligence disclosure duty at collection; since Burkina Faso's Law predates Niger's by twenty months, Burkina Faso is the source of that drafting on the tracker and Niger the follower. Two rows therefore carry an express artificial-intelligence clause, not one. Burkina Faso goes one step beyond Niger in art. 31 by making predictive-AI decision-support processing subject to prior authorisation, which is the only ex ante licensing gate on artificial intelligence in any data-protection statute on the tracker. The four-way African lineage picture: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, sn-loi200812-art48, ci-loi2013450-art25, ne-loi202259-art52, bj-code-num-art401, ml-loi2013015-art2 and now bf-loi0012021-art15; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — Art. 79 is the entire criminal chapter and creates no offence of its own: breaches of the Law are punished by the Penal Code in its provisions dealing with offences in computing matters and by means of information and communication technologies, so no criminal figure is attributed to art. 15 here. Everything operative is administrative and belongs to the CIL. Art. 63 lets the CIL, following the verification and inspection missions under art. 57 and without prejudice to criminal proceedings, impose a warning, a mise en demeure, an injunction to cease the processing carried out, blocking of certain personal data, a flat-rate fine, or withdrawal of the authorisation. Art. 65 fixes the flat-rate fine by reference to turnover rather than to a currency ceiling, which is unique among the Francophone rows: proportionate to the gravity of the failures and the advantages drawn from them, it is one per cent of pre-tax turnover for the last closed financial year on a first failure and five per cent on recidivism, recovered as a debt due to the State. Arts. 67 to 75 then set specific CIL fines: 5,000,000 to 10,000,000 francs CFA for obstructing the CIL's action in three specified ways; 5,000,000 to 20,000,000 francs CFA for processing without the prior formalities prescribed by the Law, which is the provision that reaches a failure to obtain the art. 31 prior authorisation for decision-support or predictive-artificial-intelligence processing; 5,000,000 to 20,000,000 francs CFA for processing without the precautions needed to preserve data security and 1,000,000 to 10,000,000 francs CFA for communicating data to unauthorised third parties or intentionally accessing files without authorisation; 5,000,000 to 100,000,000 francs CFA for purpose diversion; 5,000,000 to 100,000,000 francs CFA for fraudulent, unfair or unlawful collection, and for health-research processing in breach of art. 36; 2,000,000 to 5,000,000 francs CFA for processing despite a legitimately founded objection; 10,000,000 to 100,000,000 francs CFA for keeping sensitive data in computerised memory without express agreement, and for offence, conviction or security-measure data outside the permitted cases; 5,000,000 to 20,000,000 francs CFA for retaining identifiable data beyond the declared or authorised period, except for State processing; and 5,000,000 to 20,000,000 francs CFA for unauthorised divulgation harming honour, consideration or the intimacy of private life, reduced to 2,000,000 to 5,000,000 francs CFA where committed by imprudence or negligence. Art. 15 is named in none of them, so the route to it is the art. 63 general list including the art. 65 turnover-based flat-rate fine. Art. 76 lets the CIL order confiscation of the material media carrying the data or their erasure, even where the media do not belong to the sanctioned person, and, where it sanctions under arts. 67 to 75, ban the controller from managing any processing personally or through an intermediary for up to two years. Art. 77 lets it order publication of the decision or extracts in one or more newspapers at the sanctioned person's expense. Art. 64 requires sanctions to rest on a report by a CIL member designated by the President, notified to the controller, who may file observations and be represented or assisted at a hearing, requires decisions to be reasoned and notified, and makes sanction decisions appealable to the competent administrative court. Art. 66 lets the President of the CIL, or the person whose rights and freedoms are violated, apply in référé for any measure necessary to safeguard those rights, under astreinte, where the infringement of the Chapitre 2 rights is serious and immediate, and preserves compensation for moral or material damage.

In force · 30 Mar 2021 checked 17 Aug 2026 Loi n° 001-2021/AN art. 15 ↗ medium confidence

Burundi 1

Burundi Binding

Loi 1/03 arts. 19-20 — the automated decision a human must retake from scratch, and the first statute here to name AI in an operative duty

Binds Responsables du traitement and sous-traitants. Art. 2 applies the Law to any automated or non-automated processing of personal data by a natural person, the State, local authorities and legal persons of public or private law; to any processing by a controller or processor «établi ou non sur le territoire burundais» that resorts to processing means situated in Burundi, excluding means used only for transit; and to processing concerning public security, defence, the investigation and prosecution of criminal offences or State security, subject to the derogations the Law itself defines and to specific provisions in other legislation. A controller or processor not established in Burundi designates a representative established there unless its processing is occasional, without prejudice to actions that may be brought against it. Art. 3 excludes processing by a natural person in the exclusive framework of personal or domestic activities provided the data are not intended for systematic communication to third parties or dissemination, and temporary technical copies made for automatic, intermediate and transitory storage in transmission and network-access activities. Impact tier: all entities — arts. 19 and 20 turn on the effects of the decision, legal or important effects on the data subject's situation, not on the size or sector of the entity taking it, and art. 17(7)'s artificial-intelligence disclosure item attaches to every collection of personal data from the data subject regardless of effect.. Articles 19 and 20 of Loi n°1/03 du 10 mars 2026 portant protection des données à caractère personnel give Burundi the most demanding automated-decision regime on the tracker, and the Law is also the first tracked data-protection statute to name l'intelligence artificielle in an operative duty rather than in a recital or a definition. Art. 20 is a permission rule, not a right to object: «les prises de décisions automatisées produisant des effets juridiques ou des effets importants sur la situation de la personne concernée, ne sont autorisées que lorsque» they are provided for by a legislative or regulatory act laying down appropriate safeguards, taken with the data subject's consent, or strictly necessary for the conclusion or performance of a contract between the data subject and the controller. Where such a decision is permitted it must be accompanied by an individual motivation — which, the article concedes, may itself be produced by automated processing — and then comes the limb that has no equivalent anywhere else on the tracker: after learning the decision and its motivation, the data subject «a le droit de faire reformuler la décision», is invited by the controller to submit written observations in support of their case, and «une nouvelle décision motivée est prise par un être humain, qui remplace entièrement la première». Not a right to human intervention alongside the machine, as in GDPR art. 22(3), but a right to have the automated decision vacated and retaken by a person. Art. 19 supplies the transparency half twice over. Its first paragraph: where an automated decision produces legal effects or important effects on the data subject's situation, the existence of the automatism must be signalled to them and «la logique sous-jacente du traitement lui être expliquée en termes clairs et simples» — explained in clear and simple terms, a plain-language standard rather than the GDPR's «informations utiles». Its second paragraph reaches the decision-support case that most statutes leave untouched: where the processing merely aids a decision with such effects, the controller «décrit l'apport propre du décideur humain intervenant après l'automatisme, en particulier les méthodes et les critères sur lesquels il fonde son appréciation» — describes what the human decider actually added after the machine, and on what methods and criteria. That is a rubber-stamp rule: it puts the burden on the controller to show the human in the loop did something. Art. 20 closes with a sentence whose drafting is imperfect in the gazetted text — «Les motivations de la décision humaine ne peuvent s'appuyer que sur les résultats du traitement automatisé opaque» — which as printed says the opposite of what its Kirundi column and its context indicate, namely that the human decision's reasons cannot rest on opaque automated output; it is quoted here as gazetted rather than silently corrected. Upstream of all of this, art. 17(7) makes «du traitement des données à l'aide de l'intelligence artificielle pour la prise de décision automatisée» a mandatory item of the information the controller gives the data subject at the moment the data are obtained, and art. 21 carries the same list, plus the source of the data, into indirect collection with a one-month deadline. Impact tier: all entities.

Force, and the date is exact. Art. 55, the final article, provides «La présente loi entre en vigueur le jour de sa promulgation», and the instrument closes «Fait à Gitega, le 10 mars 2026», signed by President Evariste Ndayishimiye and countersigned by the Minister of Justice, Human Rights and Gender, Alfred Ahingejeje, under the seal of the Republic — so entry into force is 10 March 2026 with no vacatio legis. Art. 54 abrogates all earlier contrary provisions. Two forward deadlines follow from art. 53, which requires all processing to answer the Law's prescriptions within, from entry into force, one year for processing carried out on behalf of the State, a public establishment, a local authority or a private legal person charged with a public-service mission — 10 March 2027 — and six months for processing carried out on behalf of anyone else — 10 September 2026. Art. 52 leaves public-sector processing that predates entry into force subject only to a declaration to the data-protection organ. Neither transition suspends arts. 19 and 20 for processing begun after 10 March 2026. Supersession: none; the Law is four months old. Text read in the copy published by the Agence de Régulation et de Contrôle des Télécommunications, the Burundian regulator, on its own gov.bi site, which posted it on 18 March 2026; the file is the signed and sealed original, 32 pages, printed in parallel French and Kirundi columns with the initials of the signatories on every page, and it is image-only (Flate-wrapped DCTDecode page streams, no text layer), so it was read as page images. Coverage of the read: arts. 1-3 object, scope and exclusions; the head of the art. 4 definitions; arts. 11-12 on processors; the whole of the automated-decision material — arts. 17 information at collection, 19 explanation duties, 20 permission rule and human re-decision, 21 indirect collection and 22 opposition — verbatim; art. 46 breach notification; and the whole of Chapitre VII, arts. 47-51, and Chapitre VIII, arts. 52-55. Confidence high on the substance: arts. 19, 20 and 17(7) were read verbatim in the signed original and the entry-into-force clause is explicit and dated on its face. Two points are recorded as read rather than resolved. First, the art. 20 closing sentence quoted in the summary is defective as gazetted and no corrigendum was found. Second, «intelligence artificielle» appears in the operative text of art. 17(7) but is not defined: the art. 4 definitions run in French alphabetical order and no artificial-intelligence entry sits between «fichier de données à caractère personnel» and «personne concernée par un traitement», where one would fall. Institutionally the Law creates a data-protection organ and, per the regulator's own announcement and the parliamentary record of the 15 January 2026 adoption, an agency under the Ministry with responsibility for the digital economy; the standing-up of those bodies was not verified against primary text in this pass and no claim about their present operation is made here.

Stated maximum penalty — Up to 20,000,000 Burundian francs for a private legal person, or six months to five years' imprisonment with a fine of 500,000 to 10,000,000 francs for a natural person, and the route to arts. 19-20 is indirect: the penal chapter, arts. 47-51, names no article of the Law, so the automated-decision provisions are enforced through the general offences rather than through a limb of their own. The one that fits them is art. 48, which punishes whoever, even absent any data breach, has collected or processed data «de manière déloyale, illicite ou non transparente au regard des personnes concernées» for purposes that are undetermined, non-explicit, illegitimate or incompatible with the original purposes — the non-transparency limb is what an undisclosed automated decision or an unexplained logic engages. It carries six months to five years' penal servitude and a fine of 500,000 to 10,000,000 Burundian francs, or one of those penalties alone, where the author is a natural person, and a fine of 5,000,000 to 20,000,000 francs where the offence was committed by a private legal person, that second figure being doubled where the offender is a responsable majeur de traitement. Art. 47 punishes any personal-data breach with three months to one year and a fine of 50,000 to 500,000 francs for an intentional natural person, or 1,000,000 to 20,000,000 francs for a private legal person, and allows a suspension of activities of up to six months on recidivism where the legal person is a responsable majeur de traitement. Art. 50 sets 500,000 to 5,000,000 francs for processing revealing racial or ethnic origin, political, philosophical or religious opinions, trade-union membership or health data, and for biometric processing for the selective identification of a natural person, outside the art. 10 conditions. Art. 49 punishes obstruction of archival, scientific, historical or statistical processing. Art. 51 preserves the penal provisions of other laws, naming the cybercrime law and the Penal Code, so the fines above are floors rather than the whole exposure. Upstream of the criminal route, art. 46 obliges the controller to notify the data subjects themselves, within 96 hours of becoming aware, of a breach of the obligations flowing from processing liable to create a high risk to their rights and freedoms, in clear and simple terms.

In force · 10 Mar 2026 checked 21 Aug 2026 Loi 1/03 arts. 19-20 ↗ high confidence

Benin 1

Benin Binding

Code du numérique art. 401 — a Directive-shaped bar widened to significant effects, with profiling named, mandatory safeguards inside the exception and a full logic-disclosure right

Binds Responsables du traitement within the scope of Livre cinquième, whose art. 379 states that the Livre's provisions establish a legal framework for the protection of private and professional life consequent on the collection, processing, transmission, storage and use of personal data, and that any processing, in whatever form, must respect the fundamental rights and freedoms of natural persons whatever their nationality or residence, while taking account of the prerogatives of the State, the rights of local authorities and the purposes for which undertakings were created. Prior formalities under Chapitre III of Titre II are a standing precondition, and Chapitre IV imposes the controller obligations, including the arts. 415 and 416 information duties that carry the automated-decision disclosure. The Autorité de Protection des Données à caractère Personnel established by Titre III supervises. The first paragraph of art. 401 binds the courts themselves; the second binds any decision-maker whose decision produces legal effects or significantly affects the person, irrespective of size or sector. Impact tier: all entities.. Article 401 of Loi n° 2017-20 du 20 avril 2018 portant code du numérique en République du Bénin, headed "Fondement d'une décision de justice — Aspects de la personnalité d'une personne physique", is Benin's operative automated-decision rule. It sits in Livre cinquième (protection of personal data), Titre II, Chapitre IV, immediately after the direct-marketing prohibition in art. 400. Its first paragraph bars any judicial decision involving an appraisal of the conduct of a natural person from having as its foundation an automated processing — expressly including profiling — of personal data intended to evaluate certain aspects of that person's personality. Its second paragraph bars any decision producing legal effects with regard to a person, or significantly affecting them, from being taken on the sole basis of an automated processing of data intended to evaluate certain aspects of their personality: the significant-effects limb is what separates Benin from Senegal, Morocco and Algeria, whose second limb stops at legal effects. Its third paragraph is the exception, and it is conditional rather than absolute — the prohibition does not apply where the decision is taken in the context of a contract or is founded on a provision laid down by or under the provisions of the Livre, a decree or an ordinance, but that contract or provision must contain appropriate measures safeguarding the legitimate interests of the person concerned, and the person must at least be permitted to put their point of view usefully. Benin is unusual among the Francophone rows in defining profiling: art. 1 defines it as any form of automated processing of personal data consisting in using those data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict elements concerning work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Unlike Senegal, Côte d'Ivoire, Morocco and Algeria, Benin also carries a full logic-disclosure right modelled on the GDPR: arts. 415 and 416 require the controller to inform the data subject, at collection and where data are obtained indirectly, of the existence of automated decision-making including profiling within the meaning of art. 401 and, at least in such cases, of useful information about the underlying logic and about the significance and the envisaged consequences of that processing for the data subject, and the access right repeats the same entitlement, with a copy of the information to be supplied without delay and at the latest within sixty days of the request. Art. 401 processing is also a named data protection impact assessment trigger: a systematic and extensive evaluation of personal aspects based on automated processing including profiling, on the basis of which decisions producing legal effects or similarly significantly affecting a natural person are taken, requires a prior impact assessment. There is no right to obtain human intervention or a fresh non-automated decision; the safeguard the Law names is the opportunity to put one's point of view usefully, and it exists only inside the exception.

The Code carries no commencement article: its final provision abrogates earlier texts, naming among them Loi n° 2009-09 du 24 mai 2009 portant protection des données à caractère personnel en République du Bénin, and ends with a bare execution clause, "La présente loi sera exécutée comme loi de l'État". The date recorded is the date the Law bears, 20 April 2018, which is also the date printed in the running head of every page of the enacted text. Confidence is medium for the same reason as the other Francophone rows: the Beninese general publication-to-force rule was not read against a primary source, and the date of the Journal officiel de la République du Bénin carrying the Code could not be established from an official host this run, so entry into force can only be that date or later. Supersession is settled on the face of the text: Loi n° 2009-09 of 2009 is abrogated and is not tracked. Note the Law's own numbering oddity, which is not an error in this entry — the instrument is numbered 2017-20 but dated 20 April 2018, because it was voted by the Assemblée nationale in 2017 and promulgated in 2018. One drafting defect is recorded for candour: art. 461, which fixes the penalties, refers to "les infractions visées à l'article 445" where the offence list is in fact art. 460, and the same article then refers correctly to "l'article 460" twice in its later paragraphs, so the cross-reference in the first sentence is a slip. Text read in the edition of the Code printed by the Autorité de Protection des Données à caractère Personnel, the supervisory authority established by Titre III of Livre cinquième, which carries the Assemblée nationale imprint; art. 401 and its heading, arts. 415 and 416, the impact-assessment article, the arts. 452 to 459 administrative chapter and the arts. 460 and 461 penal chapter were each read in full. Coverage symmetry against the thirteen African rows already tracked: art. 401 is the hybrid of the Francophone group. Its shape is the Directive 95/46/EC art. 15 shape — a judicial limb, a general limb, an exception — but three features are imported from the GDPR: the significant-effects alternative in the second limb, the express naming of profiling as a defined term, and the logic-disclosure and impact-assessment machinery. That makes Benin the bridge between the two African lineages rather than a member of either. Within the Francophone family the split is now three ways: Senegal, Morocco and Algeria keep the Directive drafting with a legal-effects threshold and a deeming clause; Côte d'Ivoire and Niger take the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting in which any administrative or private decision appraising human conduct is caught; Benin keeps the Directive skeleton and grafts GDPR flesh onto it. Benin's exception is also the strongest-conditioned of the Francophone rows: where Senegal, Morocco and Algeria simply deem contract decisions with an opportunity to present observations outside the bar, and Niger admits consent, contract and legal authorisation outright, Benin requires the contract or the enabling provision itself to contain appropriate measures safeguarding the person's legitimate interests, with the right to put one's point of view usefully as an express minimum. The four-way African lineage picture: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, sn-loi200812-art48, ci-loi2013450-art25, ne-loi202259-art52 and now bj-code-num-art401 as its GDPR-inflected outlier; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — No offence reaches art. 401 directly. Art. 460 enumerates fifteen offences under Livre cinquième — obstructing the Autorité in three specified ways, processing without the prescribed prior formalities, knowingly using data collected by a fraudulent process, processing sensitive, offence-related or national-identification-number data outside the permitted conditions, processing without implementing the prescribed measures, collecting data by fraudulent, unfair or unlawful means, diverting or manipulating data held for registration, classification, transmission or other processing, transferring data to a third State without satisfying the transfer requirements, using violence, threats, gifts or promises to compel a person to hand over information obtained under art. 436 or to consent to processing, processing despite a well-founded rectification request or objection, failing to respect the Livre's provisions on informing data subjects, failing to respect its provisions on access rights, retaining data beyond the declared period outside historical, statistical or scientific purposes, unauthorised divulgation harming the person's consideration or the intimacy of their private life, and participating in an association or agreement formed to commit any of those offences — and the automated-decision bar is not among them. Two of the fifteen do reach the disclosure duties that art. 401 feeds: the failure to respect the Livre's provisions on informing data subjects and the failure to respect its provisions on access rights both catch a controller that withholds the art. 415, 416 and access-right information about the existence of automated decision-making including profiling, the underlying logic, and its significance and envisaged consequences. Art. 461 punishes those offences with imprisonment of six months to ten years and a fine of 10,000,000 to 50,000,000 francs CFA, or one of those penalties only, with complicity and attempt punished identically; where the formalities offence is committed by simple negligence only a fine of 5,000,000 to 50,000,000 francs CFA may be imposed. The court may order erasure of all or part of the data processed, may pronounce complementary penalties including confiscation of the material media carrying the data, excluding computers, and final convictions are published in the Journal officiel de la République du Bénin and on an electronic medium at the convicted person's expense. The route that reaches art. 401 itself is administrative. Art. 452 lets the Autorité issue a warning to a controller that does not respect the obligations arising under the Livre and a formal notice to end the observed failure within a period not exceeding eight days. Art. 453 defines grave failures — unfair collection, communication to an unauthorised third party, unlawful collection of sensitive, offence-related or national-identifier data, collection or use causing serious harm to fundamental rights or to the intimacy of private life, and obstruction of an on-site inspection. Art. 454 lets the Autorité, respecting the adversarial principle, impose a pecuniary sanction (except where the processing is implemented by the State), an injunction to cease the processing, definitive or temporary withdrawal of the authorisation, or blocking of certain data. Art. 455 fixes the amount: proportionate to the gravity of the failures and the advantages drawn from them, not exceeding 50,000,000 francs CFA on a first failure and, on a repeated failure within five years from the date the previous pecuniary sanction became definitive, not exceeding 100,000,000 francs CFA or, for an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of 100,000,000 francs CFA; where the Autorité's pecuniary sanction becomes definitive before the criminal court rules on the same or connected facts, that court may set the sanction off against its fine. Art. 456 lets any sanction be coupled with an injunction to make any useful modification or deletion in the operation of the processing within a period not exceeding eight days; art. 457 requires a report notified to the controller, who has fifteen days to make written or oral observations and may attend or be represented; art. 458 makes sanction decisions appealable to the competent administrative court; and art. 459 lets the Autorité publish the sanctions imposed.

In force · 20 Apr 2018 checked 22 Aug 2026 Code du numérique art. 401 (Loi n° 2017-20) ↗ medium confidence

Brazil 3

Brazil Binding

Brazil LGPD Art. 20 — right to review of solely-automated decisions

Binds Processing agents (controllers and operators) under LGPD Art. 3 — processing carried out in Brazil, processing aimed at offering goods or services to, or processing data of, individuals located in Brazil, or data collected in Brazil, regardless of where the agent or the data is based. Impact tier: all entities.. Data subjects may request review of decisions taken solely on the basis of automated processing of personal data that affect their interests, expressly including decisions that define personal, professional, consumer or credit profiles or aspects of personality. On request the controller must give clear and adequate information about the criteria and procedures used for the automated decision, subject to trade and industrial secrecy; where secrecy is invoked the ANPD may audit the processing for discriminatory effects.

Art. 20 as amended by Lei 13.853/2019: the original "por pessoa natural" wording was removed, so this is a right to review, NOT a guaranteed human-review right. The proposed reinstatement (Art. 20 s.3) was vetoed. Commencement traced through Art. 65: Lei 13.853/2019 set Art. 65 II at 24 months after publication (LGPD published DOU 15.8.2018); MP 959/2020 (DOU 29.4.2020, in force on publication) art. 4 pushed Art. 65 II to 3 May 2021; Congress dropped that amendment on conversion, and the conversion law Lei 14.058/2020 (17 Sept 2020, DOU 18.9.2020, in force on publication) contains no amendment to Lei 13.709 — so the postponement fell away and the general articles, including Art. 20, took effect on 18 September 2020. The administrative sanctions regime (Arts. 52-54) commenced separately on 1 August 2021 under Art. 65 I-A, inserted by Lei 14.010/2020. Coverage-symmetry check 2026-08-14: no ANPD normative act specifically regulating AI or automated decision-making — a DOU sweep of "RESOLUÇÃO CD/ANPD" and of ANPD acts mentioning inteligência artificial / decisões automatizadas returned only internal-organisation and international-transfer resolutions (e.g. Res. 32/2026 EU adequacy, Res. 33/2026 staffing). Brazil's AI-specific bill remains proposed — see br-pl2338.

Stated maximum penalty — LGPD Art. 52: warning; simple fine up to 2% of the private-law entity's, group's or conglomerate's Brazilian turnover in its last financial year, excluding taxes, capped in total at R$50,000,000 per infraction; daily fine; publicisation; blocking, deletion, partial or total suspension of processing or of the database (up to 6 months, renewable); partial or total prohibition of processing activities. ANPD enforcement; sanctions applicable since 1 August 2021 (Art. 65 I-A).

In force · 18 Sep 2020 checked 14 Aug 2026 LGPD (Lei 13.709/2018) Art. 20 ↗ high confidence
Brazil Binding

Brazil ECA Digital (Lei 15.211/2025) — algorithmic duties for services used by minors

Binds Suppliers of information-technology products or services (including internet application providers, social networks, app stores, electronic games and child-monitoring products) that are directed at children and adolescents or likely to be accessed by them, offered in Brazilian territory, including foreign companies, which must keep a legal representative in Brazil (Art. 40). Art. 39 modulates the duties in Arts. 6, 17, 18, 19, 20, 27, 28, 29, 31, 32 and 40 by the product's characteristics and functionalities, the provider's degree of interference over content, user numbers and size, and exempts editorially-controlled services and licensed-content providers that meet the four conditions in Art. 39 s.1. Impact tier: all entities, modulated by size and degree of content control.. Providers of information-technology products or services directed at, or likely accessed by, children and adolescents must give parents control over personalised recommendation systems, including the option to switch them off, and must regularly review the artificial-intelligence tools in the service with the participation of specialists and competent bodies against technical criteria that ensure their safety and suitability for use by minors, with non-essential functionalities capable of being disabled. Behavioural profiling of child and adolescent users for advertising is prohibited, as is profiling-based ad targeting and the use of emotional analysis, augmented, extended or virtual reality for that purpose. Where content is removed, the provider must tell the user whether the content was identified by human or automated analysis.

Lei 15.211/2025 ("ECA Digital"), sanctioned 17 September 2025 and published DOU 17.9.2025 extra edition. Art. 41-A originally set entry into force at six months after publication (inserted by MP 1.319/2025); the version now in force, inserted by Lei 15.352/2026, fixes the date expressly: "Esta Lei entra em vigor em 17 de março de 2026." Scope call 2026-08-14: kept in the tracker because the statute imposes express algorithmic-system duties rather than only platform-safety duties — Art. 17 s.4 V (control over personalised recommender systems with an off switch as a default parental-supervision setting), Art. 17 s.4 VIII (regular expert review of AI tools in the service), Art. 30 II (disclosure of whether a removal decision came from human or automated analysis), Art. 22 (ban on profiling for ad targeting and on emotional analysis / AR / XR / VR for that purpose) and Art. 26 (ban on building behavioural profiles of minors from personal, group or collective data, including data obtained in age verification, for advertising). Art. 24 s.3 age-assurance and Art. 27 automated illicit-content detection duties feed the separate transparency-report obligation tracked as br-lei15211-art31-report. Enforcement: Art. 34 gives the autonomous administrative authority for the protection of children's and adolescents' rights in the digital environment supervisory and complementary-rulemaking power; Decreto 12.622/2025 designates the ANPD as that authority and Decreto 12.880/2026 (DOU 18.3.2026 extra edition) is the implementing regulation. Distinct from br-lgpd-art20, which is a data-subject right under the LGPD.

Stated maximum penalty — Art. 35: warning with up to 30 days to take corrective measures; simple fine of up to 10% of the economic group's Brazilian turnover in its last financial year or, absent turnover, R$10 to R$1,000 per registered user, capped in total at R$50,000,000 per infraction; temporary suspension of activities; prohibition of activities. Fines and warnings are applied by the ANPD; suspension and prohibition by the Judiciary (Art. 35 s.5) and enforced if needed by blocking orders to connectivity providers, IXPs and DNS resolvers (Art. 35 s.6). A foreign company's Brazilian branch or establishment is jointly liable for the fine (Art. 35 s.2); fine amounts are indexed annually to the IPCA (Art. 35 s.4).

In force · 17 Mar 2026 checked 14 Aug 2026 Lei 15.211/2025 (ECA Digital) ↗ high confidence
Brazil Binding

Brazil ECA Digital Art. 31 — semi-annual transparency report, first due 17 September 2026

Binds Internet application providers directed at or likely accessed by children and adolescents with more than 1,000,000 registered users in that age band with an internet connection in Brazilian territory. Exempt: providers below that threshold, and editorially-controlled services and licensed-content providers meeting the four conditions in Art. 39 s.1 (Despacho Decisório CD/ANPD 122/2026 item VII). Impact tier: enterprise.. Internet application providers directed at, or likely accessed by, children and adolescents with more than 1,000,000 registered users in that age band connecting from Brazil must publish semi-annual reports in Portuguese on their own website. The report must cover the complaint channels and investigation systems, the number of complaints received, the volume of content and account moderation by type, the measures used to identify child accounts on social networks under Art. 24 s.3 and to identify illicit acts under Art. 27, technical improvements for personal-data protection and privacy and for ascertaining parental consent under LGPD Art. 14 s.1, and the methods used and results of impact assessments and of the identification and management of risks to the safety and health of children and adolescents. Providers must also give academic, scientific, technological, innovation and journalistic institutions free access to the data needed to research the service's impact on minors.

Art. 31 of Lei 15.211/2025 has been in force since 17 March 2026 (Art. 41-A as amended by Lei 15.352/2026), but the statute only says the reports are semi-annual and sets no publication date. Despacho Decisório CD/ANPD 122/2026 (DOU 11.8.2026, Section 1, p. 59) fixes the calendar until specific regulation supervenes: the time runs from entry into force on 17 March 2026; the first report covers 1 January to 30 June 2026, and providers without data for January and February may limit it to 17 March to 30 June 2026; the first report must be published by 17 September 2026 (item III); from the second report the periods follow the civil semesters, published by 1 August for the first semester and by 1 February for the second (item IV). Art. 45 of Decreto 12.880/2026 adds, under Art. 31 II, the number of notifications received by category and proportional data on how they were followed up. Art. 47 of the decree requires the child-safety-and-health impact assessment behind Art. 31 VII, with a plain-language summary made public, and lets an ANPD act set its minimum content and periodicity. The ANPD recommends emailing a copy of each report to monitoramento@anpd.gov.br at publication (item VIII). Tracked separately from br-lei15211-eca-digital because 17 September 2026 is a distinct near-term deadline.

Stated maximum penalty — Art. 35: warning with up to 30 days to correct; simple fine up to 10% of the economic group's Brazilian turnover in its last financial year or, absent turnover, R$10 to R$1,000 per registered user, capped at R$50,000,000 per infraction; temporary suspension of activities; prohibition of activities. ANPD applies the warning and fine (Art. 35 s.5).

Applies 17 Sep 2026 checked 22 Aug 2026 Lei 15.211/2025 Art. 31; Despacho CD/ANPD 122/2026 ↗ high confidence

Canada 1

Canada Binding

Quebec Law 25 — automated decision transparency

Binds Organisations making automated decisions using personal information in Quebec. Right to be informed + disclosure of key factors for automated decisions using personal info (Quebec).

Stated maximum penalty — AMPs up to C$10M / 2% turnover

In force · 22 Sep 2023 checked 13 Aug 2026 Quebec Law 25 (s.12.1) ↗ high confidence

Democratic Republic of the Congo 1

Democratic Republic of the Congo Binding

Code du numérique art. 209 — the logic behind the decision must be disclosed, but no decision is ever forbidden

Binds Responsables de traitement — controllers — and their representatives, with sous-traitants (processors) reached through the same Titre. Art. 184 fixes the scope in four limbs and it is unusually wide: the Titre catches the collection, processing, transmission, storage and use of personal data by l'Etat, la Province, Entités Territoriales Décentralisées et Déconcentrées, legal persons of public or private law and natural persons; processing automated or not of data contained in or intended for a file; «le traitement de données mis en œuvre sur le territoire national ou à l'étranger» — processing implemented on the national territory or abroad, with no establishment, targeting or means limb to narrow it; and processing concerning public security, defence, the investigation and prosecution of criminal offences or State security, subject to derogations laid down by other legislation in force. Art. 185 excludes processing by a natural person in the exclusive framework of personal or domestic activities provided the data are not intended for systematic communication to third parties or for dissemination; temporary copies made in the technical activities of transmission and of providing access to a computer network for automatic, intermediate and transitory storage; and processing by competent authorities for the prevention and detection of criminal offences, investigations and prosecutions or the execution of criminal penalties. Impact tier: all entities — art. 209 attaches to every controller subject to the Titre with no employee-count, turnover, sector or high-risk-system threshold, and because the disclosure duty is triggered by the existence of automated decision-making including profiling rather than by a legal-effects threshold, a scoring or profiling deployer owes it even where the DPIA trigger in art. 245 would not bite.. Article 209 of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique is the Democratic Republic of the Congo's automated-decision provision, and it is the mirror image of Angola's. The DRC's data-protection Titre is GDPR-template — it carries a délégué à la protection des données, a portability right, and a data-protection impact assessment — but it took the transparency half of the GDPR's automated-decision package and left the prohibition behind. Under art. 209, the natural person whose personal data are processed may ask the controller for, among other things, «l'existence d'une prise de décision automatisée, y compris un profilage, et, au moins en pareils cas, des informations utiles concernant la logique sous-jacente, ainsi que l'importance et les conséquences prévues de ce traitement pour la personne concernée» — the existence of automated decision-making, including profiling, and at least in such cases meaningful information about the underlying logic as well as the significance and the envisaged consequences of that processing for the data subject. The same limb is repeated twice more as an up-front duty rather than an on-request one: art. 220 requires the controller or its representative to give it to the data subject at the latest at the moment of collection, whatever the means and medium employed, and art. 235 requires it where the data were not collected from the data subject. Art. 245 then makes «l'évaluation systématique et approfondie d'aspects personnels concernant des personnes physiques, qui est fondée sur un traitement automatisé, y compris le profilage, et sur la base de laquelle sont prises des décisions produisant des effets juridiques à l'égard d'une personne physique ou l'affectant de manière significative de façon similaire» the first named trigger for a mandatory data-protection impact assessment. What is absent is the GDPR art. 22 analogue. Nothing in the Titre gives a right not to be subject to a decision based solely on automated processing, and there is no human-intervention right and no right to contest the decision after the fact. The rights section, Chapitre VI Section 1, runs from art. 209 through the general opposition right in art. 213 — a right exercisable «à tout moment, pour des motifs légitimes» against processing as such, not against automated decisions as a category — and never reaches a prohibition. Nor is profiling gated ex ante: art. 187 lists the processing operations needing prior authorisation from the Autorité de protection des données — genetic and medical data and research on them, offence and conviction data, national identification numbers and other identifiers of the same nature including telephone numbers, biometric data, and public-interest processing — and automated decision-making and profiling are on none of those limbs; art. 186 leaves them in the ordinary prior-declaration regime. So the DRC and Angola between them bracket the two halves of the GDPR provision: Angola forbids the decision and never makes anyone disclose the logic, the DRC compels disclosure of the logic three times over and never forbids the decision. Impact tier: all entities.

Force, and the date is exact. Art. 390, the final article, provides «La présente ordonnance-loi entre en vigueur à la date de sa promulgation» — the Ordonnance-loi enters into force on the date of its promulgation — and the instrument closes «Fait à Kinshasa, le 13 mars 2023», signed by President Félix-Antoine Tshisekedi Tshilombo and countersigned by Prime Minister Jean-Michel Sama Lukonde Kyenge, so entry into force is 13 March 2023 with no vacatio legis and no phased application. Art. 389 abrogates all earlier provisions contrary to the Ordonnance-loi. Art. 388 carries the only transition: digital-service providers operating on titles obtained before the Ordonnance-loi had six months from entry into force — to 13 September 2023 — to bring themselves into conformity; that window is long closed and it did not defer art. 209 for anyone else. Supersession: none. Text read in the certified copy of the Ordonnance-loi issued by the Cabinet of the President of the Republic — the last page carries the stamp «Pour copie certifiée conforme à l'originale, Le 13 mars 2023, Le Cabinet du Président de la République, Guylain NYEMBO MBWIZYA, Directeur de Cabinet» — which is the same 175-page file the Autorité de régulation publishes on are.gouv.cd (the ARE download page states 45.30 MB against the 47,498,251 bytes of the copy read, i.e. the same file). That satisfies Primary Source First on the same footing as the Angola, Chad and Equatorial Guinea copies. Two independent renderings of the same instrument were used and cross-checked against each other: the certified scan, which is image-only (Flate-wrapped DCTDecode page streams, no text layer) and was read as page images; and a born-digital rendering whose text layer covers arts. 186 to 390 contiguously with no missing article heading, which was used for full-text search. Coverage of the read: arts. 184 scope and 185 exclusions verbatim; art. 186 prior declaration and art. 187 prior authorisation in full; arts. 209 and 210 verbatim in the scan, including the logic-disclosure indent of art. 209(2); arts. 212 and 213 verbatim; arts. 219, 220, 235 and 245 in the text layer; the enforcement chain at arts. 255 to 258; and arts. 383 to 390 verbatim in the scan. The negative finding — no art. 22 analogue — rests on both renderings: a normalised full-text search of arts. 186-390 returns no «ne pas faire l'objet d'une décision», no «décision individuelle», and no occurrence of «automatis» outside the seven hooks listed here, and the rights-section pages were additionally read as images to guard against the lossy-text-layer failure mode that parked Cabo Verde. Confidence high: the disclosure limb was read verbatim in a certified government copy, the entry-into-force clause is explicit and dated on its face, and the sanction route was traced through arts. 255-257 rather than assumed. No AI-specific statute is in force in the DRC and the data-protection Titre neither defines nor separately regulates artificial-intelligence systems; its automated-decision hooks are the three disclosure limbs and the DPIA trigger.

Stated maximum penalty — 8,000,000 to 200,000,000 Congolese francs, but only on the second step — the enforcement chain runs through a mise en demeure and the fine attaches to defying it, not to the underlying breach. Art. 255 lists the manquements under the Titre, among them unfair collection, communication of personal data to an unauthorised third party, collection of sensitive, strategic, offence-related or national-identification-number data without meeting the legal conditions, collection or use of personal data having the consequence of seriously infringing fundamental rights or the intimacy of the data subject's private life, and obstructing an on-site inspection by the services of the Autorité de protection des données. Art. 256 then gives the Autorité a warning against a controller that fails to comply with the obligations flowing from the Titre, and lets it put the controller on formal notice — mise en demeure — to end the established breach within a fixed period «qui ne peut excéder huit jours», not exceeding eight days. Art. 257 is the sanction: where the controller does not comply with the mise en demeure, the Autorité may, respecting the adversarial principle, order (1) payment of eight million to two hundred million Congolese francs where the violation had no serious impact on the State and/or the data subjects; (2) payment of 5% of its annual turnover excluding tax for the closed financial year where the violation led to the death or attempted murder of one or more persons; or (3) an injunction to cease the processing of personal data where the violation endangered national security and safety and/or led to a mass crime or genocide. The turnover limb is drafted to homicide and mass-atrocity outcomes rather than to data-protection gravity, which is unusual and means that in the ordinary case — an undisclosed scoring model — the exposure is the capped 8M-200M CDF band, not a percentage of turnover. Art. 257 also reserves the State's right to bring criminal proceedings against the controller and to claim damages. Art. 258 makes the sanction pronounced by the Autorité appealable. Separately, art. 310 sets the penalties for cybercrime offences as servitude pénale, fine and special confiscation, and art. 311 makes the maximum fine for legal persons five times that for natural persons; those are the cybercrime Livre, not the data-protection Titre, and do not attach to art. 209.

In force · 13 Mar 2023 checked 18 Aug 2026 Code du numérique art. 209 ↗ high confidence

Central African Republic 1

Central African Republic Binding

Loi 24.001 art. 30 — the access limb without the bar: the only tracked statute that lets you contest an automated decision but never forbids one

Binds Responsables de traitement, and through the art. 6 definition also sous-traitants, being any natural or legal person, public or private, any other body or association that processes data on the controller's behalf. The art. 4 scope is territorial-plus-effects and unusually explicit about the public sector: the Law applies to processing carried out in the context of the activities of an establishment of a controller or a processor on the territory of the Central African Republic, whether or not the processing takes place in the Central African Republic; to processing that deploys effects in the Central African Republic even where those effects arose abroad or through a controller established abroad; to processing concerning public security, defence, the investigation and prosecution of criminal offences or state security, subject to derogations fixed by other laws in force; to processing not provided for by a special law; and to processing in the context of court proceedings. Art. 4 excludes purely personal or domestic processing by a natural person, and temporary technical copies made for transmission and network access provision. Art. 31 removes the art. 30 right altogether for processing concerning public security and for the collection of information necessary to establish offences and pursue the consequent proceedings, and lets the controller refuse requests that are manifestly abusive by their number or their repetitive or systematic character, with the burden of proof on the controller in case of contestation. For state-security, defence and public-security processing the access and rectification rights are exercised indirectly through the agency rather than against the controller. No ex ante gate attaches to automated decision-making or to profiling: the only prior-authorisation regimes in the Law are art. 28, which subjects the interconnection of files held by legal persons managing a public service with differing public interests, processing operated by the State for users of remote e-administration services, and interconnection of files with differing purposes, to the prior authorisation of the agency — an interconnection must not entail discrimination or prejudice to rights, freedoms and guarantees — and arts. 24 to 27, which govern transfers. Those transfer articles are the first on the tracker to draw the free-flow perimeter around CEMAC and CEEAC rather than around a national adequacy list: a controller may transfer personal data to a state that is not a member of CEMAC or CEEAC only where that state ensures a sufficient level of protection, the agency must be informed before any such transfer, and art. 27 lets the agency authorise a transfer to a non-adequate non-member state where the controller offers sufficient guarantees, which may result from appropriate contractual clauses. Impact tier: all entities.. Article 30 of Loi 24.001 du 25 janvier 2024 portant protection des données à caractère personnel is the Central African Republic's only operative automated-decision provision, and it is an access limb, not a bar. It sits in Chapitre VI, Des droits liés au traitement des données à caractère personnel, which opens at art. 29 with the right of any person showing a legitimate motive to object at any time and free of charge to the processing of their personal data, and a free-standing right to object to the use of their data for prospection without having to justify a motive. Art. 30 then gives every person the right to be informed of the processing of their data, subject to proof of identity, and to obtain from the controller three things: information on the purposes of the processing, the categories of personal data processed and the recipients or categories of recipient to whom the data are communicated; the communication of all the data concerning them together with any available information as to their origin; and — the automated-decision limb — les informations permettant de connaître et de contester le mécanisme du traitement automatisé en cas de décision prise sur le fondement de celui-ci et produisant des effets juridiques à l'égard de l'intéressé, the information allowing the person to know and to contest the mechanism of the automated processing where a decision is taken on the foundation of that processing and produces legal effects in respect of them. That is the Directive 95/46/EC art. 12(a) third-indent form word for word, and it is the whole of it. The right is exercised free of charge, on the spot or remotely, and must be granted without delay, with a copy of the data conforming to the content of the processing delivered on request. What the Central African Republic does not have is the second half of the Directive template. There is no art. 15-style rule anywhere in the Law providing that a decision producing legal effects may not be taken on the sole foundation of an automated processing, no deeming clause for contractual decisions, no human-intervention right, and no GDPR art. 22 right of objection to automated decisions. The word automatisé appears exactly three times in the fifty-eight articles: in the art. 6 definition of Profilage, in the art. 6 definition of Traitement, and in this indent of art. 30. Nothing prohibits an automated decision in the Central African Republic; art. 30 only entitles the person, after the fact and on their own initiative, to be told how the machine worked and to argue with it. The Law is therefore the thinnest automated-decision regime yet recorded in the African block, and the only one where the rule is purely reactive.

Force. Art. 58, the Law's final provision, is explicit and self-executing: la présente Loi qui prend effet à compter de la date de sa promulgation, est enregistrée et publiée au Journal Officiel — the Law takes effect from the date of its promulgation, and publication in the Journal Officiel is a separate, non-suspensive formality. That removes the ambiguity that forced a medium confidence on Morocco, Congo-Brazzaville, Gabon and Cameroon, where the final article was a bare publication clause and the publication-to-force rule had to be assumed. Nothing in the Law defers art. 30. Confidence is nevertheless medium, for a different and narrower reason: the promulgation date is not legible in the copy read. The text was read in the scanned copy published by the Autorité de Régulation des Communications Électroniques et des Postes, the Central African regulator, and its title page carries only LOI N° 24.001 PORTANT PROTECTION DES DONNEES A CARACTERE PERSONNEL with no date, while the date block on the signature page — over the signature of President Faustin-Archange Touadéra — falls inside the stamped and handwritten region of the scan and does not survive text extraction. The date recorded here, 25 January 2024, comes from ARCEP's own regulation index, which cites the instrument as Loi 24.001 du 25 janvier 2024, portant protection des données à caractère personnel and lists it immediately beside Loi 24.002 du 21 février 2024, relative à la cybersécurité et à la lutte contre la cybercriminalité. That is the publishing regulator's own citation of the file it hosts, not a news report, and the 24.001 numbering is consistent with a January 2024 first law of the year; but it is one step removed from the face of the enacted text, so the entry is not marked high. The one dated duty in the Law has already run: art. 57 gives the Ministère en charge de l'Economie Numérique, des Postes et Télécommunications a period of twelve (12) months from promulgation to put in place the agency in charge of personal data protection, which expired on 25 January 2025, and provides that until the agency is in place its missions are discharged by the supervising Ministry. Whether the agency has since been constituted was not verified and does not affect the existence of the art. 30 duty, which runs against controllers directly; it affects only which body answers an indirect-access request under art. 32 and which body opens an administrative sanction file. Art. 58 also provides that a decree in Council of Ministers shall fix, as needed, the modalities of application of the Law; art. 30 is not among the provisions that await one and is operative on its own terms. Supersession: none. The Central African Republic had no dedicated data-protection statute before Loi 24.001 — its adjacent instruments are Loi 18.002 du 17 janvier 2018 régissant les communications électroniques, Loi 22.002 du 11 janvier 2022 régissant les transactions électroniques and the companion Loi 24.002 du 21 février 2024 relative à la cybersécurité, none of which carries an automated-decision rule. Nothing on the tracker is superseded by this row. No AI-specific statute is in force and the Law does not define artificial intelligence; Gabon's Loi 025/2023 remains the only Francophone African data-protection statute that does. Text read article by article across the fifty-eight articles of the ARCEP copy, covering the arts. 1 to 5 object and scope, the art. 6 definitions, the arts. 7 to 21 principles and sensitive-data regime, the arts. 22 to 27 transfer chapter, the art. 28 interconnection chapter, the arts. 29 to 36 rights chapter, the arts. 37 to 46 agency and administrative-sanction chapter, the arts. 47 to 56 penal chapter and the arts. 57 and 58 final provisions.

Stated maximum penalty — No penalty in the Law attaches to art. 30 by name, and the route to it is administrative. The agency's administrative sanctions are pronounced on the basis of a report drawn up by its services or by a member it designates; the report is notified to the controller, who may make written and oral observations and be represented or assisted, and the rapporteur may speak but does not take part in the deliberation. Decisions are reasoned, notified, made public, and may be published in journals the agency designates at the sanctioned person's cost, and they may be appealed to the administrative courts. The ceiling is turnover-based and is the operative maximum for an art. 30 refusal: le montant de la sanction pécuniaire ne peut excéder 5% du chiffre d'affaires hors taxes du dernier exercice clos, recovered as a debt due to the State. Every sanction decision must carry a period within which the object of the dispute is to be modified or suppressed, and the agency may go to the competent court by way of référé to obtain, if need be under a penalty payment, any security measure necessary to safeguard the rights and freedoms mentioned in art. 1. The penal chapter, Section 2 of Chapitre VIII, does not reach the access right, but it does reach the neighbouring art. 29 objection right, which is the closest criminal exposure a Central African controller running automated processing faces: two (2) to five (5) years' imprisonment and a fine of one million (1,000,000) to ten million (10,000,000) FCFA for anyone who processes the personal data of a natural person despite that person's request for rectification or objection, where the request is founded on legitimate grounds. The rest of the chapter, for context on the scale: six (6) months to five (5) years and 100,000 to 5,000,000 FCFA for obstructing the agency's missions; six (6) months to two (2) years and 100,000 to 2,000,000 FCFA for negligently processing without the prior formalities required by law; two (2) to five (5) years and 1,000,000 to 10,000,000 FCFA for collecting personal data by fraudulent, unfair or unlawful means; the same range for diverting a file from its initial purpose, notably on the occasion of recording, classification or transmission; six (6) months to two (2) years and 100,000 to 2,000,000 FCFA for retaining data beyond the period declared to the agency, unless the retention is for historical, statistical or scientific purposes on the conditions provided by law; and two (2) to five (5) years and 1,000,000 to 10,000,000 FCFA for bringing to the knowledge of an unqualified third party, without the data subject's authorisation, data whose disclosure harms the person's standing or the intimacy of their private life. The court may order the erasure of all or part of the data processed in the commission of an offence, and the agency's members and agents are empowered to verify that erasure. The Procureur de la République must inform the agency's Director General of prosecutions under the Law, and the trial court may call the Director General or their representative to file or develop observations at the hearing.

In force · 25 Jan 2024 checked 18 Aug 2026 Loi 24.001 art. 30 ↗ medium confidence

Republic of the Congo 1

Republic of the Congo Binding

Loi n° 29-2019 art. 13 — the Directive-shaped bar whose fine arrives only if the controller defies the formal notice

Binds Responsables de traitement and, through art. 12, anyone acting under their authority with access to personal data. The prior-formality regime runs through arts. 32 to 40: art. 32 and art. 33 carry the dispensations from formalities that art. 93 later cross-refers to, arts. 33 to 36 set the declaration regime, and art. 40 governs processing authorised by regulatory act, for which art. 94 requires the Commission to inform the Government so that it may take measures to end an established violation, the Government having fifteen days to report back on the action taken. Neither profiling nor automated decision-making is listed as a category attracting prior authorisation, so Congo imposes no ex ante gate on the processing art. 13 governs. Art. 82 provides for prior consultation of the Commission and arts. 90 and 91 for a data protection officer who must have due regard, in performing their tasks, to the risk associated with processing operations having regard to their nature, scope, context and purposes. The art. 13 bar binds the courts under its first limb and, under its second, every decision-maker whose decision produces legal effects in regard to a natural person, with no size or sector threshold. Impact tier: all entities.. Article 13 of Loi n° 29-2019 du 10 octobre 2019 portant protection des données à caractère personnel is the Republic of the Congo's operative automated-decision rule. It closes Chapitre 1 of Titre II on the principles governing processing, immediately after art. 12, which provides that a person acting under the authority of the controller and having access to personal data may process them only on the controller's instruction, and immediately before art. 14, which governs sensitive data. It has three unnumbered paragraphs and follows the Directive 95/46/EC art. 15 template closely. The first: no judicial decision involving an appraisal of the conduct of a natural person may have as its foundation an automated processing of personal data intended to evaluate certain aspects of their personality. The second: no decision producing legal effects in regard to a natural person may be taken on the sole foundation of an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third is a deeming clause rather than a true exception: decisions taken in the context of the conclusion or performance of a contract, and for which the person concerned was put in a position to present their observations, and decisions satisfying the requests of the person concerned, are not regarded as taken on the sole foundation of an automated processing. As in Guinea, Madagascar and Gabon, the judicial limb omits the word "seul" that the second limb carries, so a Congolese court appraising conduct may not rest on such a processing at all. The second limb takes the narrow Directive trigger confined to decisions producing legal effects, which places Congo with Gabon, Togo, Senegal, Morocco and Algeria rather than with the wide-trigger group. What distinguishes this row from every other Francophone entry is the thinness of what surrounds it. The Law creates no right to know the logic underlying an automated processing — the words logique, raisonnement and profilage appear nowhere in it — no human-review right, no right to a fresh non-automated decision, and no definition of profiling. Art. 13 is a bare prohibition with a deeming clause and nothing else.

The Law carries no commencement article. Art. 101, its final provision, is a bare publication and execution clause — the present Law shall be published in the Journal officiel de la République du Congo and executed as a law of the State — and nothing in the text defers art. 13. The date recorded here is the date of publication of the gazette in which the Law appears: Journal officiel de la République du Congo n° 45-2019, whose issue date, printed on the running heads of the issue, is Thursday 7 November 2019. The Law itself is dated 10 October 2019 at Brazzaville, over the signatures of President Denis Sassou-Nguesso, Prime Minister Clément Mouamba, the Minister of Justice Aimé Ange Wilfrid Bininga and the Minister of Posts, Telecommunications and the Digital Economy Léon Juste Ibombo, and it is by that promulgation date that it is universally cited. The gazette date is preferred here over the promulgation date because art. 101 attaches publication rather than promulgation, which is the same choice made for Togo. Confidence is medium because the Congolese general publication-to-force rule was not verified against a primary source: if force runs from promulgation rather than from publication the operative date is 10 October 2019, four weeks earlier, and if the general rule adds a clear-days delay after publication it is later. Both candidate dates are long past, so the lifecycle of this row is unaffected either way. Art. 100 is transitional and is not a deferral of art. 13, which is a prohibition rather than a conformance duty: from entry into force, all data processing had to meet the Law's prescriptions within two years where operated for the State, a public establishment, a decentralised administrative entity or a private-law legal person managing a public service, and within one year for everyone else, so the outer conformance window closed in November 2021 on the date recorded here. Art. 99 subjects already-created public-sector processing to a declaration only. The Law abrogates nothing expressly and names no predecessor statute, so nothing is superseded on the tracker. Text read in the Journal officiel itself, published by the Secrétariat général du Gouvernement, covering the whole of the Law from art. 1 to the signature block, including the definitions, the arts. 12 to 14 principles, the arts. 32 to 40 formalities, the arts. 90 and 91 data-protection-officer provisions and the arts. 92 to 101 sanctions and final chapters. No AI-specific statute or guidance is in force in the Republic of the Congo.

Stated maximum penalty — The route to art. 13 is administrative, it is two-step, and the fine is not available for the breach itself. Art. 92 gives the Commission a catch-all first step: it may pronounce a warning against a controller not respecting the obligations flowing from the present Law, and a mise en demeure to cause the breaches concerned to cease within the time limit it fixes. Because that is drafted against the Law's obligations generally rather than against an enumerated list, it reaches art. 13. Art. 93 then supplies the teeth, but only conditionally: if the controller does not comply with the mise en demeure addressed to them, the Commission may, after a contradictory procedure, pronounce a provisional withdrawal of the authorisation granted or a provisional prohibition of processing not exceeding three months, a definitive withdrawal of the authorisation or a definitive prohibition of processing, an injunction to cease the processing where it falls under the declaration regime or benefits from the arts. 32 and 33 dispensations, and a pecuniary fine of one million to one hundred million francs CFA, recovered in accordance with the legislation on the recovery of State debts. A controller that breaches art. 13 and then complies with the resulting mise en demeure is therefore exposed to no fine at all. Art. 94 supplies an urgency track independent of that sequence: where the implementation of a processing or the exploitation of personal data entails a violation of rights and liberties, the Commission may, after a contradictory procedure, decide the interruption of the processing for a maximum of three months, the locking of certain data for a maximum of three months, or the temporary or definitive prohibition of a processing contrary to the Law. Art. 95 requires sanctions to rest on a report by a designated member, notified to the controller, who may file observations and be represented or assisted; art. 96 allows sanctions to be made public and inserted in publications at the sanctioned person's expense; art. 97 opens recourse against the Commission's sanctions and decisions to the Cour suprême. On the penal side the Law creates no offence of its own: art. 98 provides simply that infringements of the provisions of the present Law are provided for and repressed by the Penal Code and by the law on combating cybercrime, which places Congo with Senegal and Burkina Faso as a statute that refers all criminal enforcement out to other instruments.

In force · 7 Nov 2019 checked 21 Aug 2026 Loi n° 29-2019 art. 13 ↗ medium confidence

Switzerland 1

Switzerland Binding

revFADP art. 21 — the automated-decision article that never prohibits anything

Binds Every controller within the Act's scope, private or federal, with no size, sector or turnover threshold — enterprise, SME and federal body alike. The obligation is drafted onto «the controller» without qualification, and the small-and-medium carve-outs that exist elsewhere in the revFADP do not reach it: the exemption in art. 12(5) from keeping a record of processing activities, granted to businesses with fewer than 250 employees whose processing poses a low risk of a violation of personality, is an exemption from the record duty alone and has no counterpart for art. 21. Switzerland is not an EU or EEA member and the GDPR does not supply this rule domestically, so art. 21 is the operative automated-decision provision for anyone processing in or into Switzerland. Extraterritorial reach follows art. 3(1), under which the Act «applies to circumstances that have an effect in Switzerland, even if they are initiated abroad» — a marketplace test written more broadly than GDPR art. 3(2), with no establishment or targeting requirement on its face, so an offshore scoring engine producing a considerable adverse effect on a person in Switzerland is inside the scope. Art. 14 requires a controller with no domicile or registered office in Switzerland to designate a representative in Switzerland in the cases it lists. Hiring, credit scoring, insurance underwriting and tenant screening all sit squarely in the wording: each turns on a decision exclusively automated and each produces either a legal consequence or a considerable adverse effect. Two boundaries are worth stating because they are where the article stops. First, «based exclusively on automated processing» — a decision with a human materially in the loop is outside art. 21 altogether, and the Act supplies no gloss on how much review defeats exclusivity. Second, profiling as such is not caught: the revFADP defines profiling in art. 5(f) and high-risk profiling in art. 5(g), and attaches consequences to them elsewhere, but art. 21 is triggered by the decision and its effect, not by the profiling that fed it.. Article 21 of the Federal Act on Data Protection of 25 September 2020 (SR 235.1) is the closest thing Switzerland has to GDPR art. 22, and the difference starts with the heading, which is worth quoting because almost every secondary account renames it. The official English rubric is «Duty to provide information in the case of an automated individual decision» — not «automated individual decision-making», and not a prohibition. Nothing in the article forbids a solely automated decision. Art. 21(1) provides that «the controller shall inform the data subject about any decision that is based exclusively on automated processing and that has a legal consequence for or a considerable adverse effect on the data subject (automated individual decision)». The trigger is therefore disjunctive and the second limb is softer than the GDPR's: a «considerable adverse effect» reaches further down than «similarly significantly affects», and the Swiss text needs no legal consequence at all if the adverse effect is considerable. Art. 21(2) supplies the safeguard pair: «It shall on request allow the data subject to express their point of view. The data subject may request that the automated individual decision be reviewed by a natural person.» Both limbs are reactive — they arm only on request, and the controller owes nothing until asked. Art. 21(3) then disapplies paras 1 and 2 entirely where (a) «the automated individual decision is directly connected with the conclusion or the processing of a contract between the controller and the data subject and the data subject's request is granted», or (b) «the data subject has explicitly consented to the decision being automated». Limb (a) is narrower than it looks and is the one most often mis-summarised: the contract connection alone does not suffice, because the exception also requires that the data subject's request be granted. A solely automated contractual refusal — the declined loan, the rejected policy, the failed tenancy screen — is precisely the case the exception does not cover, so the duty bites hardest exactly where the outcome is adverse. Art. 21(4) is the public-sector rule: a federal body issuing an automated individual decision «must designate the decision accordingly», a labelling duty owed without any request, and para. 2 falls away where art. 30(2) of the Administrative Procedure Act of 20 December 1968 or another federal act denies the data subject a hearing before the decision is taken. There is no right to an explanation of the logic anywhere in art. 21. The nearest thing sits in the art. 25 right of access, which is a general access right and not an automated-decision one.

In force since 1 September 2023, and the date belongs to the totally revised Act rather than to any amendment of it. The Federal Act on Data Protection was adopted by the Federal Assembly on 25 September 2020; art. 74(2) left commencement to the Federal Council, which fixed it by decision (BRB) of 31 August 2022, and the consolidated Fedlex text carries the running head «of 25 September 2020 (Status as of 1 September 2023)» with the closing line «Commencement date: 1 September 2023». There was no transition period and no staged entry into force for art. 21: unlike the 2018 EU changeover there was no two-year runway, and unlike the Mauritian scheme there is no power to appoint different dates for different sections. The Act replaced the Federal Act on Data Protection of 19 June 1992 outright, and the 1992 Act contained no automated-decision provision at all, so 1 September 2023 is the first date on which any Swiss automated-decision rule bound a private controller. Two adjacent dates should not be carried into this row. The Data Protection Ordinance (DPO, SR 235.11) of 31 August 2022 commenced the same day but adds nothing on automated decisions. And the Council of Europe's modernised Convention 108+, which Switzerland signed on 10 October 2018 and whose art. 9(1)(a) carries a right not to be subject to a solely automated decision, is not yet in force — it needs 38 ratifications under its own amending-protocol terms and Switzerland's ratification followed the revFADP rather than preceding it, so the treaty is not an independent operative source here in the way the Malabo Convention is for Namibia. Convention 108 in its original 1981 form, which Switzerland ratified on 2 October 1997, has no automated-decision article. One live supersession watch: Switzerland and the EU concluded a package of bilateral agreements in 2025 whose institutional provisions could bear on the adequacy footing this Act was drafted to protect, and the European Commission's adequacy decision for Switzerland, adopted 15 January 2024 under GDPR art. 45, is subject to periodic review. Neither touches the text of art. 21, and neither is treated as changing it here.

Stated maximum penalty — CHF 250,000 — but on a natural person, on complaint only, and not for every breach of art. 21, and each of those three qualifications is load-bearing. The revFADP gives the Federal Data Protection and Information Commissioner no power to impose an administrative fine at all; this is the structural difference from the GDPR and the reason the headline figure is so often misread as a corporate exposure. Art. 60(1) provides that «on complaint, a fine not exceeding 250,000 francs shall be imposed on private persons who: a. violate their duties under Articles 19, 21 and 25–27, in that they wilfully provide false or incomplete information; b. fail wilfully: 1. to provide information to the data subject in accordance with Articles 19 paragraph 1 and 21 paragraph 1». Three limits follow from that text. It reaches art. 21(1), the duty to inform, and it does not reach art. 21(2): a controller who receives a request for human review and simply refuses it commits no offence under art. 60, because para. 2 appears nowhere in the list. It requires wilfulness — negligence is not enough. And it is an offence prosecuted «on complaint» (Antragsdelikt), not ex officio. Art. 64 then decides who pays. Art. 64(1) routes corporate criminal liability to arts. 6 and 7 of the Federal Act of 22 March 1974 on Administrative Criminal Law, and art. 64(2) provides that «if a fine not exceeding 50,000 francs is under consideration and if the identification of the perpetrators in accordance with Article 6 ACLA requires measures that would be disproportionate in view of the potential penalty, the authority may decide not to pursue these persons but instead to order the business to pay the fine». So the CHF 250,000 maximum is aimed at the responsible individual, and the route to fining the undertaking instead is capped at CHF 50,000 and is available only as a proportionality shortcut. Art. 65(1) makes prosecution and adjudication a matter for the cantons, with the FDPIC able under art. 65(2) to file a complaint and exercise the rights of a private claimant; art. 66 sets a five-year statute of limitations. The FDPIC's own powers under art. 51 are corrective rather than pecuniary — it may order processing to be adjusted, suspended or terminated and data to be deleted. Impact tier: all entities.

In force · 1 Sep 2023 checked 22 Aug 2026 revFADP art. 21 ↗ high confidence

Côte d'Ivoire 1

Côte d'Ivoire Binding

Loi 2013-450 art. 25 — no judicial, administrative or private decision appraising human conduct may rest on automated profiling, with no carve-out at all

Binds Responsables du traitement within the scope of art. 3, which subjects to the Law any collection, processing, transmission, storage and use of personal data by a natural person, the State, local authorities or legal persons of public or private law; any processing, automated or not, of data contained in or intended to form part of a file; any processing implemented on national territory; and any processing concerning public security, defence, investigation and prosecution of criminal offences or State security, subject to derogations fixed by other legislation in force. Art. 4 excludes processing by a natural person in the exclusive course of personal or domestic activities where the data are not intended for systematic communication to third parties or for dissemination, and temporary copies made for technical transmission and access purposes. Prior declaration to the Autorité de protection is a standing precondition under art. 5, with prior authorisation required under art. 7 for genetic, medical and research data, offence and conviction data, national identification numbers, biometric data, public-interest processing and transfers to third countries, and art. 13 requiring a decree for processing on behalf of the State. The art. 25 bar binds courts under its first limb and every administrative or private decision-maker under its second, irrespective of size or sector. Impact tier: all entities.. Article 25 of Loi n° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel is Côte d'Ivoire's operative automated-decision rule. It sits at the end of Chapitre 4 (principes-directeurs du traitement des données à caractère personnel), immediately before the cross-border-transfer article, and has two limbs in two unnumbered paragraphs. The first is addressed to the courts: no judicial decision involving an appraisal of the conduct of a natural person may have as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality. The second reaches beyond the courts and is drafted more widely than any comparable African provision: no administrative or private decision involving an appraisal of human conduct may have as its sole foundation an automated processing of personal data giving a definition of the profile or of the personality of the person concerned. Two features distinguish it. First, the second limb is not confined to decisions producing legal effects and carries no significant-effect threshold either — the trigger is an appraisal of human conduct, whoever takes the decision and whatever its effects, so it is wider on its face than Morocco's and Algeria's art. 11. Second, and unusually, the Law supplies no carve-out whatever: there is no contract-formation or contract-performance deeming clause, no consent exception, no legal-authorisation exception and no opportunity-to-present-observations proviso. The Law also creates no right to know the logic underlying an automated processing — the art. 29 access right runs to information enabling the data subject to know and to contest the processing, the confirmation that data are processed, communication of the data and of any available information as to their origin, and information on purposes, categories and recipients — and no right to obtain human intervention or a fresh non-automated decision. The Law carries no definition of profiling; art. 25 speaks of an automated processing giving a definition of the profile or the personality of the person concerned.

Art. 54, the final article, is a bare publication clause — the Law "sera publiée au Journal officiel de la République de Côte d'Ivoire et exécutée comme loi de l'Etat" — and the Law contains no commencement article and defers nothing. The text was adopted by the Assemblée nationale, promulgated by the President at Abidjan on 19 June 2013 and published in the Journal officiel de la République de Côte d'Ivoire of 8 August 2013 at pp. 474 to 482, which is the date recorded here; the promulgation date of 19 June 2013 appears in the title and above the presidential signature. Confidence is medium for the same reason as Morocco's and Algeria's art. 11: the Ivorian general publication-to-force rule was not itself read against a primary source, so it could not be confirmed whether force attaches on the day the Journal officiel is published or after the customary jour franc. Art. 53 is transitional and not a deferral of art. 25: controllers already processing personal data had six months from the entry into force of the Law to bring themselves into conformity, a period that closed in 2014. Two typesetting defects in the gazetted text are recorded for candour and neither touches art. 25: the Chapitre 2 heading on p. 476 and the opening of art. 32 on p. 479 both carry a stray line reading "du secrétaire permanent de la Commission nationale du Fonds pour l'Environnement mondial", plainly imported in error from another text in the same issue. Coverage symmetry against the ten African rows already tracked: art. 25 belongs to the Directive 95/46/EC art. 15 line that reaches West Africa through art. 42 of the ECOWAS Supplementary Act A/SA.1/01/10 on personal data protection, and it is the third member of the Directive family on the tracker alongside ma-loi0908-art11 and dz-loi1807-art11. The African picture is now four-way: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37 and rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36 and ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11 and now ci-loi2013450-art25; and a Directive-family statute from which the automated-decision article is simply absent = Tunisia's Loi organique 2004-63, which is why each Francophone statute is read article by article rather than assumed. Within the Directive family Côte d'Ivoire is the outlier in both directions: it is the widest, because its second limb reaches any administrative or private decision appraising human conduct rather than only decisions producing legal effects, and it is the barest, because Morocco and Algeria both deem contract decisions with an opportunity to present observations outside the bar while Côte d'Ivoire states no exception at all. Like Morocco and Algeria it grants no human-review right; unlike Morocco, which has the art. 7(c) right to know the logic of an automated processing, Côte d'Ivoire has no logic-disclosure right at all. Text read page by page in the Journal officiel de la République de Côte d'Ivoire of 8 August 2013 as published by the Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire, which art. 46 designates as the Autorité de protection.

Stated maximum penalty — No criminal offence attaches to art. 25. The Law's three penal provisions each name their own conduct and none of them reaches an automated decision: art. 21 punishes the collection and processing of data revealing racial, ethnic or regional origin, filiation, political opinions, religious or philosophical convictions, trade-union membership, sexual life, genetic data or health with ten to twenty years' imprisonment and a fine of 20,000,000 to 40,000,000 francs CFA; art. 22 punishes direct marketing by any means of communication using the personal data of a natural person who has not given prior consent with one to five years' imprisonment and a fine of 1,000,000 to 10,000,000 francs CFA; and art. 45 punishes obstruction of the Autorité de protection with one month to two years' imprisonment and a fine of 1,000,000 to 10,000,000 francs CFA. The route that does reach art. 25 is administrative. Art. 49 lets the Autorité de protection issue a warning to a controller that does not respect the obligations arising under the Law and a formal notice (mise en demeure) to cease the failures observed within a period it fixes. Art. 50 lets it decide, after an adversarial procedure, to interrupt the processing, to block certain data or to prohibit temporarily or definitively a processing contrary to the Law where implementation entails a violation of rights and freedoms. Art. 51 lets it, after hearing a controller or processor that has not complied with the Law and with the formal notice addressed to it, pronounce provisional withdrawal of the authorisation, definitive withdrawal of the authorisation, or a pecuniary sanction proportionate to the gravity of the failures and to the advantages drawn from them; that pecuniary sanction may not exceed 10,000,000 francs CFA, and on a repeated failure within five years from the date on which a previous pecuniary sanction became definitive it may not exceed 100,000,000 francs CFA or, in the case of an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of 500,000,000 francs CFA. Art. 51 adds that these administrative and pecuniary sanctions apply without prejudice to penal sanctions, and art. 52 leaves the modalities of withdrawal and of recovery of the pecuniary sanction to decree.

In force · 8 Aug 2013 checked 20 Aug 2026 Loi n° 2013-450 art. 25 ↗ medium confidence

Chile 2

Chile Binding

Código del Trabajo Cap. X — ban on discriminatory automated decision-making and algorithm access for digital-platform work

Binds Digital service platform companies as defined in Art. 152 quáter Q — undertakings that, by themselves or through third parties, administer or manage a computer or IT system or application to intermediate the provision of services by digital-platform workers — for services provided in Chilean territory, in respect of both dependent and independent platform workers (Art. 152 quáter P). Impact tier: enterprise (platform operators), with duties owed to every platform worker.. Ley 21.431 inserted Chapter X, 'Del trabajo mediante plataformas digitales de servicios', into Title II of Book I of the Código del Trabajo. Art. 152 quinquies E prohibits discrimination through automated decision-making: in implementing its algorithms the platform must respect equality and non-discrimination and take all measures needed to avoid any discrimination between workers, expressly in work allocation, the offer of bonuses and incentives and the calculation of pay; apparently neutral employer conduct whose result disproportionately affects one or more workers also counts as discrimination; and the platform must inform its workers of the mechanisms and procedures it adopts in giving effect to that rule. Art. 152 quinquies D adds a transparency and information right: platform-held worker data are strictly confidential, the worker may at any time request access to their personal data — in particular ratings data that bear on their work — which must be delivered within fifteen working days, may request portability in a structured, generic, commonly used format, and, for proper supervision by the competent authorities, the platform must on request give access to the programming of the algorithm, to full and sufficient explanations of how it makes its decisions, to the data it was trained on and to every other factor relevant to full compliance with the law. Art. 152 quinquies C requires the worker to be told the place of performance, the identity of the user and the means of payment before accepting a job.

Commencement is on the face of the law: Artículo primero transitorio of Ley 21.431 provides that the law enters into force on the first day of the sixth month following its publication in the Diario Oficial. The law was promulgated 8 March 2022 and published 11 March 2022 (BCN metadata fecha_promulgacion 2022-03-08, fecha_publicacion 2022-03-11), giving 1 September 2022, which is also the date stated in the BCN official summary of the norm. Text read in the Biblioteca del Congreso Nacional LeyChile XML for idNorma 1173544 and cross-checked against the consolidated Código del Trabajo (DFL 1 of 2002/2003, idNorma 207436), where Arts. 152 quinquies C, D, E and I all appear unamended. Verified 2026-08-15 after the BCN www.bcn.cl/leychile/consulta/obtxml endpoint returned HTTP 429 on repeated attempts; the same service is reachable without the quota error on the backend host servicios-leychile.bcn.cl, which is what the LeyChile front end itself calls. Artículo segundo transitorio (three years to meet the requirement of Art. 19 of the Code) and Artículo tercero transitorio (three annual Consejo Superior Laboral evaluation reports) have both expired. This is Chile's peer of mx-lft-plataformas-algoritmo and of Art. 20 of the CAC Algorithmic Recommendation Provisions (cn-algo-recommendation); unlike the Mexican chapter it carries no right to human review of deactivation decisions.

Stated maximum penalty — Art. 152 quinquies I makes the Dirección del Trabajo the supervisor of Chapter X, singling out the obligations in Arts. 152 quáter Z and 152 quinquies E, and applies the fines of Art. 506 of the Código del Trabajo, doubled on repeat offence: 1 to 5 UTM for micro enterprises, 1 to 10 UTM for small enterprises, 2 to 40 UTM for medium enterprises and 3 to 60 UTM for large enterprises, according to the gravity of the infringement. The UTM is re-set monthly by the Servicio de Impuestos Internos, so the peso value of each band moves each month.

In force · 1 Sep 2022 checked 17 Aug 2026 Código del Trabajo Cap. X (Ley 21.431) ↗ high confidence
Chile Binding

Ley 19.628 Art. 8° bis (inserted by Ley 21.719) — right to object to solely-automated decisions and profiling

Binds Controllers of personal data ('responsables de datos'), public and private, within the scope of Ley 19.628 as amended, including controllers not established in Chile whose processing is aimed at offering goods or services to data subjects in Chile or at monitoring their behaviour, expressly including its analysis, tracking, profiling or prediction. Impact tier: all entities.. Ley 21.719, which overhauls Chilean data-protection law and creates the Agencia de Protección de Datos Personales, inserts a new Art. 8° bis into Ley 19.628 headed 'Decisiones individuales automatizadas, incluida la elaboración de perfiles'. The data subject has the right to object to, and not to be subject to, decisions based on the automated processing of their personal data, including profiling, that produce legal effects on them or significantly affect them. The right does not apply where the decision is necessary to conclude or perform a contract between the subject and the controller, where the subject has given prior express consent in the form prescribed by Art. 12, or where a law so provides and lays down safeguards. In all cases of automated decision-making, including those three exceptions, the controller must adopt the measures needed to secure the subject's rights and freedoms, their right to information and transparency, and their right to obtain an explanation, to human intervention, to express their point of view and to request review of the decision. 'Elaboración de perfiles' is defined in the new Art. 2 w) as any automated processing used to evaluate, analyse or predict a person's professional performance, economic situation, health, preferences, interests, reliability, behaviour, location or movements. Two related duties attach: Art. 14 ter l) requires the controller to disclose the existence of automated decisions and profiling together with meaningful information on the logic applied and the expected consequences, and Art. 15 bis makes a data-protection impact assessment mandatory where there is systematic and exhaustive evaluation of personal aspects based on automated processing or decisions, such as profiling, producing significant legal effects.

Ley 21.719 was published in the Diario Oficial on 13 December 2024. Artículo primero transitorio provides that the amendments to Ley 19.628, Ley 20.285 and Ley 19.496 contained in the first, second and third permanent articles enter into force on the first day of the twenty-fourth month after publication, i.e. 1 December 2026 — the same date carried in the BCN norm metadata (fecha_vigencia 2026-12-01, idNorma 1209272). Artículo segundo transitorio required the implementing regulations within six months of publication and Artículo cuarto transitorio required the first Agency board to be appointed six months before entry into force; implementation instruments already published include Decreto 12 of 17 June 2025 creating the ministerial implementation commission, Resolución Exenta 202503748 of 19 December 2025 approving the model contractual clauses for international transfers, and Resolución Exenta 1400 of 24 June 2026 on the procedures for Arts. 54 and 55, the last two of which themselves take effect on 1 December 2026. Text read in the Biblioteca del Congreso Nacional LeyChile XML for idNorma 1209272 via the backend host servicios-leychile.bcn.cl after the public www.bcn.cl endpoint returned HTTP 429. Chile's peer of br-lgpd-art20, cn-pipl-art24, kr-pipa-art37-2-adm and ar-ley25326-art20; unlike Argentina's Art. 20 it is a full GDPR-style right with explanation, human intervention and review, and unlike Brazil's Art. 20 it is not yet in force. Postponement risk (as of 2026-08-17): 1 December 2026 remains the legally operative date on the face of the law — no decree or amending law has changed it — but on 4 August 2026 co-Minister of Economy Daniel Mas publicly confirmed the government is evaluating postponing entry into force, because the Agencia de Protección de Datos Personales still has no seated Consejo Directivo: the Senate rejected the President's first slate of three nominees in May 2026 for lack of the required two-thirds quorum, and the June 2026 statutory deadline to appoint the board has lapsed. No amending bill has yet been introduced. Source: https://www.emol.com/noticias/Economia/2026/08/04/1207539/gobierno-postergar-ley-datos-personales.html

Stated maximum penalty — Enforced by the Agencia de Protección de Datos Personales under the new sanction regime of Ley 19.628. Art. 35: minor infringements draw a written warning or a fine of up to 5,000 UTM, serious infringements up to 10,000 UTM and very serious infringements up to 20,000 UTM. Obstructing or impeding the legitimate exercise of the right to object is a serious infringement under Art. 34 ter e); any other breach of the rights and duties of the law that is not classified as serious or very serious is a minor infringement under Art. 34 bis f). Repeat infringement allows a fine of up to three times the amount for the infringement committed, and for an infringer that is not a smaller enterprise under Art. segundo of Ley 20.416 repeating a serious or very serious infringement, up to 2% or 4% of annual turnover from sales, services and other business activities in the last calendar year. Repeated very serious fines within twenty-four months allow suspension of processing operations for up to thirty days (Art. 38). For public bodies the fine is 20% to 50% of the monthly salary of the head of the infringing body.

Applies 1 Dec 2026 checked 22 Aug 2026 Ley 19.628 Art. 8° bis (Ley 21.719) ↗ high confidence

Cameroon 1

Cameroon Binding

Loi n° 2024/017 art. 44 — the first GDPR-shaped bar in Francophone Africa, in the only African statute that makes profiling itself a crime

Binds Responsables de traitement and sous-traitants, who art. 20 makes subject to the same obligations in respect of processing activity. The art. 2 scope is unusually wide: the Law governs any processing of personal data carried out by the State, decentralised territorial collectivities or any other natural or legal person; any processing of the personal data of any person established, resident or in transit in Cameroon; any processing carried out by a controller or processor established in Cameroon; and any processing carried out in a territory where Cameroonian law applies by virtue of international law or duly ratified conventions. The transit limb is worth noting — it reaches the data of travellers passing through. Art. 3 excludes purely personal or domestic processing not intended for systematic communication to a third party or for dissemination, temporary technical copies made in transmission and access provision, and processing for literary, artistic, public-interest archival, scientific or historical research, statistical or journalistic purposes. Cameroon is also the only jurisdiction in the African block that gates processing generally rather than by category: art. 19(1) subjects the processing of personal data to the prior obtention of an authorisation delivered by the Autorité de protection des données à caractère personnel, and art. 19(2) adds a separate prior authorisation for any interconnection or interoperability process involving sensitive data files relating to minors, with the modalities of delivery left to regulation. Automated decision-making and profiling are not singled out for their own ex ante gate because everything already needs one. Art. 29 requires a processing register, art. 27(2) an annual security report to the Authority, and art. 25 a risk evaluation on criteria and validation modalities fixed by regulation. The art. 44 right binds every controller taking a decision based exclusively on automated processing, with no size, sector or legal-effects threshold — Cameroon states no requirement that the decision produce legal effects or significantly affect the person, which makes its trigger wider than the GDPR's. Impact tier: all entities.. Article 44 of Loi n° 2024/017 du 23 décembre 2024 relative à la protection des données à caractère personnel au Cameroun is Cameroon's operative automated-decision rule, and it is the first entry in the Francophone African block that is built on the GDPR rather than on Directive 95/46/EC. It sits in Titre III, Des droits de la personne concernée, which opens at art. 37 and runs through erasure and digital oblivion (arts. 37 and 38), access (art. 39), objection (art. 40), direct-marketing consent (art. 41), rectification (art. 42) and portability (art. 43). Art. 44(1) gives the data subject the right to object to any decision based exclusively on the automated processing of their personal data, including profiling. Art. 44(2) admits two exceptions and no more: where the data subject has been informed of the use of the automated decision-making system and has given prior, explicit and informed consent; and where the processing is authorised by law, provided that law lays down appropriate measures safeguarding the rights, freedoms and legitimate interests of the data subject. There is no contract limb — the carve-out that Directive-derived statutes such as Congo, Gabon, Togo and Senegal all carry for decisions taken in the conclusion or performance of a contract is simply absent, so a Cameroonian controller cannot excuse an automated decision by pointing to a contract. Art. 44(3) then supplies the safeguard package: the data subject also has the right to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision founded on the automated processing. Cameroon therefore joins the GDPR-lineage group of Kenya, Nigeria and Rwanda as its first Francophone member, and it states all three limbs of the art. 22(3) safeguard against a shorter exception list than the GDPR itself carries. The transparency side is carried by art. 21, the controller's information duty, which must be discharged at the latest at collection and which lists, among the rights whose existence must be disclosed, the right not to be subject to an individual automated decision, including profiling, and a distinct right to information on the taking of an automated decision, the underlying logic and the envisaged consequences of the processing. Profilage is defined in the definitions article as automated processing of personal data consisting in using them to evaluate certain personal aspects relating to a natural person, notably their health, preferences, location and economic situation. Art. 33 requires a prior data-protection impact assessment for any type of processing liable to engender a high risk to the rights and freedoms of natural persons.

Force. The Law carries no commencement article: art. 75, its final provision, says that the present Law, which abrogates all prior contrary provisions, shall be registered, published according to the urgency procedure, then inserted in the Journal Officiel in French and in English. The date recorded here is the promulgation date printed on the face of the Law over the signature of President Paul Biya at Yaoundé, 23 December 2024, which is also the date from which the Law's own transitional clock runs. Confidence is medium for the same reason as Morocco, Congo-Brazzaville and Gabon: the Cameroonian general publication-to-force rule was not verified against a primary source, so if force runs from insertion in the Journal Officiel rather than from promulgation the operative date is somewhat later. Nothing turns on the difference for the lifecycle of this row, because the date that actually matters to duty-holders has now passed on either reading. That date is 23 June 2026: art. 73 gives natural and legal persons in charge of the processing of personal data a period of eighteen (18) months from the date of promulgation of the present Law to conform to its provisions. Eighteen months from 23 December 2024 expired on 23 June 2026, so the conformance window closed roughly two months before this entry was written and art. 44 is fully operative against existing controllers. Art. 73 is a transitional conformance window on the Indonesian and Rwandan pattern, not a deferred commencement — it does not postpone the Law itself, which is why the row is dated from promulgation rather than from the end of the window. Two further caveats. First, art. 74 provides that particular texts shall specify, as needed, the modalities of application of the Law, and several provisions expressly await regulation: the art. 19(3) authorisation modalities, the art. 25(1) risk-evaluation criteria, the art. 32(3) transfer-authorisation modalities and the art. 35 monitoring and control modalities. Art. 44 is not among them — it is self-executing on its own terms and needs no implementing text. Second, the Autorité de protection des données à caractère personnel that the Law creates and that arts. 54 to 61 arm with the administrative sanctions had not been verified as operational when this entry was written, which affects who can enforce art. 44 administratively but not whether the duty exists; the arts. 62 to 71 civil and penal routes do not depend on the Authority existing. Supersession: the Law abrogates all prior contrary provisions without naming a predecessor data-protection statute, because there was none — before 23 December 2024 Cameroon was one of the last African states with no dedicated personal data protection law, its nearest instruments being Loi n° 2010/012 du 21 décembre 2010 on cybersecurity and cybercriminality and Loi n° 2010/013 on electronic communications, neither of which carries an automated-decision rule. Nothing on the tracker is superseded by this row. No AI-specific statute is in force in Cameroon and the Law does not define artificial intelligence; Gabon remains the only Francophone African data-protection statute that does. Text read page by page in the certified true copy published by the Presidency of the Republic (Secrétariat général, Service du fichier législatif et réglementaire), covering the arts. 1 to 5 scope and definitions, the arts. 6 to 18 principles, the art. 19 prior-formalities chapter, the arts. 20 to 35 controller obligations, the art. 36 interconnection chapter, the arts. 37 to 46 rights chapter, and the arts. 54 to 75 sanctions and final chapters.

Stated maximum penalty — Cameroon carries the heaviest enforcement apparatus of any African row on the tracker, and it is the only one in which profiling is itself a crime. Art. 65 punishes with three (03) to ten (10) years' imprisonment and a fine of one million (1,000,000) to twenty million (20,000,000) francs CFA, or one of those two penalties only, the controller or processor who carries out or causes to be carried out a processing of personal data for profiling purposes. That is a free-standing offence attaching to the act of profiling rather than to any breach of the art. 44 right, and it has no analogue anywhere else in the African block: in Ghana, Uganda, Madagascar, Congo-Brazzaville, Gabon, Morocco and Algeria no penal article reaches the automated-decision provision at all. Read with the art. 5 definition of profilage — automated processing used to evaluate personal aspects relating to a natural person, notably health, preferences, location and economic situation — art. 65 exposes ordinary commercial scoring, segmentation and recommendation practice to a custodial sentence, and it is not qualified by any of the art. 44(2) exceptions, which are drafted against art. 44(1) and not against the offence. Art. 71 lifts the ceiling for legal persons: notwithstanding the criminal liability of their directors, legal persons may be declared criminally liable and sentenced to a fine of fifty million (50,000,000) to one billion (1,000,000,000) francs CFA where the offences provided for by the Law have been committed by the persons responsible for them. Art. 64(1) supplies the route aimed at art. 44 itself: one (01) to three (03) years' imprisonment and a fine of fifty thousand (50,000) to one million (1,000,000) francs CFA, or one of those two only, for the controller or processor who carries out or causes to be carried out a processing despite the objection of the data subject, where the processing responds to direct-marketing purposes or where the objection is founded on grounds provided for by law — and an art. 44(1) objection is founded on grounds provided for by law. Art. 63 punishes fraudulent, unfair or unlawful collection or access with two to five years and 200,000 to 5,000,000 francs CFA, doubled where accompanied by locking or encryption; art. 67 punishes purpose diversion and incompatible further processing with six months to two years and 500,000 to 5,000,000 francs CFA; art. 69 punishes unlawful international transfer with three to ten years and 2,000,000 to 20,000,000 francs CFA. On the administrative side, art. 54 gives the Authority a ten (10) day mise en demeure, an injunction to bring the processing into conformity under a penalty payment not exceeding one hundred thousand (100,000) francs CFA per day of delay, and, on non-compliance, suspension of the activity covered by the authorisation, withdrawal of the authorisation, or prohibition of any personal-data processing activity. Art. 55 exposes processing without prior authorisation to 5,000,000 to 50,000,000 francs CFA; art. 56 exposes refusal to make requested information available to the data subject to 1,000,000 to 10,000,000 francs CFA, which is the administrative route reaching an art. 21 or art. 39 failure; art. 57 exposes breach of the Authority's référentiel to 5,000,000 to 20,000,000 francs CFA; art. 61 exposes breach of a cahier des charges obligation to 10,000,000 to 100,000,000 francs CFA. Art. 62 preserves the civil route: on a serious infringement of the rights mentioned in the Law the data subject may ask the competent court, ruling under the urgency procedure, to order any measure necessary to safeguard their rights, if need be under a penalty payment, and may separately seek reparation.

In force · 23 Dec 2024 checked 20 Aug 2026 Loi n° 2024/017 art. 44 ↗ medium confidence

China 5

China Binding

China PIPL Art. 24 — automated decision-making transparency, opt-out and explanation

Binds Personal information handlers (organisations and individuals that independently determine the purposes and means of processing) processing personal information within China, and — under Art. 3 — handlers outside China processing the personal information of natural persons in China to provide them products or services or to analyse or assess their conduct. 'Automated decision-making' is defined in Art. 73(2) as activities that automatically analyse or assess an individual's behavioural habits, interests or economic, health or credit situation by computer program, and make decisions. Impact tier: all entities.. Personal information handlers using personal information for automated decision-making must ensure the transparency of the decision-making and the fairness and impartiality of the result, and may not impose unreasonable differential treatment on individuals in transaction prices or other transaction conditions. Where information push delivery or commercial marketing is carried out through automated decision-making, an option not targeted at the individual's personal characteristics must be offered at the same time, or a convenient way to refuse must be provided. Where an automated decision has a major effect on an individual's rights and interests, the individual may require the handler to explain it and may refuse a decision made solely by automated means. Art. 55(2) additionally requires a personal information protection impact assessment before any automated decision-making, with the report and processing record kept at least three years (Art. 56).

Text verified in two official versions carrying identical wording of Arts. 24, 55, 66, 73 and 74: the NPC text at http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html (http only — npc.gov.cn does not answer on https, so the cited link is the CAC republication) and the Cyberspace Administration of China republication cited here. Commencement is on the face of the statute: PIPL Art. 74 states the Law takes effect 1 November 2021 (adopted by the NPC Standing Committee 20 August 2021). Art. 24 is the general personal-data ADM duty and is distinct from, and cumulative with, China's AI-specific CAC instruments already tracked (cn-genai-interim, cn-deep-synthesis, cn-ai-labelling, cn-anthropomorphic-ai, cn-ai-agents-opinions): the trigger here is personal-information processing, not the provision of an AI service. Note the second paragraph is the statutory basis for the 'convenient refusal' switch that later CAC algorithm rules operationalise, and the first paragraph is the basis for enforcement against algorithmic differential pricing. Coverage-symmetry note (2026-08-15): the CAC Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (in force 1 March 2022) are a separate, not-yet-tracked instrument — logged as a follow-up gap, not merged into this row.

Stated maximum penalty — PIPL Art. 66: order to correct, warning, confiscation of unlawful gains, and an order to suspend or terminate the offending app; if correction is refused, a fine up to RMB 1,000,000 plus RMB 10,000-100,000 on the directly responsible persons. Where the circumstances are serious, a provincial-level or higher authority may confiscate unlawful gains and impose a fine up to RMB 50,000,000 or 5% of the prior year's turnover, order suspension of business or closure for rectification, and notify the competent authority to revoke the business permit or licence; RMB 100,000-1,000,000 on the directly responsible persons, who may also be barred for a period from serving as director, supervisor, senior manager or personal information protection officer. CAC-led enforcement.

In force · 1 Nov 2021 checked 17 Aug 2026 PIPL Art. 24 (2021) ↗ high confidence
China Binding

CAC Algorithmic Recommendation Provisions — disclosure, opt-out and algorithm filing

Binds Any provider applying algorithmic recommendation technology to supply internet information services within the territory of the PRC (Art. 2). 'Applying algorithmic recommendation technology' is defined as using generative/synthetic, personalised push, ranking and selection, retrieval and filtering, or scheduling and decision-making algorithms to provide information to users — a definition wide enough to cover feeds, search ranking, content moderation filters and platform dispatch systems, not only recommender feeds. The filing, disclosure-number and security-assessment duties in Arts. 24, 26 and 27 bind only the subset of providers with public-opinion attributes or social-mobilisation capacity. Impact tier: all entities.. Providers of internet information services that use recommendation algorithms must tell users conspicuously that an algorithmic recommendation service is being provided and publicise its basic principles, purpose and main operating mechanisms (Art. 16); offer an option not targeted at the user's personal characteristics or a convenient way to switch the recommendation service off, and let users select or delete the personal-characteristic tags used for recommendation (Art. 17); periodically review, assess and verify the algorithm's mechanisms, models, data and outputs, and not deploy models that induce addiction or excessive consumption (Art. 8); and label unlabelled algorithmically generated or synthesised information before further transmission (Art. 9). Providers with public-opinion attributes or social-mobilisation capacity must additionally file with the CAC internet information service algorithm filing system within 10 working days of starting service — submitting the provider name, service form, application field, algorithm type, algorithm self-assessment report and the intended public-disclosure content — file changes within 10 working days and deregister within 20 working days of termination (Art. 24), display the filing number and a link to the disclosure on their site or app (Art. 26), and carry out a security assessment (Art. 27). Sector rules also apply: protection duties for minors (Art. 18), the elderly (Art. 19), gig workers subject to algorithmic work dispatch (Art. 20), and a ban on unreasonable differential treatment of consumers on price or other transaction terms — algorithmic price discrimination (Art. 21).

Commencement is on the face of the instrument: Art. 35 states the Provisions take effect 1 March 2022, and the promulgation order records adoption at the 20th CAC executive meeting of 2021 on 16 November 2021, agreement by MIIT, the Ministry of Public Security and SAMR, and signature on 31 December 2021 (published 4 January 2022) as Order No. 9 of the four departments. Full Chinese text of Arts. 1-35 read at the cited CAC page. Distinct from, and cumulative with, the CAC instruments already tracked: cn-pipl-art24 is the statutory personal-information basis for the Art. 17 off-switch, while these Provisions are the operative administrative regime (filing system, self-assessment report, filing number display). Where a service also generates or synthesises content, cn-deep-synthesis, cn-genai-interim and cn-ai-labelling apply in parallel. Note npc.gov.cn is http-only; this instrument is a departmental rule (bumen guizhang), so the CAC publication is the authoritative text.

Stated maximum penalty — Art. 31: for breach of Arts. 7, 8, 9(1), 10, 14, 16, 17, 22, 24 or 26, where no other law or administrative regulation provides otherwise — warning, circulated criticism and an order to rectify within a time limit; if rectification is refused or the circumstances are serious, an order to suspend information updates plus a fine of RMB 10,000 to 100,000, with public-security penalties or criminal liability where applicable. Art. 33: obtaining a filing by concealment or false material means revocation of the filing, warning, circulated criticism and, in serious cases, suspension of information updates plus a fine of RMB 10,000 to 100,000. Art. 32 routes breaches of Arts. 6, 9(2), 11, 13, 15, 18, 19, 20, 21, 27 and 28(2) to the penalties of the underlying laws (e.g. PIPL Art. 66, up to RMB 50,000,000 or 5% of turnover, and the Minors Protection Law). Enforced by the CAC with MIIT, public-security and market-regulation authorities.

In force · 1 Mar 2022 checked 17 Aug 2026 CAC Algorithmic Recommendation Provisions (Order No. 9) ↗ high confidence
China Binding

AI-content labelling (+ GB 45438-2025)

Binds AI-content service & propagation platforms, app stores, and users. Explicit (visible) and implicit (metadata/watermark) labels on AI-generated content.

Stated maximum penalty — CAC administrative penalties

In force · 1 Sep 2025 checked 17 Aug 2026 CAC AI-Labelling Measures ↗ high confidence
China Binding

China AI Agents Implementation Opinions (CAC/NDRC/MIIT)

Binds Developers and deployers of AI agent services in China; mandatory compliance for healthcare, transportation, media, and public safety sectors; guidance-level for others. First national policy framework for AI agents. Mandatory for 19 priority sectors (healthcare, transport, media, public safety): filing, compliance testing, product recall provisions. Establishes three-tier decision authority model. AI-generated content labeling required. Enforceable via existing CSL/DSL/PIPL frameworks.

Published and operative from May 8, 2026 (jointly issued by CAC, NDRC, MIIT). Three-tier decision authority model: decisions requiring human-only authority; decisions requiring user approval; decisions agent may handle autonomously. High-risk sector filing and testing obligations enforceable under Cybersecurity Law, Data Security Law, PIPL. No standalone penalty regime; enforcement via existing frameworks.

Stated maximum penalty — Enforcement via CSL/DSL/PIPL (no standalone penalties specified)

In force · 8 May 2026 checked 17 Aug 2026 CAC/NDRC/MIIT AI Agents Implementation Opinions (May 2026) ↗ high confidence
China Binding

Anthropomorphic AI Interactive Services Measures

Binds Providers of anthropomorphic AI interactive services (virtual companions, emotional chatbots, human-like AI) publicly available in mainland China. Dedicated compliance regime for AI companion services, virtual chatbots and emotionally interactive AI; mandates AI-identity disclosure, minor protections, usage-time warnings, and prohibits inducing emotional dependence.

In force 15 Jul 2026. No confirmed enforcement actions as of 2026-08-08: exhaustive cross-check (Bird & Bird, IAPP, Covington, CAC official news/enforcement index, DigitalPolicyAlert) found no penalty decisions or enforcement notices. CAC does not publish a searchable administrative-penalty registry. A claim of 12 fines / RMB 4.2M circulates in AI-generated blog content (Cubbbix, Aug 2026; republished by Ethicore Substack verbatim) — not independently verifiable and treated as unconfirmed.

Stated maximum penalty — CAC administrative penalties; service suspension

In force · 15 Jul 2026 checked 17 Aug 2026 CAC Anthropomorphic AI Interim Measures (2026) ↗ high confidence

Cabo Verde 1

Cabo Verde Binding

Lei 133/V/2001 art. 23.º — the Lusophone prohibition rewritten to the GDPR's shape, and the second the regulator can licence

Binds Responsáveis pelo tratamento — controllers — with subcontratantes (processors) bound through art. 24(3)-(6) of the republished text. The scope article is the clearest break with the other two Lusophone rows: Lei 121/IX/2021 replaced art. 2 with a GDPR art. 3-shaped reach rather than the Lei 67/98 «means situated in national territory» test that Angola and São Tomé still use. Art. 2(1) applies the Law to processing by wholly or partly automated means and to non-automated processing of personal data contained in or intended for files. Art. 2(2) then reaches processing carried out (a) in the context of the activities of an establishment of a controller or processor, public or private, situated in national territory, irrespective of whether the processing occurs inside or outside the territory; (b) outside national territory in a place where Cabo Verdean law applies by force of international law; and (c) by a controller or processor not established in national territory that processes the personal data of data subjects who are in national territory, where the processing activities relate to the offering of goods or services to those data subjects, irrespective of whether a payment is required, or to the monitoring of their behaviour where that behaviour takes place in national territory. A foreign scoring, credit or hiring-assessment operator that has no presence in Cabo Verde but profiles people who are there is therefore inside art. 23. Art. 2(3) adds video surveillance and other capture and diffusion of sounds and images allowing identification, where the controller is domiciled or seated in national territory or uses a network access provider established there; art. 2(4) obliges a controller covered by extraterritoriality or immunity to designate a representative established in national territory, communicated to the CNPD. Impact tier: all entities — art. 23 carries no employee-count, turnover, sector or high-risk-system threshold, and the art. 5(1)(j) profiling definition expressly names professional performance and economic situation, which puts hiring and credit-scoring deployers squarely in scope. Art. 40 separately makes the processing of personal data relating to the credit and solvency of data subjects subject to prior authorisation by the CNPD, so a credit-scoring operator meets an ex ante gate as well as art. 23.. Article 23.º of Lei n.º 133/V/2001, de 22 de janeiro, in the consolidated text republished by Lei n.º 121/IX/2021, de 17 de março, is Cabo Verde's automated-decision provision, and it is the third Lusophone row on the tracker after Angola and São Tomé e Príncipe. All three descend from Portugal's Lei 67/98, but Cabo Verde is the one that has been rewritten since the GDPR, and the rewrite shows. Under art. 23(1), «qualquer pessoa tem o direito de não ficar sujeita a uma decisão que produza efeitos na sua esfera jurídica ou que a afete de modo significativo, tomada exclusivamente com base num tratamento automatizado dos seus dados pessoais, incluindo a definição de perfis» — any person has the right not to be subject to a decision producing effects in their legal sphere or significantly affecting them, taken exclusively on the basis of automated processing of their personal data, including profiling. The 2021 amendment cut the evaluative limb that Angola and São Tomé still carry — the requirement that the processing be «destinado a avaliar determinados aspectos da sua personalidade, designadamente a sua capacidade profissional, o seu crédito, a confiança de que é merecedora ou o seu comportamento» — and put profiling in its place. So Cabo Verde's bar no longer asks what the processing was for: any solely automated decision over the legal-effects-or-significant-effect threshold is caught, evaluative or not, which makes it wider than either of its Lusophone siblings and puts it in the same shape as the GDPR's own art. 22. «Definição de perfis» is then defined in art. 5(1)(j) in GDPR art. 4(4) terms — any automated processing that uses personal data to evaluate certain personal aspects of a natural person, in particular to analyse or predict aspects concerning their professional performance, economic situation, health, personal preferences, interests, reliability or conduct. The ways out are three. Art. 23(2) permits the decision under a legal authorisation, or with the person's consent where it occurs in the conclusion or performance of a contract and either their own request to conclude or perform was satisfied or adequate measures exist guaranteeing the defence of their legitimate interests and their ability «expor o seu ponto de vista, designadamente o seu direito de representação e expressão» — to express their point of view, namely their right of representation and expression. Art. 23(3) then carries the limb that until now stood alone on the tracker as Angola's: «pode ainda ser permitida a tomada de uma decisão nos termos do número 1, quando autorizadas pela CNPD e desde que sejam tomadas medidas de garantia a defesa dos interesses legítimos do titular dos dados» — the decision may further be permitted where the Comissão Nacional de Proteção de Dados authorises it, provided measures guaranteeing the defence of the data subject's legitimate interests are taken. Both clauses descend from art. 13(3) of Portugal's Lei 67/98, so the regulator-licence route is a shared Lusophone inheritance rather than an Angolan invention, and Cabo Verde and Angola are the two jurisdictions on the tracker whose supervisory authority can licence an otherwise-prohibited automated decision case by case. On disclosure Cabo Verde is the most generous of the three: art. 14(1)(c) gives the data subject, on request and without excessive delay or cost, «o conhecimento da lógica subjacente ao tratamento automatizado dos dados que lhe digam respeito, no que se refere às decisões automatizadas, incluindo a definição de perfis, referida no número 1 do artigo 23.º» — knowledge of the logic underlying the automated processing of their data as regards automated decisions including profiling, cross-referring art. 23(1) by name. São Tomé gives the «razões», the reasons; Angola gives nothing at all. What Cabo Verde does not give is a notice duty: the art. 13 information list, which the same 2021 law rewrote and extended to the contacts of the data protection officer and the legal basis of the processing, carries no automated-decision item and no logic item, so the right is reactive — invocable only by someone who already suspects a machine decided. There is no right to obtain human intervention and no right to contest the decision after the fact. Impact tier: all entities.

Force. The date carried here is the date on which the current wording of the automated-decision rule took effect. Lei n.º 121/IX/2021, de 17 de março — the second amendment to the general legal regime for the protection of the personal data of natural persons approved by Lei n.º 133/V/2001, de 22 de janeiro, as amended by Lei n.º 41/VIII/2013, de 17 de setembro — was approved by the Assembleia Nacional on 11 February 2021, promulgated by President Jorge Carlos de Almeida Fonseca on 1 March 2021, signed on 8 March 2021 and published in the Boletim Oficial da República de Cabo Verde, I Série, n.º 28, de 17 de março de 2021, at pp. 883-906. Its art. 6 (Entrada em vigor) provides «a presente lei entra em vigor trinta dias após a sua publicação», thirty days after publication, which puts the amended text in force on 16 April 2021. The obligation itself is older and continuous: art. 2 of the 2021 Law amends art. 14.º of Lei 133/V/2001, which is the article the republication in its art. 5 renumbers as art. 23.º of the consolidated text, and the parent Law's own art. 71 (Entrada em vigor) used the identical thirty-day formula against publication on 22 January 2001, so the first Cabo Verdean automated-decision bar has been in force since 21 February 2001. What the 2021 Law changed is substantive and is why the later date is carried: it replaced nos. 1 and 2 of the article outright, dropping the Lei 67/98 evaluative limb and inserting «incluindo a definição de perfis» together with the new art. 5(1)(j) profiling definition, while leaving no. 3 — the CNPD authorisation route — untouched, which the amending text marks by reproducing it as «3. []». Supersession is therefore recorded rather than duplicated: this row supersedes nothing on the tracker, and the pre-2021 wording is not published as a separate entry. One divergence inside the single gazette issue is recorded rather than resolved: in the amending body at art. 2, the new art. 14(1) reads «tomada exclusivamente com base num tratamento automatizado, incluindo a definição de perfis», while the republished consolidated text at art. 23(1) reads «tomada exclusivamente com base num tratamento automatizado dos seus dados pessoais, incluindo a definição de perfis». The republished text governs — art. 5(1) of the amending Law provides that the modifications are inserted into Lei 133/V/2001 by substitution and art. 5(2) republishes the Law in its new text together with the amending Law — and it is the republished wording that is quoted in this entry, with the amending-body wording noted so the difference is not silently smoothed over. Art. 4 of the amending Law separately revokes art. 48.º of the 2001 Law. Transitional: art. 70 of the republished text gave processing existing in manual files at entry into force a six-month window for conformity with arts. 8, 11, 13 and 14 — art. 23 is not in that list and binds without a transitional window. No AI-specific statute is in force in Cabo Verde and the Law does not define artificial intelligence. Text read in full in the copy of the Boletim Oficial pages published by the Comissão Nacional de Proteção de Dados, the supervisory authority the Law creates — the file is the gazette typesetting itself, carrying the BO running heads, page numbers 883-906 and the kiosk.incv.cv watermark, not a re-keyed edition. Coverage of the read: the amending Law arts. 1-6 in full, including the enumeration of amended articles and the entry-into-force and republication clauses; and in the republished consolidated text, art. 2 scope, art. 5 definitions, arts. 13 information, 14 access and 23 automated individual decisions verbatim, art. 24 security and processors, arts. 39-41 notification and prior control, arts. 47-58 civil liability and the administrative infractions with their coimas, and arts. 59-71 the criminal subsection, accessory sanctions, transitional provisions and entry into force. Confidence high: art. 23 and art. 14(1)(c) were read verbatim in the gazette text, both entry-into-force clauses are explicit thirty-day formulas against dated publications, and the fine attaching to art. 23 was traced to the enumerated list in art. 50(1)(b) rather than assumed.

Stated maximum penalty — 100,000$00 to 1,000,000$00 Cabo Verdean escudos, and the fine reaches art. 23 by name. Art. 50 (Outras infrações) of the republished text makes it an administrative infraction punishable with a coima of a minimum of 100,000$00 and a maximum of 1,000,000$00 for entities that fail to observe the obligations established in arts. 6.º, 13.º, 14.º, 20.º, 23.º, 25.º, 33.º and 43.º(3), or that fail to designate a representative under art. 2(4). Art. 23 — the automated-decision bar — and art. 14 — the access right carrying the logic-disclosure limb — are both inside that enumerated list, which puts Cabo Verde with São Tomé e Príncipe, where art. 32(1) also names the automated-decision article, and against Angola, where art. 29 appears in neither art. 51 contravention list and enforcement has to run through a complaint, a judicial reparation claim or the crime of qualified disobedience. Art. 50(2) doubles the limits where the obligations in arts. 7, 8, 11, 12, 35 and 36 are the ones breached. Art. 52(1) makes negligence always punishable in the art. 50 infractions and art. 52(2) makes attempt punishable in arts. 49 and 50, so an operator cannot answer an art. 23 charge by saying the profiling was inadvertent. The neighbouring band is higher but does not reach art. 23: art. 49 punishes negligent failure to notify the CNPD, or maintaining network access for non-compliant controllers after notification, with 50,000$00 to 500,000$00 for a natural person and 300,000$00 to 3,000,000$00 for a legal person or entity without legal personality, doubled under art. 49(2) where the data are subject to prior control under art. 40. Application of the coimas belongs under art. 56 to the president of the CNPD on the Commission's prior deliberation, and that deliberation is an enforceable title if not challenged in the legal period; art. 58 gives the proceeds to the CNPD; art. 57 makes clear that paying the coima does not dispense the infringer from performing the omitted duty. Alongside the coimas, art. 69 allows accessory sanctions — temporary or definitive prohibition of the processing, blocking, erasure or total or partial destruction of the data, publicity of the condemnatory decision at the convicted party's expense in the most widely circulated periodical of the comarca for not less than 30 days, and public warning or censure of the controller. The criminal subsection sits behind that and does not reach art. 23 directly: art. 59 punishes with up to one year's imprisonment or a fine up to 120 days the intentional omission of a notification or authorisation request under arts. 39 and 40, false information in one, diversion or use of data incompatibly with the purpose of collection, unlawful interconnection, failure to comply within a deadline fixed by the CNPD, and maintaining network access after being notified not to; arts. 60-61 punish undue access and the vitiation or destruction of data; art. 62 makes it qualified disobedience to fail, after notification, to interrupt, cease or block processing, to refuse the CNPD the cooperation demanded, or to fail to erase or destroy data — so once the CNPD orders an art. 23 profiling operation stopped, defying that order is a crime. Arts. 64-67, added by the 2021 amendment, create the further offences of diversion of data, use of data incompatibly with the purpose of collection, unlawful interconnection and insertion of false data. Art. 51(1) provides that where the same act is both a crime and an administrative infraction, the agent is always punished as for the crime.

In force · 16 Apr 2021 checked 21 Aug 2026 Lei 133/V/2001 art. 23.º ↗ high confidence

Germany 1

DE Binding

Germany AI Market Surveillance Act (KI-MIG)

Binds AI providers, importers, distributors, and deployers of AI systems operating in Germany under EU AI Act scope (Reg. EU 2024/1689). Designates Bundesnetzagentur (BNetzA) as Germany's lead AI authority; establishes enforcement architecture for EU AI Act in Germany, including AI regulatory sandboxes (KI-Reallabore) and domestic penalty regime.

National implementing law for EU AI Act. EU phased obligations still apply: Art.50 transparency in force Aug 2, 2026; high-risk Annex I AI → Aug 2, 2028 (per the Digital Omnibus, Reg. (EU) 2026/1744); full high-risk Annex III → Dec 2, 2027.

Stated maximum penalty — €35M or 7% global turnover (prohibited AI practices); €15M or 3% (high-risk violations); €50K for domestic procedural violations (KI-MIG §§15–17)

In force · 29 Jul 2026 checked 22 Aug 2026 KI-MIG ↗ high confidence

Algeria 1

Algeria Binding

Loi 18-07 art. 11 — no decision with legal effects may rest on the sole basis of automated profiling or personality evaluation, and no court may found an appraisal of conduct on one at all

Binds Responsables du traitement within the territorial scope of art. 4: processing carried out by a natural or legal person whose controller is established on Algerian territory (a controller carrying on an activity in Algeria through an installation, whatever its legal form, is treated as established there) or on the territory of a State whose legislation is recognised as equivalent; and processing by a controller not established in Algeria that resorts, for the purposes of processing, to automated or non-automated means situated on Algerian territory, excluding means used only for transit. In that second case the controller must notify the national authority of the identity of its representative installed in Algeria, who substitutes for it in all rights and obligations under the Law. The first limb of art. 11 binds the courts themselves. Art. 6 excludes from the Law data processed by a natural person in the exclusive course of personal or domestic activities and not destined for communication to third parties or dissemination, data collected and processed in the interest of national defence and security, and data collected and processed for the prevention, prosecution and punishment of offences and held in judicial databases.. Article 11 of Loi n° 18-07 du 25 Ramadhan 1439 correspondant au 10 juin 2018 relative à la protection des personnes physiques dans le traitement des données à caractère personnel is Algeria's operative automated-decision rule. It sits in Titre II, Chapitre I (fundamental principles), immediately before the declaration and authorisation machinery of art. 12, and has two limbs. The first is absolute and is addressed to the courts: no judicial decision involving an appraisal of a person's conduct may be founded on an automated processing of personal data intended to evaluate certain aspects of that person's personality — there is no consent, contract or safeguards exception to this limb. The second is the general rule: no other decision producing legal effects with respect to a person may be taken on the sole basis of an automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third paragraph supplies the only carve-out, and it operates by deeming rather than by exemption: decisions taken in the course of the conclusion or performance of a contract for which the person concerned has been put in a position to present their observations, and decisions satisfying the requests of the person concerned, are not regarded as taken on the sole basis of an automated processing. The Law carries no profiling definition, no right to an explanation of the logic involved and no human-review right; the opportunity to present observations exists only inside the contractual deeming clause.

Art. 76, the final article, is a bare publication clause — "La présente loi sera publiée au Journal officiel de la République algérienne démocratique et populaire" — and the Law contains no commencement article and no deferral for art. 11. The date used here is therefore the date of the Journal officiel that carries the Law: JO n° 34 of 25 Ramadhan 1439 corresponding to 10 June 2018, whose masthead and per-page footers were read directly in the JORADP French edition. Confidence is medium for the same reason as Morocco's art. 11: the Algerian general publication-to-force rule (art. 4 of the Code civil, Ordonnance n° 75-58) was not primary-source verified — the 1975 Journal officiel volumes on JORADP are image scans with no recoverable text layer, and Loi n° 05-10 of 20 June 2005, which amended the Code civil, was read in full and does not touch art. 4 — so it could not be confirmed whether force attaches on the day of publication or the day after. Art. 75 is a transitional provision, not a deferral of art. 11: persons already carrying on a processing activity at the date of promulgation must bring themselves into conformity within a maximum of one year from the date of installation of the national authority, on pain of the art. 56 penalties. Art. 11 itself is self-executing and is not conditioned on the authority existing; the art. 46 administrative route that enforces it is.

Stated maximum penalty — No criminal offence attaches to art. 11. The penal chapter (arts. 56 to 74) enumerates the articles it punishes — art. 12 processing without declaration or authorisation, sensitive data without express consent, purpose deviation, fraudulent collection, unauthorised access, obstruction of the national authority, the art. 28 national register, the art. 32, 34, 35 and 36 data-subject rights, arts. 38 and 39 security, art. 43 breach notification and art. 44 cross-border transfer — and art. 11 appears in none of them. Art. 47's fixed fine of 500,000 DA is likewise confined to arts. 32, 34, 35, 36 and to the notifications under arts. 4, 14 and 16. The route that does reach art. 11 is art. 46, under which non-observance of the provisions of the Law by the responsable du traitement leads the national authority to take administrative measures against them: a warning, a formal notice (mise en demeure), provisional withdrawal for a period not exceeding one year or definitive withdrawal of the declaration receipt or the authorisation, and a fine — with no amount fixed for it in the text. Decisions of the national authority are open to appeal before the Conseil d'Etat. Art. 70 refers offences by legal persons to the Penal Code and art. 74 doubles the penalties of the penal chapter on recidivism, but neither enlarges the reach of art. 11.

In force · 10 Jun 2018 checked 17 Aug 2026 Loi n° 18-07 art. 11 ↗ medium confidence

European Union 2

EU Comprehensive

Article 50 transparency & deepfake labelling

Binds Providers & deployers of interactive, synthetic-content or biometric AI. Disclosure of AI interaction; marking of AI-generated content.

In force 2 August 2026. Commission adopted Guidelines on Transparency Obligations under Art. 50 on 20 July 2026, C(2026) 5054 final (https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems) (soft law, interpretive guidance on chatbots, deepfakes, emotion recognition, AI-generated text). No enforcement actions by national authorities reported as of 2026-08-09; first enforcement expected Q4 2026 as national market surveillance authorities build capacity (10 of 27 member states advanced implementation). Note: marking/watermarking of systems already on market before 2 Aug 2026 deferred to 2 Dec 2026 per Reg. (EU) 2026/1744.

Stated maximum penalty — Up to 3% turnover or €15M

In force · 2 Aug 2026 checked 17 Aug 2026 EU AI Act ↗ high confidence
EU Comprehensive

Art. 50(2) marking retrofit — synthetic-content systems placed on the market before 2 Aug 2026

Binds Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content placed on the EU market before 2 August 2026. Four-month transitional period: providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text and were placed on the EU market before 2 Aug 2026 have until 2 Dec 2026 to implement the Art. 50(2) machine-readable marking of synthetic output.

Added by the Digital Omnibus on AI, Regulation (EU) 2026/1744, Article 1(39)(b), which adds a new paragraph 4 to Article 111 of Regulation (EU) 2024/1689 (OJ L, 24.7.2026). Recital (38) describes it as a transitional period of four months for providers who had already placed their systems on the market. Distinct from the Article 50 transparency entry, which binds from 2 Aug 2026, and from the new Article 5 CSAM/NCII prohibitions, which share the 2 Dec 2026 date but sit in the higher Article 99(3) penalty tier.

Stated maximum penalty — Up to 3% turnover or €15M

Applies 2 Dec 2026 checked 22 Aug 2026 EU AI Act Art. 111(4) (Digital Omnibus) ↗ high confidence

Gabon 1

Gabon Binding

Loi n° 025/2023 art. 77 — the recast that carries the Francophone family's only statutory definition of artificial intelligence

Binds Responsables de traitement, on the terms of the art. 4 scope: the Law applies to any collection, processing, transmission, storage and use of personal data by a natural person or by public-law or private-law legal persons, and to any processing, automated or not, of personal data contained or intended to be contained in a file. Art. 78 subjects automated processing to a declaration to the APDPVP, excepting the processing mentioned in arts. 80, 81 and 82 or in art. 111; art. 79 requires the declaration to carry an undertaking that the processing satisfies the Law's requirements, to be addressed by any means leaving a trace, and requires the controller to notify data breaches likely to seriously affect fundamental rights and freedoms to the competent supervisory authority without excessive delay. Neither profiling nor automated decision-making is listed as a category attracting prior authorisation, so Gabon imposes no ex ante gate on the processing art. 77 governs. Art. 206 and art. 207 distinguish controllers holding a récépissé or an authorisation from de facto controllers holding neither. The art. 77 bar binds the courts under its first limb and, under its second, every decision-maker whose decision produces legal effects in regard to a person, with no size or sector threshold. Impact tier: all entities.. Article 77 of Loi n° 025/2023 du 12 juillet 2023 portant modification de la loi n° 001/2011 du 25 septembre 2011 relative à la protection des données à caractère personnel is Gabon's operative automated-decision rule. Like its predecessor it is not a free-standing article: the automated-decision paragraphs are appended to the article governing data relating to offences, convictions and security measures, which reserves such processing to public and judicial authorities and legal persons managing a public service acting within their legal remit, and to auxiliaires de justice for the strict needs of the missions the law confers on them. Three unnumbered paragraphs follow. The first: no judicial decision involving an appraisal of a person's conduct may have as its foundation a computerised processing of data intended to evaluate certain aspects of their personality. The second: no other decision producing legal effects in regard to a person may be taken on the sole foundation of an automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third deems decisions taken in the context of the conclusion or performance of a contract, and for which the person concerned was put in a position to present their observations, and those satisfying the requests of the person concerned, not to be issued from an automated processing. As in Guinea, Madagascar and Congo, the judicial limb omits the word "seul" that the second limb carries. The second limb takes the narrow Directive 95/46/EC trigger confined to decisions producing legal effects. What sets Gabon apart from every other Francophone row on the tracker is the surrounding apparatus, which is GDPR-grade and, uniquely, AI-aware on the face of the statute. The definitions article defines Intelligence Artificielle as a logical and automated process generally resting on an algorithm which is able to carry out well-defined tasks, adding that any tool used by a machine constitutes an artificial intelligence; it separately defines raw data in the field of artificial intelligence as data having undergone no transformation since its initial observation, input data in the field of artificial intelligence as data used for machine learning or for the decision-making of the system, and the artificial neuron by reference to whether it should be activated. It also defines Profilage as a processing using an individual's personal data with a view to analysing and predicting their characteristics, and Portabilité. Art. 43, the access right, carries the full GDPR transparency package: the existence of automated decision-making, including profiling, and at least in such cases meaningful information about the underlying logic as well as the significance and the envisaged consequences of that processing for the person concerned, together with a distinct right for the data subject to obtain on request knowledge of the reasoning underlying the processing of the data where the results of that processing are applied to them. Gabon is therefore the one jurisdiction in this block where the automated-decision bar sits alongside both a logic-disclosure right and a reasoning right.

Supersession: this row replaces, and does not duplicate, the automated-decision provision of Loi n° 001/2011 du 25 septembre 2011, which carried the same rule at its art. 50 in the same unusual placement, appended to the article on offence and conviction data. Loi n° 025/2023 is styled a modification of the 2011 Law but is in substance a full recast, running to 221 articles against the predecessor's shorter frame and renumbering throughout; its art. 221 provides that the present Law, which abrogates all prior contrary provisions, notably certain provisions of Loi n° 001/2011, shall be registered, published in the Journal Officiel and executed as a law of the Republic. Because the abrogation is of contrary provisions rather than of the 2011 Law as a whole, and because the recast reproduces the automated-decision rule rather than repealing it, the obligation is continuous from 2011; only the article number, the wording and the enforcement apparatus changed. The wording changes are small but real: the 2011 judicial limb read "traitement automatisé" where the 2023 text reads "traitement informatisé", and the 2011 deeming clause read that such decisions are not regarded as taken on the sole foundation of an automated processing, where the 2023 clause reads that they are not considered as issued from an automated processing. The institutional change is larger: the Commission nationale pour la protection des données à caractère personnel created by the 2011 Law is replaced by the Autorité pour la Protection des Données Personnelles et de la Vie Privée, the APDPVP, which is the body named throughout the enforcement chapter. The Law carries no commencement article and art. 221 is a bare registration, publication and execution clause, so nothing is deferred. The date recorded here is the date of the gazette in which the Law was promulgated and published: Journal Officiel de la République Gabonaise n° 218 Bis of 15 July 2023, printed on the running head of every page of the issue. The Law itself is dated 12 July 2023 at Libreville, and the promulgating decree in the same issue bears the same date. Confidence is medium because the Gabonese general publication-to-force rule was not verified against a primary source: if force runs from promulgation the operative date is 12 July 2023, three days earlier. Both candidate dates are long past, so the lifecycle of this row is unaffected either way. On sourcing: the official gazette host journal-officiel.ga returned HTTP 503 on every path when checked for this entry, so the text was read in the scan of Journal Officiel n° 218 Bis published by the AFAPDP, the association of Francophone data-protection authorities of which Gabon's regulator is a member. That file is a reproduction of the official gazette, carrying its running heads, pagination and the other laws promulgated in the same issue, and is treated as primary on the same basis as the archived official texts used for Burkina Faso and Nigeria. Care is needed with that issue: it also carries Loi n° 027/2023 on cybersecurity and cybercrime, whose own arts. 49 to 66 create heavy imprisonment and fine penalties that have nothing to do with the data-protection Law and must not be attributed to it. Text read across the whole of Loi n° 025/2023, including the definitions, the arts. 4 to 6 scope, the art. 43 access right, arts. 77 to 79, and the arts. 199 to 221 recourse, control, sanctions and final chapters. No AI-specific statute is in force in Gabon, but the definitions article of this Law is the only place in the Francophone African block where artificial intelligence is defined in a binding data-protection statute.

Stated maximum penalty — Art. 77 is reached by the administrative catch-all in art. 203, which provides that the Authority appraises and pronounces, without graduation, according to the breach of the present Law established, a warning against a controller not respecting the obligations flowing from the Law, a mise en demeure to cause the established breaches to cease within the time limit it fixes, and a pecuniary sanction. The phrase "sans graduation" matters: unlike Congo, where the fine becomes available only once a mise en demeure has been defied, the Gabonese Authority is expressly freed from any obligation to escalate through the list in order. Art. 204 sets the pecuniary regime. Where the controller does not comply with the mise en demeure addressed to them they may be summoned to a hearing, and after contradictory debate the APDPVP may pronounce a provisional suspension of the collection and processing of personal data for three months, becoming definitive on expiry, and a fine of one million to one hundred million francs CFA. The amount must be proportionate to the gravity of the breaches and to the advantages derived from them. On a first breach it may not exceed ninety-eight million four hundred thousand francs CFA. On recidivism it may not exceed three hundred million francs CFA or, in the case of an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of one hundred and ninety-six million francs CFA. That absolute ceiling on the percentage limb is distinctive and is worth reading carefully: because the 5 per cent figure is itself capped at one hundred and ninety-six million francs CFA, the turnover limb binds only undertakings with pre-tax turnover below roughly 3.9 billion francs CFA, and above that threshold the percentage ceases to have any effect — the opposite of how the equivalent ceilings work in Guinea, Côte d'Ivoire, Niger and Burkina Faso, where the percentage is the escalating term. Where the APDPVP has pronounced a pecuniary sanction that has become definitive before the criminal court has finally ruled on the same or connected facts, the court may order the pecuniary sanction to be set off against the fine it pronounces. Art. 205 allows warnings to be made public and, where the controller is in bad faith, the insertion of sanctions in publications at the sanctioned person's expense. Art. 206 exposes a controller holding a récépissé or authorisation who does not respect the Law's obligations, after mise en demeure, to suspension of the récépissé or authorisation for up to two months, definitive withdrawal on expiry of the suspension, and a fine of one million to one hundred million francs CFA. Art. 207 treats a controller holding neither as a de facto controller, exposed to a fine of one million to one hundred million francs CFA together with a mise en demeure to regularise. Art. 208 supplies emergency powers, including interruption of the processing for a maximum of three months, where implementation of a processing or exploitation of data entails a violation of rights and liberties. On the penal side art. 213 punishes obstruction of the APDPVP with six months to one year's imprisonment and a fine of one million to ten million francs CFA; no penal article of this Law reaches art. 77.

In force · 15 Jul 2023 checked 22 Aug 2026 Loi n° 025/2023 art. 77 ↗ medium confidence

Ghana 1

Ghana Binding

Data Protection Act s. 41 — notice-based right against solely-automated decisions, plus an automatic duty to notify and reconsider

Binds Data controllers within the scope of s. 45(1): those established in Ghana processing data in Ghana; those not established in Ghana but using equipment or a data processor carrying on business in Ghana to process the data; and processing in respect of information originating partly or wholly from Ghana. Section 45(3) treats as established in Ghana an individual ordinarily resident there, a body incorporated under Ghanaian law, a partnership or person registered under the Registration of Business Names Act, 1962 (Act 151) or the Trustees Incorporation Act, 1962 (Act 106), an unincorporated joint venture or association operating in part or in whole in Ghana, and any other person maintaining an office, branch or agency there; s. 45(2) requires a controller not incorporated in Ghana to register as an external company. Registration with the Data Protection Commission is a standing precondition of processing: s. 53 prohibits processing personal data without registration and s. 56 makes failure to register an offence. The s. 41 duties bind any controller that takes a solely-automated decision significantly affecting an individual, irrespective of size. Impact tier: all entities.. Section 41 of the Data Protection Act, 2012 (Act 843), headed “Rights in relation to automated decision-taking”, carries Ghana's operative automated-decision rule, in the block of data-subject rights at ss. 35 to 44. Subsection (1) entitles an individual at any time, by notice in writing to a data controller, to require the controller to ensure that any decision taken by or on behalf of the controller which significantly affects that individual is not based solely on the processing by automatic means of personal data in respect of which that individual is the data subject. Subsection (2) then operates despite the absence of such a notice: where a decision which significantly affects an individual is based solely on that processing, the controller shall as soon as reasonably practicable notify the individual that the decision was taken on that basis, and the individual is entitled, by notice in writing, to require the controller to reconsider the decision within twenty-one days after receipt of the notification. Subsection (3) gives the controller twenty-one days after receipt of that notice to inform the individual in writing of the steps it intends to take in compliance with that notice. Subsection (4) disapplies the section where the decision is made in the course of considering whether to enter into a contract with the data subject, with a view to entering into the contract, in the course of performance of the contract, for a purpose authorised or required by or under an enactment, or in other circumstances prescribed by the Minister. Subsection (5) lets the Commission, if satisfied on a complaint by a data subject that a person taking a decision has not complied, order the controller into compliance; subsection (6) preserves the rights of third parties. Section 43 separately gives a data subject who suffers damage or distress through a controller's contravention of a requirement of the Act a right to compensation from that controller.

Commencement is not stated on the face of the Act. Section 99 provides that the Minister shall specify the date when the Act comes into force by publication in the Gazette, and the enacted text records only a Date of Gazette notification of 18 May 2012, which is the publication of the Act itself and not the appointed commencement. The Data Protection Commission — the statutory supervisory authority established by s. 1 of this Act, so the body whose own existence dates from the appointed day — states on its Who We Are page that the Commission “was established by the Data Protection Act 2012 (Act 843) which came into force 16th October 2012”. That regulator statement is the date recorded here. The underlying ministerial commencement instrument itself could not be retrieved: the Commission publishes no commencement or Executive Instrument in its media library, and Ghana has no online official gazette that serves the instrument. The date is therefore taken from the supervisory authority's own publication rather than from the gazette notice, and should be revisited if the instrument surfaces. Section 41 carries no separate or deferred commencement of its own. Act 843 remains the principal Act: it has no amendment on the Commission's records and the Commission has published no automated-decision or AI guidance under it, so the statutory text is the whole of the binding rule. Ghana is the tracker's fourth African jurisdiction, after South Africa, Kenya and Nigeria. Its drafting is the oldest of the four and is modelled on the UK Data Protection Act 1998 s. 12 rather than on GDPR Art. 22: the right is exercised by written notice rather than existing as a standing prohibition, and the contract carve-out in s. 41(4) is wider than the GDPR-style exceptions in ke-dpa-s35 and ng-ndpa-s37 because it excludes pre-contractual consideration and contract performance outright, without requiring compensating safeguards. Against that, s. 41(2) is stronger than all three peers on one axis: the duty to notify and the right to demand reconsideration bite automatically whenever a solely-automated significant decision is taken, without the data subject having served any prior notice, and both legs run on a hard twenty-one-day clock, where ke-dpa-s35 says only “within a reasonable period” and za-popia-s71 and ng-ndpa-s37 set no deadline at all. Text read in the copy of the Act published by the Data Protection Commission, the supervisory authority established under it.

Stated maximum penalty — Section 41 non-compliance is not itself an offence. The route to a sanction runs through the Commission: on a complaint by a data subject under s. 41(5) the Commission may order the controller to comply, and where the Commission is satisfied that a controller has contravened or is contravening any of the data protection principles it shall serve an enforcement notice under s. 75 requiring specified steps or a halt to specified processing. Failure to comply with an enforcement notice or an information notice is an offence under s. 80(1), punishable on summary conviction by a fine of not more than one hundred and fifty penalty units or a term of imprisonment of not more than one year, or both. Section 95 sets a general penalty, for an offence under the Act for which no penalty is specified, of a fine of not more than five thousand penalty units or imprisonment of not more than ten years, or both, and s. 94(2) applies the same five-thousand-penalty-unit ceiling to offences under Regulations made under the Act. Section 43 gives the data subject a separate civil claim for compensation for damage or distress caused by a failure to comply with a requirement of the Act. Penalty units are valued under the Fines (Penalty Units) Act, 2000 (Act 572), which is not part of Act 843.

In force · 16 Oct 2012 checked 17 Aug 2026 Data Protection Act s. 41 (Act 843) ↗ high confidence

Guinea 1

Guinea Binding

Loi L/2016/037/AN art. 27 — the strictest Francophone automated-decision bar, with no exception of any kind and a general penalty running to 7% of turnover

Binds Responsables du traitement and their sous-traitants, subordonnés and préposés. The prior formalities are set out in Chapitres V and VI: art. 7 subjects six categories to prior authorisation before any implementation — genetic and medical data and scientific research in those fields, data on offences, convictions or security measures pronounced by the courts, national identification numbers or identifiers of the same nature including telephone numbers, biometric data, public-interest processing including for historical, statistical or scientific purposes, and transfers to a third country — while art. 8 lets the Authority establish norms simplifying or exempting the declaration duty for the most common categories, and art. 6 exempts processing for which a data protection correspondent has been designated except where a third-country transfer is envisaged. Art. 9 fixes the minimum contents of a request for opinion, a declaration or an authorisation request, art. 11 the channels for filing, and art. 12 gives the Authority two months, extendable once by two months on a reasoned decision, to accept or refuse — with the notable rule that silence beyond those periods amounts to implicit acceptance of the declaration or a tacit authorisation, and that an appeal against a refusal is not suspensive. Profiling and automated decision-making appear in none of the art. 7 authorisation categories, so Guinea, like Togo and unlike Burkina Faso and Niger, imposes no ex ante gate on the processing art. 27 governs. Art. 17 requires a reasoned opinion of the Authority before processing on behalf of the State, a public-law legal person or a private-law legal person managing a public service is authorised by regulation, in the fields of State security, national defence or public security, the prevention, investigation, establishment or prosecution of criminal offences or the execution of criminal convictions or security measures, the population census, and the processing of salaries, pensions, taxes, duties and other settlements. The art. 27 bar binds the courts under its first limb and every administrative or private decision-maker appraising human conduct under its second, irrespective of size or sector. Impact tier: all entities.. Article 27 of Loi n° L/2016/037/AN du 28 juillet 2016 relative à la cybersécurité et la protection des données à caractère personnel is Guinea's operative automated-decision rule. It sits in Chapitre VIII on the guiding principles of personal-data processing, between the art. 26 press-and-Penal-Code saving and the art. 28 cross-border-transfer article, in two unnumbered paragraphs. The first: no judicial decision involving an appraisal of the conduct of a natural person may have as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality. The second: no administrative or private decision involving an appraisal of human conduct may have as its sole foundation an automated processing of personal data giving a definition of the profile or of the personality of the person concerned. Two things make this the strictest formulation in the Francophone family tracked. First, the judicial limb does not contain the word "seul", so it bars any judicial decision appraising conduct from resting on such a processing at all, whatever else the court also relies on, while the qualifier is present in the second limb of the same article. That asymmetry is not unique to Guinea, and an earlier version of this entry wrongly said it was: Madagascar's art. 3, Congo-Brazzaville's art. 13, Gabon's art. 77 and Algeria's art. 11 all drop the qualifier from the judicial limb and keep it in the other, which makes the pattern a shared inheritance of the Francophone family rather than a Guinean innovation. What Guinea combines with it is what no other row does: its wide second limb reaches any administrative or private decision appraising human conduct, not merely decisions producing legal effects as in Congo, Gabon, Togo, Morocco and Algeria. Second, and like Côte d'Ivoire, Mali and Burkina Faso, the Law supplies no carve-out whatever — no contract exception, no consent exception, no legal-authorisation exception and no opportunity to present observations. The Law creates no right to know the logic underlying an automated processing: art. 30 lists what must be given at collection and art. 31 the access right, which runs to information enabling the data subject to know and to contest the processing, confirmation, communication of the data and their origin, and purposes, categories and recipients. There is no human-review right and no right to a fresh non-automated decision, and the Law carries no definition of profiling. What the rights chapter does carry, unusually for a 2016 Francophone statute and evidently drawn from the then-new GDPR rather than from the Directive, is a right to erasure and digital oblivion in arts. 35 to 39 and a right to data portability in art. 40.

Unusually for this block, the commencement rule is express and needs no inference. Art. 65, the final article, reads that the present Law, which abrogates all prior contrary provisions and enters into force from the date of its promulgation, shall be registered and published in the Journal Officiel de la République de Guinée and executed as a law of the State. The date stamped in the signature block over the signature of President Prof. Alpha Condé at Conakry is 28 July 2016, and 28 July 2016 is therefore the date recorded here. This resolves a discrepancy that runs through the secondary record: several repositories, including the copy indexed by the Cour Suprême, cite the Law as "du 26 juillet 2016", while the National Assembly's own page and the copy published by ANSSI Guinée carry 28 July. The enacted text read for this entry carries 28 July, and because art. 65 attaches force to promulgation rather than to publication, the Journal Officiel date does not need to be established for the date on this row to be sound. Confidence is medium rather than high for one reason only: the promulgation date is a rubber stamp impressed into a blank on the signature page of a scanned document rather than typeset, and the Journal Officiel citation for the Law could not be established from a primary source, so the two-day margin around 26-28 July 2016 cannot be closed by a second official instrument. Art. 63 is transitional and is not a deferral of art. 27: controllers had a maximum of one year from promulgation to bring themselves into conformity, a period that closed on 28 July 2017. Art. 64 leaves unspecified application modalities to decrees, orders and decisions. The abrogation in art. 65 names no statute, so no predecessor is superseded on the tracker. Guinea is not an ECOWAS outlier by accident: it is a founding member, and its art. 27 takes the wider ECOWAS Supplementary Act A/SA.1/01/10 drafting in its second limb — any administrative or private decision appraising human conduct — placing it with Côte d'Ivoire, Burkina Faso, Niger and Mali rather than with Togo, Morocco and Algeria, whose second limb is confined to decisions producing legal effects. Within that ECOWAS group Guinea is the strictest, because its judicial limb alone omits the word "seul". The Law is a combined instrument: cybersecurity and cybercrime occupy roughly its first two thirds and personal data protection the last, with the data-protection part restarting its own definitions at p. 34 of the enacted text and running from art. 1 to art. 65. Text read page by page in the copy published by the Agence Nationale de la Sécurité des Systèmes d'Information, the Guinean State agency, including the definitions, arts. 7 to 13, 14 to 17, 18 to 29, 30 to 40, 41 to 43 and 55 to 65. The pages were read as page images because the file is a scan with no text layer.

Stated maximum penalty — Guinea is the one jurisdiction in this block where the automated-decision bar is directly and heavily enforceable, and the reason is that art. 56 is a general catch-all rather than a list of named offences. Art. 56 provides that any controller, or their processor, subordinate or agent, who does not respect the provisions of the present Law shall be punished by a fine of 50,000,000 to 150,000,000 Guinean francs. On recidivism within the five years following the date on which that fine became definitive, the fine is raised to an amount which may not exceed 1,500,000,000 Guinean francs and, where an undertaking is concerned, to an amount which may not exceed 7 per cent of pre-tax turnover for the last closed financial year. Because art. 56 is drafted against "les dispositions de la présente loi" without enumeration, it reaches art. 27 on its face — no other Francophone row on the tracker has a penalty that reaches its automated-decision article directly, and the 7 per cent turnover ceiling is the highest in the block, against 5 per cent in Côte d'Ivoire, Niger and Burkina Faso. Art. 55 separately punishes obstruction of the Authority in charge of Personal Data Protection, or failure to comply with its decisions and injunctions, with six months to three years' imprisonment and a fine of 20,000,000 to 150,000,000 Guinean francs, with accomplices liable to the same penalties and the Procureur de la République or competent judge to be informed without delay. Art. 57 leaves the modalities of recovery of the Authority's pecuniary sanctions to regulation. Art. 58 allows administrative and penal sanctions to be aggravated on recidivism at the discretion of the Authority or the competent judicial authority, with imprisonment doubled and fines doubled for a natural person and doubled to quintupled for a legal person. Art. 59 allows additional sanctions of the same nature as those in the cybercrime law. Art. 60 requires that sanctions be published at least in the Journal Officiel, on the Authority's website and on the CERT's, in a newspaper or legal-notices journal and at the registry of the competent court, the last two at the convicted person's expense. Art. 61 preserves the sanctions available under the cybercrime law, and art. 62 aligns limitation periods with the Penal Code and the Code of Criminal Procedure.

In force · 28 Jul 2016 checked 21 Aug 2026 Loi n° L/2016/037/AN art. 27 ↗ medium confidence

Equatorial Guinea 1

Equatorial Guinea Binding

Ley 1/2016 art. 13(b) — impugnación de valoraciones: disclose the program, challenge any decision, but nothing forbids the machine

Binds Responsables del fichero o del tratamiento, defined at art. 4(i) as any natural or legal person, public or private, engaged in the processing of personal data, and encargados del tratamiento through the art. 8 processor-contract regime. Art. 2 makes the scope explicitly dual-sector: the Law applies to the personal data of all citizens recorded on any kind of medium, in the public sector as much as in the private, that make them susceptible of processing or of later use by other natural or legal persons or by public and private entities, where that processing is carried out or used on means situated in the national territory, or where Equatoguinean legislation applies to a controller not established in the country. Art. 2(2) additionally brings electoral, statistical, civil-registry and criminal-registry files, and images and sounds obtained by security video cameras, within the Law subject to their specific rules. Art. 3 excludes files kept by natural persons in the exercise of exclusively personal or domestic activities, files established for organised crime and terrorism, and files relating to classified matters — an unusually broad security carve-out that removes the whole of the state-security sector from art. 13(b). Art. 14 further disapplies the rights: controllers of files held for police or tax purposes may deny access, rectification, opposition or cancellation having regard to the gravity and danger that might follow for the defence of the State or public security, the protection of third-party rights, or ongoing investigations; and where the information could affect national defence, national security, or the prevention and investigation of criminal and administrative offences and delinquency in general, the controller is not merely permitted but obliged to refuse. A refused data subject must first lodge a queja or reposición with the controller who decided the processing, and only after exhausting that internal route may they claim to the Órgano Rector de Protección de Datos Personales, which resolves with reasons. No ex ante gate attaches to automated decision-making or to profiling: there is no impact assessment, no prior authorisation for scoring, and no notification duty specific to automated processing. Public files are created by Decree under art. 19 and entered in the Registro General de Protección de Datos, whose contents any person may consult under art. 13(c). Impact tier: all entities.. Article 13(b) of Ley núm. 1/2016, de 22 de julio, de Protección de Datos Personales is Equatorial Guinea's automated-decision provision, and it is the Spanish LOPD form, not the Directive 95/46/EC form that every other Central African row on the tracker carries. Título III, Garantía y protección de los derechos de las personas, opens at art. 13 with a single article listing the citizen's rights, and the second of them is headed Impugnación de valoraciones: El interesado tendrá derecho a obtener información del responsable del fichero sobre los criterios de valoración de sus datos personales y de su comportamiento, y el programa utilizados en el tratamiento de los mismos, pudiendo impugnar todo acto administrativo o decisión que implique una valoración de su conducta o comportamiento y definición de sus características o personalidad — the data subject has the right to obtain from the file controller information on the criteria used to evaluate their personal data and their behaviour, and on the program used in processing them, and may challenge any administrative act or decision that involves an evaluation of their conduct or behaviour and a definition of their characteristics or personality. Two features make it wider than the templates around it. First, the disclosure limb reaches el programa utilizado — the program itself, not merely the logic involved — which is the most explicit software-disclosure wording of any statute on the tracker. Second, the challenge limb carries no solely-automated trigger and no legal-effects threshold: it bites on todo acto administrativo o decisión involving a profiling-style evaluation, whether a machine or a human reached it, where the GDPR art. 22 family and the Directive art. 15 family both require that the decision be based solely on automated processing and produce legal or similarly significant effects. What Equatorial Guinea does not have is a prohibition. There is no rule anywhere in the Law that a decision may not be taken on the sole basis of automated processing, no human-intervention right, no right to express a point of view, and no obligation to disclose the existence of automated decision-making up front: art. 13(b) is exercised after the fact, by an interesado who already suspects they were scored. The Law is otherwise LOPD-lineage throughout — arts. 5 to 12 carry consent, purpose limitation, data quality, processor contracts, security and secrecy, and art. 13 gathers access, the impugnación limb, consultation of the Registro General de Protección de Datos, rectification and cancellation within fifteen days, and a damages right into one article. It is the first Hispanophone row in the African block and the first anywhere on the tracker to place the challengeable object at acto administrativo o decisión rather than at automated decision.

Force. The Disposición Final is a twenty-day vacatio: La presente Ley entrará en vigor a los veinte (20) días de su publicación en el Boletín Oficial del Estado, sin perjuicio de su publicación en los demás Medios Informativos Nacionales. The Law was given at Malabo on 22 July 2016 over the signature of President Obiang Nguema Mbasogo, and the date recorded on this entry is that date, the one the instrument carries on its face and cites itself by (Ley Núm. 1/2016, de fecha 22 de Julio). The Boletín Oficial del Estado issue in which it was published is not stated in the official copy read and the Equatoguinean BOE is not published online, so the exact day on which the twenty days expired cannot be pinned to a primary source; the entry is marked medium for that reason alone. Nothing turns on it for a 2026 reader — the vacatio ran out in 2016 on any publication date and the Law has been in force for a decade — but the in-force date is a range in August or September 2016, not a verified day, and it is recorded as such rather than assumed. One structural condition does remain open. Art. 15 provides that the Órgano Rector de Protección de Datos Personales, que será creado mediante Decreto, is the body that protects the rights derived from the Law; the Law itself does not constitute it, and no creating Decree was found on the Equatoguinean government hosts. Art. 35 covers the gap on the enforcement side: the Ministro de Telecomunicaciones y Nuevas Tecnologías exercises the sanctioning power under the Law against any infringer, on a procedure opened and instructed by the Dirección General de Nuevas Tecnologías, or where applicable by the Órgano Rector, with an appeal by recurso de alzada to the Consejo de Ministros within thirty days. So art. 13(b) is enforceable today through the Ministry whether or not the Órgano Rector exists; what the missing Decree affects is the art. 14(3) claim route, which names the Órgano Rector as the body that resolves a refusal. Supersession: none. Equatorial Guinea had no dedicated data-protection statute before Ley 1/2016 and no AI-specific statute is in force; the Law does not define artificial intelligence, and Gabon's Loi 025/2023 remains the only data-protection statute in the African block that does. Text read in the official scanned copy published by the Ministerio de la Función Pública y la Reforma Administrativa, which satisfies Primary Source First on the same basis as the Nigeria, Burkina Faso, Gabon and Chad copies; the WorldLII mirror Cloudflare-blocks automated retrieval and was not relied on. The copy is a 45-page image-only scan with no text layer and was read as page images. Coverage of the read: arts. 1 to 15 in full (object, scope, exclusions, definitions, the Título II principles, the whole of the art. 13 rights list, the art. 14 exceptions and the art. 15 tutela article), art. 19 on public files, and the whole of the Título VI sanctioning regime — art. 35 competence, arts. 39 to 41 the three infringement classes, art. 42 the penalty scale, art. 43 the graduation criteria, art. 44 procedure — plus the Disposición Final. The intervening arts. 16 to 34, on the police-file regime, public and private files, the Registro General, international transfers and the authority's inspection powers, were read by heading and spot-check; no automated-decision or profiling rule appears in them, and art. 13(b) is the Law's only evaluation-and-challenge provision.

Stated maximum penalty — Administrative, and the route to art. 13(b) is explicit. Art. 40 makes it an infracción grave to obstruct, impede or hinder the exercise of the rights of access, rectification, cancellation and opposition by the interested or affected person (art. 40(b)), and separately to fail to attend to the requests, complaints and claims of interested or affected persons (art. 40(g)) — either limb catches a controller who refuses an art. 13(b) request for the valuation criteria or the program used. Art. 42(1)(b) sets the grave scale: a fine of 500,001 to 5,000,000 FCFA, suspension of the file's activity and of the processing of personal data, and sealing of the premises or installations for a period not exceeding fifteen (15) working days. Below that, art. 42(1)(a) puts leves at amonestación, written warning, or a fine of 200,000 to 500,000 FCFA; art. 39(f) sweeps any other breach of the Law that is not grave or muy grave into that class. Above it, art. 42(1)(c) puts muy graves at fines of 5,000,001 to 15,000,000 FCFA together with one or more of seizure of equipment and other material, definitive closure of the premises and installations, disqualification of the infringer from the activity of file-keeping and personal-data processing for one year or definitively, and cancellation and revocation of the administrative resolution, authorisation or concession creating the file and of its entry in the Registro General de Protección de Datos. Art. 42(2) adds that in grave or muy grave cases where the processing, communication, transfer or international transfer could impair the fundamental rights of those affected, the sanctioning body may require public and private controllers alike to cease the unlawful use, and art. 42(3) lets it immobilise the files by reasoned resolution if that requirement is not met. Art. 43 grades the sanction by the proportionality of the harm and its social or economic repercussion, intentionality, continuity, the volume of processing, the unlawful benefit obtained, the degree of participation, recidivism, and the nature of the harm caused to the interested and to third parties. Separately from the sanctioning regime, art. 13(e) gives the data subject a damages right — before the ordinary courts against private files, and under the State responsibility rules against public ones.

In force · 22 Jul 2016 checked 18 Aug 2026 Ley 1/2016 art. 13(b) ↗ medium confidence

Indonesia 1

Indonesia Binding

UU 27/2022 (PDP Law) Arts. 10 and 34 — objection to solely-automated decisions and mandatory impact assessment

Binds Personal-data controllers ('Pengendali Data Pribadi') within the scope of Art. 2: any person, public body or international organisation acting inside Indonesian jurisdiction, and those outside it whose acts have legal effect in Indonesia or affect Indonesian data subjects abroad. Processing by a natural person for purely personal or household activity is excluded. Impact tier: all entities.. Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi is Indonesia's general data-protection statute. Art. 10(1) gives the data subject the right to object to a decision taken solely on the basis of automated processing, including profiling, that produces legal effects or has a significant impact on them; Art. 10(2) leaves the procedure for lodging that objection to a Government Regulation (Peraturan Pemerintah). Art. 34(1) separately obliges the personal-data controller to carry out a personal-data-protection impact assessment where processing carries a high potential risk to the data subject, and Art. 34(2)(a) lists automated decision-making with legal effect or significant impact on the data subject as the first such high-risk category — alongside large-scale processing, systematic evaluation, scoring or monitoring, data matching or combination, and the use of new technologies. The elucidation of Art. 10(1) defines 'pemrofilan' as electronically identifying a person by reference to matters including employment history, economic condition, health, personal preferences, interests, reliability, behaviour, location or movements.

Enacted and promulgated in Jakarta on 17 October 2022; Lembaran Negara 2022 No. 196, Tambahan Lembaran Negara No. 6820. Art. 76 provides that the Act enters into force on the date of promulgation, so 17 October 2022 is the in-force date. Art. 74 is a transitional rule, not a deferred commencement: controllers, processors and other parties involved in personal-data processing were given at most two years from promulgation to align their processing with the Act, so the adjustment window closed on 17 October 2024 and the duties are now fully exigible. Two implementation caveats, both verified rather than assumed. First, no Government Regulation implementing the Act has been issued: a search of the Sekretariat Negara legal database returns no PP under UU 27/2022, and the Komdigi JDIH record for the Act carries an empty 'Peraturan Pelaksanaan' section. The Art. 10(2) objection procedure and the Art. 34(3) impact-assessment procedure therefore still lack their detailed rules. Second, Art. 57(1) lists the provisions carrying administrative sanctions and Art. 34(1) is on that list while Art. 10 is not — the sanctioned duty is the impact assessment, while the Art. 10 right is exercised through the supervisory body and the dispute-resolution route of Chapter XIII. Indonesia's peer of br-lgpd-art20, cn-pipl-art24, kr-pipa-art37-2-adm, ar-ley25326-art20 and cl-ley21719-art8bis: like Brazil and Argentina it is already in force, and like Chile it pairs the objection right with a mandatory impact assessment, but unlike Korea it grants no express right to an explanation or to human re-processing. Text read in the full statutory text published by the JDIH of the Kementerian Komunikasi dan Digital, the ministry of record for the Act; the Sekretariat Negara salinan (LN 2022/196) is a scanned image and carries no text layer, and peraturan.bpk.go.id returned HTTP 403 to every request.

Stated maximum penalty — Administrative sanctions under Art. 57 for breach of the Art. 34(1) impact-assessment duty: written warning, temporary suspension of processing, erasure or destruction of the personal data, and/or an administrative fine of at most 2 per cent of annual revenue or annual receipts measured against the variable of the violation, imposed by the supervisory body. Art. 57(5) leaves the procedure for imposing those fines to a Government Regulation that has not yet been issued.

In force · 17 Oct 2022 checked 21 Aug 2026 UU 27/2022 Arts. 10, 34 (LN 2022/196) ↗ high confidence

India 1

India Binding

IT Rules — synthetic-content (deepfake) labelling

Binds Intermediaries, significant social-media intermediaries (5M+ users), GenAI tool providers. Mandatory labels on AI-generated (SGI) content; 3-hour government-ordered takedown; significant-platform traceability.

Stated maximum penalty — Loss of safe harbour; IT Act offences

In force · 20 Feb 2026 checked 5 Aug 2026 IT Rules 2026 amendments (SGI) ↗ high confidence

Japan 1

Japan Comprehensive

Japan Election AI Labelling & Platform Obligations (2026 Amendment)

Binds All internet users (duty not to spread false election information); candidates and campaign organisations (AI labelling obligation); large-scale platform operators (X, YouTube, Meta) operating in Japan. AI-generated election content must display an 'AI作成' label; large social media platforms must implement harm-mitigation measures and publish annual reports covering election misinformation. Applies from March 2027.

Passed the House of Councillors July 13, 2026; promulgated July 17, 2026 as Law No. 58 of Reiwa 8 (令和8年法律第58号). Amends the Public Offices Election Law and the Platform Countermeasures Act (情プラ法). Enforcement March 1, 2027 ahead of April 2027 unified local elections. No new criminal penalties for platform duties (political compromise). AI-generated content that could be mistaken for authentic footage must display 'AI作成' label; clearly identifiable illustrations/animation are exempt.

Stated maximum penalty — No new criminal penalties created; existing election law criminal provisions (Art. 235-2) continue to apply to candidates

Applies 1 Mar 2027 checked 12 Aug 2026 Election SNS Regulation Law (Law No. 58/2026, Amendment) ↗ high confidence

Kenya 1

Kenya Binding

Data Protection Act s. 35 — right against solely-automated decisions, with written notification and a right to reconsideration

Binds Data controllers and data processors within the scope of s. 4, that is those established or ordinarily resident in Kenya and processing personal data while in Kenya, and those not so established or resident but processing personal data of data subjects located in Kenya. Registration with the Office of the Data Protection Commissioner under ss. 18 and 19 is a precondition of acting as a controller or processor, subject to the thresholds set by the Data Protection (Registration of Data Controllers and Data Processors) Regulations. The s. 35 duties bind any controller or processor that takes a solely-automated decision with legal or significant effect. Impact tier: all entities.. Section 35 of the Data Protection Act No. 24 of 2019 gives every data subject a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning or significantly affects the data subject (s. 35(1)). The right does not apply where the decision is necessary for entering into or performing a contract between the data subject and a data controller, is authorised by a law to which the controller is subject and which lays down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, or is based on the data subject's consent (s. 35(2)). Where a controller or processor does take such a decision, s. 35(3) imposes two duties: it must as soon as reasonably practicable notify the data subject in writing that a decision has been taken based solely on automated processing, and the data subject may then, after a reasonable period from receipt of that notification, request the controller or processor to reconsider the decision or to take a new decision that is not based solely on automated processing. On receipt of such a request the controller or processor must within a reasonable period consider the request including any relevant information the data subject provides, comply with it, and inform the data subject in writing of the steps taken in compliance and of the outcome (s. 35(4)). Section 35(5) empowers the Cabinet Secretary to make further provision by Regulations. Section 31 separately makes a data protection impact assessment mandatory where a processing operation is likely to result in high risk to the rights and freedoms of a data subject.

Commencement is stated on the face of the published Act: the gazetted text of the Data Protection Act No. 24 of 2019 records a Date of Assent of 8 November 2019 and a Date of Commencement of 25 November 2019, and s. 35 carries no deferred or separately-appointed commencement. The Office of the Data Protection Commissioner was constituted in November 2020 and has exercised its enforcement powers since; the section itself has been operative from 25 November 2019. Kenya is the tracker's second African jurisdiction, added in the same sweep as za-popia-s71. Section 35 follows the GDPR Art. 22 shape more closely than the South African provision does: it grants an express right to demand a new decision that is not based solely on automated processing, which POPIA s. 71 does not, and it attaches an affirmative written-notification duty on the controller rather than leaving disclosure to a request. It stops short of the Korean kr-pipa-art37-2-adm model in that it confers no standalone right to an explanation of the criteria used. Text read in the official copy of the Act published by the Office of the Data Protection Commissioner, the supervisory authority established by Part II of the Act; new.kenyalaw.org and kenyalaw.org return HTTP 403 to non-browser clients, so the ODPC copy is cited.

Stated maximum penalty — Section 63 caps the administrative penalty the Data Commissioner may impose by penalty notice, in relation to an infringement of a provision of the Act, at five million Kenyan shillings, or in the case of an undertaking one per centum of its annual turnover of the preceding financial year, whichever is lower; s. 62 governs the penalty notice and s. 58 the enforcement notice that ordinarily precedes it. Section 65 gives a person who suffers damage by reason of a contravention a right to compensation from the controller or processor. Section 73 provides a general penalty, for offences under the Act for which no specific penalty is prescribed, of a fine not exceeding three million shillings or imprisonment for a term not exceeding ten years, or both. Appeals against administrative action lie to the High Court under s. 64.

In force · 25 Nov 2019 checked 16 Aug 2026 Data Protection Act s. 35 (No. 24 of 2019) ↗ high confidence

Kyrgyzstan 2

Kyrgyzstan Binding

Digital Code arts. 194-196 - self-classified high-danger AI needs a signed public declaration of conformity before first use

Binds Владельцы (owners) and пользователи (users) of AI systems that the owner's own danger assessment classifies as high-danger, plus, by art. 126, every provider of a digital wellbeing service that uses AI within the service, without any assessment step. Duties split by role: arts. 194 and 195 fall on the owner, art. 196 on the user, and art. 196(3) moves the owner's set onto a rebrander, repurposer or substantial modifier. No size or sector threshold; Resolution No. 770 para. 2 restates the scope as all owners irrespective of legal form, sectoral affiliation or ownership.. Where the art. 193 danger assessment returns a system whose use raises the risk of harm to the protected goods to a level requiring risk management, art. 194(1) makes it a «система искусственного интеллекта повышенной опасности» - a high-danger AI system - and the Digital Code's substantive regime attaches for the whole life cycle. The classification is comparative and self-executed rather than annex-driven: it asks whether the system raises risk relative to alternative ways of doing the same thing, and art. 194(3) expressly excludes systems whose role in the decision or action is purely auxiliary and does not raise risk. Art. 194(4) hands the Cabinet of Ministers the four requirement families - risk management, system characteristics (openness, explainability, controllability, accuracy, reliability, digital resilience), digital data quality, and technical documentation - and all four now exist as annexes to Resolution No. 770. Art. 194(5) lists seven owner duties: conform to the mandatory requirements; implement and maintain a risk-management system across the whole life cycle; produce proper technical documentation; preserve the system logs while the system is under its control; confirm conformity before first application; remedy identified non-conformities; and, on demand of the competent state body, suspend - and on a final court act terminate - design and development carried on in breach. Art. 195 is the gate: before a high-danger system may be applied, its owner must adopt a declaration of conformity in the form and content approved by the Cabinet of Ministers, cast as a digital document, signed with a qualified digital signature, and posted on the owner's website as a publicly accessible digital record. Art. 196 then binds the user (deployer): operate per the manual, keep the processed data relevant, maintain effective supervision with named responsible persons and allocated resources, notify the owner and suspend use the moment there is ground to believe the manual-compliant use could cause harm, preserve logs, and suspend or terminate on official demand or court act. Art. 196(2) adds an explanation right where the output feeds a decision capable of infringing rights: general information about the system's characteristics and operating principles must be published on the site for consumer-facing systems and supplied in accessible form otherwise, and anyone whose interests the decision touches may demand, free of charge, information letting them understand and check how the result about them was arrived at. Art. 196(3) transfers the owner's duties to whoever puts the system into service under their own name or mark, changes its purpose, makes substantial modifications, or turns it into a high-danger system - the EU AI Act art. 25 pattern - and art. 196(4) releases the original owner in the latter two cases. Art. 196(5) exempts purely personal or family use from most duties, but makes that user and whoever gave them access jointly and severally liable where third-party rights are infringed. One sector is classified by statute rather than by assessment: art. 126 declares AI systems used to deliver digital wellbeing services to be high-danger systems as a matter of law.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. The regime is operable rather than pending: Cabinet of Ministers Resolution No. 770 of 2 December 2025 («Эркин-Тоо» No. 96 (3753) of 5 December 2025) supplies all four art. 194(4) requirement families as annexes 2 to 5, and the art. 195 declaration was completed separately by Cabinet of Ministers Order No. 1181-т of 31 December 2025, which approved the Requirements for the content of the declaration of conformity of high-danger AI systems. Both are «Действует» in ЦБД. Resolution No. 770 commences fifteen days after the Code, i.e. 21 February 2026 on the arithmetic of its own para. 4; the ЦБД card states no dateOfEntry for it.

Stated maximum penalty — Nothing, in administrative terms. The Code of Offences contains no article penalising application of a high-danger AI system without a declaration, non-conformity with the Resolution No. 770 requirements, absence of a risk-management system, loss of logs, or refusal of the art. 196(2) explanation. Art. 228-10, the only AI-specific offence, is confined to the art. 192(2) targeted-unlawful-harm prohibition (200 расчетных показателей for natural persons, 650 for legal persons; the расчетный показатель is 100 som, so 20,000 and 65,000 som). What does bite is non-monetary and, for an operating business, heavier: art. 194(5)(7) and art. 196(1)(7) let the competent state body order suspension of design, development or application on demand, with termination on a final court act. Civil exposure is the other real channel - art. 192(3) makes owners and users liable for harm caused, and for digital wellbeing services art. 127(2) lets the consumer elect a statutory compensation of 100 to 400 расчетных показателей (10,000 to 40,000 som) in place of proving damages, with the burden on the provider to disprove causation.

In force · 6 Feb 2026 checked 22 Aug 2026 KG Digital Code arts. 194-196 ↗ high confidence
Kyrgyzstan Binding

Digital Code art. 197 - tell consumers they are talking to an AI, tell people they are being emotion- or biometrically classified, and label deepfakes

Binds Owners and users of AI systems that interact with natural persons as consumers (part 1); users of emotion-recognition and biometric-classification systems (part 2); users of AI systems for deepfakes (part 4). Danger tier is irrelevant here - a minimal-danger chatbot owes part 1 - and there is no size, sector or nationality threshold. Part 1's register limb additionally reaches the sectoral regulator of the national ecosystem, which must publish the same information on its own site.. Art. 197 is Kyrgyzstan's transparency article and, unlike the rest of Chapter 23, it applies to AI systems at any danger level. Part 1 obliges owners and users who design, develop or apply AI systems in order to interact with natural persons as consumers to inform those consumers of the fact that they are interacting with an AI system, except where it is obvious from the circumstances; it further declares information about the use of AI systems within digital-environment legal relations to be publicly accessible information, which must be posted in accessible and intelligible form both on the sites of the users of those systems and on the site of the sectoral regulator of the national ecosystem - a disclosure register duty that goes beyond the EU AI Act art. 50 equivalent. Part 2 requires users of systems intended for emotion recognition or for the classification of natural persons by biometric characteristics to inform the persons concerned that such a system is being applied to them; Kyrgyzstan regulates these by notification rather than banning them in workplaces and education as the EU does. Part 4 requires users of AI systems for deepfakes to disclose the artificial origin or alteration of the material. Part 3 disapplies parts 1 and 2 - not part 4 - for functions where informing would frustrate lawful use for defence, national security, or public order in the detection, prevention and investigation of crime and criminal prosecution; part 5 disapplies part 4 for lawful use protecting those same goods or in exercise of the freedom of scientific, technical and artistic creativity, teaching and learning, which is a notably wide carve-out from deepfake labelling. Part 6 conditions every one of those exceptions on necessary measures having been taken to protect the affected human and civil rights and freedoms.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. Art. 197 needs no implementing act and none has been issued: the duties are self-executing on the text, and neither Resolution No. 770 nor Order No. 1181-т touches transparency. What has NOT been located is any published register on the site of the sectoral regulator of the national ecosystem under part 1, which the article requires; that is recorded as an open follow-up rather than asserted either way.

Stated maximum penalty — Nothing. There is no administrative offence for failing to disclose AI interaction, for applying emotion recognition or biometric classification without notifying the person, or for publishing an unlabelled deepfake. Art. 228-10 of the Code of Offences, the only AI-specific offence, covers the art. 192(2) targeted-unlawful-harm prohibition alone (200 расчетных показателей for natural persons, 650 for legal persons, at 100 som per показатель). Kyrgyzstan therefore sits at the opposite end from Kazakhstan on this one point: Kazakhstan's KoAP art. 641-1 does penalise failure to inform users about misleading synthetic outputs, at 15 to 100 MRP, while Kyrgyzstan's identical duty carries no fine at all.

In force · 6 Feb 2026 checked 22 Aug 2026 KG Digital Code art. 197 ↗ high confidence

South Korea 2

S. Korea Comprehensive

Korea PIPA Art. 37-2 — rights against fully automated (AI) decisions

Binds Personal information controllers in Korea (and, via Art. 26(8), their processors) that make significant decisions about individuals through fully automated systems, including AI systems. Where a decision made by processing personal data with a completely automated system — expressly including systems applying artificial-intelligence technologies — significantly affects a data subject's rights or duties, the data subject may object to it and may request an explanation. On objection or an explanation request the controller must not apply the automated decision absent compelling reason, or must take necessary measures such as re-processing with human involvement and providing an explanation. Controllers must also publicly disclose the criteria and procedures for automated decisions and how personal data is processed in them.

Inserted by the PIPA amendment Act No. 19234, promulgated 14 March 2023. Addenda Art. 1(1) defers Art. 37-2 (and Art. 75(2) 24) to 'the date one year elapses after the date of promulgation' = 15 March 2024, unlike the bulk of the amendment which took effect 15 September 2023. Art. 37-2(1) excludes automatic dispositions by administrative authorities under Art. 20 of the Framework Act on Administration, and the right to object does not apply where the automated decision is made under Art. 15(1) 1, 2 or 4 (consent, statutory obligation, or performance of a contract) — in those cases only the explanation/review rights remain. Detailed procedures are set by the PIPA Enforcement Decree (Arts. 44-2 to 44-5), also effective 15 March 2024. Distinct from and additional to the AI Basic Act duties (see kr-aibasic-transparency, kr-aibasic-highimpact): this duty is triggered by personal-data processing, not by AI-operator status.

Stated maximum penalty — Administrative fine up to KRW 30 million for failing to take the measures required by Art. 37-2(3) (PIPA Art. 75(2) 24); PIPC enforcement

In force · 15 Mar 2024 checked 14 Aug 2026 PIPA Art. 37-2 (Act No. 19234) ↗ high confidence
S. Korea Comprehensive

AI Basic Act — transparency & labelling

Binds AI business operators offering AI products/services in Korea (extraterritorial). Pre-notify users that a service uses AI; label generative and realistic synthetic outputs.

MSIT enforcement grace period of AT LEAST one year from 22 Jan 2026 before administrative fines are imposed — confirmed in an MSIT primary release (English press release on the AI Basic Act Enforcement Decree legislative notice, 12 Nov 2025: https://www.msit.go.kr/eng/bbs/view.do?sCode=eng&mPid=2&mId=4&bbsSeqNo=42&nttSeqNo=1191). That release states MSIT "will implement a grace period of at least one year before administrative fines are imposed" and that "efforts are currently underway to gather opinions to finalize the detailed operation plan and duration of this grace period" — so ~22 Jan 2027 is a FLOOR, not a confirmed end date, and the release states no exception or carve-out to the grace period. The 22 Jan 2026 in-force date is separately primary-sourced (law.go.kr).

Stated maximum penalty — Admin fine up to ₩30M

In force · 22 Jan 2026 checked 21 Aug 2026 AI Basic Act ↗ high confidence

Kazakhstan 2

Kazakhstan Binding

AI Law art. 21 — tell users AI was involved, and machine-readably mark every synthetic output you distribute

Binds Art. 21(1) is expressed impersonally and attaches to whoever produces or supplies goods, works or services using AI systems, so it reaches commercial and public suppliers alike with no size or sector threshold. Arts. 21(2), (3) and (5) place the marking, informing and output-conformity duties on собственники и (или) владельцы of the AI systems concerned — owners and holders — again without threshold. The administrative offence backing the synthetic-output limb is graded by business size, from natural person through small, medium and large business entities.. Art. 21 of Law No. 230-VIII carries Kazakhstan's transparency and synthetic-media rules, and unlike the labelling provisions in Russia's 243-FZ it is a genuine duty rather than an entitlement. Art. 21(1) requires that users be informed that goods, works and services are produced or supplied using AI systems — a broad, unthresholded disclosure obligation attached to the commercial offering itself, not merely to generated content. Art. 21(2) then provides that dissemination of synthetic results of AI activity is permitted only on condition that they are marked in machine-readable form AND accompanied by a visual or other form of warning that the user can actually perceive without methods that impede such perception — a dual-layer requirement, machine-readable plus human-perceptible, with an express anti-obfuscation limb. Art. 21(3) places responsibility for informing users about synthetic outputs on the owners or holders of the systems, and art. 21(5) makes the owner and (or) holder responsible for ensuring that the outputs of AI systems conform to the requirements of Kazakh legislation generally. Art. 21(4) is the signpost that matters for automated decision-making: requirements for taking decisions on the basis of exclusively automated processing of personal data are set by the personal-data legislation, i.e. art. 19-1 of Law No. 94-V, tracked separately at kz-pd-art19-1. Art. 22 supports art. 21 by mandating machine-readable forms that allow conditions to be recognised automatically and unambiguously by AI systems and other data-processing means, with the procedure for developing, applying and distributing them to be determined by the authorised body — so the technical standard for the art. 21(2) marking is delegated and not yet fixed on the face of the statute.

In force since 18 January 2026. Art. 31 commences the Law «по истечении шестидесяти календарных дней после дня его первого официального опубликования», with no article carved out. The А́ділет record card gives first official publication as the newspapers «Егемен Қазақстан» No. 222 (31202) and «Казахстанская правда» No. 222 (30600), both of 18 November 2025, with the Reference Control Bank of NPA in electronic form following on 20 November 2025. The sixty days run from 19 November 2025 and expire at the end of 17 January 2026, so the Law entered into force on 18 January 2026. А́ділет serves the text as «Обновленный» (consolidated and current), database state 19 August 2026, and flags the only pending change — Law No. 326-VIII of 24 June 2026 — as a future «Примечание ИЗПИ» note rather than as applied text. Note that the machine-readable marking standard contemplated by arts. 21(2) and 22(3) is to be determined by the authorised body and no such act has been identified as at 21 August 2026, so the form of compliant marking is not yet fixed even though the duty itself is in force.

Stated maximum penalty — KoAP art. 641-1(1)(1) penalises the failure by owners or holders of AI systems to inform users about synthetic results of the system's activity that are capable of misleading them, where the act or omission carries no indicia of a criminal offence. First offence: 15 MRP for natural persons, 20 MRP for small business entities and non-commercial organisations, 30 MRP for medium business entities, 100 MRP for large business entities. Repeat within a year of a penalty being imposed: 30, 50, 70 and 200 MRP respectively, together with suspension or prohibition of the operation of the AI system. Two limits are worth stating precisely. The offence is drafted around informing about synthetic outputs «которые могут ввести их в заблуждение» — capable of misleading — so it is narrower than art. 21(2), which conditions dissemination of ALL synthetic results on marking; and it does not reach the art. 21(1) duty to disclose that goods, works or services are produced using AI at all. Cases are decided by the authorised body in the field of artificial intelligence under KoAP art. 692-3. Amounts are stated in the mесячный расчетный показатель (MRP, monthly calculation index), the statutory unit the Code uses; the tenge value of one MRP is reset every year by the republican budget law, so the MRP figures rather than a converted tenge sum are the stable statement of the penalty.

In force · 18 Jan 2026 checked 21 Aug 2026 KZ AI Law art. 21 ↗ high confidence
Kazakhstan Binding

Personal Data Law art. 19-1 — automated processing that changes your rights is banned without consent, and objections get three working days

Binds Собственник и (или) оператор, а также третье лицо — the owner and (or) operator of a personal-data database and any third party, with no size, sector or turnover threshold, so enterprise, SME and public body are covered alike. Note that the art. 19-1 duty runs to the third party as well as to the owner and operator, which is broader than the equivalent Russian and Uzbek provisions. The general exclusions in art. 19 for the exercise by state bodies of their statutory functions, for private notaries, private court enforcement agents and advocates, and for collection and processing for statistical, sociological or scientific purposes attach to art. 19 and not to art. 19-1.. Kazakhstan's automated-decision rule is new: art. 19-1 was added to the Law No. 94-V of 21 May 2013 «О персональных данных и их защите» by Law No. 231-VIII of 17 November 2025, the companion act to the AI Law, and it took effect on 18 January 2026. Art. 19-1(1) prohibits automated processing of personal data as a result of which the subject's rights or legitimate interests arise, change or cease, except where the subject's consent has been obtained or in cases provided by the laws of Kazakhstan. Three drafting choices distinguish it from the neighbouring regimes the tracker already carries. First, the trigger is the automated PROCESSING rather than a decision taken on its basis, and art. 1(2-3) of the Law defines automated processing as processing by an informatisation object that excludes the participation of the owner, operator or third party in the process — so the exclusivity test sits in the definition. Second, the consequence limb is drafted as rights or legitimate interests arising, changing or ceasing, which is narrower than Russia's art. 16 «иным образом затрагивающих» catch-all but avoids GDPR art. 22(1)'s significance threshold. Third, and unlike both Russia's art. 16(2) and Uzbekistan's art. 24, there is NO contract exception and NO written-form qualifier on the consent: ordinary consent under the Law suffices, which makes the exit both easier to reach and less formal than Russia's art. 9(4) written consent with identity-document particulars. Art. 19-1(2) is a standing, proactive duty on the owner, operator and third party to explain to the subject the procedure of the automated processing of their personal data and its possible consequences, to provide the opportunity to state an objection to that processing, and to explain how the subject may protect their rights, freedoms and legitimate interests. Art. 19-1(3) then gives THREE WORKING DAYS from receipt to consider the objection and notify the subject of the outcome — markedly tighter than Uzbekistan's ten days and Russia's thirty — and preserves the right to challenge the acts or omissions of the owner, operator or third party in the manner established by law. As in Russia and Uzbekistan, nothing obliges the controller to change the decision, and no right to human intervention or to an explanation of the LOGIC is expressed. Note for anyone working from the earlier research note: art. 20 of this Law is not the relevant provision — it is a general guarantee that personal data are protected by the state — and the automated-processing rule is art. 19-1.

In force since 18 January 2026. The Сноска to art. 19-1 records that Chapter 2 was supplemented with the article by Law No. 231-VIII of 17 November 2025 «по вопросам искусственного интеллекта и цифровизации», commencing on expiry of sixty calendar days after first official publication. The Әділет record card for 231-VIII gives that publication as «Егемен Қазақстан» No. 222 (31202) and «Казахстанская правда» No. 222 (30600), both 18 November 2025, so the period expired at the end of 17 January 2026 and the article took effect on 18 January 2026 — the same day as the AI Law. Art. 19-1 has not itself been amended since; the pending Law No. 326-VIII of 24 June 2026 is flagged by ИЗПИ against arts. 19(1), 22(2) and others but not against art. 19-1. Text checked in the consolidated redaction, database state 19 August 2026.

Stated maximum penalty — No penalty is addressed to art. 19-1 specifically. KoAP art. 641-1, the AI offence created alongside it by Law No. 232-VIII, covers only the synthetic-output information failure and the high-risk risk-management failure, and neither reaches automated processing under the Personal Data Law. Breach therefore falls back on the general personal-data offences in the Code — principally KoAP art. 79-1, unlawful collection and processing of personal data — whose bands are not specific to automated processing, and on the art. 27 remedies of the Law itself. This entry states no figure rather than importing an adjacent band, because the offence that would apply depends on which limb of art. 19-1 was breached and the Code contains no automated-processing article.

In force · 18 Jan 2026 checked 21 Aug 2026 KZ Personal Data Law art. 19-1 ↗ medium confidence

Morocco 1

Morocco Binding

Loi 09-08 art. 11 — neutrality of the effects of automated processing: bar on decisions grounded solely in automated profiling

Binds Controllers within the scope of art. 2: processing of personal data wholly or partly by automated means, and non-automated processing of personal data contained in or intended to form part of manual files, where the controller is established on Moroccan territory and carries on an activity there, or is not established in Morocco but resorts, for the purposes of processing personal data, to automated or non-automated means situated on Moroccan territory. A controller in the second case must designate a representative established in Morocco who is substituted for it in the rights and obligations arising under the Law. Prior declaration to, or prior authorisation from, the Commission Nationale de contrôle de la protection des Données à caractère Personnel is a standing precondition of processing under arts. 12 and 13, with art. 12 requiring prior authorisation for sensitive-data and other listed processing. The art. 11 bar binds any controller taking a decision with legal effects grounded solely in automated profiling or personality evaluation, irrespective of size, and its first paragraph binds courts. Impact tier: all entities.. Article 11 of Law No. 09-08 relating to the protection of individuals with regard to the processing of personal data, headed “Neutralité des effets d'un traitement automatisé”, carries Morocco's operative automated-decision rule. Its first paragraph provides that no judicial decision involving an appraisal of a person's conduct may be founded on automated processing of personal data intended to evaluate certain aspects of that person's personality. Its second paragraph extends the bar beyond the courts: no other decision producing legal effects in respect of a person may be taken on the sole basis of automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. Its third paragraph sets the carve-out: decisions taken in the course of the conclusion or the performance of a contract, and for which the data subject has been put in a position to make observations, are not regarded as taken on the sole basis of automated processing, and neither are decisions granting a request made by the data subject. Article 7(c) supplies the companion transparency right, entitling the data subject to knowledge of the logic underlying any automated processing of personal data concerning them, alongside the confirmation and communication rights in art. 7(a) and (b). Article 11 is a transposition of art. 15 of Directive 95/46/EC by way of the French model, drafted in 2009 and so predating the GDPR: it speaks of automated processing intended to profile or to evaluate personality rather than of “profiling” as a defined term, and the safeguard it names is an opportunity to make observations rather than human intervention.

Law 09-08 was promulgated by Dahir nº 1-09-15 of 22 safar 1430 (18 February 2009) and published, together with the dahir, in Bulletin Officiel nº 5714 of 7 rabii I 1430 (5 March 2009), the date recorded here. The Law contains no commencement clause and no deferred-commencement mechanism: it ends at art. 67 and the dahir simply orders publication in the Bulletin Officiel. The date is therefore the publication date of the Bulletin Officiel carrying the text, read off the header of the copy published by the CNDP; the general Moroccan rule tying entry into force to that publication has not itself been read against a primary source, which is why confidence is recorded as medium rather than high. Article 67 is transitional only: it gave persons already carrying on processing before publication a maximum of two years, running from the date of the CNDP's installation as recorded by an administrative act published in the Bulletin Officiel, to regularise their declarations and authorisations, and on its own terms it reaches the declaration and authorisation regime rather than the art. 11 bar. Décret nº 2-09-165 was taken for the application of the Law; the CNDP publishes it only in Arabic and no date claim is drawn from it here. Coverage symmetry against the four African rows already tracked: Morocco is the oldest drafting of the five and the only one in the Directive 95/46/EC lineage rather than the GDPR art. 22 or UK DPA 1998 s. 12 lineages. Structurally it is closest to za-popia-s71 — both are prohibitions whose contract exception is conditioned on the data subject having had an opportunity to make representations, and neither grants human intervention or a fresh decision — but Morocco is narrower in two ways and wider in one. It is narrower in that its bar reaches only decisions producing legal effects, with no “substantial degree” or “significant effect” limb as in South Africa, Kenya, Nigeria, Rwanda, Tanzania and Ghana, and in that its disclosure duty sits in art. 7(c) as an access right rather than inside the automated-decision article as in za-popia-s71(3). It is wider in that its first paragraph binds courts directly, which no other row on the tracker does. It carries no deadline. Text read in the copy of the Law published by the CNDP, the supervisory authority instituted by the Law.

Stated maximum penalty — Article 11 has no dedicated penalty: the criminal tier in Chapter VII attaches to named articles and art. 11 is not among them. Article 53 punishes a controller that refuses the access, rectification or objection rights under arts. 7, 8 and 9 with a fine of MAD 20,000 to MAD 200,000 per infringement, which reaches the art. 7(c) right to know the logic underlying automated processing but not the art. 11 bar itself. The nearest general route is art. 63, under which a controller that refuses to apply the decisions of the Commission Nationale is liable to imprisonment of three months to one year and a fine of MAD 10,000 to MAD 100,000, or one of those penalties only; art. 62 punishes obstruction of the Commission's supervisory functions with imprisonment of three to six months and a fine of MAD 10,000 to MAD 50,000, or one of them. Article 64 doubles the fines where the offender is a legal person, without prejudice to penalties on its officers, and allows partial confiscation of assets, confiscation under art. 89 of the Penal Code, and closure of the establishment where the offence was committed; art. 65 doubles the sanctions on repeat offence within a year of a final conviction. Article 66 lets sworn agents of the Commission, alongside judicial police officers, investigate and record infringements by procès-verbal for transmission to the Crown Prosecutor within five days.

In force · 5 Mar 2009 checked 20 Aug 2026 Loi 09-08 art. 11 ↗ medium confidence

Madagascar 1

Madagascar Binding

Loi n° 2014-038 art. 3 — the wide automated-decision bar stated as a founding principle, with no exception and a 5% turnover catch-all behind it

Binds Responsables de traitement, on the terms of the art. 5 scope: the Law applies to any processing of personal data, automated or not, contained or intended to be contained in files, carried out in whole or in part on Malagasy territory, excluding processing for exclusively personal activities and processing for the sole purposes of journalism or literary or artistic expression. Art. 6 fixes the applicable-law rules. The prior-formality regime runs through Chapitre VI: art. 43 sets the declaration channel and art. 44 the categories reserved to a regulatory act, with art. 76 providing that processing governed by art. 44 and already created is subject only to a declaration. Neither profiling nor automated decision-making appears as a category attracting prior authorisation, so Madagascar, like Guinea and Togo and unlike Burkina Faso and Niger, imposes no ex ante gate on the processing art. 3 governs. The art. 3 bar itself binds two distinct classes of decision-maker with no size or sector threshold: under its first limb the courts, and under its second every administrative and private decision-maker appraising human conduct. Art. 52 provides for a délégué à la protection des données who exercises their functions independently, receives no instructions from the controller and may not be sanctioned for exercising them. Impact tier: all entities.. Article 3 of Loi n° 2014-038 du 9 janvier 2015 sur la protection des données à caractère personnel is Madagascar's operative automated-decision rule, and it is placed as a founding principle rather than as an operative duty: it sits in Chapitre premier, Dispositions générales, immediately after art. 2, which declares that data processing must serve every person and respect human identity, human rights, privacy and individual and public liberties, and immediately before art. 4, which creates the Commission Malagasy de l'Informatique et des Libertés. The article has two unnumbered paragraphs. The first: no judicial decision involving an appraisal of human conduct may have as its foundation an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The second: no administrative and private decision involving an appraisal of human conduct may have as its sole foundation an automated processing of data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. Three features of the drafting matter. The judicial limb does not carry the word "seul", while the second limb of the same article does, so a court appraising conduct may not rest on such a processing at all, whatever else it also relies on. The second limb takes the wide trigger — any administrative and private decision involving an appraisal of human conduct — rather than the narrow Directive 95/46/EC trigger confined to decisions producing legal effects, which is what Congo-Brazzaville, Gabon, Togo, Morocco and Algeria use. And the Law supplies no carve-out whatever: no contract exception, no consent exception, no legal-authorisation exception, and no opportunity to present observations. Madagascar therefore joins Côte d'Ivoire, Mali, Burkina Faso and Guinea in barring the conduct outright rather than deeming some decisions outside it. The Law does create a logic right, but it is narrower than the bar it accompanies: the third indent of the art. 23 access right entitles a data subject to the information enabling them to know and to contest the logic underlying an automated processing where a decision has been taken on its foundation and produces legal effects in their regard. Art. 3's own second limb is not limited to legal effects, so a decision appraising conduct without legal effects is barred by art. 3 while falling outside the art. 23 logic right. There is no human-review right, no right to a fresh non-automated decision, and the Law carries no definition of profiling.

The Law carries no commencement article. Its final provision, art. 78, is a bare publication and execution clause — the present Law shall be published in the Journal Officiel and executed as a law of the State — and nothing in the text defers art. 3 or any other article. The date recorded here, 9 January 2015, is the date of promulgation stamped in the signature block at Antananarivo over the signature of President Rajaonarimampianina Hery Martial, and it is the date by which the Law is universally cited, including in the ILO NATLEX record. The Law is numbered for 2014 and promulgated in 2015 because it was adopted by the National Assembly in 2014 and cleared by the Haute Cour Constitutionnelle first: the preamble recites décision n° 02-HCC/D3 du 07 janvier 2015, two days before promulgation. Confidence is medium for one reason only, and it is the same reason as for Morocco, Algeria and Togo: because art. 78 attaches publication rather than force, the operative date depends on the Malagasy general publication-to-force rule, which was not verified against a primary source, and the Journal Officiel issue and date for the Law could not be established from an official source. If Malagasy law makes force turn on Journal Officiel publication rather than on promulgation, the true date is later than the one recorded here by the length of the publication lag, and the row would need amending. Art. 76 is transitional and is not a deferral of art. 3: all processing implemented before entry into force had one year from publication to conform, on a sectoral timetable fixed by the Commission and published in the Journal Officiel, a period long since closed. Art. 77 leaves application modalities to regulatory texts. The Law abrogates nothing expressly and names no predecessor statute, so nothing is superseded on the tracker. Text read end to end — all 78 articles, from the exposé des motifs to the signature block — in the edition published by the Unité de Gouvernance Digitale, the Malagasy State's digital-governance unit, which serves the full statutory text as HTML and credits CNLEGIS, the State's legislative database, as its source. No AI-specific statute or guidance is in force in Madagascar.

Stated maximum penalty — Art. 3 is not an offence, and none of the penal articles reaches it — but the administrative route does, because art. 55 is a general catch-all. Art. 55 provides that the Commission Malagasy de l'Informatique et des Libertés may pronounce against a controller, in the event of a breach of one or more of the provisions of the present Law and after a contradictory procedure, a warning, a mise en demeure, a pecuniary sanction, and the further measures the article lists, with pecuniary sanctions doubled on recidivism. Because art. 55 is drafted against "une ou plusieurs des dispositions de la présente loi" without enumeration, it reaches art. 3 on its face. Art. 59 caps the pecuniary sanction: its amount must be proportionate to the gravity of the breaches and to the advantages derived from them, and it may not exceed 5 per cent of pre-tax turnover for the last closed financial year — the same ceiling as Côte d'Ivoire, Niger and Burkina Faso, and below Guinea's 7 per cent. Art. 57 allows any sanction decision to be coupled with an injunction to make, within a time limit the Commission sets, any modification or deletion it judges useful. Art. 58 requires the sanction to rest on a report notified to the controller, who may file written and oral observations and be represented or assisted, and provides that sanction decisions may be appealed to the Conseil d'Etat. Art. 60 makes sanction decisions public, allows the identity of natural persons to be anonymised, and lets the Commission order their insertion in publications or newspapers at the sanctioned person's expense. The penal articles, by contrast, are a closed list of named offences and none of them names art. 3: art. 61 punishes obstruction of the Commission with six months to two years' imprisonment and a fine of 800,000 to 8,000,000 Ariary; art. 62 failure to observe prior formalities, six months to two years and 200,000 to 2,000,000 Ariary; art. 63 unlawful processing of sensitive data, offence files or the national identification number by reference to arts. 14, 15, 17 and 18, two to five years and 800,000 to 8,000,000 Ariary; art. 64 breach of the art. 15 security measures; art. 65 unfair collection, two to five years and 1,000,000 to 10,000,000 Ariary; art. 66 misuse of purpose; art. 67 disregard of a founded rectification or objection request; art. 68 breach of the art. 27 information duty; art. 69 breach of the art. 23 access right; art. 70 over-retention; and art. 71 disclosure harming the person's standing or private life, two to five years and 1,000,000 to 10,000,000 Ariary. Art. 72 allows erasure of the data to be ordered in any of those cases and art. 73 requires the Procureur de la République to notify the Commission's president of prosecutions.

In force · 9 Jan 2015 checked 20 Aug 2026 Loi n° 2014-038 art. 3 ↗ medium confidence

Mali 1

Mali Binding

Loi 2013-015 art. 2 — a one-limb bar, stated as a founding principle, on decisions with legal effects resting solely on computerised profiling, with no exception of any kind

Binds Responsables du traitement within the scope of arts. 4 and 5. Art. 4 applies the Law to any processing of personal data carried out wholly or partly on national territory. Art. 5 subjects to the Law any processing of personal data by the State, local authorities, personalised public bodies, natural persons and private-law legal persons; any processing implemented by a controller established on national territory or not, excluding means used only for transit on that territory; and any processing concerning public security, national defence, the investigation and prosecution of criminal offences or State security, even where linked to an important economic or financial interest of the State, subject to the derogations provided by the Law or by other texts. Art. 6 excludes processing by a natural person in the exclusive course of personal or domestic activities where the data are not intended for systematic communication to third parties or for dissemination, and temporary copies made in the course of technical transmission and access activities. Art. 57 makes declaration to the Autorité de Protection des Données à caractère Personnel a standing precondition, and provides that where that formality has been omitted in bad faith the Autorité imposes the appropriate administrative sanction assessed by reference to the gravity of the fault. The art. 2 bar binds any decision-maker whose decision induces legal effects, irrespective of size or sector. Impact tier: all entities.. Mali's automated-decision rule is not in a rights chapter at all: it is the third paragraph of art. 2, in Chapitre I of Loi n° 2013-015 du 21 mai 2013 portant protection des données à caractère personnel en République du Mali, the chapter headed "De l'objet". Article 2 opens with the founding principle that informatics must be at the service of every person and must respect human identity, human rights, private life and public and individual freedoms, states that everyone has a right to the protection of the personal data concerning them, and then provides that no decision inducing legal effects with regard to a person may be taken on the sole basis of a computerised processing intended to define the profile of the person concerned or to evaluate certain aspects of their personality. Three features make it the leanest formulation in the Francophone family. It has one limb only — there is no separate bar addressed to the courts, which every other Francophone row on the tracker carries. It states no exception whatever: there is no contract deeming clause, no consent exception, no legal-authorisation exception and no opportunity to present observations, so on its face it shares that absence with Côte d'Ivoire's art. 25 alone. And it speaks of a "traitement informatique" rather than a "traitement automatisé", which is the older French formula. The companion right sits in art. 12, in Chapitre V on the rights of persons: everyone has the right to obtain from a controller the communication, in an intelligible form, of all the data concerning them together with any available information as to their origin, and — the operative half for automated decisions — the information and the reasoning used in computerised processing whose results are relied on against them. That right is exercised free of charge, on the spot or remotely, must be answered without delay, and a copy of the data conforming to the content of the processing is delivered on request; where there is a risk of concealment or disappearance of the data the Autorité may order any appropriate measure. There is no defined term for profiling and no right to obtain human intervention or a fresh non-automated decision.

The Law contains no commencement article: Chapitre X, headed "Des dispositions finales", consists of art. 69 alone, which provides only that practical implementation matters not covered by the Law are to be supplied by deliberation of the Autorité de Protection des Données à caractère Personnel in conformity with the spirit of the Law, and the text then ends with the promulgation formula "Bamako, le 21 mai 2013" and the signature of the interim President of the Republic, Professor Dioncounda Traoré. The date recorded here is the date of the Journal officiel de la République du Mali that carries the Law: fifty-fourth year, numéro 26 of 28 June 2013, pp. 1002 to 1011, whose masthead, table of contents entry and per-page footers were read directly. That is the same basis used for Morocco, Algeria and Côte d'Ivoire. Confidence is medium for the same reason: the Malian general publication-to-force rule was not itself read against a primary source, so it could not be confirmed whether force attaches on the day of publication of the Journal officiel or after a delay. Art. 68 is transitional and not a deferral of art. 2: public services and natural or legal persons whose activity before the date of promulgation consisted, principally or incidentally, in processing personal data had a maximum of six months to conform, failing which their activities are deemed contrary to the Law and must cease without delay — a period that closed in 2013. The Law was adopted by the Assemblée nationale in its sitting of 9 May 2013. Text read in the Journal officiel itself, which is the official gazette published by the Secrétariat général du Gouvernement. Coverage symmetry against the fourteen African rows already tracked: art. 2 belongs to the Directive 95/46/EC art. 15 line but is the shortest and oldest-sounding member of it, and it is the only automated-decision provision on the tracker that sits inside a purposes-and-principles article rather than in a rights or obligations chapter. Against its neighbours: Senegal's art. 48, Morocco's and Algeria's art. 11 all carry a judicial limb and a contract deeming clause, and Mali has neither; Côte d'Ivoire's art. 25 and Niger's art. 52 carry a judicial limb and, in Côte d'Ivoire's case, no exception, so Mali and Côte d'Ivoire are the only two African rows with no exception at all, and Mali is the barer of the two because it lacks the judicial limb. Mali's art. 12 reasoning-disclosure right is, word for word in substance, the third paragraph of Niger's art. 52 — the right to know and contest the information and the reasoning used in processing whose results are relied on against the person — which puts Mali and Niger together as the only Francophone rows on the tracker with that right, though Niger states it inside the automated-decision article itself and adds an artificial-intelligence clause that Mali has nothing resembling. The four-way African lineage picture is unchanged: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, sn-loi200812-art48, ci-loi2013450-art25, ne-loi202259-art52, bj-code-num-art401 and now ml-loi2013015-art2; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — No offence reaches art. 2. Art. 58 provides that, save where the Law makes special provision in computing matters, the classification of offences and the penalties applicable to them are those defined by the Penal Code, the Code des personnes et de la famille, the electoral law and the other laws creating offences in the field of personal data protection, with procedure governed by the Code de Procédure Pénale. The Law's own two fine articles name their own conduct and neither names an automated decision. Art. 65 punishes with a fine of 5,000,000 to 20,000,000 francs the communication to unauthorised third parties of, or unauthorised or unlawful access to, personal data engaging fundamental rights, individual freedoms or private life; the diversion or any modification of the purpose of a collection or processing without the express and reasoned authorisation of the Autorité; collection by fraudulent, unfair or unlawful means, or processing of nominative information concerning a natural person despite that person's objection where the objection is founded on legitimate reasons connected to their fundamental rights or private life; automated processing of nominative personal data for health research in violation of laws and regulations; and, outside the cases provided by law, placing or keeping in computerised memory nominative data concerning offences, convictions or national security measures, that last offence applying also to non-automated or mechanographic files. Art. 66 punishes with a fine of 2,500,000 to 10,000,000 francs processing nominative information without taking all precautions to preserve its security, in particular against distortion or damage, and placing or keeping in computerised memory, without the prior agreement of the person concerned, nominative data revealing directly or indirectly racial or ethnic origins, political, philosophical or religious opinions or trade-union membership. The route that reaches art. 2 is administrative and is set out in art. 61, which lists the Law's administrative sanctions exhaustively: a warning against any good-faith controller that has not observed the administrative formalities of collection, processing and management laid down by the Law or by the Autorité's regulatory acts; a mise en demeure of the controller at fault to bring itself into conformity; an injunction to cease personal-data processing activities in case of fault; and withdrawal of the agrément where the Autorité finds it necessary. Art. 62 lets the Autorité use every technical means in its possession to secure the automatic execution of its decision; art. 63 requires administrative sanction decisions to be reasoned on pain of nullity and notified to those concerned; art. 59 confirms that the Autorité imposes the administrative and pecuniary sanctions flowing from the Law without prejudice to criminal sanctions and may institute simple-police contraventions by lawfully made regulations; art. 67 lets the Autorité settle any pecuniary sanction by transaction at the offender's request, subject to the scales fixed by law; and art. 56 lets the President of the Autorité denounce any infringing user to the Procureur de la République or bring a complaint before the competent courts. Art. 60 leaves civil actions to the Code de Procédure Civile, Commerciale et Sociale and the Régime Général des Obligations. Notably, art. 61 attaches no fine to a breach of art. 2 — the administrative list stops at withdrawal of agrément.

In force · 28 Jun 2013 checked 17 Aug 2026 Loi n° 2013-015 art. 2 ↗ medium confidence

Mauritania 1

Mauritania Binding

Loi n° 2017-020 art. 19 — the pre-GDPR bar with no exception at all, and a judicial limb the others do not have

Binds Every controller within art. 3, which sets four cumulative reaches: any processing of personal data carried out by a natural person, by the State, by local authorities, or by legal persons of public or private law; any automated or non-automated processing of data contained in or intended to figure in a file, excepting the processing at art. 4; any processing implemented by a controller on Mauritanian territory or anywhere Mauritanian law applies; and any processing implemented by a controller, established on Mauritanian territory or not, that has recourse to processing means situated on the national territory. That last limb is the means-in-territory test rather than the GDPR's targeting test, so a foreign controller computing an automated decision on Mauritanian infrastructure is caught while one scoring Mauritanian residents entirely from abroad may not be. No size or sector threshold applies — enterprise, SME, public body and individual controllers alike. The first paragraph of art. 19 binds a different addressee entirely: the courts, and by extension anyone submitting automated behavioural assessment into judicial proceedings. Hiring sits inside the second paragraph only where the outcome produces legal effects — the termination or refusal of a contract of employment does; a ranked shortlist on its own is harder to place, and the Law gives no gloss. Two neighbouring articles matter for scope: art. 12 prohibits collection and processing revealing racial, ethnic, linguistic or regional origin, filiation, political opinions, religious or philosophical convictions, trade-union membership, sexual life, genetic data or health data, subject to the art. 13 exceptions, so a profiling model drawing on those inputs fails at art. 12 before art. 19 is reached; and art. 18 requires prior consent for direct marketing by any means of communication.. Article 19 of Loi n° 2017-020 du 22 juillet 2017 sur la protection des données à caractère personnel is two paragraphs, and the first has no counterpart in any other row on the tracker. It provides that «aucune décision de justice impliquant une appréciation sur le comportement d'une personne, ne peut avoir pour fondement un traitement automatisé des données à caractère personnel destiné à évaluer certains aspects de sa personnalité» — no judicial decision involving an assessment of a person's conduct may be founded on automated processing of personal data intended to evaluate certain aspects of their personality. That is a rule addressed to courts, not to controllers, and it bars algorithmic input into sentencing, bail and any other judicial appraisal of behaviour outright. The second paragraph is the general bar: «aucune décision, produisant des effets juridiques à l'égard d'une personne, ne peut être prise sur le seul fondement d'un traitement automatisé des données à caractère personnel destiné à définir le profil de l'intéressé ou à évaluer certains aspects de sa personnalité» — no decision producing legal effects with respect to a person may be taken on the sole basis of automated processing intended to define that person's profile or to evaluate certain aspects of their personality. This is art. 2 of France's Loi n° 78-17 in its pre-2018 wording, carried across whole, and it is the pre-GDPR shape in three respects. It has no exception limb of any kind — no contract, no consent, no legal authorisation, nothing — so on its face it is as absolute as art. 14(5) of the Malabo Convention. It has no profiling definition; «définir le profil» does the work as an ordinary-language phrase. And its threshold is narrower than the modern one: it catches decisions producing «effets juridiques» only, with no «significantly affects» limb, so a purely commercial automated refusal with no legal effect falls outside the second paragraph even where it would be caught in Zambia, Mauritius or under the Convention. There is no explanation limb anywhere in the Law. The art. 53 right of access runs to five items — information allowing the person to know and where appropriate contest the processing, confirmation, communication of the data in accessible and intelligible form, purposes and categories and recipients, and envisaged third-country transfers — and none of them is a logic item; the information duty at collection runs to nine items ending at the right to ask to be removed from the file, and carries no automated-decision item either. There is no right to human intervention and no right to contest the decision as such. Mauritania is the Angola shape at a different latitude: the machine decision is forbidden and never has to be explained.

Dated 22 July 2017 and published in the Journal Officiel de la République Islamique de Mauritanie no. 1400 of 15 November 2017, which is the date printed in the running head of every page of the official text. Article 101 is the standard promulgation formula — «La présente loi sera exécutée comme loi de l'Etat et publiée au Journal Officiel de la République Islamique de Mauritanie» — signed at Nouakchott on 22 July 2017 by President Mohamed Ould Abdel Aziz, Prime Minister Yahya Ould Hademine and the Minister for Employment, Vocational Training and Information and Communication Technologies. There is no deferred commencement clause and no proclamation power, so the law date is carried here, consistent with how every other Francophone row on the tracker is dated. Two qualifications keep this row at medium rather than high confidence, and neither is about the text of art. 19. First, arts. 99 and 100 create a transitional regime that runs from a compound trigger: «à compter de la date d'entrée en vigueur de la présente loi et de la mise en place effective de l'Autorité de Protection des Données à caractère personnel», existing processing had three years to conform where operated for the State, a public establishment, a local authority or a private legal person managing a public service, and two years otherwise, with art. 100 deeming unregularised processing to have been carried on without declaration or authorisation. The Autorité de Protection des Données à caractère personnel was not stood up in 2017 — its members were sworn in years later — so the transitional clock started late, and while art. 19 is a prohibition rather than a formality subject to régularisation, an enforcement action grounded on the pre-authority period would meet that argument. Second, the currency. The fines in this Law are stated in ouguiyas as they stood in 2017; Mauritania redenominated on 1 January 2018 at ten old ouguiya (MRO) to one new ouguiya (MRU), so every figure in the Law reads ten times larger than its present-day equivalent unless converted. Mauritania deposited its instrument of ratification of the Malabo Convention on 9 May 2023, and that deposit is the fifteenth — it is the instrument that triggered art. 36 and brought the Convention into force for every party on 8 June 2023. So Mauritania is both bound by art. 14(5) and the reason art. 14(5) binds anyone. Where the two diverge they diverge very little: neither art. 19 nor art. 14(5) admits any exception, and the only real gap is that the Convention adds a «significantly affects to a substantial degree» limb that art. 19's «effets juridiques» threshold does not reach.

Stated maximum penalty — Administrative only, and no criminal penalty attaches to art. 19. The penal section, arts. 84 to 98, was read article by article: art. 84 obstruction of the Authority, art. 85 processing without the prior formalities, art. 86 processing subject to an art. 77, 78 or 79 measure, art. 87 collection by fraudulent, unfair or unlawful means, art. 88 processing without the required security measures, art. 89 processing despite the person's opposition, art. 90 storing sensitive data without express consent, arts. 91 to 94 retention beyond purpose, diversion of purpose and breach of confidentiality. None of them names art. 19 and no article of the Law cross-refers to it, so a solely-automated decision is not, on its own, an offence in Mauritania. What does reach it is art. 80: for breaches of the legal and regulatory provisions on personal data, and beyond the measures at arts. 77 to 79 (warning, mise en demeure, provisional or definitive withdrawal of authorisation, interruption of processing for up to three months, blocking of data), the Authority may impose pecuniary sanctions proportionate to the gravity of the breach — on a first breach not exceeding ten million ouguiyas, and on a repeat breach within five years of a previous sanction becoming final not exceeding fifty million ouguiyas or, for an undertaking, 5% of pre-tax turnover for the last closed financial year. Read in post-redenomination currency those ceilings are MRU 1,000,000 and MRU 5,000,000 respectively. Article 82 permits publication of the sanction at the sanctioned party's expense; art. 83 gives a right of appeal to the Cour Suprême. Article 96 makes legal persons other than the State, local authorities and public establishments criminally liable for offences under the Law committed on their behalf, and art. 97 sets corporate fines at five times the natural-person maximum, with dissolution available — but that machinery hangs off the penal articles, which art. 19 is not among. Impact tier: all entities.

In force · 22 Jul 2017 checked 22 Aug 2026 Loi n° 2017-020 art. 19 ↗ medium confidence

Mauritius 1

Mauritius Binding

Data Protection Act 2017 s. 38 — the African automated-decision bar that a criminal penalty actually backs

Binds Every controller and processor within the Act's reach. Section 3(1) binds the State expressly and s. 3(2) treats each Ministry or Government department as separate from every other, so a public-sector automated decision is in scope on the same terms as a private one — a drafting choice worth noting, because the Convention's own machinery assumes a national authority policing both. Section 3(3) applies the Act to processing of personal data wholly or partly by automated means, and to non-automated processing where the data form or are intended to form part of a filing system. The exclusions at s. 3(4) are narrow: exchanges of information between Ministries, Government departments and public sector agencies on a need-to-know basis, and processing by an individual in the course of a purely personal or household activity. There is no size, sector or turnover threshold, so the bar reaches enterprise, SME, public body and — Mauritius being a substantial offshore financial centre — the management companies and global-business licensees the Data Protection Office has issued separate registration advice to. Hiring is in scope through the s. 2 definition of profiling, which names «performance at work» among the personal aspects it covers, and credit, insurance and AML/CFT screening decisions fall the same way; the s. 38(2)(b) legal-authorisation limb is the one most likely to be reached for by a regulated financial institution, and it is the limb that requires the authorising law itself to lay down safeguards. The s. 5(i) function of the Commissioner is the tell that this was drafted with automated decisions in mind: the Commissioner is to «examine any proposal for automated decision making or data linkage that may involve an interference with, or may otherwise have an adverse effect, on the privacy of individuals and ensure that any adverse effect of the proposal on the privacy of individuals is minimised».. Section 38(1) of the Data Protection Act 2017 (Act 20/2017) provides that «every data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or significantly affects him». Mauritius passed the Act on 8 December 2017, three days before the GDPR's own application date was a year away, and the transposition is close: s. 38(2) carries the three exceptions in GDPR order — (a) necessary for entering into, or performing, a contract between the data subject and a controller; (b) authorised by a law to which the controller is subject «and which lays down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests»; (c) based on the data subject's explicit consent. Two refinements distinguish it from the Zambian and Francophone rows. Section 38(3) bars any automated processing intended to evaluate certain personal aspects relating to an individual from being based on special categories of personal data — an outright prohibition rather than a consent-gated permission, and stricter on its face than GDPR art. 22(4), which allows special-category automated decisions on explicit consent or substantial public interest. And s. 38(5) narrows the safeguard duty to the contract and explicit-consent limbs at s. 38(2)(a) and (c), leaving the s. 38(2)(b) legal-authorisation route to be policed by the safeguards the authorising law itself must lay down. Mauritius also has the fullest explanation limb of the four Malabo parties added in this pass, and it runs in three places. Section 23(1)(g), the information duty at collection, requires the controller to give «the existence of automated decision making, including profiling, and information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject» — proactive, not on request. Section 37(2)(h) repeats the same item inside the right of access, so it is available reactively too. And s. 38(4) adds a specific overlay: where an exception at s. 38(2) is relied on, the s. 23 information «shall include information as to the existence of processing for a decision of the kind referred to in subsection (1) and the envisaged effects of such processing on the data subject». Section 34(2)(a) then makes a data protection impact assessment mandatory before «a systematic and extensive evaluation of personal aspects relating to individuals which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the individual or significantly affect the individual».

In force since 15 January 2018, by proclamation. Section 58(1) provides that the Act «shall come into operation on a date to be fixed by Proclamation» and s. 58(2) allows different dates for different sections; the header of the official Data Protection Office text records «Proclaimed by [Proclamation No. 3 of 2018] w.e.f. 15 January 2018», with no sectional split, so the whole Act including s. 38 has run from that date. The surrounding dates are all distinct and none of them is the operative one: passed by the National Assembly on 8 December 2017, assented by President Bibi Ameenah Firdaus Gurib-Fakim on 22 December 2017, published in the Government Gazette of Mauritius No. 120 of 23 December 2017. The Act is not a first-generation instrument — s. 56 repeals the Data Protection Act 2004, and s. 57 carries transitional provisions, so a Mauritian automated-decision rule of some kind predates 2018; the 2017 rewrite is what put the GDPR-shaped s. 38 in place and that is the date carried here. Mauritius ratified the Malabo Convention on 6 March 2018 and deposited on 14 March 2018 — the earliest deposit of the four parties added in this pass, and eight weeks after its own Act commenced — so from 8 June 2023 both instruments bind. Where they diverge the statute is the operative rule and the treaty runs behind it, because art. 14(5) of the Convention admits no contract, consent or legal-authorisation exception while s. 38(2) admits all three. Mauritius is also the only one of the four whose national law goes further than the Convention in the other direction: art. 16 and art. 17 of the Convention carry no logic item at all, while ss. 23(1)(g), 37(2)(h) and 38(4) carry three overlapping ones. So the Mauritian position is a bar with more exits than the treaty allows, guarded by an explanation duty the treaty never imposed.

Stated maximum penalty — A fine not exceeding 200,000 rupees and imprisonment for a term not exceeding 5 years, under s. 43(1) — and unlike Zambia, the route to it is explicit on the face of the section. Part VII (rights of data subjects, ss. 37-41) contains no penalty of its own, but s. 43(1) is drafted to sweep: «Any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act shall, on conviction, be liable to a fine not exceeding 200,000 rupees and to imprisonment for a term not exceeding 5 years». The words «or who otherwise contravenes this Act» are what carry a s. 38 breach into the penalty; without them the Mauritian position would be the Zambian one. Note the conjunction: the subsection reads «and» rather than «or» between fine and imprisonment, which on a literal reading makes both cumulative on conviction rather than alternative — an unusual drafting result, recorded as it stands rather than softened. Section 43(2) adds that the Court may order forfeiture of any equipment or article used or connected with the offence, and may order or prohibit the doing of any act to stop a continuing contravention. Separately, s. 42 creates a specific unlawful-disclosure offence, with s. 42(5) reaching a person who offers to sell personal data obtained in breach of it and s. 42(6) treating an advertisement indicating that personal data is or may be for sale as an offer to sell. Enforcement short of prosecution runs through the Commissioner: s. 6 investigation of complaints, s. 7 power to require information, s. 8 preservation order and s. 9 enforcement notice, with a right of appeal under s. 51 and the special jurisdiction of the Tribunal under s. 52. Impact tier: all entities.

In force · 15 Jan 2018 checked 19 Aug 2026 Data Protection Act 2017 s. 38 ↗ high confidence

Mexico 1

Mexico Binding

LFT Capítulo IX Bis — algorithmic work-management policy and human review for digital-platform workers

Binds Natural or legal persons that operate or manage digital platforms assigning tasks, services or jobs to workers in Mexico, in their capacity as employer, where the service requires the worker's physical presence (Art. 291-A/291-B); users, consumers or beneficiaries ordering through the app are not employers. Impact tier: enterprise (platform operators), with duties owed to every platform worker.. Chapter IX Bis of the Ley Federal del Trabajo, added by the decree published in the Diario Oficial de la Federación (Edición Vespertina) of 24 December 2024, treats work mediated by a digital platform that requires the worker's physical presence as a subordinate employment relationship (Art. 291-A) and regulates the algorithm that runs it. Art. 291-J requires the rules for assigning tasks, services or jobs through algorithms or analogous mechanisms to be transparent, clear and known to every platform worker, defines an algorithm as a decision-making system that exercises command and supervision over the worker in an automated or analogous way, and requires the platform to produce an 'algorithmic work-management policy' document in plain language covering (I) the consequences of complying or not complying with instructions, including expected waiting, travel and service times; (II) the consequences and impact of third-party ratings; (III) the incentives and penalties used to influence intensity, quality, frequency, timing or pace of work; (IV) any categories whose membership affects task allocation and their general rules; and (V) any other criteria feeding algorithmic decisions, including those affecting access to future tasks, bonuses or sanctions. That policy forms part of the employment contract, has to be known at the start of the relationship and re-accepted on any change, and the algorithm has to be reasonable in its requirements, not endanger the worker's health or integrity, and not operate as a factor of discrimination. Art. 291-P separately requires platforms to provide a channel to review decisions that affect or interrupt a worker's connection or access to the platform, and requires that channel to be run by staff with autonomy and review power — expressly not by algorithms or similar mechanisms; deactivation without a written notice stating the conduct relied on, accompanied by a detailed task, connection-time and rating report, is void.

Commencement is on the face of the decree: Transitorio Primero of the DOF decree of 24 December 2024 provides that it enters into force 180 days after publication, i.e. 22 June 2025. Text read in the Cámara de Diputados reproduction of the DOF Edición Vespertina of 24 December 2024 (LFT_ref49_24dic24.pdf) and cross-checked against the consolidated LFT (Última Reforma DOF 14-05-2026), where Arts. 291-A to 291-Q and Art. 997-B all carry the note 'Artículo adicionado DOF 24-12-2024'. Transitorio Segundo required IMSS/INFONAVIT to publish general rules for an obligatory pilot on social-security enrolment (Art. 291-K V and VI) within 5 days of entry into force; that pilot affects the enrolment duties only, not the Art. 291-J algorithmic-policy or Art. 291-P human-review duties, which apply from 22 June 2025 without a pilot phase. Distinct from mx-lft-lfda, which is the May 2026 performer-voice/image AI reform of the same statute. This is Mexico's peer of the CAC Algorithmic Recommendation Provisions Art. 20 tracked at cn-algo-recommendation.

Stated maximum penalty — Art. 997-B LFT (added DOF 24-12-2024), applied by the labour authorities and independent of any sanction under other laws: 1,000 to 25,000 times the Unidad de Medida y Actualización (UMA) for failing to issue the algorithmic work-management policy of Art. 291-J or to notify changes to it; 500 to 25,000 UMA for failing to establish the Art. 291-P review mechanisms; 2,000 to 25,000 UMA for not registering the model contract under Art. 291-G; and 250 to 5,000 UMA for breach of the special employer duties in Art. 291-K. The UMA is set annually by INEGI, so the peso value of each band moves each February.

In force · 22 Jun 2025 checked 21 Aug 2026 LFT Cap. IX Bis (DOF 24-12-2024) ↗ high confidence

Mozambique 1

Mozambique Binding

Malabo Convention art. 14(5) — the automated-decision bar that binds by treaty, in a country with no data-protection law

Binds Anyone processing personal data in Mozambique. The Convention's scope article, art. 9(1), reaches (a) any collection, processing, transmission, storage or use of personal data by a natural person, the State, local communities and public or private corporate bodies; (b) any automated or non-automated processing of data contained in or meant to be part of a file; (c) any processing of data undertaken in the territory of a State Party; and (d) processing relating to public security, defence, research, criminal prosecution or State security, subject to exceptions in other extant laws. Art. 9(2) excludes purely personal or household processing not systematically communicated to third parties, and temporary technical copies made for network transmission. The territorial hook at art. 9(1)(c) is a processing-in-territory test, narrower than the GDPR art. 3 targeting test Cabo Verde adopted in 2021 and narrower than the Democratic Republic of the Congo's art. 184, which reaches processing carried out abroad; a foreign scoring or hiring-assessment operator with no processing activity in Mozambique is not obviously caught. Impact tier: all entities — art. 14(5) carries no employee-count, turnover, sector or high-risk-system threshold, and its «intended to evaluate certain personal aspects» trigger is the classical Directive 95/46/EC art. 15(1) formula that reaches credit scoring, hiring assessment and conduct profiling alike. The practical qualification is enforcement rather than scope. Almost all of the Convention's machinery is routed through a «national protection authority»: art. 10(2) makes processing subject to a declaration before it, art. 10(4) makes genetic, health-research, offence, file-interconnection, national-identifier and biometric processing subject to its prior authorisation, art. 12 gives it audit and sanctioning powers, and art. 14(6)(b) makes it the gate for third-country transfers. Mozambique has not established one. The Autoridade Nacional de Proteção de Dados is to be created by the Proposta de Lei approved by the Council of Ministers on 3 March 2026 and still before the Assembleia da República. Until it exists, the substantive rule at art. 14(5) stands without an administrative enforcer, and the realistic routes are constitutional (art. 71 of the Constitution restricts the use of informatics for recording and processing individually identifiable data) and ordinary civil liability.. Mozambique has no national data-protection statute, and yet a solely-automated-decision prohibition binds there — it arrives by treaty rather than by legislation. Article 14(5) of the African Union Convention on Cyber Security and Personal Data Protection, adopted at Malabo on 27 June 2014, provides that «a person shall not be subject to a decision which produces legal effects concerning him/her or significantly affects him/her to a substantial degree, and which is based solely on automated processing of data intended to evaluate certain personal aspects relating to him/her». Mozambique signed on 29 June 2018, ratified on 2 December 2019 by Resolução n.º 5/2019 of the Assembleia da República, and deposited its instrument with the Chairperson of the African Union Commission on 21 January 2020. Under art. 18 of the Constitution of the Republic of Mozambique, validly approved and ratified international treaties are in force in the Mozambican legal order after official publication and for as long as they bind the State internationally, with the same rank as infra-constitutional acts of the Assembly and the Government — so the Convention is domestic law in Mozambique, not merely an international undertaking. The drafting of art. 14 is the thing to read closely, because the same article speaks in two registers. Paragraph 1 is addressed to governments: «State Parties shall undertake to prohibit any data collection and processing revealing racial, ethnic and regional origin...» — a duty to legislate, discharged only by passing a law. Paragraph 5 is not framed that way at all. It states a rule about what may be done to a person, in the passive voice, addressed to nobody in particular, and it therefore reads as self-executing in a way paragraph 1 does not. That split inside one article is why this row is carried at medium confidence rather than high: the obligation is real and its wording is direct, but no Mozambican court has been shown to apply it and no domestic instrument repeats it. What the Convention conspicuously does not do is explain. The bar has no exceptions — no contract limb, no consent limb, no legal-authorisation limb, unlike art. 15(2) of Directive 95/46/EC from which it descends and unlike every Lusophone and Francophone row on the tracker — so on its face it is the most absolute automated-decision prohibition tracked anywhere. But art. 16, the right to information, lists eight items (a)-(h) — identity, purposes, categories, recipients, removal, access and rectification, retention period, proposed transfers — and none of them is an automated-decision or logic item. Art. 17, the right of access, lists four items and carries neither. Art. 18 gives a right to object on legitimate grounds; art. 19 gives rectification, blocking and erasure. There is no right to obtain human intervention, no right to contest the decision, and no logic disclosure anywhere in the Convention. Mozambique is therefore the Angola shape reached by a different road: the machine decision is forbidden and never has to be explained. Impact tier: all entities.

Force since 8 June 2023, and the date is computed from the instrument rather than taken from a summary. Art. 36 (Entry into Force) provides that the Convention «shall enter into force thirty (30) days after the date of the receipt by the Chairperson of the Commission of the African Union of the fifteenth (15th) instrument of ratification». There is no separate per-State entry-into-force clause, so the Convention entered into force on the same day for every State that had already deposited, Mozambique included. On the African Union's own status list (dated 8 July 2024, the depositary's record), the deposits in chronological order are Senegal 16/08/2016, Mauritius 14/03/2018, Guinea 16/10/2018, Namibia 01/02/2019, Ghana 03/06/2019, Rwanda 21/11/2019, Mozambique 21/01/2020, Angola 11/05/2020, Congo 23/10/2020, Zambia 24/03/2021, Togo 19/10/2021, Cape Verde 05/02/2022, Niger 16/03/2022, Côte d'Ivoire 03/04/2023, Mauritania 09/05/2023 and São Tomé & Príncipe 15/02/2024. Mauritania is the fifteenth; thirty days after 9 May 2023 is 8 June 2023, which is the date carried here. Mozambique's own dates on that list are signature 29/06/2018, ratification 02/12/2019 and deposit 21/01/2020 — all three earlier than entry into force, which is why the treaty's date governs and not the deposit. The ratifying instrument is Resolução n.º 5/2019 of the Assembleia da República, whose subject the Imprensa Nacional de Moçambique — the state printer that publishes the Boletim da República — records verbatim in its catalogue as ratifying the African Union Convention on Cybersecurity and Personal Data Protection adopted at the 23rd Ordinary Session in Malabo on 27 June 2014. Secondary Mozambican legal commentary dates that Resolução to 20 June 2019 and places it in Boletim da República I Série n.º 119; the Imprensa Nacional catalogue page itself interleaves citations across adjacent items and attributes a 2023 Boletim reference to this 2019 Resolução, so the gazette page number is not asserted here and the Resolução's own text was not read. That gap does not touch the date carried, which comes from art. 36 and the depositary's list, nor the substance, which comes from the Convention text. Confidence medium, and the reason is domestication rather than dating: art. 8(1) frames the Convention's personal-data chapter as a commitment by each State Party «to establishing a legal framework», which is an argument that the chapter as a whole is programmatic, while art. 14(5) is drafted as a directly-worded rule and art. 18 of the Constitution receives ratified treaties into the domestic order with statutory rank. No national implementing law exists, no supervisory authority exists, and no penalty attaches. What Mozambique does have is not a substitute. Lei n.º 3/2017, de 9 de Janeiro (Lei de Transacções Electrónicas) carries a personal-data chapter at arts. 63-65 — accuracy and purpose limitation, notice on indirect collection, security, access, reasoned refusal and objection at art. 63(6), a bar on cross-institution sharing at art. 64, and a designated responsible individual at art. 65 — and none of it touches automated decisions or profiling; the words «perfil» and «perfis» do not occur in the Law, and every occurrence of «automatizado» is the UNCITRAL automated-message-system vocabulary of arts. 35, 37 and 40 about contract formation, input errors and automated calling systems, not about decisions taken on people. INTIC, the national ICT institute, publishes the same enumeration of the country's current data-protection framework — Constitution art. 71, Lei 3/2017 arts. 63-65, Decreto n.º 67/2017 on e-government interoperability, and the regulation on intermediate electronic service providers — and none of those instruments regulates automated decision-making. Watch item: the Proposta de Lei establishing the Regime Jurídico de Proteção de Dados Pessoais was approved by the Council of Ministers at its 6th ordinary session on 3 March 2026 and sent to the Assembleia da República; it creates the ANPD and, if gazetted, will supersede this row's basis with a domestic one. Two further Mozambican laws were published in the Boletim da República on 1 July 2026 and take effect on 29 September 2026 — Lei n.º 13/2026 on cybersecurity and Lei n.º 14/2026 on cybercrime — neither of which has been read in full here and neither of which is claimed to carry an automated-decision or AI obligation. Coverage symmetry: art. 14(5) binds all sixteen States that have deposited, and eleven of them already carry a national row on the tracker (Senegal, Guinea, Ghana, Rwanda, Angola, Congo-Brazzaville, Togo, Cabo Verde, Niger, Côte d'Ivoire, São Tomé e Príncipe), where the national statute is the operative rule and this treaty is background. The four remaining parties — Mauritius, Namibia, Zambia and Mauritania — are not yet tracked and are recorded as a follow-up coverage gap; Namibia in particular has no national data-protection statute and is expected to be the same shape as this row. Guinea-Bissau is a closed negative on the same sweep: it signed the Convention on 31 January 2015 but has never ratified it, has no data-protection law and no data-protection authority, and the legislation index of ARN, its national regulator, lists only the 2013 telecommunications decrees.

Stated maximum penalty — None stated, and that is the honest answer rather than an unresearched one. The Malabo Convention attaches no fine, no imprisonment and no administrative sanction to art. 14(5). Its sanctioning provisions run the other way: art. 12(2)(h) empowers the national protection authority to impose administrative and monetary sanctions on data controllers, but leaves the amounts to national law, and Mozambique has neither designated an authority nor set amounts. The Convention's own penal content sits in Chapter III on cybercrime — offences against computer systems and computerised data — and does not reach the automated-decision rule. Nor does domestic Mozambican law supply a figure: Lei n.º 3/2017's Chapter X on inspection and contraventions attaches to that Law's own duties, not to the Convention's, and art. 14(5) has no counterpart in it. The practical consequence for a deployer is that art. 14(5) is a rule of conduct without a tariff: the exposure is a civil claim, a constitutional challenge under art. 71 of the Constitution, or the retrospective risk that the pending Proposta de Lei, once enacted, gives the new Autoridade Nacional de Proteção de Dados both a domestic prohibition and a penalty band to apply. This entry deliberately records no monetary range rather than importing one from a peer jurisdiction.

In force · 8 Jun 2023 checked 20 Aug 2026 Malabo Convention art. 14(5) ↗ medium confidence

Namibia 1

Namibia Binding

Malabo Convention art. 14(5) — the second country where the automated-decision bar arrives only by treaty

Binds Anyone processing personal data in Namibia, on the Convention's own scope article. Art. 9(1) reaches (a) any collection, processing, transmission, storage or use of personal data by a natural person, the State, local communities and public or private corporate bodies; (b) any automated or non-automated processing of data contained in or meant to be part of a file; and (c) processing carried out in the territory of a State Party or by a controller using means situated on that territory. There is no size, sector or turnover threshold — enterprise, SME and public body alike — and no national supervisory authority stands between the rule and the party it binds, because Namibia has not established one. Hiring, credit scoring and insurance underwriting all sit inside the wording: the bar catches any decision producing legal effects or significantly affecting a person to a substantial degree where it rests solely on automated processing «intended to evaluate certain personal aspects». Two Namibian instruments were checked and neither supplies a competing rule. Article 13(1) of the Constitution gives a right against interference with the privacy of homes, correspondence or communications save as in accordance with law and as necessary in a democratic society — a privacy right, not a data-processing regime, with no automated-decision content. And the Data Protection Bill, drafted in successive versions since 2013 and most recently circulated as the Data Protection Bill 2023, does contain a solely-automated-decision provision with consent and contract exceptions and a human-intervention safeguard — but it has not been enacted. The Ministry of Information and Communication Technology indicated in August 2025 that the Bill was in its final stages and would be tabled between September and October 2025; as at this check no enactment has been traced, and until it is gazetted the Convention is the only automated-decision rule in force in Namibia. When the Bill does pass, art. 144's «unless otherwise provided by ... Act of Parliament» means this row must be superseded rather than duplicated.. Namibia has no data-protection statute in force, and an automated-decision prohibition binds there anyway. Article 14(5) of the African Union Convention on Cyber Security and Personal Data Protection, adopted at Malabo on 27 June 2014, provides that «a person shall not be subject to a decision which produces legal effects concerning him/her or significantly affects him/her to a substantial degree, and which is based solely on automated processing of data intended to evaluate certain personal aspects relating to him/her». Namibia never signed the Convention: on the African Union's own status list its signature column is empty, and it acceded on 25 January 2019, depositing its instrument with the Chairperson of the African Union Commission on 1 February 2019. Reception into domestic law is more direct here than in Mozambique. Article 144 of the Constitution of the Republic of Namibia, in Chapter 21, provides that «unless otherwise provided by this Constitution or Act of Parliament, the general rules of public international law and international agreements binding upon Namibia under this Constitution shall form part of the law of Namibia» — automatic incorporation, with no publication precondition of the kind Mozambique's art. 18 imposes, and Namibia is conventionally described as one of the more thoroughly monist constitutions on the continent for exactly this clause. The qualification to read carefully is «under this Constitution»: art. 63(2)(e) gives the National Assembly the power and function «to agree to the ratification of or accession to international agreements which have been negotiated and signed in terms of Article 32(3)(e)», so incorporation runs through the National Assembly's agreement to accession, not through the executive act alone. The other qualification is the opening words — «unless otherwise provided by this Constitution or Act of Parliament» — which means a future Namibian Data Protection Act could displace art. 14(5) rather than merely supplement it. As in Mozambique, the Convention forbids without ever explaining: art. 16 lists eight information items (a) to (h) and art. 17 four access items, and none of them is an automated-decision or logic item; art. 18 gives objection on legitimate grounds and art. 19 rectification, blocking and erasure. There is no right to human intervention and no right to contest, and no exception of any kind — no contract limb, no consent limb, no legal-authorisation limb.

Force since 8 June 2023, on the Convention's own entry-into-force clause rather than on anything Namibian. Art. 36 provides that the Convention «shall enter into force thirty (30) days after the date of the receipt by the Chairperson of the Commission of the African Union of the fifteenth (15th) instrument of ratification», and there is no separate per-State entry-into-force clause, so a party that deposited before the fifteenth is bound from the collective date and not from its own deposit. On the African Union's status list of 8 July 2024 the fifteenth deposit is Mauritania's, on 9 May 2023; thirty days later is 8 June 2023. Namibia's accession on 25 January 2019 and deposit on 1 February 2019 both precede that comfortably — Namibia is the sixth deposit in date order — so the treaty's own date governs. The same list records 21 signatures, 16 ratifications and 16 deposits out of 55 African Union member states. Confidence is medium, and the reason is domestication rather than dating, exactly as for the Mozambique row this one is modelled on. Article 14 speaks in two registers within a single article: para. 1 is addressed to governments — «State Parties shall undertake to prohibit any data collection and processing revealing racial, ethnic and regional origin...» — a duty to legislate discharged only by passing a law, and art. 8(1) frames the whole personal-data chapter the same programmatic way, as a commitment «to establishing a legal framework». Para. 5 is not drafted that way at all: it states, in the passive and addressed to nobody in particular, a rule about what may be done to a person, and so reads as self-executing where its own para. 1 does not. No Namibian court has been shown to apply it, no domestic instrument repeats it, and no supervisory authority exists to enforce it. What is stronger here than in Mozambique is the reception clause itself: art. 144 incorporates without requiring publication, where Mozambique's art. 18 conditions entry into the domestic order on official publication. What is weaker is that art. 144 is expressly subject to being overridden by an Act of Parliament, and an Act of Parliament on precisely this subject is pending.

Stated maximum penalty — None stated. The Malabo Convention attaches no fine, no imprisonment and no administrative sanction to art. 14(5). Its sanctioning provisions run in the other direction: art. 12(2)(h) empowers the national protection authority to impose administrative and monetary sanctions on data controllers, leaving the amounts to national law, and Namibia has neither established that authority nor legislated any amounts. No monetary range is recorded here rather than one imported from a peer jurisdiction. A Namibian data subject subjected to a solely automated decision therefore has a rule in force and no statutory remedy attached to it; the available routes are constitutional — art. 13 privacy, art. 18 administrative justice, and art. 25 enforcement of fundamental rights before the courts — and none of them is a data-protection penalty. This will change on enactment of the Data Protection Bill, which carries its own enforcement machinery; until then the entry is deliberately silent on quantum. Impact tier: all entities.

In force · 8 Jun 2023 checked 20 Aug 2026 Malabo Convention art. 14(5) ↗ medium confidence

Niger 1

Niger Binding

Loi 2022-59 art. 52 — automated individual decisions: a two-limb bar, a right to know and contest the reasoning, and an express artificial-intelligence disclosure duty at collection

Binds Responsables du traitement and sous-traitants within the scope of arts. 3 and 4. Art. 3 subjects to the Law any collection, processing, transmission, storage and use of personal data by legal persons of public or private law and by natural persons; any processing, automated or not, of personal data contained in or intended to form part of a file; and any processing concerning public security, defence, investigation and prosecution of criminal offences or State security, subject to derogations defined by the Law or other legislation in force. Art. 4 applies the Law to processing implemented by a controller or processor established on national territory and in any place where national law applies. Prior formalities are a standing precondition: art. 31 requires prior authorisation from the Haute Autorité à la Protection des Données à caractère Personnel for, among others, any processing permitting profiling or behavioural analysis, biometric processing, unique-identifier processing, interconnection of files, and transfers to third countries, and art. 79 requires every private-law legal person acting as a controller to appoint an internal data protection correspondent, with public-sector controllers appointing a point focal in that role. The first limb of art. 52 binds the courts themselves; the second binds every administrative and private decision-maker; the third and fourth paragraphs bind any controller whose results are relied on against a person, and the fourth bites at the moment of collection wherever the processing falls within artificial intelligence. Impact tier: all entities.. Article 52 of Loi n° 2022-59 du 16 décembre 2022 relative à la protection des données à caractère personnel, headed "Décision individuelle basée sur le traitement automatisé", is Niger's operative automated-decision rule and the richest of the Directive-family provisions tracked in Africa. It has five paragraphs. The first bars any judicial decision involving an appraisal of the conduct of a natural person from having as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality. The second bars any administrative or private decision involving an appraisal of human conduct from having as its sole foundation an automated processing of personal data giving a definition of the profile or the personality of the person concerned. The third creates a free-standing right: every person has the right to know and to contest the information and the reasoning used in processing, automated or not, whose results are relied on against them. The fourth is the artificial-intelligence clause, which Niger shares only with art. 19 of Burkina Faso's Loi n° 001-2021/AN and with no other row on the tracker — where that processing falls within artificial intelligence, the criteria and the nature of the personal data on which the processing is founded must be indicated to the person from the point of collection. The fifth supplies the exceptions: an automated individual decision is nevertheless admitted where it is founded on the explicit consent of the person concerned, necessary to the conclusion or performance of a contract between the person concerned and a controller, or authorised by a legislative or regulatory provision. Unlike Morocco, Algeria and Côte d'Ivoire, Niger defines profiling: art. 1 defines it as any automated processing of personal data with a view to evaluating certain personal aspects relating to a natural person, in particular to analyse or predict elements concerning work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Art. 31 separately subjects any processing permitting profiling or behavioural analysis to prior authorisation by the HAPDP. The Law grants no right to obtain human intervention or a fresh non-automated decision.

Supersession: art. 112 of Loi n° 2022-59 abrogates all prior contrary provisions and names in particular Loi n° 2017-28 du 3 mai 2017 relative à la protection des données à caractère personnel as modified by Loi n° 2019-71 du 24 décembre 2019. Loi 2017-28 is therefore no longer the operative Nigerien instrument and is not tracked. Art. 112 combines abrogation and publication in a single article — the Law "est publiée au Journal Officiel de la République du Niger et exécutée comme loi de l'Etat" — and there is no commencement article and no deferral of art. 52. The date recorded here is the date of promulgation printed on the face of the enacted text: "Fait à Niamey, le 16 décembre 2022", signed by the President of the Republic Mohamed Bazoum and countersigned by the Prime Minister Ouhoumoudou Mahamadou, with an ampliation by the Deputy Secretary-General of the Government. Confidence is medium and the reason is narrower than for Morocco, Algeria and Côte d'Ivoire, where the general publication-to-force rule was the only unverified link: here the date of the Journal officiel de la République du Niger that carries the Law could not be established at all, because no Nigerien official-gazette host resolved this run — sgg.gouv.ne, www.sgg.gouv.ne, journal-officiel.ne and assemblee.ne all fail to resolve — so the entry uses the promulgation date, and the true entry into force can only be that date or later. Art. 111, replaced by Ordonnance n° 2024-16 du 26 avril 2024, is transitional and not a deferral of art. 52: already-created processing operations carried out for the State, a public establishment, a local authority or a private-law body managing a public service are notified to the HAPDP, and from the date of entry into force all processing must meet the Law's prescriptions on pain of its sanctions. The text was read twice over: article by article in the enacted, signed forty-six-page copy of Loi n° 2022-59 published by the HAPDP, in which art. 52 was read directly on p. 27, and against the HAPDP's own April 2026 consolidated version, which integrates Loi n° 2023-31 du 4 juillet 2023, Ordonnance n° 2024-16 du 26 avril 2024 and Ordonnance n° 2024-29 du 24 juin 2024 and marks amended articles "(nouveau)". Art. 52 is not so marked and is identical in both, so no amendment has touched it; the consolidation renumbers the enacted art. 112 into arts. 112 and 113. The consolidated document states on its face that it is provided for information only and does not replace the official texts published in the Journal officiel, which is why the enacted copy is cited as the source. Coverage symmetry against the eleven African rows already tracked: art. 52 belongs to the Directive 95/46/EC art. 15 line that reaches West Africa through art. 42 of the ECOWAS Supplementary Act A/SA.1/01/10, which the Law's preamble expressly cites alongside the African Union Convention on Cyber Security and Personal Data Protection. Its first two paragraphs are word-for-word the two limbs of Côte d'Ivoire's art. 25, which makes those two the closest pair in Africa, but Niger then goes considerably further in both directions. It is stronger, because it adds the right to know and contest the information and reasoning relied on — a right Côte d'Ivoire lacks entirely and Morocco has only in the narrower art. 7(c) form — and because it names artificial intelligence and attaches a disclosure duty to it at the point of collection. That artificial-intelligence clause is not unique to Niger: art. 19 of Burkina Faso's Loi n° 001-2021/AN du 30 mars 2021 carries it in materially identical words, and Burkina Faso's Law predates Niger's by twenty months, so Burkina Faso is the source of the drafting and Niger the follower. Burkina Faso goes one step further still, because its art. 31 subjects predictive-artificial-intelligence decision-support processing to prior authorisation, which Niger does not. It is weaker, because Côte d'Ivoire states no exception at all while Niger admits explicit consent, contract and legal authorisation, which is the GDPR art. 22(2) exception set grafted onto a Directive-era bar. The four-way African lineage picture is unchanged: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, ci-loi2013450-art25 and now ne-loi202259-art52; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — Niger is the first Directive-family row on the tracker where a penal article does reach part of the automated-decision provision, and the reach is partial. Art. 102 punishes obstructing without legitimate reason the exercise of a right conferred by the Law in the course of a processing of personal data with imprisonment of three months to two years and a fine of 1,000,000 to 20,000,000 francs CFA, or one of those penalties only. The third paragraph of art. 52 confers a right on the person — to know and contest the information and reasoning used — so art. 102 reaches a refusal of that right. The first two paragraphs of art. 52 are prohibitions on the decision-maker rather than rights of the person, and no offence in Chapitre XIV names them: arts. 95 to 104 are confined to unlawful sensitive-data processing (three months to five years and 5,000,000 to 50,000,000), unconsented direct marketing (three months to three years and 1,000,000 to 10,000,000), obstruction of the HAPDP (three months to two years and 1,000,000 to 10,000,000), failure to take security precautions (three months to two years and 1,000,000 to 10,000,000), purpose deviation (three months to five years and 5,000,000 to 50,000,000), unauthorised communication of or access to files (three months to five years and 5,000,000 to 50,000,000), fraudulent, unfair or unlawful collection (three months to five years and 5,000,000 to 50,000,000), unlawful retention beyond the permitted period (three months to two years and 5,000,000 to 50,000,000) and unauthorised divulgation harming honour or privacy (three months to five years and 5,000,000 to 50,000,000, reduced to a fine of 500,000 to 1,000,000 where committed by imprudence or negligence). Art. 105 applies Penal Code arts. 59 to 61 on recidivism, and art. 106 lets the court order confiscation or erasure of the media carrying the data, ban the convicted controller from managing any processing for up to two years, and order publication of extracts in legal-notice journals at the convicted person's expense. The administrative route reaches the whole of art. 52. Art. 92 lets the HAPDP, after an adversarial procedure, issue a warning and a mise en demeure to end the failures within a period it fixes, and, if the controller does not comply, pronounce provisional or definitive withdrawal of the authorisation or a pecuniary sanction. Art. 93 lets it order interruption of the processing, blocking of certain data, or temporary or definitive prohibition of a processing contrary to the Law. Art. 94 fixes the ceiling: the pecuniary sanction is proportionate to the gravity of the failures and the advantages drawn from them and may not exceed 100,000,000 francs CFA, rising on a repeated failure within two years from the date the previous pecuniary sanction became definitive to 200,000,000 francs CFA or, for an undertaking, 5 per cent of pre-tax turnover for the last closed financial year within a limit of 500,000,000 francs CFA, and applies without prejudice to penal sanctions. Art. 108 lets any person who claims to be injured in their private life by a processing, or whose complaint to the controller has gone unanswered, complain to the HAPDP; art. 109 makes the HAPDP's sanctions and decisions appealable to the Conseil d'Etat; and art. 110 preserves an effective judicial remedy, including urgent interim relief under astreinte where the infringement is serious and immediate.

In force · 16 Dec 2022 checked 20 Aug 2026 Loi n° 2022-59 art. 52 ↗ medium confidence

Nigeria 1

Nigeria Binding

Nigeria Data Protection Act s. 37 — right against solely-automated decisions, with a duty to provide human intervention on request

Binds Data controllers and data processors within the scope of s. 2(2): those domiciled in, resident in, or operating in Nigeria; any processing of personal data that occurs within Nigeria; and controllers or processors not domiciled, resident or operating in Nigeria that process personal data of a data subject in Nigeria. Section 2(1) applies the Act to processing whether by automated means or not, and s. 3(1) carves out processing carried out solely for personal or household purposes. The s. 37 right binds any controller taking a solely-automated decision with legal or similar significant effect, irrespective of size. A narrower registration and governance tier sits above it: a data controller or data processor “of major importance” — defined in s. 65 as one domiciled, resident or operating in Nigeria that processes personal data of more than such number of data subjects in Nigeria as the Commission may prescribe, or such other class the Commission may designate as processing data of particular value or significance to the economy, society or security of Nigeria — must register with the Commission under s. 44(1) within six months after the commencement of the Act or on becoming one, and must designate a Data Protection Officer under s. 32(1). Impact tier: all entities.. Section 37 of the Nigeria Data Protection Act, 2023 (Act No. 37 of 2023) carries Nigeria's operative automated-decision rule, in Part VI (rights of a data subject). Subsection (1) gives a data subject the right not to be subject to a decision based solely on automated processing of personal data, including profiling, which produces legal or similar significant effects concerning the data subject. Subsection (2) disapplies that right where the decision is necessary for entering into or the performance of a contract between the data subject and a data controller, is authorised by a written law which establishes suitable measures to safeguard the fundamental rights and freedoms and the interests of the data subject, or is authorised by the consent of the data subject. Subsection (3) is the operative duty on the controller: where an exception is relied on, the data controller shall implement suitable measures to safeguard the data subject's fundamental rights, freedoms and interests, including the rights to obtain human intervention on the part of the data controller, to express the data subject's point of view, and to contest the decision. Section 65 defines “automated decision-making” as a decision based solely on automated processing by automated means, without any human involvement. Section 36(3) separately gives a right to object at any time to processing for direct marketing purposes, which includes profiling to the extent that it is related to such direct marketing, and s. 36(4) requires processing for those purposes to stop on objection.

Commencement is stated on the face of the enacted Act: the gazetted text prints “[12th Day of June, 2023]” immediately above the enacting formula, and s. 37 carries no deferred or separately-appointed commencement, so the section has been in force since 12 June 2023. The Act was published by The Federal Government Printer, Lagos as a supplement to the Federal Republic of Nigeria Official Gazette No. 119, Vol. 110 of 1 July 2023, Government Notice No. 82, as Act No. 37, at pages A719 to A758. Section 37 follows the GDPR Art. 22 shape and is the closest of the tracker's three African provisions to it: unlike the South African za-popia-s71, which offers only representations plus disclosure of the underlying logic, Nigeria expressly grants human intervention, the right to express a point of view and the right to contest the decision; unlike the Kenyan ke-dpa-s35 it imposes no affirmative written-notification duty when a solely-automated decision is taken, and confers no express right to demand a fresh non-automated decision. Source access: the Nigeria Data Protection Commission is the statutory supervisory authority established by s. 4 of the Act and ndpc.gov.ng is the only official host that serves the Act text, but the host returns HTTP 403 (nginx, not a challenge page) to every non-browser client from this network, on the apex domain and on every subdomain except the services portal; nass.gov.ng's publications register does not carry the Act, and nigeriagazette.gov.ng does not resolve. The text cited here was therefore read from the Internet Archive's byte-for-byte capture of the NDPC-hosted gazette PDF at the source_url (capture of 31 May 2025, origin Last-Modified 1 March 2024): https://web.archive.org/web/20250531105744/https://ndpc.gov.ng/wp-content/uploads/2024/03/Nigeria_Data_Protection_Act_2023.pdf. No secondary or NGO copy was relied on. Not yet verified: the NDPC General Application and Implementation Directive 2025 (issued 20 March 2025) may add implementation detail on automated decision-making; every archived capture of it replays 503, so it is excluded from this entry and left for a later check.

Stated maximum penalty — Section 48 governs sanctions. After an investigation under s. 46, the Commission may order the controller or processor to remedy the violation, to compensate a data subject who has suffered injury, loss or harm, to account for the profits realised from the violation, or to pay a penalty or remedial fee (s. 48(2)). Under s. 48(3)–(5) that penalty may be up to the “higher maximum amount” for a data controller or data processor of major importance, being the greater of ₦10,000,000 and 2% of its annual gross revenue in the preceding financial year, or the “standard maximum amount” for one not of major importance, being the greater of ₦2,000,000 and 2% of that revenue. Failure to comply with a compliance order made under s. 47 is a separate offence under s. 49, punishable on conviction by a fine of up to the same higher or standard maximum amount, or imprisonment for a term not more than one year, or both. Section 51 gives a data subject who suffers injury, loss or harm a civil action for damages, and s. 50 allows an application to court for judicial review of a Commission order within 30 days.

In force · 12 Jun 2023 checked 22 Aug 2026 NDPA s. 37 (Act No. 37 of 2023) ↗ high confidence

Philippines 1

Philippines Binding

Data Privacy Act IRR Secs. 34 and 48 — automated decision-making: logic disclosure, NPC notification and the consent bar

Binds Personal information controllers and personal information processors within the scope of the Act and Rule II of the IRR, including entities not established in the Philippines that use equipment located in the country or maintain an office, branch or agency here. The Section 48 notification duty binds any controller whose automated processing becomes the sole basis for a decision significantly affecting a data subject; the Section 34 transparency and objection rights bind all controllers. Impact tier: all entities.. The Implementing Rules and Regulations of Republic Act No. 10173 (Data Privacy Act of 2012) carry the Philippines' operative automated-decision regime. Section 34 gives the data subject a right to be informed whether personal data are processed 'including the existence of automated decision-making and profiling', and requires the controller to furnish, before entry of the data into the processing system or at the next practical opportunity, the methods used for automated access together with 'meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject' (Sec. 34(a)(f)); the same section carries a right to object to processing 'including processing for direct marketing, automated processing or profiling', and a right of access to 'information on automated processes where the data will, or is likely to, be made as the sole basis for any decision that significantly affects or will affect the data subject'. Section 48 adds a filing duty and a substantive bar: a controller carrying out wholly or partly automated processing operations must notify the National Privacy Commission once the automated processing becomes the sole basis for making decisions about a data subject and the decision would significantly affect that subject, submitting the purpose of processing, the categories of data and data subjects, the consent forms or manner of obtaining consent, the recipients, the retention period, the 'methods and logic utilized for automated processing', the decisions that would be made on the basis of the processed data or that would significantly affect the rights and freedoms of the data subject, and the name and contact details of the data protection officer; and 'no decision with legal effects concerning a data subject shall be made solely on the basis of automated processing without the consent of the data subject'. Section 16(c)(6) of the Act itself carries the statutory root of the access right.

Commencement is computed from the face of the instrument. IRR Section 72 provides that the Rules take effect fifteen days after publication in the Official Gazette; the Rules were promulgated by the National Privacy Commission on 24 August 2016 and published in the Official Gazette on 25 August 2016, which places entry into force on 9 September 2016. IRR Section 67 gave controllers one year from that date to register their data processing systems or automated processing operations subject to notification, so that window closed on 9 September 2017 and the Section 48 duty is now fully exigible. The parent statute, Republic Act No. 10173, was approved on 15 August 2012 and took effect fifteen days after newspaper publication under its Section 45. Note the division of labour between statute and rules: RA 10173 Sec. 16(c)(6) grants only access to information on automated processes used as the sole basis for a significant decision, while the consent bar on solely-automated decisions with legal effects and the meaningful-information-about-the-logic requirement appear only in the IRR, at Secs. 48 and 34 respectively. Asian peer of cn-pipl-art24, kr-pipa-art37-2-adm and id-uu27-adm: like Indonesia and Korea it is already in force, and like Korea it reaches the logic of the decision, but unlike Korea it grants no express right to human re-processing — the Philippine mechanism is a consent gate plus a regulator filing rather than a post-hoc review right. Text read at the National Privacy Commission's own publication of the IRR and cross-checked against the Supreme Court E-Library copy (elibrary.judiciary.gov.ph/thebookshelf/showdocs/2/70735), which carries the identical Secs. 34, 48, 67 and 72. officialgazette.gov.ph returns HTTP 403 to non-browser clients, so the NPC copy is cited.

Stated maximum penalty — IRR Section 65 subjects violations of the Act, the Rules and Commission issuances to compliance and enforcement orders, cease and desist orders, a temporary or permanent ban on processing, or fines under a schedule published by the Commission. That schedule is NPC Circular No. 2022-01 (Guidelines on Administrative Fines, 8 August 2022): each infraction of a data subject right under Sec. 16 of the DPA affecting more than 1,000 data subjects is a grave infraction carrying 0.5 per cent to 3 per cent of the annual gross income of the preceding year, and 1,000 or fewer affected subjects is a major infraction carrying 0.25 per cent to 2 per cent, with total administrative fines capped at PHP 5,000,000. Criminal liability under Chapter VIII of the Act runs separately for the enumerated offences, for example unauthorised processing of personal information at one to three years' imprisonment and a fine of PHP 500,000 to PHP 2,000,000 under Sec. 25(a).

In force · 9 Sep 2016 checked 21 Aug 2026 DPA of 2012 IRR Secs. 34, 48 (RA 10173) ↗ high confidence

Russia 3

Russia Binding

152-FZ art. 16 — a solely automated decision is forbidden unless the person signed a written consent

Binds Every «оператор» — under art. 3(2) any state body, municipal body, legal person or natural person that, alone or jointly with others, organises and (or) carries out the processing of personal data and determines its purposes, composition and the operations performed. There is no size, sector or turnover threshold, so enterprise, SME, sole trader and public body are all covered. Art. 1(1) applies the Law to processing by federal and regional state bodies, other state and municipal bodies, legal persons and natural persons using automation means or without them where the processing corresponds to how it would be done with automation; art. 1(2) carves out processing by a natural person for purely personal and family needs, archival processing, and processing of information constituting a state secret. Art. 2(1) of Federal Law No. 242-FZ localisation duties sit separately and are not part of art. 16.. Russia's automated-decision rule predates the GDPR and is drafted as a flat prohibition with a very narrow way out. Article 16 of Federal Law No. 152-FZ of 27 July 2006 «О персональных данных» opens by forbidding outright the taking, on the basis of solely automated processing of personal data, of decisions «порождающих юридические последствия в отношении субъекта персональных данных или иным образом затрагивающих его права и законные интересы», except in the cases in part 2. The trigger is wider than the European one: the second limb catches any decision that «otherwise affects the rights and legitimate interests» of the person, with no significance qualifier at all, so nothing corresponding to GDPR art. 22(1)'s «similarly significantly affects» threshold has to be cleared. Part 2 then admits exactly two routes: the written consent of the data subject, or a case provided for by a federal law that also lays down measures to secure the person's rights and legitimate interests. There is no contract limb. GDPR art. 22(2)(a) lets a controller automate a decision that is necessary for entering into or performing a contract, and Zambia's s. 62(2) and Mauritius's s. 38(2) carry the same escape; Russia does not, so an automated credit refusal, tenancy screen or insurance decline taken in the course of contracting sits in the prohibition unless a signed consent exists. The consent route is also heavier than it looks, because art. 9(4) governs what a «согласие в письменной форме» has to contain — among other particulars the person's identity-document number and the date and issuing body of that document — and an electronic document signed with an electronic signature is the only equivalent of a handwritten signature. Part 3 is a standing, unconditional duty: the operator explains to the data subject «порядок принятия решения» — the procedure by which the decision is taken — and the possible legal consequences of it, provides the opportunity to state an objection to the decision, and explains how the person may protect their rights and legitimate interests. That duty is proactive rather than answer-on-request, which is stronger than GDPR arts. 13(2)(f) and 15(1)(h); but its object is the procedure, not «логика», so no meaningful-information-about-the-logic right exists anywhere in the Law. Part 4 gives the operator thirty days from receipt to consider the objection and notify the person of the result. It stops there: nothing obliges the operator to change the decision, and no right to obtain human intervention and no right to contest before a person are expressed as such. The rest of the Law is silent on automated decisions — the art. 14(7) access list runs to ten items and none of them is an automated-decision or logic item, and the art. 18(3) notice for data not collected from the subject runs to five items with no such limb either. The Law carries no AI-specific rule; its only three mentions of «искусственный интеллект» are cross-references to the Moscow AI experiment statute, Federal Law No. 123-FZ of 24 April 2020, and they are permissions to process anonymised data rather than obligations.

In force since 26 January 2007, and the 2006 date on the face of the Law is not the operative one. Art. 25(1) puts the Law in force «по истечении ста восьмидесяти дней после дня его официального опубликования». The official record card at pravo.gov.ru lists three publications — «Российская газета» No. 165 of 29 July 2006, «Парламентская газета» Nos. 126-127 of 3 August 2006, and Собрание законодательства РФ 2006 No. 31 (Part I) item 3451 — and the earliest of them, 29 July 2006, is the official publication for the purposes of Federal Law No. 5-FZ of 14 June 1994 art. 4. The 180-day period therefore ran from 30 July 2006 and expired at the end of 25 January 2007, putting the Law in force on 26 January 2007. Art. 16 in its present wording is the redaction of Federal Law No. 261-FZ of 25 July 2011, which rewrote much of the Law; the article has not been touched since. The most recent amendment to the Law, Federal Law No. 265-FZ of 26 July 2026, rewrote parts of art. 12 on cross-border transfers and left art. 16 alone, so the text checked here is the current consolidated official text.

Stated maximum penalty — Art. 24(1) of the Law only refers offenders to «предусмотренную законодательством Российской Федерации ответственность», so the amounts sit in the Code of Administrative Offences, and which paragraph applies depends on which part of art. 16 was breached. Taking the decision without the written consent that art. 16(2) requires is the offence in KoAP art. 13.11(2) — processing without the written consent of the data subject in the cases where that consent has to be obtained, or processing in breach of the requirements as to what the written consent has to contain — carrying 10,000-15,000 roubles for citizens, 100,000-300,000 for officials and 300,000-700,000 for legal persons, and on repetition under art. 13.11(2-1) 15,000-30,000, 300,000-500,000, 500,000-1,000,000 for individual entrepreneurs and 1,000,000-1,500,000 for legal persons. Failing the art. 16(3) duty to explain is the separate and much smaller offence in KoAP art. 13.11(4) — failure to provide the data subject with information concerning the processing of their personal data — at 40,000-80,000 roubles for legal persons. The general paragraph, art. 13.11(1), at 150,000-300,000 roubles for legal persons since Federal Law No. 420-FZ of 30 November 2024, expressly excludes the cases falling under parts 2 and 11-18, so it is the residual rather than the headline figure here. Enforcement is split: Roskomnadzor draws up the protocol under KoAP art. 28.3(2)(58) but does not impose the fine, because art. 13.11 cases are decided by a judge under KoAP art. 23.1. Art. 24(2) of the Law adds compensation for moral harm, recoverable independently of pecuniary damage and of the subject's losses.

In force · 26 Jan 2007 checked 21 Aug 2026 152-FZ art. 16 ↗ high confidence
Russia Binding

243-FZ art. 10(1) — whoever lets you use a large foundational model has to tell you who owns the output

Binds Any person that provides the ability to use a large foundational AI model as defined in art. 3(2) — not fewer than 1 billion parameters, general-purpose across a large number of tasks, and serving as the basis for creating and refining other software. The duty is expressed without a nationality, size or turnover limb, in contrast to arts. 6 to 8, which apply only to Russian legal persons developing models granted sovereign or national status. Art. 1(3) reserves to other federal laws and presidential acts the setting of special rules for defence, state security, operational-search activity, public order and property protection, public and road safety including counter-terrorism, anti-money-laundering and counter-terrorist-financing, emergency prevention, diplomatic and consular service and state administration, so those uses may be governed differently.. Federal Law No. 243-FZ of 26 July 2026 «О поддержке развития технологий искусственного интеллекта в Российской Федерации» is Russia's first AI statute, and this is its broadest genuine duty. Art. 10(1) requires «лица, предоставляющие возможность применения больших фундаментальных моделей искусственного интеллекта» — the persons who make a large foundational model available for use — to notify the user of two things unless another federal rule provides otherwise: to whom the rights belong in the results of intellectual activity obtained with the help of the model, and on what conditions the user is given access to, use of, and retention of those results, retention being qualified by technical possibility. Unlike arts. 6 to 8, the duty is not confined to sovereign or national models or to Russian developers, so it reaches any provider offering such a model to users in Russia. Its scope is set entirely by the art. 3(2) definition: a large foundational model is a computer program intended to perform intellectual tasks at a level comparable to or exceeding human intellectual activity, using algorithms and trained on data sets to infer patterns, supply information, take decisions or forecast results against human-set goals, simultaneously serving as the basis for creating and refining various kinds of software, containing not fewer than 1 billion parameters and applied to a large number of different tasks. Every cumulative limb has to be met, so smaller and narrow-purpose models fall outside the Law altogether. Art. 10(2) sits alongside as a permission rather than a duty: accessing information contained in copyright and neighbouring-rights objects for the practical application of what they contain, including machine extraction, comparison, classification and analysis of patterns, trends and correlations, and short-term reproduction in machine memory, is declared not to infringe — but only where it is done exclusively to train a sovereign and (or) national large foundational model, and only where the developer uses a lawfully obtained copy or the work had been communicated to the public and was available for analysis without technical restriction. A text-and-data-mining exception that is available only to models holding a state-conferred status is an unusual shape and worth noting when comparing it with the EU and Singapore exceptions.

The date on which this duty starts is 1 March 2027, not the 1 September 2026 date reported as the commencement of the Law. Art. 13(1) does put the Law in force on 1 September 2026, but art. 13(2) then defers arts. 8, 9 and 10 in full, together with art. 5(2) points 3 to 5 and art. 6 parts 2 to 5, to 1 March 2027. What actually commences on 1 September 2026 is the subject matter, aims, definitions and principles in arts. 1 to 4, the coordination and support-measure powers in art. 5(1) and art. 5(2) points 1 and 2, the statement of purpose in art. 6(1), the art. 7 list of what a status-holding developer may do, the bare liability referral in art. 11, and arts. 12 and 13 — none of which places a compliance duty on anyone. The official record confirms the position: the pravo.gov.ru register carries the Law as «Не вступил в силу» with a single original redaction marked «вступает в силу 01.09.2026». Adopted by the State Duma on 8 July 2026, approved by the Federation Council on 17 July 2026, officially published on the legal-information portal on 26 July 2026 under number 0001202607260003, and reproduced at Собрание законодательства РФ 2026 No. 30 item 4089 and in «Российская газета» of 31 July 2026.

Stated maximum penalty — None is stated in the Law. Art. 11 is a bare referral — participants in relations in the field of development, deployment and application of large foundational models bear responsibility «в соответствии с законодательством Российской Федерации» for breaches of the Law and of the acts adopted under it — and as at 21 August 2026 the Code of Administrative Offences carries no article addressed to large foundational AI models, so no monetary band attaches to art. 10(1). Where the failure to notify also amounts to a consumer-information failure or a personal-data breach, the existing KoAP articles apply on their own terms. This entry deliberately states no figure rather than importing one from an adjacent regime.

Applies 1 Mar 2027 checked 21 Aug 2026 243-FZ art. 10(1) ↗ high confidence
Russia Binding

243-FZ art. 9 — platforms above 500,000 daily users enable an AI label; nobody is made to apply one

Binds Owners of sites, site pages, information systems and computer programs meeting all of the art. 9(3) limbs at once: intended for or used by users to supply or distribute information via personal pages the users create; carrying information in the state language of the Russian Federation, in the state languages of republics within it, or in other languages of the peoples of Russia, on which advertising aimed at attracting the attention of consumers located in Russia may be distributed; and accessed within twenty-four hours by more than 500,000 internet users located in Russia. That is a large-platform threshold, so the practical population is a short list of user-generated-content services. Art. 9(1) and (2) address the person applying the model and the person providing the ability to apply it, but neither is placed under a duty by them.. Russia's first AI statute stops short of an AI-content labelling mandate, and the gap between what art. 9 says and what it is widely reported to say is the point of this entry. Art. 9(1) provides that a person who applies a large foundational model to create informational material in audio and (or) visual form «обеспечивается возможность размещения информационного предупреждения» — is provided with the possibility of placing an informational warning about the use of AI technologies. That is an entitlement, not a duty, and art. 9(2) confirms the reading by leaving the format, content and manner of placing the warning to be fixed by agreement between the person applying the model and the person providing the ability to apply it, which is not how a statutory labelling obligation is drafted. The single hard duty in the article is art. 9(3), and it falls on the platform rather than on the creator: the owner of a site or page of a site on the internet, or of an information system, or of a computer program that is intended for or used by its users to supply and (or) distribute information through personal pages they create, on which advertising directed at consumers located in Russia may be distributed, and access to which within twenty-four hours exceeds five hundred thousand internet users located in Russia, has to ensure that users distributing information created with large foundational models on their personal pages have the possibility of placing an informational warning about that use. The obligation is therefore to build and offer the labelling affordance, not to label, not to detect AI-generated material, and not to take anything down. Compare the EU AI Act art. 50 machine-readable marking duty on the generating provider and the deployer's disclosure duty, or the Chinese labelling measures, both of which put the duty on the party that makes or publishes the content: Russia's rule leaves the decision to label with the user and makes the large platform supply the button.

Art. 9 is one of the articles art. 13(2) defers: the Law enters into force on 1 September 2026 under art. 13(1), but arts. 8, 9 and 10, along with art. 5(2) points 3 to 5 and art. 6 parts 2 to 5, take effect on 1 March 2027. The platform enablement duty therefore does not bite on the commencement date that most accounts of the Law report. Adopted by the State Duma on 8 July 2026, approved by the Federation Council on 17 July 2026, officially published 26 July 2026 as number 0001202607260003 on the official legal-information portal, and carried at Собрание законодательства РФ 2026 No. 30 item 4089 and in «Российская газета» of 31 July 2026. The official register records the Law as not yet in force with a single original redaction commencing 1 September 2026.

Stated maximum penalty — None is stated in the Law. Art. 11 refers offenders to «законодательство Российской Федерации» generally, and as at 21 August 2026 no article of the Code of Administrative Offences is addressed to large foundational AI models or to the art. 9(3) enablement duty, so no figure can be stated. The separate marking rules that apply to advertising and to information intermediaries are outside this entry.

Applies 1 Mar 2027 checked 21 Aug 2026 243-FZ art. 9 ↗ high confidence

Rwanda 1

Rwanda Binding

Law No. 058/2021 art. 21 — right not to be subject to a decision based on automated data processing

Binds Data controllers, data processors and third parties within the scope of art. 2: those established or residing in Rwanda and processing personal data while in Rwanda, and those neither established nor resident in Rwanda that process the personal data of data subjects located in Rwanda. Article 2 reaches processing of personal data by electronic or other means through an automated or non-automated platform. Registration with the supervisory authority is a standing precondition of acting as a controller or processor: arts. 29 to 36 govern registration, the registration certificate, its renewal, modification and cancellation, and the register itself, and operating without a registration certificate is an administrative misconduct under art. 54. The art. 21 right binds any controller taking a solely-automated decision with legal or significant consequences, irrespective of size. The National Cyber Security Authority is the designated supervisory authority. Impact tier: all entities.. Article 21 of Law Nº 058/2021 of 13/10/2021 relating to the protection of personal data and privacy carries Rwanda's operative automated-decision rule, in Chapter III (rights of the data subject). Its first paragraph gives the data subject the right not to be subject to a decision based solely on automated personal data processing, including profiling, which may produce legal consequences or significant consequences to him or her. The second paragraph disapplies that right where the decision is based on the explicit consent of the data subject, is necessary for entering into or performance of a contract between the data subject and the data controller, or is authorised by Laws to which the data controller is subject and which also put in place suitable measures to safeguard the data subject's rights, freedoms and legitimate interests. The third paragraph adds a free-standing limit that binds even inside those exceptions: any automated processing of personal data intended to evaluate certain personal aspects relating to a natural person does not base on sensitive personal data unless one of the grounds in art. 10 is met. Article 3 supplies the definitions that give the rule its reach — item 11° defines profiling as a form of automated processing used to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements; item 8° defines legal consequences as consequences that negatively affect a person's legal status or legal rights; and item 7° defines significant consequences as consequences having an impact as significant as legal effects that negatively affect the behaviour and choices of a data subject. Two adjacent duties attach to the same processing: art. 14 requires the controller to disclose to the data subject the existence of automated decision making, including profiling, together with information about the logic involved and the significance and envisaged consequences of the processing, and art. 45 makes a personal data protection impact assessment mandatory where there is a systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing of personal data, including profiling, on which decisions producing effects concerning such persons are based.

Commencement is stated on the face of the Law and needs no separate instrument: art. 70 provides that the Law comes into force on the date of its publication in the Official Gazette of the Republic of Rwanda, and it was published in Official Gazette nº Special of 15/10/2021, so art. 21 has been in force since 15 October 2021. Article 67 gave a controller or processor already in operation a period not exceeding two years from that publication date to conform its operations to the Law; that transitional window closed on 15 October 2023 and does not defer art. 21 itself. Article 66 lets the competent organ, in collaboration with the supervisory authority, put in place regulations; no regulation specific to automated decision-making has been issued. Coverage symmetry against the four African rows already tracked: art. 21 is a standing prohibition in the GDPR art. 22 shape, like ke-dpa-s35 and ng-ndpa-s37 and unlike the notice-based gh-dpa-s41, but its remedy is the thinnest of the five — where Nigeria's s. 37(3) expressly grants human intervention, the right to express a point of view and the right to contest, and Kenya's s. 35(3)-(4) grants written notification plus reconsideration or a fresh non-automated decision, Rwanda's art. 21 sets out only the right and its exceptions and prescribes no safeguard measures inside the exceptions at all. It carries no hard deadline; the thirty-day and sixty-day clocks in arts. 19, 20 and 22 attach to objection, portability and restriction, not to art. 21. Its distinctive addition is the art. 21 third-paragraph bar on grounding evaluative automated processing in sensitive personal data, which none of the four peers has. Text read in the Official Gazette as published by the National Cyber Security Authority, the supervisory authority designated under the Law; the English, French and Ikinyarwanda columns of the gazette were read together and agree.

Stated maximum penalty — There is no offence specific to art. 21. Enforcement runs through Chapter VIII. Under art. 54 a listed administrative misconduct — including processing personal data contrary to the Law, operating without a registration certificate, failure to designate a personal data protection officer and the breach-notification failures — carries an administrative fine of not less than RWF 2,000,000 and not more than RWF 5,000,000, or one per cent of the global turnover of the preceding financial year, and for a corporate body or legal entity one per cent of that global turnover; the same article lets the supervisory authority make regulations determining further administrative misconducts and sanctions. The criminal tier in arts. 56 to 61 is narrower and does not name automated decision-making: art. 56 punishes accessing, collecting, using, offering, sharing, transferring or disclosing personal data contrary to the Law with one to three years' imprisonment and a fine of RWF 7,000,000 to RWF 10,000,000, or one of those penalties, and art. 60 punishes collecting or processing sensitive personal data contrary to the Law with seven to ten years' imprisonment and a fine of RWF 20,000,000 to RWF 25,000,000, or one of those penalties. Article 62 sets the corporate penalty for any of the arts. 56 to 61 offences at 5% of the annual turnover of the preceding financial year, and art. 63 lets the court order seizure or confiscation of the objects used and the proceeds gained, and permanent or temporary closure of the entity or premises. Article 65 gives a person who suffers serious damage from a controller's or processor's breach a claim for compensation before the competent court.

In force · 15 Oct 2021 checked 20 Aug 2026 Law No. 058/2021 art. 21 ↗ high confidence

Singapore 1

Singapore Binding

Singapore MAS — Agentic AI in Scope of Supervisory Expectations (binding AI Risk Management Guidelines pending)

Binds MAS-regulated financial institutions (banks, insurers, payment service providers, capital market intermediaries) using autonomous AI agents in Singapore. MAS's 5 Aug 2026 parliamentary reply states existing supervisory expectations already extend to AI agents used by financial institutions, and that MAS will continue to review and update these as needed. The binding instrument — MAS's proposed AI Risk Management Guidelines (consultation paper 13 Nov 2025) — remains in consultation, with a 12-month compliance transition once issued but no MAS-confirmed issuance date. Separately, MAS published a voluntary industry paper, SAFR (Safeguards for Agentic Finance at Runtime), on 3 Jul 2026 — SAFR itself is not binding.

MAS parliamentary reply (5 August 2026) by Deputy Prime Minister and MAS Chairman Gan Kim Yong states existing supervisory expectations (via tech-risk frameworks) already extend to AI agents; the reply's own language is that MAS will "continue to review... and update where necessary," not a declaration that a codified binding rule for agentic AI already exists. The binding track is MAS's proposed AI Risk Management Guidelines (consultation paper of 13 Nov 2025, para 4.7: 12-month transition period proposed after the Guidelines are issued); those Guidelines remain in consultation with no MAS-confirmed finalization date (Q4 2026 is market/analyst expectation, not a MAS commitment). SAFR (Safeguards for Agentic Finance at Runtime), published 3 July 2026, is an industry-led voluntary information paper, distinct from and not itself the binding Guidelines.

Stated maximum penalty — MAS administrative sanctions under financial institution licensing (no specific penalty quantum in parliamentary reply)

In force · 5 Aug 2026 checked 20 Aug 2026 MAS AI Risk Management Guidelines (proposed) / SAFR (voluntary) ↗ medium confidence

Senegal 1

Senegal Binding

Loi 2008-12 art. 48 — no decision with legal effects on the sole basis of automated profiling, and no judicial appraisal of conduct founded on one at all

Binds Responsables du traitement within the scope of art. 2, which subjects to the Law any collection, processing, transmission, storage and use of personal data by a natural person, by the State, by local authorities or by legal persons of public or private law; any processing, automated or not, of data contained in or intended to form part of a file, save the processing excluded by art. 3; any processing implemented by a controller on Senegalese territory or in any place where Senegalese law applies; and any processing implemented by a controller, established in Senegal or not, that resorts to means of processing situated on Senegalese territory, excluding means used only for transit. In that last case the controller must designate a representative established on Senegalese territory, without prejudice to actions that may be brought against the controller itself. Prior formalities are a standing precondition: declaration to the Commission de Protection des Données Personnelles is the default, art. 20 puts health, offence, interconnection, national-identifier, biometric and public-interest processing under prior authorisation, and art. 21 requires a regulatory act taken after the reasoned opinion of the Commission for State, public-establishment, local-authority and public-service processing touching State security, defence, public safety, criminal enforcement, the population census and sensitive data. The first paragraph of art. 48 binds the courts themselves; the second binds any controller taking a decision with legal effects, irrespective of size or sector. Impact tier: all entities.. Article 48 of Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel is Senegal's operative automated-decision rule. It sits in Chapitre III among the substantive processing obligations, between the direct-marketing prohibition in art. 47 and the cross-border-transfer regime in art. 49, and it has three paragraphs. The first is absolute and addressed to the courts: no judicial decision involving an appraisal of a person's conduct may have as its foundation an automated processing of personal data intended to evaluate certain aspects of that person's personality — there is no consent, contract or safeguards exception to this limb. The second is the general rule: no decision producing legal effects with regard to a person may be taken on the sole basis of an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third supplies the only relief and operates by deeming rather than by exemption: decisions taken in the course of the conclusion or the performance of a contract and for which the person concerned has been put in a position to present their observations, and decisions satisfying the requests of the person concerned, are not regarded as taken on the sole basis of an automated processing. The Law carries no definition of profiling, no right to know the logic underlying an automated processing — the art. 58 information list stops at identity, purposes, categories, recipients, whether answering is compulsory, the right to be removed from the file, the existence of access and rectification rights, the retention period and any envisaged foreign transfers — and no right to obtain human intervention or a fresh non-automated decision. The safeguard it names is an opportunity to present observations, and it exists only inside the contractual deeming clause.

The Law contains no commencement article and, in the copy published by the Commission de Protection des Données Personnelles, no publication clause either: the text runs from the exposé des motifs to art. 78, which reserves the application measures for the digitised national identity card to a separate regulation, and stops there. The date recorded is therefore the date the Law itself bears, 25 January 2008. Confidence is medium, and for a reason one step weaker than Morocco's and Algeria's: not only was the Senegalese general publication-to-force rule not read against a primary source, but the date of the Journal officiel de la République du Sénégal carrying the Law could not be established at all, because no Senegalese gazette host resolved this run — jo.gouv.sn and www.jo.gouv.sn both fail to resolve over http and https. Entry into force can therefore only be that date or later. Art. 77 is transitional and not a deferral of art. 48: from the date of entry into force, processing operations carried out for the State, a public establishment, a local authority or a private-law body managing a public service had two years to conform and all other processing had one year, periods that closed in 2010 and 2009 respectively; art. 76 subjects already-created public-sector processing to declaration only, under art. 18. Décret n° 2008-721 du 30 juin 2008 was taken for the application of the Law; no date claim is drawn from it here. Supersession: the CDP's own legislation index, checked this run, still carries Loi n° 2008-12 as the governing statute, with no amending or replacing instrument listed. Text read end to end in the copy published by the CDP, the independent administrative authority created by art. 5 of the Law; the CDP serves that copy from its own signed document store, and the entry cites the CDP legislation page because the storage link is a time-limited signed URL. Coverage symmetry against the twelve African rows already tracked: art. 48 belongs to the Directive 95/46/EC art. 15 line, and within that family Senegal is the closest match to Morocco's art. 11 and Algeria's art. 11 anywhere in Africa — the three share the same three-paragraph shape, the same absolute judicial limb, the same legal-effects threshold on the second limb, and the same contractual deeming clause conditioned on an opportunity to present observations. That makes the Francophone family split cleanly in two: Senegal, Morocco and Algeria keep the Directive's own drafting, while Côte d'Ivoire's art. 25 and Niger's art. 52 take the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting, in which the second limb reaches any administrative or private decision appraising human conduct and the legal-effects threshold disappears. Senegal predates the Supplementary Act by two years, which is consistent with that split. The four-way African lineage picture is unchanged: GDPR art. 22 = ke-dpa-s35, ng-ndpa-s37, rw-law058-2021-art21; UK Data Protection Act 1998 s. 12 = gh-dpa-s41, tz-pdpa-s36, ug-dppa-s27; Directive 95/46/EC art. 15 = ma-loi0908-art11, dz-loi1807-art11, ci-loi2013450-art25, ne-loi202259-art52 and now sn-loi200812-art48; Directive-family statute with the automated-decision article absent = Tunisia's Loi organique 2004-63.

Stated maximum penalty — Senegal is the only row on the tracker whose data-protection statute creates no offences of its own. Art. 75, the whole of Chapitre VI, provides that infringements of the Law's provisions are laid down and punished by the Penal Code and by the law relating to cybercrime — Loi n° 2008-11 du 25 janvier 2008 sur la cybercriminalité, adopted the same day — so no penalty figure can be attributed to art. 48 from the data-protection statute itself, and none is asserted here. The route that reaches art. 48 within the Law is administrative and runs through the Commission de Protection des Données Personnelles. Art. 29 lets the Commission issue a warning to a controller that does not respect the obligations arising under the Law and a formal notice (mise en demeure) to end the failures within a period it fixes. Art. 30 provides that if the controller does not comply with the formal notice the Commission may, after an adversarial procedure, pronounce provisional withdrawal of the authorisation granted for three months, at the expiry of which the withdrawal becomes definitive, and a pecuniary fine of 1,000,000 to 100,000,000 francs CFA, recovered under the legislation on recovery of State debts. Art. 31 adds an urgency power where the implementation of a processing or the exploitation of personal data entails a violation of rights and freedoms: after an adversarial procedure the Commission may order interruption of the processing for a maximum of three months, blocking of certain processed data for a maximum of three months, or temporary or definitive prohibition of a processing contrary to the Law. Art. 32 makes the Commission's sanctions and decisions appealable to the Conseil d'Etat. Arts. 25 to 28 supply the inspection powers, exercisable on professional premises under the Code de Procédure Pénale with the Procureur de la République informed in advance, requiring authorisation from the President of the Regional Court where the occupier objects, and recorded in an adversarial procès-verbal.

In force · 25 Jan 2008 checked 20 Aug 2026 Loi n° 2008-12 art. 48 ↗ medium confidence

São Tomé e Príncipe 1

São Tomé e Príncipe Binding

Lei 3/2016 art. 13.º — the Lusophone prohibition without Angola's regulator escape hatch, and with a right to the reasons

Binds Responsáveis pelo tratamento — controllers — with subcontratantes (processors) bound through art. 17, which forbids anyone acting under the authority of the controller or processor, and the processor itself, from processing personal data without the controller's instructions save under legal obligation. Art. 3(1) applies the Law to processing by wholly or partly automated means and to non-automated processing of personal data contained in or intended for manual files. Art. 3(2) sets four territorial limbs: processing by a controller headquartered in São Tomé e Príncipe; processing in the context of the activities of a controller established in São Tomé e Príncipe even where that controller is not headquartered in national territory; processing outside national territory in a place where São Tomé law applies by force of public or private international law; and processing by a controller not established in São Tomé e Príncipe that resorts, for the processing, to means situated in national territory. Art. 3(3) makes that last limb wide in the same terms Angola uses — a controller is deemed to resort to means in São Tomé territory where the processing operations are carried out with means situated in national territory or where the personal data are hosted on means so situated, the mere use of such means for the collection, recording or transit of personal data in national territory being enough — and art. 3(4) then obliges that controller to designate a representative established in São Tomé e Príncipe. A foreign scoring, credit or hiring-assessment operator that merely hosts on São Tomé infrastructure is therefore inside art. 13 and owes a local representative. Impact tier: all entities — art. 13 carries no employee-count, turnover, sector or high-risk-system threshold, and its named evaluation grounds (professional capacity, credit, trustworthiness, conduct) put hiring and credit-scoring deployers squarely in scope.. Article 13.º of Lei n.º 3/2016 — Lei de Protecção de Dados Pessoais is São Tomé e Príncipe's automated-decision provision, and it is the second Lusophone row on the tracker after Angola. Both descend from Portugal's Lei 67/98 and the operative sentence is close to word-for-word: under art. 13(1), «qualquer pessoa tem o direito de não ficar sujeita a uma decisão que produza efeitos na sua esfera jurídica ou que a afecte de modo significativo, tomada exclusivamente com base num tratamento automatizado de dados destinado a avaliar determinados aspectos da sua personalidade, designadamente a sua capacidade profissional, o seu crédito, a confiança de que é merecedora ou o seu comportamento» — any person has the right not to be subject to a decision producing effects in their legal sphere or significantly affecting them, taken exclusively on the basis of automated processing intended to evaluate certain aspects of their personality, namely their professional capacity, their credit, their trustworthiness or their conduct. Where the two Lusophone rows part company is on the way out and on what the data subject gets to see. São Tomé keeps only the two statutory exceptions of the parent law — art. 13(2)(a), a decision taken in the conclusion or performance of a contract, conditioned on the person's own request having been satisfied or on adequate measures guaranteeing their legitimate interests, expressly their right of representation and expression; and art. 13(2)(b), a decision authorised by a law that lays down measures guaranteeing the data subject's rights and legitimate interests. There is no third route: nothing lets the Agência Nacional de Protecção de Dados Pessoais licence an otherwise-prohibited decision, which is exactly the limb Angola carries as art. 29(3) and Cabo Verde as art. 23(3) — São Tomé is the one member of the Lusophone group that dropped the regulator-licence route of art. 13(3) of Portugal's Lei 67/98. In the other direction São Tomé is the more generous of the pair, because art. 11(1)(c) gives the data subject the right to obtain from the controller «o conhecimento das razões subjacentes ao tratamento automatizado dos dados que lhe digam respeito» — knowledge of the reasons underlying the automated processing of data concerning them. The parent Portuguese provision speaks of the lógica subjacente, the underlying logic; São Tomé's drafters wrote razões, reasons, which on its face asks for the grounds of the processing rather than the mechanics of the model, and it is drafted as an access right exercisable on request rather than as a notice duty — the art. 10 information list carries no automated-decision item at all. Angola's Lei 22/11 has no equivalent of either. So among the three African rows added this month the shape is: São Tomé prohibits the decision and lets the data subject ask why the machine processed them, Angola prohibits the decision and never lets them ask, and the Democratic Republic of the Congo never prohibits it but compels disclosure of the underlying logic three times over. Impact tier: all entities.

Force. The Law was approved by the Assembleia Nacional in São Tomé on 15 February 2016, promulgated by President Manuel do Espírito Santo Pinto da Costa on 18 March 2016, and published in the Diário da República n.º 39 de 10 de Maio de 2016 at pp. 285-299 — the gazette number and date run in the running head of every page of the text read. The date carried here is that publication date, and it is the one point in the entry that is not exact to the day: art. 47.º (Entrada em vigor) says only «a presente lei entra em vigor nos termos legais», deferring to the general rule on the entry into force of diplomas rather than fixing a date or a vacatio period on its face, so the operative date is the publication date or a small number of days after it. Applying Deadline Specificity strictly, that residual is stated rather than papered over: no primary text of the São Tomé rule on entry into force of diplomas was located in this pass, secondary accounts point to the five-day PALOP vacatio inherited from Base LXXIX of Lei 5/72, and that account has not been verified against primary text and is not relied on here. Ten years on, nothing on the tracker turns on the difference. Art. 45 sets the only transition and it does not touch art. 13: processing existing in manual files at entry into force was given two years for conformity with arts. 7, 8, 10 and 11. Supersession: none — no successor or amending law was found, and no AI-specific statute is in force in São Tomé e Príncipe. Text read in full in the copy of the Diário da República pages published by the Red Iberoamericana de Protección de Datos, the network of Ibero-American data-protection authorities of which the São Tomé Agência Nacional de Protecção de Dados Pessoais is a member; the file is the gazette typesetting itself, carrying the DR running heads, page numbers 285-299 and the closing signature block, not a re-keyed edition. Coverage of the read: arts. 2 principles, 3 scope and 4 definitions; the whole of Capítulo III on data-subject rights, arts. 10 information, 11 access, 12 opposition, 13 automated individual decisions and 14 compensation, verbatim; arts. 16-18 on sensitive-data authorisations, processors and professional secrecy; the whole enforcement chain — arts. 30-35 administrative infractions and their fines, arts. 36-41 the criminal section, arts. 42-43 accessory penalties; art. 44 on the Agência; and arts. 45-47 the transitional and final provisions. Confidence high on the substance: art. 13 and art. 11(1)(c) were read verbatim in the gazette text and the fine attaching to art. 13 was traced to the enumerated list in art. 32(1) rather than assumed. The Agência Nacional de Protecção de Dados Pessoais, whose organic law art. 44 leaves to the Assembleia Nacional, does exist and is operational — it is a listed member of the African Network of Data Protection Authorities and of the Rede Lusófona de Protecção de Dados, where it leads the video-surveillance working group — so unlike Equatorial Guinea's never-created Órgano Rector, the enforcement route in art. 35 has an addressee.

Stated maximum penalty — 25,000,000 to 50,000,000 dobras, and the notable point is that the fine reaches art. 13 directly. Art. 32(1) enumerates by article number the provisions whose breach is an administrative infraction at that band — arts. 5, 10, 11, 12, 13, 16, 17 and 25(3) — so both the automated-decision prohibition in art. 13 and the right to know the reasons underlying automated processing in art. 11 are inside the sanctioned list. That is the opposite of Angola, where art. 29 appears in neither art. 51 contravention list and enforcement has to run through a complaint, a judicial reparation claim or the crime of qualified disobedience. Art. 32(2) sets a higher band, 45,000,000 to 90,000,000 dobras, for breach of arts. 6, 7, 8, 9, 19 and 20. Art. 31 sets the notification-failure band — 50,000,000 to 120,000,000 dobras for a natural person, 100,000,000 to 200,000,000 for a group without legal personality, and 250,000,000 to 500,000,000 for a legal person — doubled under art. 31(2) where the data are subject to prior control, and art. 34(1) makes negligence always punishable there. All amounts are as written in the 2016 text and are nominal dobras of that date; São Tomé e Príncipe redenominated its currency after the Law was passed, so the figures need conversion before they are quoted as a present-day exposure, and no conversion is asserted here because none was verified against primary text in this pass. Art. 35 gives the application of the fines to the Agência Nacional de Protecção de Dados Pessoais and makes its decision an enforceable title where it is not challenged in the legal period. Alongside the fines, art. 42 allows accessory penalties — temporary or definitive prohibition of the processing, blocking, erasure or total or partial destruction of the data, publicity of the conviction under art. 43 at the convicted party's expense in a widely circulated Portuguese-language periodical for not less than 30 days, and public warning or censure of the controller by the Agência. The criminal section sits behind that: art. 36 punishes intentional failure to notify or to seek authorisation, false information in a notification, diversion or use of personal data incompatibly with the purpose determining their collection, and unlawful interconnection, with up to one year's imprisonment or a fine up to 120 days; art. 37 punishes undue access and art. 38 the vitiation or destruction of data with up to two years; art. 39 makes it qualified disobedience to fail, after notification, to interrupt, cease or block processing, or to refuse the Agência the cooperation demanded of one; art. 40 punishes breach of professional secrecy with up to two years, aggravated by half where the agent is a public official or acted for gain; and art. 41 makes attempt always punishable. Under art. 33(1), where the same act is both a crime and an administrative infraction, the agent is always punished as for the crime.

In force · 10 May 2016 checked 21 Aug 2026 Lei 3/2016 art. 13.º ↗ high confidence

Togo 1

Togo Binding

Loi 2019-014 art. 27 — a judicial limb, a legal-effects limb and a contract carve-out: the Directive 95/46 shape, not the wider ECOWAS one

Binds Responsables du traitement within the scope of art. 2, which subjects to the Law any collection, processing, transmission, storage and use of personal data by a natural person, the State, local authorities or legal persons of public or private law; any processing, automated or not, of data contained in or intended to form part of a file; any processing implemented by a controller on Togolese territory or anywhere Togolese law applies; any processing by a controller established or not in Togo that resorts to means of processing situated on Togolese territory other than for mere transit; and any processing concerning public security, defence, investigation and prosecution of criminal offences or State security, subject to the Law's own derogations. Art. 3 excludes processing by a natural person in the exclusive course of personal or domestic activities where the data are not intended for systematic communication to third parties or dissemination, and temporary copies made in the technical activities of transmission and network access. The formalities are graduated: art. 5 dispenses some processing entirely, art. 6 makes declaration to the Instance de protection the default and provides that only receipt of the récépissé confers the right to implement the processing, art. 7 lets the Instance publish simplified or exempting norms, art. 8 requires prior authorisation for six categories — genetic data and health research, offence and conviction data, file interconnection, national identification numbers, biometric data and public-interest processing — and art. 9 requires a reasoned opinion before regulatory acts for State, public-establishment and public-service processing. Profiling and automated decision-making appear in none of the art. 8 authorisation categories, so unlike Burkina Faso and Niger, Togo imposes no ex ante gate on the processing art. 27 governs. The art. 27 bar binds the courts under its first limb and every decision-maker taking a decision producing legal effects under its second, irrespective of size or sector. Impact tier: all entities.. Article 27 of Loi n° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel is Togo's operative automated-decision rule. It is headed "Du fondement d'une décision de justice" and sits in Chapitre III on the rights of the data subject, between the art. 26 direct-marketing prohibition and the art. 28 cross-border-transfer article, in three unnumbered paragraphs. The first: no judicial decision involving an appraisal of a person's conduct may have as its sole foundation an automated processing of personal data intended to evaluate certain aspects of their personality. The second: no decision producing legal effects with respect to a person may be taken on the sole foundation of an automated processing of personal data intended to define the profile of the person concerned or to evaluate certain aspects of their personality. The third is a deeming carve-out: decisions taken in the context of the conclusion or the performance of a contract, and for which the data subject has been put in a position to present their observations, and decisions satisfying the data subject's requests, are not taken on the sole foundation of an automated processing. Two features place Togo away from its Francophone West African neighbours and alongside Morocco and Algeria. First, the second limb is drafted on the Directive 95/46/EC art. 15 model — its trigger is a decision producing legal effects — and not on the wider ECOWAS Supplementary Act model used by Côte d'Ivoire, Burkina Faso and Niger, whose second limb reaches any administrative or private decision appraising human conduct whatever its effects. Second, the judicial limb carries the word "seul": unlike Côte d'Ivoire's art. 25, Burkina Faso's art. 15 and Guinea's art. 27, a Togolese judicial decision is barred only where the automated processing is its sole foundation. Togo does supply the exception clause that Côte d'Ivoire, Mali and Burkina Faso omit, and it is the Moroccan and Algerian one: contract decisions with an opportunity to present observations, plus decisions satisfying the data subject's own requests. The Law creates no right to know the logic of an automated processing — the art. 39 access right runs to information enabling the data subject to know and to contest the processing, confirmation, communication of the data and their origin, purposes, categories, recipients and envisaged transfers, and nothing more — and no right to obtain human intervention or a fresh non-automated decision. The Law carries no definition of profiling.

Art. 97, the final article, is a bare execution clause — "La présente loi est exécutée comme loi de l'Etat" — and the Law contains no commencement article and defers nothing. The date recorded here, 29 October 2019, is the date carried in the Law's own title and citation and is also the date of the Journal officiel de la République togolaise, 64e année, n° 26 ter, in which it was published. Confidence is medium, and the reason is specific and is recorded here rather than smoothed over: the signature block of the enacted text reads "Fait à Lomé, le 30 octobre 2019" over the signatures of President Faure Essozimna Gnassingbé and Prime Minister Selom Komi Klassou, one day AFTER the date of the gazette issue that carries it. The discrepancy is on the face of the gazette itself and is consistent with the Togolese practice of numbered "ter" special issues, but it means the promulgation date and the publication date cannot both be right as printed, and the Togolese general publication-to-force rule was not read against a primary source either, so it could not be confirmed whether force attaches on publication or after a jour franc. Anyone relying on a one-day margin around 29-30 October 2019 should read the gazette page directly. Art. 96 abrogates all prior contrary provisions but names no statute, so no predecessor is superseded on the tracker. Art. 95 is transitional and is not a deferral of art. 27: from entry into force, processing for the State, a public establishment, a local authority or a private legal person managing a public service had two years to conform and all other processing had one year, periods that closed in 2021 and 2020 respectively; art. 94 additionally reduced pre-existing public-sector processing to a declaration under art. 6. Coverage symmetry against the Francophone rows already tracked: Togo is the seventh member of the Directive 95/46/EC art. 15 family on the tracker and it splits that family further. Morocco's art. 11, Algeria's art. 11 and now Togo's art. 27 take the narrow legal-effects trigger with a contract carve-out; Côte d'Ivoire's art. 25, Mali's art. 2, Burkina Faso's art. 15 and Niger's art. 52 take the wider ECOWAS trigger reaching any administrative or private decision appraising human conduct. Togo is a founding ECOWAS member and its Law postdates the ECOWAS Supplementary Act A/SA.1/01/10 by nine years, yet it did not take the Supplementary Act's wider drafting — which is why each statute in this block is read article by article rather than inferred from membership. Text read page by page in the Journal officiel de la République togolaise of 29 October 2019 as published by the Government of Togo's own gazette service, including arts. 2, 3, 5 to 9, 26 to 28, 38 to 41, 70 to 73, 79 to 93 and 94 to 97.

Stated maximum penalty — No criminal offence attaches to art. 27. The Law's penal chapter is arts. 79 to 93 and every one of its fifteen offences names its own conduct — failure to observe the prior formalities, disregard of a provisional withdrawal of authorisation, disregard of simplified or exempting norms, unauthorised processing of identification data, failure of security measures, fraudulent processing, disregard of the right to object, unlawful processing of sensitive data, of offence data and of health-research data, breach of the retention period, processing of data kept beyond it, diversion of purpose, unauthorised disclosure, and obstruction of the Instance de protection — and none of them reaches an automated decision. Those offences run from three months to five years' imprisonment and from 100,000 to 25,000,000 francs CFA, or one of the two penalties. The route that does reach art. 27 is administrative. Art. 70 lets the Instance de protection des données à caractère personnel issue a warning to a controller not respecting the obligations arising under the Law and a mise en demeure to cease the failures within a period it fixes. Art. 71 provides that where the controller does not comply with that mise en demeure the Instance may, after an adversarial procedure, pronounce a provisional withdrawal of the authorisation for three months which becomes definitive if no corrective measures follow, and a fine which may not exceed 100,000,000 francs CFA, recovered under the legislation on the recovery of State debts. Art. 72 adds urgent measures where implementation of a processing entails a violation of rights and freedoms: interruption of the processing for up to three months, blocking of certain data for up to three months, an injunction to bring the processing into conformity which may carry an astreinte of up to 5,000,000 francs CFA per day except where the State is the controller, and a formal reprimand. Art. 73 adds conservatory measures where a processing is implemented without the prior formalities, including the affixing of seals by a huissier at the controller's expense.

In force · 29 Oct 2019 checked 20 Aug 2026 Loi n° 2019-014 art. 27 ↗ medium confidence

Thailand 1

Thailand Binding

Royal Decree on Digital Platform Service Businesses Sec. 17 — publication of the main parameters of ranking, advertising and review algorithms

Binds Operators of digital platform services subject to prior notification under Sec. 8 — a service with annual revenue from the platform earned in Thailand above THB 1.8 million for a natural person or above THB 50 million for a juristic person, or with more than 5,000 average monthly users. The Sec. 17 disclosure duty applies to the services listed in Sec. 16: platforms provided for remuneration that act as an intermediary in offering goods or services to consumers under contractual relationships with business users, and online search engines. Sec. 3 and the deeming rules extend the Decree to foreign operators serving users in Thailand, indicated by Thai-language display, a Thailand-signifying domain, Thai baht payment, Thai governing law or forum, or paid search placement for Thai users. The heavier Secs. 19 to 21 duties bind only large platforms — above THB 300 million annual revenue per service type, above THB 1 billion across all types, or users exceeding 10 per cent of the Thai population — and designated specified platforms. Impact tier: SME and enterprise.. The Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification, B.E. 2565 (2022), issued under Secs. 32 and 33 of the Electronic Transactions Act B.E. 2544, requires the platform operators identified in Sec. 16 to publish their terms and conditions of service clearly and appropriately, before or at the time the service is used. Section 17 fixes the minimum content of that publication and three of its limbs are algorithmic disclosure duties: the main parameters of the algorithms or of the criteria the operator uses to rank or recommend the list of goods or services to users; the main parameters of the algorithms or criteria used to present advertisements of goods or services to users; and the main parameters of the algorithms or criteria used to collect, moderate and publish user reviews. The same section also requires disclosure of service suspension or termination and remuneration terms, access to and use of data received from the service, support channels, the internal complaint-handling system and dispute resolution with time frames, and the rating of goods, services or content. Separately, operators designated as large or specified digital platform services under Sec. 18 must conduct risk assessments and implement mitigation measures, maintain system security, carry out crisis management, appoint compliance officers and undergo external audit (Secs. 19 to 21), and report annually on that compliance to the Electronic Transactions Development Agency (Sec. 22).

Commencement is computed from the face of the instrument: Sec. 2 provides that the Royal Decree comes into force after the expiration of 240 days from the date of its publication in the Government Gazette, and the publication footnote records Government Gazette Vol. 139, Part 78a, page 17, dated 23 December 2022. Two hundred and forty days from 23 December 2022 expire on 20 August 2023, so the Decree is in force from 21 August 2023. The Sec. 43 transitional rule gave operators already trading on the day before commencement ninety days from that date to file the prior notification, a window that closed on 19 November 2023, and Sec. 44 gave the Sec. 8 paragraph four operators one year. This is Thailand's first entry on the tracker. It is the ASEAN counterpart of cn-algo-recommendation and of the EU ranking-transparency model rather than of the data-protection line: it reaches ranking, advertising and review-moderation algorithms as a platform-transparency duty owed to users, not a right of an individual data subject against a decision. Thailand's Personal Data Protection Act B.E. 2562 contains no equivalent of GDPR Art. 22, so no solely-automated-decision right is tracked for Thailand. Text read in the official English translation published by the Electronic Transactions Development Agency, the supervising authority named in the Decree; ratchakitcha.soc.go.th returns HTTP 403 on its legacy document paths, so the ETDA publication is cited.

Stated maximum penalty — The Decree carries administrative rather than monetary sanctions. Under Sec. 33, where an operator contravenes or fails to comply with the rules, procedures or conditions in Chapter II — which contains Sec. 17 — or with Notifications of the Commission or the Agency, the competent official shall order the operator to stop providing the digital platform service until the rules have been correctly and fully complied with; if the operator fails to comply with that order within ninety days of its issuance, the competent official shall revoke the acknowledgement of its notification from the notification registry, notify it in writing and publish the revocation publicly through the Sec. 14 channel. Revocation removes the operator's lawful basis to trade in Thailand, since Sec. 8 makes prior notification a condition of operation.

In force · 21 Aug 2023 checked 16 Aug 2026 Royal Decree on Digital Platform Service Businesses B.E. 2565 Sec. 17 ↗ high confidence

Türkiye 1

Türkiye Binding

KVKK art. 11(g) — a right to object with no offence of its own to enforce it

Binds Every data controller processing personal data in Türkiye, with no size, sector or turnover threshold — the right is asserted against «the data controller» without qualification, so enterprise, SME and public body alike. Art. 2 applies the Law to natural persons whose personal data are processed and to natural or legal persons processing personal data wholly or partly by automated means, or by non-automated means provided the processing forms part of a data filing system. The exemptions in arts. 28(1) and 28(2) are the boundary to check before assuming coverage, and the second of them matters here: art. 28(2) disapplies certain articles — but not the Law as a whole — where processing is, among other cases, necessary for preventive, protective and intelligence activities by public institutions charged with national defence, national security, public security or the economic security of the State, or is carried out for investigation, prosecution, trial or execution proceedings by judicial authorities. Hiring, credit scoring and insurance underwriting all fall inside the ordinary scope. Two practical features shape who is exposed. First, VERBİS: art. 16 requires controllers to enrol in the Data Controllers' Registry before beginning to process, subject to exemptions the Board sets by criteria including the number of employees, annual balance sheet total and the nature of the business, so the population of registered controllers is enumerated and the Authority knows where to look. Second, the representative rule — a controller not resident in Türkiye must appoint a representative there and enrol through it — so an offshore scoring engine reaching Turkish data subjects is not outside the frame. The limit to state plainly is the one in the text: art. 11(g) attaches to a result produced by analysing data processed «solely» through automated systems, and the Law offers no guidance on what degree of human involvement defeats that, nor has the Board issued a decision defining it.. Türkiye's automated-decision rule is a single sub-paragraph of a rights article, and it is drafted as an objection right rather than as a prohibition. Article 11 of Law No. 6698 on the Protection of Personal Data lists what a data subject may demand of a controller, and limb (g) gives the right «to object to the occurrence of a result against the person himself/herself by analyzing the data processed solely through automated systems». Read against GDPR art. 22 the differences are structural rather than cosmetic. There is no bar on taking the decision: the controller may make it, and the data subject's remedy is to object after the fact. There is no exception architecture, because a right to object needs none — no contract limb, no explicit-consent limb, no authorised-by-law limb, and so nothing corresponding to GDPR art. 22(2) or to the three ways out in s. 62(2) of Zambia's Act. There is no right to obtain human intervention and no right to contest as a distinct step, so the safeguard triad that Zambia carries in full is absent here. And there is no explanation limb anywhere: art. 11 runs (a) to (ğ) and none of its limbs is a logic-disclosure item, while the art. 10 duty to inform at the point of collection covers the controller's identity, the purpose of processing, to whom and for what purpose processed data may be transferred, the method and legal reason of collection, and the art. 11 rights themselves — it does not require a controller to volunteer that a decision was automated. The trigger wording is also narrower than the European one in a way worth preserving: «a result against the person» (kişinin kendisi aleyhine bir sonucun ortaya çıkması) requires an adverse outcome, where GDPR art. 22 catches legal or similarly significant effects whether adverse or not, and where the Swiss art. 21(1) reaches a decision with a legal consequence even absent adversity. A favourable automated decision produces no art. 11(g) right. The 2024 amendment to the Law, made by Law No. 7499 of 12 March 2024, rewrote art. 6 on special categories of personal data and art. 9 on transfers abroad and added the standard-contract notification duty now penalised in art. 18; it did not touch art. 11.

In force since 7 October 2016, and the publication date of the Law is not the operative date for this article. Law No. 6698 was published in the Official Gazette of 7 April 2016, No. 29677, and art. 32 splits commencement: most of the Law entered into force on publication, but arts. 8, 9, 11, 13, 14, 15, 16, 17 and 18 «shall enter into force after six months as of the date of its publication», which brings art. 11 — and with it limb (g) — to 7 October 2016. The 7 April 2016 date carried by most secondary accounts is the Law's date, not this obligation's, and the six-month tranche is easy to miss because it is stated once in the final article rather than in the rights article itself. The grouping is also informative: the same tranche carries art. 13 (application to the controller), art. 14 (complaint to the Board), art. 15 (examination by the Board) and art. 18 (misdemeanours), so the right and its entire enforcement route commenced together on one date, by design. Nothing since has moved it. Law No. 7499 of 12 March 2024, published 12 March 2024, amended arts. 6 and 9 and added a limb to art. 18 with its own 1 June 2024 commencement for the transfer regime, and left art. 11 untouched. Türkiye signed Convention 108+ on 10 October 2018 but has not ratified it, and the Convention itself is not in force, so art. 9(1)(a) of that instrument supplies no independent Turkish rule of the kind the Malabo Convention supplies for Namibia. A live watch, recorded rather than published: a draft AI law modelled on the EU AI Act was submitted to the Grand National Assembly in June 2024 and referred to committee, and successive drafts have circulated since; none has been enacted, so Türkiye has no AI-specific statute in force and art. 11(g) remains the operative automated-decision rule.

Stated maximum penalty — No fine attaches to art. 11(g) directly, and finding that out means reading art. 18 limb by limb rather than quoting the headline range. Art. 18(1) penalises exactly five things: failure to fulfil the art. 10 duty to inform; failure to fulfil the art. 12 data-security obligations; failure to comply with decisions issued by the Board under art. 15; breach of the art. 16 registry obligations; and, since Law No. 7499, failure to make the art. 9(5) standard-contract notification. Breach of a data subject's art. 11 rights is not among them. The enforcement route is therefore indirect and sequential, and it is the route the Law commenced alongside the right itself. Art. 13 requires the data subject to apply to the controller first, and the controller to conclude the request within thirty days at the latest. Art. 14 allows a complaint to the Personal Data Protection Board where the application is rejected, the reply is insufficient, or no reply arrives in time — within thirty days of learning the reply and in any case within sixty days of the application. Art. 15(5) then provides that where an infringement is established the Board «shall decide that the identified infringements shall be remedied by the relevant data controller», and that decision must be implemented without delay and within thirty days at the latest. Only if the controller fails to implement it does a fine become available, and it becomes available under art. 18(1)(c) — non-compliance with a Board decision — rather than under anything about art. 11. The statutory band for that limb is 25,000 to 1,000,000 Turkish lira as printed in the 2016 text, and the printed figures are not the payable ones: art. 18 fines are uprated for every calendar year under art. 17(7) of the Misdemeanour Law No. 5326 read with repeated art. 298 of the Tax Procedure Law No. 213, using the annual revaluation rate, so a decade of compounding sits between the statutory numbers and the current ones. The revalued figures are not published in this row because the Authority's own annual announcement was not retrieved for this check; the statutory band and the revaluation mechanism are recorded instead, and the current-year table should be read from the Authority before any figure is quoted. Two further routes exist alongside: art. 11(ğ) preserves a right to claim compensation for damage through the ordinary courts, and arts. 135 to 140 of the Turkish Penal Code No. 5237 create separate imprisonment offences for unlawful recording, transfer and non-deletion of personal data — none of which is an automated-decision offence. Impact tier: all entities.

In force · 7 Oct 2016 checked 19 Aug 2026 KVKK art. 11(g) ↗ high confidence

Tanzania 1

Tanzania Binding

Personal Data Protection Act s. 36 — rights in relation to automated decision making, with a duty to notify and reconsider

Binds Data controllers and data processors within the scope of s. 22(1): any collection and processing of personal data performed wholly or partly by manual or automated means; processing carried out in the performance of the activities of a controller domiciled in the United Republic or in a territory where its laws apply by virtue of international public law; and processing by a controller or processor not domiciled in the United Republic where the processing is in the United Republic and is not for mere transit of personal data through Tanzania to another country. Section 2 applies the Act to Mainland Tanzania as well as to Tanzania Zanzibar, save that in Zanzibar it does not apply to non-union matters, so a purely Zanzibari matter falls outside it. Registration with the Personal Data Protection Commission under ss. 14 to 16 is a precondition of acting as a controller or processor, and s. 21 deems public institutions that collect and process personal data registered from commencement. The s. 36(2) notify-and-reconsider duty binds any controller that takes a solely-automated decision significantly affecting a data subject, irrespective of size. Impact tier: all entities.. Section 36 of the Personal Data Protection Act, 2022 (Act No. 11 of 2022, Chapter 44) carries Tanzania's operative automated-decision rule, in Part VI (rights of data subjects). Subsection (1) lets a data subject, through the procedures prescribed in the regulations, require the data controller to ensure that any decision taken by or on behalf of the controller which significantly affects the data subject shall not be based solely on processing by automatic means. Subsection (2) operates without prejudice to that request and bites of its own force: where a decision which significantly affects a data subject is based solely on automated processing, the controller shall as soon as practicable notify the data subject that the decision was taken on that basis, and the data subject may require the controller to reconsider the decision. Subsection (3) disapplies the section where the decision is necessary for entering into or performance of a contract between the data subject and a data controller, is authorised by any written law, or is based on the data subject's explicit consent. Section 37 separately entitles a data subject who suffers damage by reason of any contravention of the Act to compensation from the controller or processor.

Commencement was deferred to a ministerial instrument and that instrument is identified on the face of the published Act: the Chapter 44 text as republished in the Special Gazette prints “[1st May, 2023]” together with “[GN. NO. 326 of 2023]” immediately above Part I, so Government Notice No. 326 of 2023 appointed 1 May 2023 as the date on which the Act, including s. 36, came into operation. The Act itself is Act No. 11 of 2022; the text relied on here is the Chapter 44 republication issued as Government Notice No. 395B in Special Supplement No. 21 to the Special Gazette of the United Republic of Tanzania No. 15 Vol. 104 of 13 June 2023, printed by the Government Printer, Dodoma. Section 36(1) is not self-executing — the data subject's requirement runs “through the procedures prescribed in the regulations”, which are the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 — but s. 36(2) is, because it applies “without prejudice to subsection (1)” and imposes the notification duty directly on the controller. The copy of those 2023 Regulations published by the Personal Data Protection Commission is a scanned image with no text layer, so the prescribed procedure could not be read and no claim about its content is made here; the entry rests on the statute. Coverage symmetry against the four African rows already tracked: s. 36 is drawn from the same UK Data Protection Act 1998 s. 12 lineage as gh-dpa-s41 rather than from GDPR art. 22, and the two are the closest pair on the tracker — both pair a request-based right with an automatic notify-and-reconsider duty. The difference is the clock: Ghana fixes hard twenty-one-day periods in both directions, while Tanzania says only “as soon as practicable” for the notification and sets no period at all for the controller's response, so Ghana remains the only African row with hard deadlines. Tanzania's carve-out in s. 36(3) is narrower than Ghana's s. 41(4) because it does not exclude pre-contractual consideration, and unlike ke-dpa-s35 it gives no right to demand a fresh non-automated decision — only reconsideration of the existing one. Text read in the copy of the Act published by the Personal Data Protection Commission, the supervisory authority established by s. 6 of the Act.

Stated maximum penalty — Enforcement is administrative and runs through Part VII. The Commission investigates complaints under ss. 39 to 42, may serve a notice of enforcement under s. 45 and a notice of penalty under s. 46, and s. 46 lists the factors bearing on the amount, including the nature, gravity and duration of the failure, compliance with previous enforcement or penalty notices, adherence to codes of ethics, and financial benefits gained or losses suffered. Section 47 caps the amount: the maximum penalty that may be imposed by the Commission in a penalty notice in relation to a contravention of the provisions of the Act is one hundred million Tanzanian shillings. Section 48 allows the Commission to review its own decision and s. 49 gives a person aggrieved by the administrative action, including directions in an enforcement notice or a penalty imposed, a right of appeal. Section 37 gives the data subject a separate entitlement to compensation from the controller or processor for damage suffered by reason of any contravention of the Act, and s. 50 governs payment of that compensation. The criminal offences in ss. 60 to 62 address unlawful disclosure and unlawful destruction, deletion, concealment or alteration of personal data and do not attach to s. 36.

In force · 1 May 2023 checked 22 Aug 2026 Personal Data Protection Act s. 36 (Act No. 11 of 2022) ↗ high confidence

Uganda 1

Uganda Binding

Data Protection and Privacy Act s. 27 — notice-based right against solely-automated decisions, an automatic duty to notify and reconsider on a twenty-one-day clock, and a fourteen-day route to the regulator

Binds Data controllers within the scope of s. 1, which applies the Act to a person, institution or public body collecting, processing, holding or using personal data within Uganda, and to a person outside Uganda who collects, processes, holds or uses personal data relating to Ugandan citizens. “Authority” in s. 27(5) is the National Information Technology Authority — Uganda (NITA-U); the Personal Data Protection Office established by s. 4 sits within it and is charged by s. 5 with overseeing implementation and enforcement of the Act. Registration is a standing precondition of processing: s. 29 requires the Authority to register every person, institution or public body collecting or processing personal data in the data protection register. The s. 27 duties bind any controller that takes a solely-automated decision significantly affecting a data subject, irrespective of size or sector. Impact tier: all entities.. Section 27 of the Data Protection and Privacy Act, 2019 (Act 9 of 2019), headed “Rights in relation to automated decision-taking”, is Uganda's operative automated-decision rule and sits in the Part V block of data-subject rights at ss. 23 to 28. Subsection (1) lets a data subject, by notice in writing to a data controller, require the controller to ensure that any decision taken by or on behalf of the controller which significantly affects that data subject is not based solely on the processing by automatic means of personal data in respect of that data subject. Subsection (2) operates without prejudice to subsection (1) and therefore bites even where no such notice has been served: where a decision which significantly affects a data subject is based solely on automated processing, (a) the data controller shall as soon as reasonably practicable notify the data subject that the decision was taken on that basis, and (b) the data subject is entitled, by notice in writing, to require the controller to reconsider the decision within twenty-one days after receipt of that notification. Subsection (3) then gives the controller twenty-one days after receipt of that notice to inform the data subject in writing of the steps the controller has taken in compliance with it. Subsection (4) disapplies the section entirely where the decision is made in the course of considering whether to enter into a contract with the data subject, with a view to entering into the contract, in the course of the performance of the contract, or for a purpose authorised or required by or under any law. Subsection (5) adds an escalation the Ghanaian and Tanzanian analogues do not have: where the data subject is not satisfied with the controller's subsection (3) response, the data subject shall complain in writing to the Authority within fourteen days.

The Act carries no commencement clause of its own, so the default rule supplies the date: s. 14(1) of the Acts of Parliament Act (Chapter 2, Act 16 of 2000) provides that the commencement of an Act shall be such date as is provided in or under the Act, or where no date is provided, the date of its publication as notified in the Gazette, and s. 14(2) deems every Act to come into force at the first moment of the day of commencement. The Act was published in Uganda Gazette no. 21 of 3 May 2019, so s. 27 has been in force since 3 May 2019. The enacted text relied on here is the copy of Act 9 of 2019 published by the Ministry of ICT and National Guidance, which reproduces the printed impression certified by the Clerk to Parliament as a true copy of the bill on 04/02/2019 and the President's assent page dated 25/2/2019; the Clerk's authentication and assent pages were read directly, as was s. 27 in full. Section 39 lets the Minister, after consultation with the Authority, make regulations by statutory instrument; no statutory instrument text could be retrieved from an official host this run, so nothing is claimed here about subsidiary rules, and the entry rests on the statute alone. Coverage symmetry against the seven African rows already tracked: s. 27 belongs to the UK Data Protection Act 1998 s. 12 lineage rather than to GDPR art. 22, and it is a near-verbatim sibling of Ghana's gh-dpa-s41 and a closer sibling still of Tanzania's tz-pdpa-s36 — all three pair a notice-based right with an automatic notify-and-reconsider duty. Uganda now joins Ghana as the only African rows with hard deadlines, and it is the stricter of the two on the data subject's own side: Ghana's twenty-one-day clocks run to reconsideration and to the controller's answer, and Uganda replicates both in s. 27(2)(b) and s. 27(3), but Uganda alone then fixes a further fourteen-day period in s. 27(5) for complaining to the Authority if the answer does not satisfy. Its carve-out in s. 27(4) is as wide as Ghana's — pre-contractual consideration, contract formation and contract performance are all excluded outright, with no compensating safeguards required — and therefore wider than the GDPR-shaped exceptions in ke-dpa-s35, ng-ndpa-s37 and rw-law058-2021-art21. Unlike Kenya, it gives no right to demand a fresh non-automated decision, only reconsideration of the existing one. Two drafting wrinkles in the gazetted text: the printed s. 27(3) duplicates a verb, reading “the steps that the data controller has taken to take …”, and s. 27(5) refers to “sub clause (3)” rather than subsection (3).

Stated maximum penalty — Section 27 non-compliance is not itself an offence: Part VIII creates only three offences — unlawfully obtaining or disclosing personal data (s. 35, fine not exceeding two hundred and forty currency points or imprisonment for ten years or both), unlawfully destroying, deleting, concealing or altering personal data (s. 36, fine not less than two hundred and forty currency points or imprisonment not exceeding ten years or both) and sale of personal data (s. 37, fine not exceeding two hundred and forty five currency points or imprisonment not exceeding ten years or both) — and none of them reaches a solely-automated decision. The Schedule values one currency point at twenty thousand shillings, so the s. 35 to s. 37 ceilings are UGX 4,800,000, UGX 4,800,000 and UGX 4,900,000. Where an offence under ss. 35, 36 or 37 is committed by a corporation, s. 38(1) makes the corporation and every officer who knowingly and willfully authorised or permitted the contravention liable, and s. 38(2) lets the convicting court additionally order the corporation to pay a fine not exceeding two percent of its annual gross turnover. The route to a sanction for s. 27 is administrative and runs through the regulator: s. 27(5) requires the dissatisfied data subject to complain in writing to the Authority within fourteen days, s. 31 lets any person who believes a data collector, processor or controller is infringing their rights or violating the Act complain to the Authority in the prescribed manner, and s. 32 obliges the Authority to investigate every complaint and lets it direct the party to remedy the breach or take such action as the Authority specifies to restore the rights of the data subject. The Act attaches no fine to disobeying such a direction.

In force · 3 May 2019 checked 17 Aug 2026 Data Protection and Privacy Act s. 27 (Act 9 of 2019) ↗ high confidence

United Kingdom 2

UK Binding

UK DUAA 2025 — Automated Decision-Making reform (Arts. 22A–22D)

Binds UK controllers making significant automated decisions with legal or similarly significant effects on data subjects. Replaces UK GDPR Art. 22 default prohibition on significant automated decisions. Controllers may now make such decisions using any lawful basis (incl. legitimate interests), but must: notify data subjects pre-decision, allow representations, provide meaningful human review, and enable contest rights. Special category data remains more restricted.

In force February 5, 2026 per SI 2026/82 (Commencement No. 6). Replaces and substantively restructures UK GDPR Art. 22: removes default prohibition; adds mandatory pre-decision notification, representations, human review, and contest rights. Secondary legislation: UK GDPR (Amendment) Regulations 2026.

Stated maximum penalty — UK GDPR penalties (up to £17.5M or 4% global annual turnover — whichever higher); ICO enforcement

In force · 5 Feb 2026 checked 21 Aug 2026 DUAA 2025, ss.22A–22D (UK GDPR replacement for Art. 22) ↗ high confidence
UK Binding

UK SI 2026/425 — mandatory ICO code of practice on AI and automated decision-making

Binds Information Commissioner (duty to prepare the code); indirectly all UK controllers and processors developing or using AI or making automated decisions under the UK GDPR and DPA 2018 (except Part 4, intelligence services). Requires the Information Commissioner to prepare a statutory code of practice on good practice in processing personal data for (a) developing and using AI and (b) automated decision-making under Arts. 22C(1) UK GDPR / s.50C(1) DPA 2018. The code must include guidance on children's personal data. Once issued, the code is admissible in evidence and regulators and courts must take it into account, so it will set the compliance benchmark for UK controllers developing or deploying AI.

Made 16 April 2026, laid before Parliament 21 April 2026, in force 12 May 2026 (reg. 1(2): 21 days after laying). Powers: DPA 2018 ss.124A(1)-(2) and 124B(11), inserted by Data (Use and Access) Act 2025 ss.92(2) and 93. Reg. 3 modifies the s.124B panel requirement so the panel must not consider or report on any aspect of the code relating to national security. The code itself has NOT yet been issued or consulted on — no publication date is set in the instrument, so the code's own commencement is date TBD; the ICO lists 'Code of Practice on AI and Automated Decision Making' among its current AI work areas. The Explanatory Note states no significant sector impact from the instrument itself; the impact falls when the ICO produces the code (for which the ICO must produce its own impact assessment). Extends to England and Wales, Scotland and Northern Ireland. Companion to uk-duaa-adm.

Stated maximum penalty — No penalty in the instrument itself; the resulting code is enforced through UK GDPR/DPA 2018 powers (up to £17.5M or 4% of global annual turnover, whichever is higher)

In force · 12 May 2026 checked 21 Aug 2026 SI 2026/425 (DPA 2018 AI & ADM Code of Practice Regs) ↗ high confidence

United States 28

US · NY Binding

AI Companion Models Law (GBL Art. 47)

Binds Operators of AI companion models serving New York users (excludes customer-service / internal-productivity-only systems). AI-identity disclosure at session start + every 3h and suicide/self-harm crisis referral (988) for AI companion operators; NY AG enforces.

Stated maximum penalty — Up to $15,000/day per violation (AG only; no private right of action)

In force · 5 Nov 2025 checked 13 Aug 2026 NY GBL Art. 47 ↗ high confidence
US · CA Binding

California companion-chatbot safeguards (SB 243)

Binds Operators of companion-chatbot platforms available in California. AI-status disclosure + self-harm protocols.

Stated maximum penalty — Private right of action

In force · 1 Jan 2026 checked 13 Aug 2026 SB 243 ↗ high confidence
US · CA Binding

AB 2013 — GenAI training-data transparency

Binds Developers of generative AI systems made available to Californians. Public dataset-summary disclosure for generative AI offered to Californians.

Stated maximum penalty — Civil enforcement

In force · 1 Jan 2026 checked 13 Aug 2026 AB 2013 ↗ high confidence
US · TN Binding

Tennessee AI regulation study mandate (SB 1700 / PC 1082, "CHAT Act")

Binds Tennessee Advisory Commission on Intergovernmental Relations (TACIR) — study mandate only; imposes no compliance duties on AI operators. As enacted, SB 1700 does not impose chatbot safety requirements on operators. Senate amendments stripped the original companion-chatbot restrictions and replaced them with a directive for TACIR to study potential AI/chatbot regulation (federal law, other states' approaches, constitutional issues, minor/mental-health safeguards, economic impact); no report deadline is specified.

Effective 2026-05-22, the date carried in the "Effective date(s)" field of the Tennessee General Assembly bill-status record; Section 4 of Public Chapter 1082 reads "This act takes effect upon becoming a law, the public welfare requiring it" (publications.tnsosfiles.com/acts/114/pub/pc1082.pdf), so there is no deferred application. The same record lists the governor's signature action on 2026-05-27; the enrolled chapter's approval stamp is a handwritten scan and is not machine-readable, so the 05/22 effective date is taken from the legislature's own field rather than reconstructed from the signature. Bill was substantially amended (Senate amendments adopted 2026-04-14) before passage, removing the original chatbot-safety restrictions.

Stated maximum penalty — None — study mandate only; no compliance obligation imposed on AI operators

In force · 22 May 2026 checked 13 Aug 2026 SB 1700 / PC 1082 ↗ high confidence
US · NY Binding

New York Synthetic Performer Disclosure Law (S.8420-A / Ch. 617)

Binds Persons, firms, or corporations engaged in commerce who produce or create advertisements using synthetic performers with actual knowledge of their use in New York. Requires conspicuous disclosure when AI-generated synthetic performers (digitally created human assets not recognizable as any identifiable real person) appear in advertisements in any medium — newspapers, magazines, radio, TV, streaming, billboards, and transit. Advertisers must have actual knowledge of synthetic performer use. Exempts expressive works, audio-only ads, and language-translation uses.

Stated maximum penalty — $1,000 first violation; $5,000 subsequent violations (civil penalties)

In force · 9 Jun 2026 checked 13 Aug 2026 S.8420-A / Ch. 617 (2025) ↗ high confidence
US · WA Binding

Washington Prior Authorization AI Transparency Act (SB 5395)

Binds Private health carriers and public employee health plans using AI in prior authorization in Washington. AI cannot be sole basis for denying health care services; human clinical review required for AI-generated denials.

Annual reporting to OIC on AI-generated prior auth statistics required.

Stated maximum penalty — OIC enforcement (civil penalties; license actions)

In force · 11 Jun 2026 checked 13 Aug 2026 SB 5395 ↗ high confidence
US · RI Binding

Rhode Island Healthcare AI Documentation Act (H 7538)

Binds Healthcare providers (physicians, PAs, dentists, RNs, LPNs, APRNs, nursing assistants, other DOH-licensed professionals) and healthcare facilities (§ 23-17-2) in Rhode Island. R.I. Gen. Laws ch. 23-106. Healthcare providers and healthcare facilities that employ AI to document in-person or telehealth visits must notify patients of that use and must review the AI-generated documentation for accuracy after the visit (§ 23-106-3).

Enacted as Substitute A (LC004720/SUB A) creating R.I. Gen. Laws ch. 23-106; signed 22 June 2026; effective upon passage. Verified against the enacted Sub A text 2026-08-10.

Stated maximum penalty — RI healthcare licensing enforcement

In force · 22 Jun 2026 checked 13 Aug 2026 H 7538 ↗ high confidence
US · IA Binding

Iowa Conversational AI Safety Act (SF 2417)

Binds Operators of conversational AI services serving Iowa consumers. Disclosure and safeguard obligations for conversational AI operators serving Iowa users; compliance applicable 2027-07-01.

Law in force 2026-07-01; compliance obligations applicable from July 1, 2027.

Stated maximum penalty — Civil enforcement by Iowa AG (amount TBD)

In force · 1 Jul 2026 checked 13 Aug 2026 SF 2417 ↗ high confidence
US · HI Binding

Hawaii AI Disclosure and Safety Act (SB 3001 / Act 248)

Binds Operators of conversational AI services accessible in Hawaii. AI-identity disclosure, minor safeguards, and suicide-prevention protocols for conversational AI operators.

Annual crisis-intervention referral reports to Behavioral Health Administration beginning 2028-01-01.

Stated maximum penalty — $1,000/violation up to $1,000,000/operator

In force · 14 Jul 2026 checked 13 Aug 2026 SB 3001 / Act 248 ↗ high confidence
US · CA Binding

California AI Transparency Act (SB 942)

Binds Covered GenAI providers with >1M monthly users accessible in California. AI-detection tool + content provenance for >1M-user providers.

Operative 2 August 2026 under Bus. & Prof. Code s 22757.6 as amended by AB 853, which pushed the original 1 January 2026 start date back. Covers the s 22757.3 covered-provider duties: a free public AI-detection tool, latent disclosures in AI-generated image, video and audio output, and an optional manifest disclosure. A covered provider is one whose GenAI system has over 1,000,000 monthly visitors or users and is publicly accessible within California (s 22757.1(d)). AB 853's later tranches are tracked as us-ca-ab853 (1 January 2027) and us-ca-ab853-capture-device (1 January 2028).

Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)

In force · 2 Aug 2026 checked 13 Aug 2026 SB 942 (amd. AB 853) ↗ high confidence
US · CO Binding

Colorado Psychotherapy AI Restrictions (HB 26-1195)

Binds Regulated psychotherapy professionals in Colorado using AI; any entity misrepresenting AI as professional-equivalent. AI cannot deliver psychotherapy without licensed professional's real-time involvement; disclosure and written consent required.

Signed 3 Jun 2026 by Gov. Polis; enacted without a safety clause, so the general post-session effective date applies. IN FORCE since 12 Aug 2026 — the Colorado General Assembly bill record (leg.colorado.gov/bills/hb26-1195) lists the session law as Chapter 358 with Effective Date 08/12/2026, re-confirmed on the day of entry into force. No amendments or delays. Unaffected by the federal court injunction pausing CO SB 26-189 (the broader Colorado AI Act). AG holds exclusive enforcement; $20,000 per violation; 60-day cure period.

Stated maximum penalty — Unfair trade practice (CO Consumer Protection Act; AG enforcement); $20,000 per violation

In force · 12 Aug 2026 checked 13 Aug 2026 HB 26-1195 ↗ high confidence
US · CT Binding

Connecticut PA 26-15 (SB 5) tranche 1 — subscription AI, frontier models, synthetic content, state agencies

Binds Subscription-based AI providers, frontier developers, generative AI providers with >1,000,000 monthly users publicly accessible for personal use, and CT state agencies. Subscription-based AI providers give consumer disclosures; frontier developers publish safety frameworks; large generative providers embed provenance data; state agencies gated on OPM/DAS AI policies.

Public Act No. 26-15, signed by the Governor 27 May 2026. This row carries the 1 Oct 2026 tranche: s 1 (subscription-based provider disclosures), s 2 (frontier developer duties), s 15 (covered provider provenance/detectability of synthetic digital content, >1,000,000 monthly users), s 38 (state agency AI use and procurement). The Act's later tranches are carried as separate rows: AI companions 1 Jan 2027 (us-ct-sb5-companion), automated employment-related decision technology 1 Oct 2027 (us-ct-sb5-aedt), covered-platform minors 1 Jan 2028 (us-ct-sb5-minors). Sections 17, 18, 31 (AI Academy, working group, higher-education alliance) took effect 1 Jul 2026 but create state-programme duties only, not private-sector obligations. Bill status page: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&bill_num=SB5&which_year=2026

Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)

Applies 1 Oct 2026 checked 22 Aug 2026 CT PA 26-15 (SB 5) ↗ high confidence
US · AL Binding

Alabama AI Health Insurance Transparency Act (SB 63)

Binds Health insurers using AI in coverage determinations in Alabama. AI may not be sole basis for coverage denial; health insurers must disclose AI use and file annual certification with Alabama DOI.

Annual certification to Alabama DOI required.

Stated maximum penalty — Alabama DOI disciplinary action (license revocation/suspension)

Applies 1 Oct 2026 checked 22 Aug 2026 SB 63 ↗ high confidence
US · CA Binding

California AI Transparency Act — AB 853 large online platform & GenAI hosting platform duties

Binds Large online platforms (public-facing social media, file-sharing, mass messaging or stand-alone search) exceeding 2,000,000 unique monthly users over the preceding 12 months; and GenAI hosting platforms offering model weights or source code for download. Large online platforms must detect, display and preserve content provenance data; GenAI hosting platforms may not offer models that omit AI disclosures.

AB 853 (approved by the Governor 13 October 2025) adds three tranches to the California AI Transparency Act. The covered-provider regime under Bus. & Prof. Code s 22757.3 became operative 2 August 2026 and is tracked separately as us-ca-sb942. This entry covers the second tranche: s 22757.3.1 (large online platform provenance detection, a provenance user interface, user inspection/download, and a bar on knowingly stripping provenance data or digital signatures) and s 22757.3.2 (GenAI hosting platforms may not knowingly make available a GenAI system that omits s 22757.3 disclosures). Both carry an express operative date of 1 January 2027 (s 22757.3.1(c), s 22757.3.2(b)). The capture-device manufacturer tranche starts 1 January 2028 and is tracked as us-ca-ab853-capture-device. Threshold correction 2026-08-12: the large online platform test is 2,000,000 unique monthly users (s 22757.1(h)(1)), not the 1,000,000 figure that governs covered providers; broadband internet access service and telecommunications service are excluded. Note a drafting inconsistency in the enacted text: s 22757.3.2 uses 'GenAI system hosting platform' while the defined term at s 22757.1(g) is 'GenAI hosting platform'.

Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)

Applies 1 Jan 2027 checked 22 Aug 2026 AB 853 (amds. SB 942) ↗ high confidence
US · UT Binding

Utah AI Prior Authorization Disclosure Act (SB 319)

Binds Health insurers operating in Utah for prior authorization processes. Insurers must disclose AI use in prior authorization reviews; adverse determinations must reflect independent medical judgment.

Stated maximum penalty — Disclosure to Utah Insurance Department required

Applies 1 Jan 2027 checked 20 Aug 2026 SB 319 ↗ high confidence
US · WA Binding

Washington AI Companion Chatbot Safety Act (HB 2225 / Ch.168)

Binds AI companion chatbot operators serving Washington users. Non-human disclosure, minor safeguards, and self-harm protocols for AI companion chatbot operators.

Disclosures every 3 hours (all users) or 1 hour (minor users).

Stated maximum penalty — Actual damages + injunctive relief + attorney fees; WA AG (Consumer Protection Act)

Applies 1 Jan 2027 checked 22 Aug 2026 HB 2225 / Ch.168 ↗ high confidence
US · OR Binding

Oregon AI Companion Act (SB 1546 / Ch.85)

Binds AI companion and chatbot platform operators serving Oregon users. AI disclosure, self-harm protocols, and minor protections; first chatbot law with private right of action and per-violation statutory damages.

Stated maximum penalty — Greater of actual damages or $1,000 per violation; private right of action; attorney fees

Applies 1 Jan 2027 checked 22 Aug 2026 SB 1546 / Ch.85 ↗ high confidence
US · CO Binding

Colorado Conversational AI Safety Act (HB 26-1263)

Binds Conversational AI operators serving Colorado users. Safety, disclosure, and minor protection obligations for conversational AI operators in Colorado.

Signed 2026-05-29; legal effective date 2026-08-12; compliance obligations from 2027-01-01.

Stated maximum penalty — CO AG enforcement

Applies 1 Jan 2027 checked 22 Aug 2026 HB 26-1263 ↗ high confidence
US · RI Binding

Rhode Island AI Chatbot Safety Act (S 2195)

Binds Chatbot and companion AI operators serving Rhode Island users. Chatbot/companion AI operators must include suicidal-ideation protocols and crisis referrals; annual reporting to AG from 2027-07-01.

Signed 2026-06-22 by Governor McKee; general effective date 2027-01-01. Annual reports to RI AG beginning July 1, 2027.

Stated maximum penalty — RI AG enforcement

Applies 1 Jan 2027 checked 22 Aug 2026 S 2195 ↗ high confidence
US · IL Binding

Illinois AI Teacher Evaluation Restrictions (SB 2909 / PA 104-0565)

Binds Public school evaluators and teachers subject to Illinois teacher evaluation requirements. Prohibits evaluators from using AI to assign numerical scores or qualitative ratings in teacher performance evaluations; prohibits teachers from using AI to generate evaluation evidence. AI may still assist with administrative tasks. Teachers must disclose AI tool name and purpose if used for support.

Signed 2026-07-10 by Governor Pritzker; effective 2027-01-01.

Stated maximum penalty — Administrative enforcement; no direct monetary penalty specified

Applies 1 Jan 2027 checked 20 Aug 2026 SB 2909 / PA 104-0565 ↗ high confidence
US · WA Binding

Washington AI Content Disclosure Act (HB 1170 / Ch.167)

Binds AI content creators and operators serving Washington users. Operators/creators must inform users when content is developed or modified through AI.

Signed 2026-03-24; codified as Chapter 167, Laws of 2026. Enforced exclusively by the WA Attorney General under the Consumer Protection Act (ch. 19.86 RCW).

Stated maximum penalty — Civil penalty up to $100,000 per covered provider (WA Consumer Protection Act, ch. 19.86 RCW; AG enforcement only)

Applies 1 Feb 2027 checked 22 Aug 2026 HB 1170 / Ch.167 ↗ high confidence
US · GA Binding

Georgia Conversational AI Safety Act (SB 540)

Binds Operators of conversational AI chatbot services accessible to the Georgia public. Age verification, parental controls, AI-identity disclosure, and crisis protocols for conversational AI chatbot operators.

Stated maximum penalty — Up to $10,000 per knowing violation (GA AG enforcement)

Applies 1 Jul 2027 checked 13 Aug 2026 SB 540 ↗ high confidence
US · ID Binding

Idaho Conversational AI Safety Act (SB 1297)

Binds Consumer-facing conversational AI service operators serving Idaho users (excludes B2B, internal, customer-service bots). AI identity disclosure, crisis referral protocols, and minor safeguards for consumer-facing conversational AI operators.

Modeled on Nebraska LB 525. Signed 2026-04-01.

Stated maximum penalty — Idaho AG enforcement (amount TBD)

Applies 1 Jul 2027 checked 13 Aug 2026 SB 1297 ↗ high confidence
US · NE Binding

Nebraska Conversational Artificial Intelligence Safety Act (LB 525)

Binds Conversational AI service operators serving Nebraska users. Operators of consumer-facing conversational AI services must disclose AI nature, apply enhanced safeguards for minors, avoid claiming to provide professional mental health care, and provide crisis intervention referrals.

Signed April 14, 2026; operative July 1, 2027 (sections 12–18).

Stated maximum penalty — $1,000 per violation; up to $500,000 per operator per enforcement action; Nebraska AG enforcement only

Applies 1 Jul 2027 checked 13 Aug 2026 LB 525 ↗ high confidence
US · CT Binding

Connecticut PA 26-15 (SB 5) tranche 3 — automated employment-related decision technology

Binds Developers and deployers of automated employment-related decision technology deployed in Connecticut on or after 1 Oct 2027. Developers and deployers have until 1 Oct 2027, when the duties attach to any automated employment-related decision technology deployed in Connecticut on or after that date.

Public Act No. 26-15 ss 7-12. Date nuance: the sections themselves are '(Effective October 1, 2026)', but the operative duties in ss 8, 9 and 10 each attach only to technology 'deployed in the state on or after October 1, 2027', so 1 Oct 2027 is the date on which the obligations bite. s 8 is the developer-to-deployer disclosure; ss 9-10 are the deployer notice duties; s 11 carries the trade-secret carve-out; s 12 makes violations of ss 8-11 unfair or deceptive trade practices enforced solely by the Attorney General.

Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)

Applies 1 Oct 2027 checked 12 Aug 2026 CT PA 26-15 (SB 5) ss 7-12 ↗ high confidence
US · CA Binding

California AI Transparency Act — AB 853 capture device latent disclosures

Binds Capture device manufacturers, for any capture device first produced for sale in California on or after 1 January 2028 (cameras, mobile phones with built-in cameras or microphones, voice recorders); no user threshold applies. Camera, phone and recorder makers must offer, and switch on by default, latent provenance disclosures in captured content.

Bus. & Prof. Code s 22757.3.3, added by AB 853 (approved 13 October 2025). A capture device manufacturer must (1) give the user the option to include a latent disclosure in content captured by the device and (2) embed latent disclosures by default, in each case only to the extent technically feasible and consistent with widely adopted specifications from an established standards-setting body. The duty attaches to devices first produced for sale in the state on or after 1 January 2028, and s 22757.3.3(c) sets the same operative date. Unlike the covered-provider (1,000,000 monthly users) and large online platform (2,000,000 unique monthly users) tranches, this one has no size threshold: s 22757.1(c)(1) defines a capture device manufacturer simply as a person who produces a capture device for sale in the state. Added 2026-08-12 to close a coverage gap; the 2028 date previously appeared in no entry.

Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)

Applies 1 Jan 2028 checked 13 Aug 2026 AB 853 (amds. SB 942) ↗ high confidence
US · CT Binding

Connecticut PA 26-15 (SB 5) tranche 4 — covered-platform restrictions for minors

Binds Covered operators of covered platforms serving Connecticut users who are under eighteen. Covered platform operators have until 1 Jan 2028 before personalised feed and related restrictions apply to users under 18.

Public Act No. 26-15 s 39, expressly '(Effective January 1, 2028)'. Bars a covered operator from serving a covered minor a personalised recommendation feed based on information associated with the user or the user's device unless one of the listed conditions is met, including commercially reasonable and technically feasible age determination or verifiable parental consent. s 39(g) deems violations of subsections (b)-(e) unfair or deceptive trade practices under Conn. Gen. Stat. s 42-110b(a).

Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)

Applies 1 Jan 2028 checked 12 Aug 2026 CT PA 26-15 (SB 5) s 39 ↗ high confidence

Uzbekistan 1

Uzbekistan Binding

Personal Data Law art. 24 — solely automated decisions

Binds Owners and operators of personal data (собственник и (или) оператор) processing personal data under Law ЗРУ-547. Right not to be subject to a decision based solely on automated processing, with three exits, plus duties to explain the decision, accept an objection and answer it within ten days.

Art. 24 of Law No. ЗРУ-547 of 2 July 2019 'On Personal Data'. Date is not derived: art. 36 of the Law states it enters into force on 1 October 2019. Art. 24 is ORIGINAL text — the 01.10.2019 redaction on lex.uz and the current 25.07.2026 redaction are word-for-word identical, so none of the five subsequent amendment rounds touched it. Structure is close to GDPR 22 and, unlike Russia's 152-FZ art. 16 (ru-152fz-art16), it DOES have a contract limb: a solely automated decision affecting the subject's rights and legitimate interests and producing legal consequences is barred unless (a) the subject consented in writing, including by electronic document, (b) the decision is taken in performance of a contract between owner and subject or to fulfil the conditions of a previously concluded contract, or (c) legislation provides for it. Part three then imposes three affirmative duties on the owner/operator — explain how the decision is taken and its possible legal consequences, give the subject the opportunity to object, and explain how the subject may defend their rights — and part four requires the objection to be considered and the outcome notified to the subject in WRITING WITHIN TEN DAYS, a third of Russia's thirty. What the article does not give: no right to disclosure of the logic, and no right to have the decision changed or re-taken by a human. On penalties, no KoAO article names art. 24; art. 46² part one reaches unlawful use of personal data generally (7 BRV for citizens, 50 BRV for officials), and since 21 Jan 2026 part two reaches unlawful AI processing coupled with dissemination (uz-koao-46-2-ai).

Stated maximum penalty — No article names art. 24; KoAO art. 46²(1) reaches unlawful processing generally (7 BRV citizens / 50 BRV officials)

In force · 1 Oct 2019 checked 21 Aug 2026 Law ЗРУ-547 art. 24 ↗ high confidence

Vietnam 2

Vietnam Comprehensive

AI-content labelling & interaction disclosure

Binds Providers / deployers of generative AI and user-facing AI systems. Machine-readable labels on AI media; disclose when users interact with AI; deceptive deepfakes banned.

Stated maximum penalty — Admin fines (decree-set)

In force · 1 Mar 2026 checked 14 Aug 2026 Law 134/2025/QH15 ↗ high confidence
Vietnam Comprehensive

Vietnam Decision 33 — 46 High-Risk AI Systems List

Binds Operators and providers of the 46 designated high-risk AI systems in Vietnam. Designates 46 specific AI systems as high-risk; new deployments require pre-deployment conformity assessment from Aug 15 2026.

In force from 15 August 2026. Day-of verification (15 Aug 2026): the Government legal-document portal record for Decision 33/2026/QD-TTg lists Ngay ban hanh (issued) 30-06-2026 and Ngay co hieu luc (effective) 15-08-2026. Existing systems have a transition period: 1 March 2027 (most sectors) or 1 September 2027 (healthcare, education, finance); new deployments of the 46 designated systems require pre-deployment conformity assessment from today. MoST (mst.gov.vn) published explainer content on the 6 covered sectors and both transition deadlines on 3 Jul 2026 (https://mst.gov.vn/46-he-thong-ai-duoc-xep-vao-nhom-rui-ro-cao-phai-quan-ly-nghiem-ngat-197260703152945179.htm), with a further notice on 8 Jul 2026 — contextual guidance, not a new binding regulation.

Stated maximum penalty — Enforcement under Vietnam AI Law 134/2025 / Decree 142

In force · 15 Aug 2026 checked 15 Aug 2026 Decision 33/2026/QD-TTg ↗ high confidence

South Africa 1

South Africa Binding

POPIA s. 71 — bar on decisions taken solely on automated processing that profiles the data subject

Binds Responsible parties as defined in s. 1, that is public or private bodies or any other person which alone or in conjunction with others determines the purpose of and means for processing personal information. Section 3(1) applies the Act to processing entered in a record by or for a responsible party by automated or non-automated means where the responsible party is domiciled in the Republic, or is not domiciled in the Republic but makes use of automated or non-automated means in the Republic other than merely to forward information through it. Data subjects include juristic persons, so the section reaches automated credit and supplier scoring of companies as well as of natural persons. Impact tier: all entities.. Section 71 of the Protection of Personal Information Act 4 of 2013 carries South Africa's operative automated-decision rule, in Chapter 8 (rights of data subjects regarding direct marketing by unsolicited electronic communications, directories and automated decision making). Subsection (1) provides that a data subject may not be subject to a decision which results in legal consequences for him, her or it, or which affects him, her or it to a substantial degree, which is based solely on the basis of the automated processing of personal information intended to provide a profile of such person, including his or her performance at work, or his, her or its creditworthiness, reliability, location, health, personal preferences or conduct. Subsection (2) disapplies that bar where the decision has been taken in connection with the conclusion or execution of a contract and either the data subject's request in terms of the contract has been met or appropriate measures have been taken to protect the data subject's legitimate interests, or where the decision is governed by a law or code of conduct in which appropriate measures are specified for protecting the legitimate interests of data subjects. Subsection (3) fixes what those appropriate measures must do: provide an opportunity for the data subject to make representations about the decision, and require the responsible party to provide the data subject with sufficient information about the underlying logic of the automated processing of the information relating to him or her to enable him or her to make those representations. The profiling limb is broader than the GDPR Art. 22 analogue in one respect — it names performance at work, creditworthiness, reliability, location, health, personal preferences and conduct on the face of the statute.

Commencement is fixed by proclamation, not by the Act: s. 115(1) provides that POPIA commences on a date determined by the President by proclamation in the Gazette, and s. 115(2) allows different dates for different provisions. Proclamation No. R. 21 of 2020, signed at Hyde Park on 17 June 2020 and published in Government Gazette No. 43461 (Regulation Gazette No. 11136) of 22 June 2020, determined 1 July 2020 as the date on which ss. 2 to 38, ss. 55 to 109, s. 111 and s. 114(1), (2) and (3) commence, and 30 June 2021 as the date for ss. 110 and 114(4). Section 71 falls inside the 55-to-109 block, so it has been in force since 1 July 2020. Section 114(1), which commenced on the same day, required all processing of personal information to be made to conform to the Act within one year, so that transitional window closed on 1 July 2021, the date the market treats as the compliance deadline. The Regulator's Chapter 10 enforcement powers (ss. 73 to 99) and the administrative-fine machinery in s. 109 also commenced on 1 July 2020. South Africa is the tracker's first African jurisdiction. Compared with the Kenyan analogue ke-dpa-s35, POPIA gives no express right to demand a fresh non-automated decision; its remedy is a right to make representations plus disclosure of the underlying logic, and only where the contract exception is relied on. Text read in the enacted Act as published in Government Gazette No. 37067 of 26 November 2013 on gov.za, and the commencement dates read in the proclamation as published by the Information Regulator, the statutory supervisory authority.

Stated maximum penalty — Enforcement runs through Chapter 10: a breach of s. 71 is interference with the protection of personal information under s. 73, which the Information Regulator may pursue by enforcement notice under s. 95. Failure to comply with an enforcement notice is an offence under s. 103(1), punishable under s. 107(a) by a fine or imprisonment for a period not exceeding 10 years, or both. Under s. 109(2)(c) the Regulator may instead serve an infringement notice specifying an administrative fine, which may not exceed R10 million. Section 99 preserves a separate civil action for damages by the data subject, or by the Regulator on the data subject's behalf, irrespective of intent or negligence.

In force · 1 Jul 2020 checked 16 Aug 2026 POPIA s. 71 (Act 4 of 2013) ↗ high confidence

Zambia 1

Zambia Binding

Data Protection Act 2021 s. 62 — the GDPR-shaped automated-decision bar that no offence backs

Binds Every data controller processing personal data in Zambia. Section 3(1) applies the Act «to the processing of personal data performed wholly or partly by automated means and to any processing otherwise than by electronic means», and s. 3(2) carves out only processing by an individual for personal use — there is no small-entity threshold, no turnover floor and no public/private split, so the bar reaches enterprise, SME and public body alike. Two structural features widen the practical reach well beyond the text of s. 62. First, s. 19(1) makes it an offence to control or process personal data at all without registering as a data controller or data processor, so the population subject to s. 62 is a registered and enumerated one. Second, s. 70(1) requires a data controller to process and store personal data on a server or data centre located in the Republic, with ministerial carve-outs under s. 70(2) and a hard localisation rule for sensitive personal data under s. 70(3) — which means an automated decision about a Zambian data subject is, as a matter of the same statute, expected to be computed on infrastructure inside Zambia. The hiring case is squarely in scope: the s. 2 definition of profiling names «performance at work» first among the aspects it covers, and an automated sift producing a hiring outcome is a decision that at least «similarly affects» the candidate. Credit and insurance scoring fall the same way. What is not in scope is a decision with a human materially in the loop — s. 62(1) catches only decisions «based solely on» automated processing, and the Act supplies no gloss on what degree of human review defeats that.. Section 62(1) of the Data Protection Act, 2021 (Act No. 3 of 2021) provides that «a data subject shall not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning that data subject or similarly affects that data subject». The drafting is GDPR art. 22 read through a Commonwealth pen: it is framed as a prohibition on the outcome rather than as a right the data subject must assert, and its three ways out at s. 62(2) are the familiar ones — (a) necessary for entering into, or performance of, a contract between the data subject and a data controller; (b) authorised by any written law; (c) based on the data subject's explicit consent. Where an exception is used, s. 62(3) requires the controller to implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, «including the right to obtain human intervention on the part of the data controller for purposes of enabling the data subject to express the data subject's point of view and contest the decision» — so Zambia carries the full human-intervention, point-of-view and contest triad that the Malabo Convention itself omits. Section 62(4) then adds a separate rule that has no GDPR counterpart in that position: automated data processing shall not be undertaken where the processing involves sensitive personal data unless the data subject has expressly consented, the processing is in the public interest, or it is permitted by any written law with suitable safeguards in place. «Profiling» is defined in s. 2 in GDPR terms — any form of automated processing consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, including analysis or prediction of performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. The explanation limb is reactive rather than proactive. Section 58(2)(d) gives a data subject who is already being processed the right to access «information about the basic logic involved in any automatic processing of data relating to the data in case of automated decision making» — but the s. 64 duty to inform at the point of direct collection runs (a) to (f) and carries no automated-decision item at all, so a Zambian controller must explain the logic when asked and need not volunteer that the decision is automated in the first place. Section 57 is the sleeper: a data controller or data processor «shall notify the Data Protection Commissioner of any third party agreement that allows the third party to trade on the profile of a data subject» — a registration duty on profile-trading that sits in Part VIII and is separate from the s. 62 bar.

In force since 1 April 2021, and the date comes from the commencement instrument rather than from the Act. Section 1 of the Act is a bare enabling clause — «This Act may be cited as the Data Protection Act, 2021, and shall come into operation on the date appointed by the Minister by statutory instrument» — so the assent date of 24 March 2021 that appears on the face of Act No. 3 of 2021 is not the operative date and must not be carried as one. The appointing instrument is Statutory Instrument No. 22 of 2021, the Data Protection Act (Commencement) Order, 2021, made under s. 1 by M. L. Kafwaya, Minister of Transport and Communication, signed at Lusaka on 31 March 2021 and reference MTC.64/9/35. Its para. 2 reads: «The Data Protection Act, 2021, shall come into operation on the date of publication of this Order». The Order was published in the Statutory Instruments of 1st April, 2021 — the date printed in the running head of the gazette pages carrying it — so the whole Act, s. 62 included, has been in force since 1 April 2021. There is no phased or sectioned commencement: SI 22 of 2021 appoints one date for the entire Act, unlike the Mauritian scheme next door, where s. 58(2) of the Data Protection Act 2017 expressly allows different dates for different sections. Zambia deposited its instrument of ratification of the Malabo Convention on 24 March 2021, three months after ratifying on 15 December 2020, so from 8 June 2023 the country is bound both by its own s. 62 and by art. 14(5) of the Convention. The two do not say the same thing, and where they diverge the national statute is the operative rule while the treaty runs behind it: s. 62(2) permits a solely automated decision on the contract, written-law and explicit-consent limbs, and art. 14(5) permits none of the three. Nothing in the Act repeals or qualifies the Convention, and Zambia has not legislated the Convention into domestic law by a separate instrument, so a controller relying on a s. 62(2) exception is in a position that is lawful under the statute and unresolved under the treaty. That tension is recorded rather than resolved here.

Stated maximum penalty — None attaches to s. 62 itself, and tracing that took reading the offence architecture rather than the summaries. The Act penalises by Part, not globally: s. 18(1) makes a body corporate that contravenes Part IV liable to a fine not exceeding one hundred million penalty units or two per cent of annual turnover of the preceding financial year, whichever is higher, and s. 55(1) does the same for Part VIII at two per cent of turnover or two million penalty units, whichever is higher, with s. 55(2) putting a natural person at up to one million penalty units or ten years. Section 62 sits in Part IX (Rights of the Data Subject), and Part IX has no equivalent clause — no section in the Act declares a contravention of Part IX an offence. Section 77, the general penalty, reaches only «a person who commits an offence under this Act for which a specified penalty is not provided», so it presupposes an offence and cannot manufacture one; the widely repeated figure of a fine plus up to three years' imprisonment for automated-decision breaches is s. 77 misapplied. What a data subject actually has is civil and administrative: s. 68, a complaint to the Data Protection Commissioner, whose functions under s. 4(2)(i) include receiving and investigating complaints; s. 69, an appeal to the High Court within thirty days of the Commissioner's decision; and s. 72, compensation from the controller or processor as determined by a court of competent jurisdiction for damage suffered from an infringement of a right under the Act. A profile-trading agreement not notified under s. 57 is likewise unpenalised on its own terms. Impact tier: all entities.

In force · 1 Apr 2021 checked 22 Aug 2026 Data Protection Act 2021 s. 62 ↗ high confidence

Questions & answers

From the data

When must a chatbot disclose that it is AI?

Several laws now require it. The EU AI Act’s Article 50, California’s SB 243 companion-chatbot rules, South Korea’s AI Basic Act and Vietnam’s Law on AI all require users to be told that they are dealing with an AI system rather than a human.

What is training-data transparency?

A duty to publish a summary of the data used to train a model. California’s AB 2013 requires generative-AI developers to post a dataset summary; the EU AI Act requires GPAI providers to publish a sufficiently detailed summary of training content.

Which AI transparency rules apply to automated decisions?

Quebec’s Law 25 gives individuals a right to be informed of, and to understand the main factors behind, an automated decision made about them using personal information; Colorado’s AI Act adds consumer notice and appeal rights for consequential automated decisions.

Which jurisdictions does AI Law Radar track for transparency & disclosure?

We currently track transparency & disclosure obligations across 57 jurisdictions: Angola, Australia, Burkina Faso, Burundi, Benin, Brazil, Canada, Democratic Republic of the Congo, Central African Republic, Republic of the Congo, Switzerland, Côte d'Ivoire, Chile, Cameroon, China, Cabo Verde, Germany, Algeria, European Union, Gabon, Ghana, Guinea, Equatorial Guinea, Indonesia, India, Japan, Kenya, Kyrgyzstan, South Korea, Kazakhstan, Morocco, Madagascar, Mali, Mauritania, Mauritius, Mexico, Mozambique, Namibia, Niger, Nigeria, Philippines, Russia, Rwanda, Singapore, Senegal, São Tomé e Príncipe, Togo, Thailand, Türkiye, Tanzania, Uganda, United Kingdom, United States, Uzbekistan, Vietnam, South Africa and Zambia. Each is dated and linked to its primary source on this page.