BlackTree Security · Infrastructure · Automation · AI

Burundi Has a Personal Data Protection Law. The Compliance Map Just Expanded.

Burundi promulgated Law No. 1/03 on the protection of personal data on 10 March 2026. The law closes a gap that the country’s National Assembly had described plainly: personal data was being collected across government, workplaces and private businesses without a dedicated general framework governing those operations.

The new law changes that position. It creates a national legal framework for the collection, processing and use of personal data and applies across public and private activity. It also introduces institutional oversight and specific penalties rather than leaving privacy harm to be addressed indirectly through other laws.

For organisations operating in Burundi, the compliance question is no longer whether a comprehensive privacy law will arrive. It is how existing systems and practices will be brought within the new framework.

The law fills a structural gap

During parliamentary consideration, the government explained that Burundi did not previously have a specific general regime governing personal-data processing. That absence mattered more as public services, employment systems, telecommunications, financial services and private platforms collected larger volumes of identifying information.

Law No. 1/03 establishes the missing baseline. It addresses automated and non-automated processing and reaches natural persons, the state, local authorities and legal entities. It also recognises that privacy protection must sit alongside legitimate public functions, with defined exceptions for areas such as public security, defence and criminal matters.

Accountability now needs evidence

A privacy framework changes the value of documentation. An organisation should be able to explain what personal data it holds, the purpose for which it is used, who receives it, how long it is retained and which safeguards protect it.

Those records are not administrative decoration. They allow an organisation to answer access and correction requests, control unnecessary processing, assess risk and respond when information is misused or exposed.

Organisations that begin with a copied foreign privacy notice will miss the larger task. The real programme sits in systems, contracts, retention schedules, access controls and the decisions that determine why data is processed.

The regulator will shape practical compliance

The parliamentary record states that the law creates a dedicated administrative authority for personal-data protection and provides specific penal provisions. That gives the framework an enforcement structure, but secondary measures and institutional implementation will determine many of the practical procedures organisations must follow.

Businesses should therefore monitor the authority’s establishment, implementing decrees, registration or authorisation procedures, guidance and reporting channels. Waiting for every procedural detail before beginning basic compliance work would create avoidable risk, but inventing requirements that the regulator has not issued would be equally unhelpful.

Security teams are part of the privacy programme

The law is aimed at preventing misuse of personal data and protecting private life. That objective cannot be delivered by legal documents alone. Access management, encryption, logging, backups, vulnerability management and incident response determine whether the organisation can actually protect the information entrusted to it.

Burundi already has cybercrime legislation and an electronic communications code. The new privacy law adds a different perspective: an incident is not only an attack on a system. It can also become harm to identifiable people and a failure of legal accountability.

What organisations should do now

  1. Inventory personal-data processing connected to Burundi, including paper records and systems operated by suppliers.
  2. Document purposes, data categories, recipients, retention periods and security measures.
  3. Review notices, consent practices and processes for handling individual rights.
  4. Update processor and service-provider contracts so that security, confidentiality and incident escalation are explicit.
  5. Map international access and transfers, including cloud hosting, remote support and centralised business systems.
  6. Track implementing decrees and official guidance from the competent authority.

A law is the beginning of the compliance cycle

Burundi’s new law is significant because it moves personal-data protection from scattered principles into a dedicated national regime. That expands rights for individuals and creates a clearer accountability problem for organisations.

The framework will become more detailed as institutions and procedures develop. The organisations in the strongest position will be those that already understand their data and can adapt documented controls as that detail arrives.

Official sources

This article provides general information and is not legal advice.

Continue the series: Africa Cyber & Digital Law Series index

Leave a Reply

Your email address will not be published. Required fields are marked *