Law / Benin

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, transfert transfrontalier de données

Loi n°2017-20 du 20 avril 2018, Livre V, arts. 391-392 (transfert transfrontalier de données)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 20 April 2018.

A cross border transfer rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the Autorité de Protection des Données Personnelles (APDP)'s finding that the destination country or international organization assures a level of data protection equivalent to Benin's own before any transfer of personal data outside Benin.
  • Obtain the Autorité's prior authorization before any actual transfer of personal data to a third country or international organization, even where an equivalence finding exists.
  • Where the destination does not assure an adequate level of protection, transfer personal data only where the data subject has given express consent, the transfer is necessary to perform or negotiate a contract with or for the benefit of the data subject, the transfer serves an important public interest or a legal claim, protects vital interests, or comes from a public register open to consultation, or where the Council of Ministers has authorized it by decree on the Autorité's opinion after you show sufficient privacy safeguards.
  • Identify in your register of processing activities every transfer of personal data to a third country or international organization, including that country's or organization's identity and, where relied on, the documents evidencing appropriate safeguards.

What it reaches

Obligation class

Transfer, Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 391 permits transferring personal data to a third country or an international organization only once the Autorité has found that the destination assures a level of data protection equivalent to this Book, weighing the rule of law, the data protection rules, and the available remedies there, and requires the Autorité's prior authorization before any actual transfer takes place.

Article 392 lets a transfer proceed despite an inadequate destination where the data subject has expressly consented, the transfer is necessary to perform or negotiate a contract with or for the data subject, it serves an important public interest or a legal claim, it protects vital interests, it comes from a public register open to consultation, or the Council of Ministers has authorized it by decree on the Autorité's opinion after the controller shows sufficient privacy safeguards.

Article 435 requires a controller's register of processing activities to identify every transfer of personal data to a third country or international organization, including its identity and, where relied on, the documents evidencing appropriate safeguards.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app