Law / Benin

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, données sensibles et mineurs

Loi n°2017-20 du 20 avril 2018, Livre V, arts. 394-404, 407 et 446 (données sensibles et mineurs)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 20 April 2018.

A sensitive categories rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Do not process sensitive personal data, including racial or ethnic origin, political opinions, religion or beliefs, trade union membership, genetic data, biometric data used to uniquely identify a person, health data, or data about a person's sex life or sexual orientation, unless a listed exception applies, such as the data subject's explicit consent or data the person has manifestly made public.
  • Verify that a minor is at least sixteen years old before processing their personal data in connection with an information society service offered directly to them, and otherwise obtain the consent of the holder of parental responsibility, making reasonable efforts to verify that consent given the technology available.
  • Obtain the Autorité's prior authorization before processing personal data covered by Article 394, personal data processed for journalism, research, artistic, or literary purposes under Article 397, a national identification number, or biometric data.
  • Do not process personal data about criminal convictions or related security measures except where the law specifically authorizes you to, such as a legal or regulatory obligation, or where it is necessary to manage your own contentious proceedings.
  • Designate the categories of staff with access to sensitive personal data, keep that list available to the Autorité, and bind them to confidentiality by a legal, statutory, or contractual obligation.
  • Where sensitive personal data is processed solely on the data subject's written consent, tell the data subject beforehand the reasons for the processing and the categories of staff who will access the data, in addition to the standard information notice.
  • Do not rely on an employee's or a dependent's consent to process their sensitive personal data where their relationship of dependency on you prevents them from freely refusing, unless the processing grants them a benefit.

What it reaches

Obligation class

Prohibition, Consent, Biometric, Age verification

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 394 prohibits processing personal data revealing racial or ethnic origin, political opinions, religion or beliefs, trade union membership, genetic data, biometric data used to uniquely identify a person, health data, or data about a person's sex life or sexual orientation, subject to listed exceptions such as the data subject's explicit consent or data the person has manifestly made public.

Article 395 confines processing of personal data about criminal convictions and related security measures to courts, public authorities, and other bodies the law specifically authorizes, and bars a complete register of criminal convictions outside the Autorité's control. Article 402 requires a controller processing the data Articles 394 and 395 cover to designate the categories of staff with access to it, keep that list available to the Autorité, and bind those staff to confidentiality.

Article 403 requires a controller relying solely on the data subject's written consent for that data to tell them beforehand the reasons for the processing and the categories of staff who will access it. Article 404 bars an employer or another party a data subject depends on from relying on that consent where the dependency prevents the data subject from freely refusing, unless the processing grants the data subject a benefit.

Article 407 requires the Autorité's prior authorization before processing the data Article 394 or Article 397 covers, a national identification number, or biometric data. Article 446 makes processing a minor's personal data in connection with an information society service offered directly to them lawful once the minor is at least sixteen years old, and otherwise requires the consent of the holder of parental responsibility, verified as far as available technology allows.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice
  • serves_minors
  • handles_health_records

Read the law

Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app