Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, notification des ruptures de sécurité
Loi n°2017-20 du 20 avril 2018, Livre V, art. 427 (notification des ruptures de sécurité)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 20 April 2018.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Autorité de Protection des Données Personnelles (APDP) and the affected person without delay of any security breach that has affected their personal data.
- As a processor, warn the controller without delay of any security breach affecting personal data you process on the controller's behalf.
- Describe in the breach notification the nature of the breach, including where possible the categories and approximate number of affected data subjects and personal data records, your data protection contact point, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
- Skip notifying the affected person only where you had already applied protective measures such as encryption that make the data unintelligible, where later measures removed the high risk, or where it would take disproportionate effort and you make an equally effective public communication instead.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 427 requires a controller to notify the Autorité de Protection des Données Personnelles (APDP) and the affected person without delay of any security breach that has affected their personal data, and requires a processor to warn the controller without delay of any breach affecting data it processes on the controller's behalf.
The notification must describe the nature of the breach, including where possible the categories and approximate number of affected data subjects and personal data records, the contact point for more information, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
Article 427 excuses notice to the affected person only where the controller had already applied protective measures such as encryption that make the data unintelligible, where later measures removed the high risk, or where it would take disproportionate effort and the controller makes an equally effective public communication instead. The Book states no fixed number of hours or days for either notification, so both run only from becoming aware of the breach and without delay.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.