Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, Autorité de Protection des Données Personnelles, sanctions et infractions pénales
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 20 April 2018.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Comply with a formal notice the Autorité issues within the period it sets, which may not exceed eight days, before it moves to a sanction.
- Expect the Autorité to impose a pecuniary sanction, an order to stop processing, a temporary or permanent withdrawal of authorization, or a lock on the data concerned where you do not comply with a formal notice, up to fifty million CFA francs for a first violation, rising to one hundred million CFA francs, or five percent of your last closed financial year's turnover excluding tax up to that same figure, for a violation repeated within five years.
- Expect a sanction the Autorité pronounces to be made public, and expect a report and the chance to respond in writing or in person before the Autorité rules on it.
- Expect a data subject to be able to complain to the Autorité about your processing, and expect them to have an effective judicial remedy against you or against the Autorité where it fails to act within ninety days.
- Expect a data subject who suffered material or moral harm from your violation of this Book to seek reparation from you or your processor, with joint liability between multiple controllers or processors who took part in the same processing.
- Do not obstruct the Autorité's investigations, and furnish it, its designated agents, or its members the information, documents, and premises access they request.
- Complete the prior formalities and security measures this Book requires, or expect criminal liability of up to ten years' imprisonment and a fine of up to fifty million CFA francs for the offenses this Book's criminal chapter lists, reduced to a fine alone for a negligent failure to complete prior formalities.
- Include an unsubscribe link in every unsolicited electronic message you send based on personal data you collected, and do not use another person's or entity's identity to deceive message recipients or website users into disclosing personal or confidential data.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
This Book's own Chapitre VII (Art. 460-461) creates the general criminal-infractions regime for a Livre V violation: obstructing the Authority, processing personal data without completing required prior formalities, processing sensitive or offense-related data outside the legal conditions, processing without required security measures, unlawfully collecting data, misappropriating or manipulating held personal data, an unauthorised cross-border transfer, coercing a data subject over their access or objection rights, or disregarding a data subject's rectification, objection, information, or access rights, each punished by six months' to ten years' imprisonment and a fine of 10,000,000 to 50,000,000 CFA francs, or either penalty alone (complicity and attempt draw the same penalties); a negligent failure to complete prior formalities alone draws a fine only, 5,000,000 to 50,000,000 CFA francs, with no imprisonment. Separately, Livre VI, Chapitre IV of the same Code (Art. 514 to 517) creates offenses specific to personal-data misuse: sending an unsolicited electronic message without an unsubscribe link (Art. 514, a fine of 500,000 to 2,000,000 CFA francs only, no imprisonment); using a person's or entity's identifying elements to deceive message recipients or website users into disclosing personal or confidential data (Art. 515, 5 years' imprisonment and a 25,000,000 CFA franc fine); using personal data or confidential information obtained this way to embezzle public or private funds (Art. 516, 10 years' imprisonment and a 100,000,000 CFA franc fine); and processing personal data without first informing the data subject individually of their access, rectification, or objection rights (Art. 517, punished under the administrative sanctions of Art. 454 rather than by imprisonment).
Penalty structure
Art. 455 sets a two-tier administrative pecuniary sanction: a first violation may not exceed 50,000,000 CFA francs; a violation repeated within five years of a prior sanction becoming final may not exceed 100,000,000 CFA francs, or, for a company, 5% of the prior closed fiscal year's turnover excluding tax, itself capped at 100,000,000 CFA francs. The Authority may instead or additionally order an injunction to cease processing, withdraw an authorization, or lock certain data (Art. 454). Separately, this Book's own Art. 460-461 criminal chapter carries a fine of 10,000,000 to 50,000,000 CFA francs alongside six months' to ten years' imprisonment for a Livre V violation (or a fine only, 5,000,000 to 50,000,000 CFA francs, for a negligent formalities failure alone), and Livre VI, Chapitre IV's data-misuse offenses (Art. 515 and 516) carry their own criminal fines up to 100,000,000 CFA francs alongside imprisonment; see criminal_exposure_note. No branch of any of these tracks exceeds the 100,000,000 CFA franc fixed_cap recorded here.
- Rule
- Fixed only
- As of
- 4 September 2026
- Currency
- XOF
- Fixed cap
- 100,000,000
Who enforces it
Enforcement body
Autorité de Protection des Données Personnelles (APDP), an independent national administrative authority created by the Code
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 462 creates the Autorité de Protection des Données Personnelles (APDP) to oversee this Book and privacy generally in Benin, and Article 463 makes it an independent administrative body with legal personality that receives no instruction from any administrative or political authority.
Article 448 lets a data subject complain to the Autorité about a processing they consider violates this Book, Article 449 gives them an effective judicial remedy against the Autorité if it does not act within ninety days, Article 450 gives them the same remedy against the controller or processor, and Article 451 lets anyone who suffered material or moral harm from a violation of this Book seek reparation from the controller or processor, with joint liability where more than one took part in the same processing.
Article 452 lets the Autorité warn a controller and give formal notice to end a violation within a period of no more than eight days.
Article 454 lets the Autorité, once a controller ignores that notice, impose a pecuniary sanction, an order to stop processing, a withdrawal of authorization, or a lock on the data concerned, and Article 455 caps that pecuniary sanction at fifty million CFA francs for a first violation, rising to one hundred million CFA francs, or five percent of the controller's last closed financial year turnover excluding tax up to that same figure, for a violation repeated within five years.
Article 459 lets the Autorité make a sanction public, and Articles 486 to 489 let it demand information, cooperation, and access to premises in the course of its investigations.
Article 460 makes obstructing the Autorité, processing without required prior formalities or security measures, unlawfully collecting or misappropriating personal data, an unauthorized cross border transfer, and disregarding a data subject's rectification, objection, information, or access rights into offenses, and Article 461 punishes them with six months to ten years' imprisonment and a fine of ten million to fifty million CFA francs, or either penalty alone, reduced to a fine only of five million to fifty million CFA francs for a negligent failure to complete prior formalities.
Elsewhere in the Code, Article 514 fines an unsolicited electronic message sent without an unsubscribe link, Article 515 punishes using a person's or entity's identity to deceive message recipients or website users into disclosing personal or confidential data with five years' imprisonment and a twenty five million CFA franc fine, and Article 516 punishes using personal data or confidential information obtained that way to embezzle public or private funds with ten years' imprisonment and a one hundred million CFA franc fine.
Loi n°2020-35 du 06 janvier 2021 later amended three articles of the Code, including Article 464 within this Titre's composition rules for the Autorité, and the amending law's own content beyond that is not established here.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsis_listed_company
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.