Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 20 April 2018.
A comprehensive regime rule binding public and private bodies.
As of 4 September 2026.
What it requires
- Obtain a lawful basis, ordinarily the data subject's consent, before collecting, processing, transmitting, storing, or using their personal data, unless a specific legal exception applies.
- Do not process sensitive personal data, including racial or ethnic origin, political opinions, religion or beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health data, or sexual life or orientation data, unless a listed exception applies, such as the data subject's explicit consent or data the person has manifestly made public.
- Do not base a decision that produces legal effects for a person, or otherwise significantly affects them, solely on automated processing, including profiling, and disclose the logic behind such a decision when the person asks.
- Notify the Autorité de Protection des Données Personnelles (APDP) and the affected person without delay of any security breach affecting personal data.
- Verify that a minor is at least sixteen years old, or otherwise obtain the consent of the holder of parental responsibility, before processing a minor's personal data in connection with an information-society service offered directly to them.
- Obtain the APDP's finding that the destination assures an equivalent level of data protection before transferring personal data to a third country or an international organization.
- Respond to a data subject's request to access, rectify, or object to the processing of their personal data, and pass on any correction to any third party the data was disclosed to.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
This Book's own Chapitre V (Art. 460-461) creates the general criminal-infractions regime for a Livre V violation: obstructing the Authority, processing personal data without completing required prior formalities, processing sensitive or offense-related data outside the legal conditions, processing without required security measures, unlawfully collecting data, misappropriating or manipulating held personal data, an unauthorised cross-border transfer, coercing a data subject over their access or objection rights, or disregarding a data subject's rectification, objection, information, or access rights, each punished by six months' to ten years' imprisonment and a fine of 10,000,000 to 50,000,000 CFA francs, or either penalty alone (complicity and attempt draw the same penalties); a negligent failure to complete prior formalities alone draws a fine only, 5,000,000 to 50,000,000 CFA francs, with no imprisonment. Separately, Livre VI, Chapitre IV of the same Code (Art. 514 to 517) creates offenses specific to personal-data misuse: sending an unsolicited electronic message without an unsubscribe link (Art. 514, a fine of 500,000 to 2,000,000 CFA francs only, no imprisonment); using a person's or entity's identifying elements to deceive message recipients or website users into disclosing personal or confidential data (Art. 515, 5 years' imprisonment and a 25,000,000 CFA franc fine); using personal data or confidential information obtained this way to embezzle public or private funds (Art. 516, 10 years' imprisonment and a 100,000,000 CFA franc fine); and processing personal data without first informing the data subject individually of their access, rectification, or objection rights (Art. 517, punished under the administrative sanctions of Art. 454 rather than by imprisonment).
Penalty structure
Art. 455 sets a two-tier administrative pecuniary sanction: a first violation may not exceed 50,000,000 CFA francs; a violation repeated within five years of a prior sanction becoming final may not exceed 100,000,000 CFA francs, or, for a company, 5% of the prior closed fiscal year's turnover excluding tax, itself capped at 100,000,000 CFA francs. The Authority may instead or additionally order an injunction to cease processing, withdraw an authorization, or lock certain data (Art. 454). Separately, this Book's own Art. 460-461 criminal chapter carries a fine of 10,000,000 to 50,000,000 CFA francs alongside six months' to ten years' imprisonment for a Livre V violation (or a fine only, 5,000,000 to 50,000,000 CFA francs, for a negligent formalities failure alone), and Livre VI, Chapitre IV's data-misuse offenses (Art. 515 and 516) carry their own criminal fines up to 100,000,000 CFA francs alongside imprisonment; see criminal_exposure_note. No branch of any of these tracks exceeds the 100,000,000 CFA franc fixed_cap recorded here.
- Rule
- Fixed only
- As of
- 4 September 2026
- Currency
- XOF
- Fixed cap
- 100,000,000
Who enforces it
Enforcement body
Autorité de Protection des Données Personnelles (APDP), an independent national administrative authority created by the Code
What it reaches
Obligation class
Consent, Data subject rights, Biometric, Transfer, Breach notice, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Benin's comprehensive personal-data statute, deliberated and adopted by the National Assembly on 13 June 2017 and promulgated by the President on 20 April 2018 after two Constitutional Court conformity decisions, repealing the earlier Loi n°2009-09 du 24 mai 2009.
It applies to the collection, processing, transmission, storage, and use of personal data by a natural person, the State, local governments, and other actors, subject only to a narrow exclusion for purely personal or domestic processing not intended for communication or diffusion to third parties.
It prohibits processing sensitive categories of personal data (racial or ethnic origin, political opinions, religion or beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health data, and sexual life or orientation data) subject to listed exceptions, including the data subject's explicit consent or data the person has manifestly made public.
It bars a legal-effect or significantly-affecting decision from resting solely on automated processing, including profiling, and gives the affected person a right to know and contest the logic behind such a decision. A controller must notify Benin's data-protection authority and the affected person without delay of any security breach affecting personal data.
Processing a minor's personal data in connection with an information-society service offered directly to them is lawful with the minor's own consent from age sixteen, and otherwise requires the consent of the holder of parental responsibility. A cross-border transfer requires the Autorité de Protection des Données Personnelles (APDP) to find that the destination country or organization assures a level of data protection equivalent to Benin's own.
Enforcement combines administrative sanctions the APDP can pronounce directly (warning, formal notice, a pecuniary fine, an order to cease processing, withdrawal of an authorization, or locking of data) with a private right of action letting a data subject seek damages for material or moral harm.
Loi n°2020-35 du 06 janvier 2021 later amended three articles of the Code, including Art. 464 within this Book's Authority-organization chapter; none of the provisions described above falls among the amended articles, and the amending law's own content beyond that is not established here.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minors