Law / Democratic Republic of the Congo

Digital Code, Livre IV: Digital Services Provider Security Obligations

Code du numérique, Livre IV, Titre III, Chapitre I, Section 2, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 295 à 297)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 March 2023.

A security baseline statutes rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This binds a digital services provider (fournisseur des services numériques) generally, regardless of the sector in which it operates.
  • Implement systems qualified to detect events likely to affect the security of your own information systems; the qualification of the detection systems and of the service providers operating them is delivered by the Ministry responsible for digital affairs, the Agence Nationale de Cybersécurité having been consulted.
  • Submit your information system to controls the Agence Nationale de Cybersécurité conducts to verify its security level and its compliance with security rules, at your own cost.
  • Expect the Agence Nationale de Cybersécurité to be able to obtain your users' or system holders' identity, postal address and electronic address when their systems are vulnerable, threatened or attacked, so as to alert them.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

No provision reviewed here states a criminal or administrative penalty specific to a digital services provider's noncompliance with Articles 295 to 297.

Who enforces it

Enforcement body

L'Agence Nationale de Cybersécurité, the national authority in charge of cybersecurity and information-system security the Digital Code establishes, which conducts the Article 296 security controls and is consulted on qualifying the Article 295 detection systems.

Settledness

As of
19 September 2026
Open questions
Has the Ordonnance of the President of the Republic organizing the Agence Nationale de Cybersécurité, which Article 275 calls for, been issued, and does it specify further operational procedures for the Article 295 to 297 duties?

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 295 requires a digital services provider to implement systems qualified to detect events likely to affect the security of its own information systems. Article 296 requires a digital services provider to submit its information system to controls the Agence Nationale de Cybersécurité conducts to verify the system's security level and its compliance with security rules, at the provider's own cost.

Article 297 lets the Agence Nationale de Cybersécurité obtain a provider's users' or system holders' identity, postal address and electronic address when their systems are vulnerable, threatened or attacked, so as to alert them to the vulnerability or compromise. None of the three articles states a fixed administrative or criminal penalty for a digital services provider's noncompliance.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique
reproduced by the Autorité de Régulation de l'Électricité (are.gouv.cd)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app