Law /
Democratic Republic of the Congo
Digital Code, Livre IV: Digital Services Provider Security Obligations
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 13 March 2023.
A security baseline statutes rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This binds a digital services provider (fournisseur des services numériques) generally, regardless of the sector in which it operates.
- Implement systems qualified to detect events likely to affect the security of your own information systems; the qualification of the detection systems and of the service providers operating them is delivered by the Ministry responsible for digital affairs, the Agence Nationale de Cybersécurité having been consulted.
- Submit your information system to controls the Agence Nationale de Cybersécurité conducts to verify its security level and its compliance with security rules, at your own cost.
- Expect the Agence Nationale de Cybersécurité to be able to obtain your users' or system holders' identity, postal address and electronic address when their systems are vulnerable, threatened or attacked, so as to alert them.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
No provision reviewed here states a criminal or administrative penalty specific to a digital services provider's noncompliance with Articles 295 to 297.
Who enforces it
Enforcement body
L'Agence Nationale de Cybersécurité, the national authority in charge of cybersecurity and information-system security the Digital Code establishes, which conducts the Article 296 security controls and is consulted on qualifying the Article 295 detection systems.
Settledness
- As of
- 19 September 2026
- Open questions
- Has the Ordonnance of the President of the Republic organizing the Agence Nationale de Cybersécurité, which Article 275 calls for, been issued, and does it specify further operational procedures for the Article 295 to 297 duties?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 295 requires a digital services provider to implement systems qualified to detect events likely to affect the security of its own information systems. Article 296 requires a digital services provider to submit its information system to controls the Agence Nationale de Cybersécurité conducts to verify the system's security level and its compliance with security rules, at the provider's own cost.
Article 297 lets the Agence Nationale de Cybersécurité obtain a provider's users' or system holders' identity, postal address and electronic address when their systems are vulnerable, threatened or attacked, so as to alert them to the vulnerability or compromise. None of the three articles states a fixed administrative or criminal penalty for a digital services provider's noncompliance.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique
reproduced by the Autorité de Régulation de l'Électricité (are.gouv.cd)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.