Law / Democratic Republic of the Congo

Digital Code, Data Protection Authority and sanctions

Code du numérique Titre III, arts. 234, 249 à 261 et Titre IV, arts. 262 à 270 (autorité de protection des données, sanctions et voies de recours)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 March 2023.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect the Data Protection Authority to have exclusive competence over your compliance with Titre III, and to be able to delegate that control only to a body that has shown it independence, expertise, and a conflict-free structure.
  • Expect a data subject to be able to complain to the Data Protection Authority, and to have a right of judicial recourse if the Authority does not act on the complaint or tell them its outcome within sixty days.
  • Expect a data subject to be able to sue you or your processor before the tribunal de paix, and to be liable, jointly and severally with any other controller or processor participating in the same processing, for material or moral harm the processing caused in violation of Titre III.
  • As joint controllers, allocate your respective duties by transparent agreement, including how you will handle a data subject's rights, and make the essence of that agreement available to the data subject.
  • Do not obstruct the Data Protection Authority's on-site inspection, and expect a warning or a formal notice giving you no more than eight days to end a breach before a sanction follows.
  • Expect an administrative fine of eight million to two hundred million Congolese francs for a violation causing no serious harm, rising to five per cent of your annual turnover where the violation caused death or an attempted murder, or an order to cease processing where it endangered national security or safety or led to a mass crime or genocide, on top of the State's separate right to bring a criminal action.
  • Expect the Authority's sanctions to rest on a notified report, to have fifteen days to respond to it, and to be able to appeal a sanction before the competent administrative court; expect the Authority to make its sanctions public.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Article 257 reserves the State's separate right to bring a criminal action against the controller and claim damages, on top of the Authority's administrative sanctions, and article 263 requires the Authority to inform the Public Prosecutor, under the Penal Code, of violations of Titre III that constitute criminal offences. Titre III's own text does not fix a criminal penalty scale; it leaves the criminal tier to the Penal Code.

Penalty structure

Article 257 sets the base administrative fine at 8,000,000 to 200,000,000 Congolese francs where the violation caused no serious harm to the State or the persons concerned. The same article separately empowers the Data Protection Authority to impose a fine of 5% of the offender's annual turnover excluding tax for the preceding financial year where the violation caused death or an attempted murder, or an order to cease processing where the violation endangered national security or safety or led to a mass crime or genocide, and reserves the State's separate right to bring a criminal action and claim damages.

Rule
Fixed only
As of
19 September 2026
Minimum
8,000,000
Currency
CDF
Fixed cap
200,000,000

Who enforces it

Enforcement body

L'Autorité de Protection des Données (APD), the independent administrative authority Titre IV of the Digital Code creates to enforce Titre III

What it reaches

Obligation class

Governance, Reporting, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 234 gives the Data Protection Authority exclusive competence to control a controller's, its delegate's or a processor's compliance with Titre III and to impose the administrative sanctions that follow from it, a competence it may delegate to a third body only where that body shows the Authority its independence and expertise, sets up its own procedures for assessing compliance and handling complaints, and shows no conflict of interest.

Article 249 gives a data subject the right to lodge a complaint with the Authority, which must tell the complainant how the complaint is progressing and how it was resolved, including the possibility of judicial recourse, and article 250 gives the data subject a right of effective recourse before the competent administrative court where the Authority does not process the complaint or inform them of its progress or outcome within sixty days.

Article 251 gives a data subject a right of effective judicial recourse against a controller or its processor before the tribunal de paix of their district where they consider a Titre III right has been violated by processing of their data, and article 252 gives anyone who suffered material or moral harm from a Titre III violation the right to obtain compensation from the controller, holds a processor liable only for its own non-compliance with the duties Titre III places on processors or for acting outside or against the controller's lawful instructions, and holds several controllers or processors responsible for the same processing jointly and severally liable for the whole of the damage.

Article 253 requires joint controllers to allocate their respective duties by transparent agreement, including how they will handle the data subject's rights, lets them name a single point of contact, and requires the essence of that agreement to be made available to the data subject.

Article 255 lists what counts as a breach of Titre III, including unfair collection of personal data, disclosing personal data to an unauthorised third party, collecting sensitive or strategic data, offence-related data or a national identification number without meeting the legal conditions, collecting or using personal data in a way that seriously harms a person's fundamental rights or privacy, and obstructing the Authority's on-site inspection.

Article 256 lets the Authority issue a warning to a non-compliant controller or give formal notice to end the breach within a period it fixes that may not exceed eight days, and article 257 lets the Authority, where the controller does not comply with that formal notice and after adversarial procedure, impose a fine of eight million to two hundred million Congolese francs where the violation caused no serious harm to the State or the persons concerned, a fine of five per cent of the offender's annual turnover excluding tax for the last financial year where the violation caused death or an attempted murder, or an order to cease processing where the violation endangered national security or safety or led to a mass crime or genocide, while reserving the State's separate right to bring a criminal action and claim damages against the controller.

Article 258 lets the Authority attach an injunction to modify or delete the processing within a maximum of eight days to any sanction it imposes, article 259 requires a sanction to rest on a report the Authority notifies to the controller, who has fifteen days to submit written or oral observations and may be assisted or represented, and requires the Authority's decisions to be reasoned and notified, and article 260 gives a right of appeal against a sanction before the competent administrative court, while article 261 requires the Authority to make its sanctions public.

Article 262 creates the Data Protection Authority, an independent administrative authority with legal personality and administrative and financial autonomy, whose organisation and operation a decree of the Prime Minister fixes on the Minister for digital affairs' proposal.

Article 263 gives the Authority a broad list of powers and duties, including answering and issuing its own opinions and recommendations, informing data subjects and controllers of their rights and duties, authorising or refusing processing including of sensitive files, receiving declarations, authorisation requests, petitions and complaints, investigating on its own initiative or on a complaint, informing the judicial authority and the public prosecutor of criminal violations it learns of, ordering rectification, erasure or destruction of unlawfully processed data, authorising and monitoring cross-border transfers and the monetisation of data, and proposing legislative reform.

Articles 264 to 270 organise the Authority into a plenary assembly, a bureau and standing commissions, backed by a technical secretariat and provincial branches, fix the plenary assembly at nine members designated by the President of the Republic, the National Assembly, the judiciary, the bar, the national human rights commission and the digital sector's employers, on a five-year renewable term set by presidential ordinance and subject to parliamentary oversight, give its members immunity for opinions expressed in office while making them answerable before the Cour de Cassation, and bar them from holding government, parliamentary, business-leadership or shareholding roles in the digital, banking or telecommunications sectors.

Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • is_listed_company

Read the law

Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique
reproduced by the Autorité de Régulation de l'Électricité (are.gouv.cd)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app