Law / Democratic Republic of the Congo

Digital Code, Title III, personal data breach notification

Code du numérique, Titre III, art. 244 (violation de données à caractère personnel)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 March 2023.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Data Protection Authority and the affected data subject without delay of any breach affecting personal data, describing the nature of the breach, the categories and approximate number of affected people and records where possible, a contact point, the likely consequences, and the measures taken or proposed to address it.
  • As a processor, warn the controller without delay of any breach of security affecting personal data you process on the controller's behalf.
  • Communicate the breach to the affected data subject unless you had applied protective measures such as encryption that render the data unintelligible, you have since eliminated the high risk to their rights and freedoms, or it would require disproportionate effort, in which case make a public communication or an equally effective measure instead.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 244 requires the controller to notify the Data Protection Authority and the affected data subject, without delay, of any breach that has affected the data subject's personal data, and states no fixed number of hours or days for either notification. The same article requires a processor to warn the controller without delay of any breach of security affecting personal data it processes on the controller's behalf.

The notification must, at a minimum, describe the nature of the breach including, where possible, the categories and approximate number of affected data subjects and of personal data records concerned, give the name and contact details of the data protection officer or another contact point, describe the likely consequences, and describe the measures taken or proposed to address the breach.

Communicating the breach to the affected data subject is not required where the controller had applied protective measures, in particular ones that render the affected data unintelligible to an unauthorised person, such as encryption, where the controller has since taken measures that mean the high risk to the data subject's rights and freedoms is no longer likely to materialise, or where it would require disproportionate effort, in which case a public communication or an equally effective measure is made instead.

Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique
reproduced by the Autorité de Régulation de l'Électricité (are.gouv.cd)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app