Law / Republic of the Congo

Law No. 29-2019, cross-border transfer of personal data

Loi n° 29-2019, articles 23 à 25 (transfert transfrontalier de données à caractère personnel)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A cross border transfer rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Do not transfer personal data to a country outside the Republic of the Congo unless it offers a sufficient level of protection for the privacy and fundamental rights and freedoms of the persons the data concerns, and inform the national commission of the transfer in advance.
  • Rely on the article 24 derogation only for a one-off, non-massive transfer, and only where the data subject has expressly consented, or the transfer is necessary to protect that person's life, safeguard the public interest, allow the establishment, exercise or defence of a legal claim, or perform a contract between you and the data subject.
  • Where the destination country does not offer a sufficient level of protection and no article 24 derogation applies, obtain the national commission's authorization for the transfer by showing sufficient guarantees for privacy, fundamental rights and freedoms, and the exercise of the corresponding rights.

What it reaches

Obligation class

Transfer

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 23 bars a cross-border transfer of personal data unless the third country offers a sufficient level of protection for the privacy and fundamental rights and freedoms of the persons the transferred data does or may concern, measured against the security measures applied, the characteristics of the processing (including its purposes and duration), and the nature, origin and destination of the data, and requires the controller to inform the national commission of any such transfer in advance.

Article 24 lets a controller transfer personal data to a third country that does not meet the article 23 condition where the transfer is a one-off, non-massive transfer and the data subject has expressly consented to it, or the transfer is necessary to protect that person's life, safeguard the public interest, allow the establishment, exercise or defence of a legal claim, or perform a contract between the controller and the data subject.

Article 25 lets the national commission authorize a transfer or a set of transfers to a third country that does not offer a sufficient level of protection where the controller offers sufficient guarantees for the privacy, fundamental rights and freedoms of the data subjects and the exercise of their corresponding rights, on a duly reasoned request from the controller.

Article 101 requires the Law's publication in the Journal Officiel de la République du Congo and its execution as law of the State, and it was signed at Brazzaville on 10 October 2019. The Journal Officiel de la République du Congo published the Law in its No. 45-2019 issue of Thursday, 7 November 2019, and no provision of the Law defers its own entry into force to a later date.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

Text of Law No. 29-2019
published in the Journal Officiel de la République du Congo No. 45-2019, reproduced by the Secrétariat Général du Gouvernement (sgg.cg)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app