Law / Republic of the Congo

Law No. 29-2019, personal-data breach notification

Loi n° 29-2019, articles 74 à 78 (violation de données à caractère personnel)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the national commission of a personal-data breach without undue delay and, where possible, within 72 hours of becoming aware of it, unless the breach is not likely to create a risk to the rights and freedoms of natural persons.
  • Communicate the breach to the affected data subject without undue delay, in clear and simple terms, where it is likely to create a high risk to their rights and freedoms.
  • As a processor, notify the controller of any personal-data breach without undue delay after becoming aware of it.
  • Put in the notification to the commission the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned, the contact point, the likely consequences, and the measures taken or proposed to remedy it and mitigate its effects.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 74 requires the controller, in the case of a personal-data breach, to notify the national commission without undue delay and, where possible, within seventy-two hours of becoming aware of it, unless the breach is not likely to create a risk to the rights and freedoms of natural persons, and to accompany a notification made after that deadline with the reasons for the delay; the processor notifies the controller of any personal-data breach without undue delay after becoming aware of it.

Article 75 fixes what the notification to the commission must contain: the nature of the breach, including where possible the categories and approximate number of data subjects and of personal-data records concerned, the name and contact details of the data protection officer or another contact point, the likely consequences, and the measures taken or proposed to remedy the breach and mitigate its adverse effects, communicated in stages without further undue delay where they cannot all be given at once.

Article 76 requires the controller to document every personal-data breach, its effects and the remedial measures taken, so the commission can verify compliance. Article 77 requires the controller, where a personal-data breach is likely to create a high risk to the rights and freedoms of a natural person, to communicate the breach to the data subject without undue delay, in clear and simple terms, and to give at least the information Article 75 requires.

Article 78 excuses that communication where the controller had applied protective measures, such as encryption, rendering the affected data unintelligible, where later measures mean the high risk is no longer likely to materialise, or where it would take disproportionate effort, in which case a public communication of equal effect is made instead.

Article 101 requires the Law's publication in the Journal Officiel de la République du Congo and its execution as law of the State, and it was signed at Brazzaville on 10 October 2019. The Journal Officiel de la République du Congo published the Law in its No. 45-2019 issue of Thursday, 7 November 2019, and no provision of the Law defers its own entry into force to a later date.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • operates_essential_service

Read the law

Text of Law No. 29-2019
published in the Journal Officiel de la République du Congo No. 45-2019, reproduced by the Secrétariat Général du Gouvernement (sgg.cg)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app