Law No. 29-2019 on the Protection of Personal Data
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A comprehensive regime rule binding public and private bodies.
As of 7 September 2026.
What it requires
- Obtain the data subject's consent before processing their personal data, unless a legal obligation, public-interest mission, vital-interest, or another statutory ground applies.
- File a prior declaration with the national commission before processing personal data, or obtain the commission's prior authorization where the processing involves genetic, health, offence or conviction, biometric, or other data the Law subjects to authorization.
- Do not process special categories of personal data, including biometric data, without a statutory ground.
- Notify the national commission of a personal-data breach within seventy-two hours where feasible, and communicate a high-risk breach to the affected person.
- Give the data subject access to, and let them rectify, port, or object to the processing of, their personal data on request.
- Do not transfer personal data outside the Republic of the Congo unless the receiving country offers a sufficient level of protection or a statutory derogation applies.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Article 98 provides that infringement of the Law's provisions is punished under the Penal Code and under Law No. 27-2020 on combating cybercrime; that cybercrime law's Chapter 6 (Articles 12 to 22) separately criminalises processing without the required formalities, undeclared or unauthorised processing, processing of special-category data, and unlawful data collection, each with imprisonment of one to five years and a fine of one million to ten million CFA francs.
Penalty structure
Article 93 empowers the commission to impose, in addition to a warning, compliance order, temporary suspension of up to three months, or a definitive withdrawal of authorization or ban on processing, an administrative fine of one million (1,000,000) to one hundred million (100,000,000) CFA francs, recovered under State debt-recovery law. Criminal penalties for the same conduct are set separately by the Penal Code and Law No. 27-2020 on combating cybercrime (see criminal_exposure_note).
- Rule
- Fixed only
- As of
- 7 September 2026
- Minimum
- 1,000,000
- Currency
- XAF
- Fixed cap
- 100,000,000
Who enforces it
Enforcement body
The national commission for the protection of personal data the Law establishes and empowers to receive declarations, grant authorizations, and impose sanctions
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Breach notice, Transfer, Licensing, Biometric
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 2 applies the Law to the collection, storage and any other use of personal data by a natural person, the State, decentralised administrative entities, or a legal person of public or private law, whether the controller is established in Congo or uses processing means located there.
Article 3 excludes only processing by a natural person for exclusively personal or domestic activities (where the data is not systematically communicated to third parties or disseminated) and processing concerning public security, defence, or the investigation of offences.
Article 5 conditions processing on the data subject's consent, unless the processing is necessary to comply with a legal obligation, perform a public-interest mission, protect vital interests, or another enumerated ground applies; a minor may consent alone from age sixteen, and jointly with a parent below that age (Article 15 area).
Articles 33 to 39 require most processing to be declared to the commission, with prior authorization required for processing of genetic data, health research data, offence or conviction data, an interconnection of files, a national identification number, or biometric data (Article 37).
Article 4 defines special categories of personal data as genetic data, data concerning minors, data on offences, convictions or security measures, and biometric data, and Article 14 separately restricts processing of data revealing ethnic or regional origin, political opinions, religious or philosophical beliefs, trade union membership, sex life, or health. Articles 46 to 61 give the data subject rights to information, access, portability, rectification and objection.
Articles 23 to 25 permit cross-border transfer only to a country the commission finds offers a sufficient level of protection, subject to derogations for consented, one-off, non-massive transfers or a commission-approved guarantee. Articles 74 to 78 require the controller to notify the commission of a personal-data breach within seventy-two hours where feasible, and to communicate a high-risk breach to the affected person.
Article 93 empowers the commission to warn, order compliance, suspend processing for up to three months, withdraw authorization, or impose an administrative fine of one million to one hundred million CFA francs, with recourse to the Supreme Court (Article 97). Article 98 provides that breach of the Law's provisions is separately punished under the Penal Code and under the law on combating cybercrime.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachhigh_risk_decisionsprocesses_biometrics
Read the law
Text of Law No. 29-2019
published in the Journal Officiel de la République du Congo No. 45-2019, reproduced by the Secrétariat Général du Gouvernement (sgg.cg)