Loi n° 2019-014, protection des données à caractère personnel
Loi n° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Before processing personal data, establish a lawful basis: the data subject's consent, or one of the law's specific grounds such as a legal obligation, a public-interest task, performing a contract, or protecting the data subject's vital interests.
- Obtain the Instance de Protection des Données à Caractère Personnel's prior authorization before processing genetic data, health-research data, a national identification number, biometric data, criminal-record data, or an interconnection of files; declare other processing to the Instance beforehand.
- Do not process data revealing racial or ethnic origin, political, religious or philosophical opinions, trade-union membership, sex life, health, or genetic data, unless a specific exception applies.
- Before transferring personal data outside Togo, give due consideration to the destination country's laws and safeguards, and inform the Instance beforehand.
- Do not send unsolicited direct marketing to a person who has not given prior consent to receive it.
- Keep personal data confidential and secure, and do not base a legal decision on a person's automated profile alone.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Chapter VII (arts. 79 to 93) states a distinct imprisonment and fine range for each offense: most carry one to five years' imprisonment and a fine of XOF 1,000,000 to XOF 10,000,000, rising to XOF 5,000,000 to XOF 25,000,000 for fraudulent collection, misuse of data beyond its declared purpose, and unlawful health-research processing, with a lower six-month to two-year, XOF 500,000 to XOF 2,000,000 range for negligent disclosure and for hindering the Instance's action.
Penalty structure
The Instance may impose an administrative fine of up to XOF 100,000,000 for breach of an authorization it granted, after a contradictory procedure (art. 71), separately from the criminal fines of XOF 100,000 to XOF 25,000,000 stated for the distinct offenses in arts. 79 to 93.
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- XOF
- Fixed cap
- 100,000,000
Who enforces it
Enforcement body
Instance de Protection des Données à Caractère Personnel (IPDCP)
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Security, Biometric
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 55 creates the Instance de Protection des Données à Caractère Personnel (IPDCP) as the independent supervisory authority. Article 1 regulates the collection, processing, transmission, storage, use and protection of personal data, and article 2 extends the law to any collection, processing, transmission, storage or use of personal data by a natural person, the State, a local authority, or a public or private legal person, whether the processing is automated or not.
Article 14 makes consent the general lawful basis for processing, subject to derogations for a legal obligation, a public-interest task, performing a contract, or protecting the data subject's vital interests, and articles 15 to 20 set the purpose-limitation, accuracy, transparency, confidentiality, security and sub-processor-selection principles.
Article 21 prohibits processing data revealing racial or ethnic origin, political, religious or philosophical opinions, trade-union membership, sex life, health or genetic data, subject to article 22's exceptions for data the person has manifestly made public, the person's written consent, safeguarding a vital interest, or a public-interest, judicial or historical, statistical or scientific purpose.
Article 8 requires the Instance's prior authorization before a treatment of genetic data or health research, criminal-record or security-measure data, an interconnection of files, a national identification number, or biometric data, while most other processing is only declared to the Instance under article 6.
Article 26 bars unsolicited direct marketing to a person who has not given prior consent, and article 27 bars founding a legal decision solely on an automated evaluation of a person's characteristics or personality.
Article 28 requires due consideration of the destination country's level of protection before a transfer of personal data outside Togo, and article 29 admits a one-off, non-massive transfer without that showing where the data subject has consented or the transfer serves one of a short list of vital, public-interest or contractual grounds.
Chapter VII (arts. 79 to 93) states distinct criminal offenses for processing without the required formalities, unauthorized use of a national identification number, fraudulent or unauthorized data collection, unlawful processing of sensitive or infraction-related data, breach of the right to object, misuse of data beyond its declared purpose, unauthorized disclosure, and hindering the Instance's action, each carrying its own imprisonment and fine range; the sources read state no separate data-breach notification duty to the Instance or to the persons affected.
When LexLint raises it
processes_biometricsautomated_outreachcrawls_web
Read the law
Journal Officiel de la République Togolaise
numéro spécial du 29 octobre 2019, cited through an Internet Archive capture of the Ministry of the Digital Economy's PDF (numerique.gouv.tg)