Benin's comprehensive personal-data statute is Livre V (Protection des Données à Caractère Personnel) of Loi n°2017-20 portant Code du Numérique en République du Bénin, adopted by the National Assembly on 13 June 2017 and promulgated on 20 April 2018, repealing the country's first data-protection statute, Loi n°2009-09 du 24 mai 2009.
It applies to collection, processing, transmission, storage, and use of personal data by a natural person, the State, local governments, and other actors, carries a heightened regime for sensitive categories (racial or ethnic origin, political opinions, religion or beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health data, and sexual life or orientation data), and bars a legal-effect or significantly-affecting decision from resting solely on automated processing, including profiling, while giving the affected person a right to know and contest the underlying logic.
A controller must notify the country's data-protection authority and the affected person without delay of any security breach affecting personal data, and processing a child's personal data in connection with an information-society service offered directly to them requires the child's own consent from age sixteen or a parent's or guardian's consent below that age.
Cross-border transfer requires the Autorité de Protection des Données Personnelles (APDP), the independent administrative authority the law creates, to find that the destination country or organization assures a level of protection equivalent to Benin's own.
Enforcement combines administrative sanctions the APDP can pronounce directly, including a two-tier pecuniary fine capped at 50,000,000 CFA francs for a first violation and 100,000,000 CFA francs (or 5% of turnover, itself capped at that same figure) for a repeat violation within five years, with a private right of action letting a data subject seek damages for the harm suffered.
Livre V itself carries a dedicated criminal-infractions chapter (Art. 460-461) reaching unauthorised processing, processing without required formalities or security measures, unlawful collection, unauthorised cross-border transfer, and disregard of a data subject's rights, punishable by six months' to ten years' imprisonment and a fine of 10,000,000 to 50,000,000 CFA francs (a negligent formalities failure alone draws a fine only, 5,000,000 to 50,000,000 CFA francs), and Livre VI elsewhere in the Code adds standalone criminal offenses for using personal data to deceive people into disclosing further data or to embezzle funds.