Comprehensive regime
Law No. 29-2019 on the Protection of Personal Data
Loi n° 29-2019 du 10 octobre 2019 portant protection des données à caractère personnel, Journal Officiel n° 45-2019 du jeudi 7 novembre 2019Text of Law No. 29-2019
In force. Binds public and private bodies.
What this law does
Article 2 applies the Law to the collection, storage and any other use of personal data by a natural person, the State, decentralised administrative entities, or a legal person of public or private law, whether the controller is established in Congo or uses processing means located there.
Article 3 excludes only processing by a natural person for exclusively personal or domestic activities (where the data is not systematically communicated to third parties or disseminated) and processing concerning public security, defence, or the investigation of offences.
Article 5 conditions processing on the data subject's consent, unless the processing is necessary to comply with a legal obligation, perform a public-interest mission, protect vital interests, or another enumerated ground applies; a minor may consent alone from age sixteen, and jointly with a parent below that age (Article 15 area).
Articles 33 to 39 require most processing to be declared to the commission, with prior authorization required for processing of genetic data, health research data, offence or conviction data, an interconnection of files, a national identification number, or biometric data (Article 37).
Article 4 defines special categories of personal data as genetic data, data concerning minors, data on offences, convictions or security measures, and biometric data, and Article 14 separately restricts processing of data revealing ethnic or regional origin, political opinions, religious or philosophical beliefs, trade union membership, sex life, or health. Articles 46 to 61 give the data subject rights to information, access, portability, rectification and objection.
Articles 23 to 25 permit cross-border transfer only to a country the commission finds offers a sufficient level of protection, subject to derogations for consented, one-off, non-massive transfers or a commission-approved guarantee. Articles 74 to 78 require the controller to notify the commission of a personal-data breach within seventy-two hours where feasible, and to communicate a high-risk breach to the affected person.
Article 93 empowers the commission to warn, order compliance, suspend processing for up to three months, withdraw authorization, or impose an administrative fine of one million to one hundred million CFA francs, with recourse to the Supreme Court (Article 97). Article 98 provides that breach of the Law's provisions is separately punished under the Penal Code and under the law on combating cybercrime.
What it requires