Comprehensive regime
Law No. 2013-450 on the Protection of Personal Data
Loi n° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnelOfficial English-language rendering of Law No. 2013-450 published by ARTCI
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 18, 2026. Publisher's page: https://www.artci.ci/images/stories/pdf-english/lois_english/loi_2013_450_english.pdfIn force. Binds public and private bodies.
What this law does
Article 2 states the Act's purpose as governing the protection of personal data, and article 3 subjects to it any collection, processing, transmission, storage or use of personal data by a natural person, the State, local authorities, or a public or private corporation, whether the processing is automated or not, excluding only an individual's strictly personal or household processing and a network operator's temporary technical copies (art. 4).
Article 5 makes ordinary processing subject to a prior declaration to ARTCI as the Autorité de Protection, while article 7 requires the Authority's prior authorization before processing genetic or medical data, an offense or conviction record, a national identification number, biometric data, data of public-interest research value, or before a cross-border transfer.
Article 21 prohibits, on pain of ten to twenty years' imprisonment and a fine of 20 million to 40 million CFA francs, processing that reveals racial, ethnic or regional origin, political, religious or philosophical opinion, trade-union membership, sex life, or genetic or health data, subject to narrow exceptions including data the person has manifestly made public, protecting a vital interest, or a judicial proceeding.
Article 25 bars any court, administrative or private decision assessing a person's behavior or personality from resting solely on automated processing of their personal data, and article 26 conditions a transfer of personal data to a third country on that country affording an equivalent or higher level of protection and on the Protection Body's prior permission.
Articles 28 to 38 give a data subject the rights to notice, access, objection, rectification, erasure and digital oblivion, and to receive a copy of their data in a portable format, and articles 39 to 44 impose confidentiality and security duties on the person responsible for the processing.
Article 22 punishes unsolicited electronic direct marketing using a person's personal data without their consent by one to five years' imprisonment and a fine of 1 million to 10 million CFA francs, and article 45 punishes obstructing the Protection Body by one month to two years' imprisonment and a fine of 1 million to 10 million CFA francs.
Article 51 lets the Protection Body impose a financial penalty proportionate to the breach, capped at 10 million CFA francs for a first failure and rising, for a repeated failure within five years, to 100 million CFA francs or, for a company, to 5 percent of the prior year's turnover excluding tax up to a maximum of 500 million CFA francs, without prejudice to any criminal penalty; the text states no separate data-breach notification duty running to the Protection Body or to the persons affected.
What it requires