Comprehensive regime
Loi n° 2019-014, protection des données à caractère personnel
Loi n° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnelJournal Officiel de la République Togolaise
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2020. Publisher's page: https://numerique.gouv.tg/wp-content/uploads/2020/01/Loi-n-2019-014-du-29-octobre-2019-relative-a-la-protection-des-donnees-a-caractere-pers…In force. Binds public and private bodies.
What this law does
Article 55 creates the Instance de Protection des Données à Caractère Personnel (IPDCP) as the independent supervisory authority. Article 1 regulates the collection, processing, transmission, storage, use and protection of personal data, and article 2 extends the law to any collection, processing, transmission, storage or use of personal data by a natural person, the State, a local authority, or a public or private legal person, whether the processing is automated or not.
Article 14 makes consent the general lawful basis for processing, subject to derogations for a legal obligation, a public-interest task, performing a contract, or protecting the data subject's vital interests, and articles 15 to 20 set the purpose-limitation, accuracy, transparency, confidentiality, security and sub-processor-selection principles.
Article 21 prohibits processing data revealing racial or ethnic origin, political, religious or philosophical opinions, trade-union membership, sex life, health or genetic data, subject to article 22's exceptions for data the person has manifestly made public, the person's written consent, safeguarding a vital interest, or a public-interest, judicial or historical, statistical or scientific purpose.
Article 8 requires the Instance's prior authorization before a treatment of genetic data or health research, criminal-record or security-measure data, an interconnection of files, a national identification number, or biometric data, while most other processing is only declared to the Instance under article 6.
Article 26 bars unsolicited direct marketing to a person who has not given prior consent, and article 27 bars founding a legal decision solely on an automated evaluation of a person's characteristics or personality.
Article 28 requires due consideration of the destination country's level of protection before a transfer of personal data outside Togo, and article 29 admits a one-off, non-massive transfer without that showing where the data subject has consented or the transfer serves one of a short list of vital, public-interest or contractual grounds.
Chapter VII (arts. 79 to 93) states distinct criminal offenses for processing without the required formalities, unauthorized use of a national identification number, fraudulent or unauthorized data collection, unlawful processing of sensitive or infraction-related data, breach of the right to object, misuse of data beyond its declared purpose, unauthorized disclosure, and hindering the Instance's action, each carrying its own imprisonment and fine range; the sources read state no separate data-breach notification duty to the Instance or to the persons affected.
What it requires