Loi N° 2009-09 du 22 mai 2009 portant protection des données à caractère personnel (Benin Personal Data Protection Act 2009)
bj-dp-2009 · Act
Benin's Law No. 2009-09 of 22 May 2009 establishes the legal framework for the protection of personal data in the Republic of Benin. Drafted on the ECOWAS model and influenced by Council of Europe Convention 108, the law applies to all automated processing of personal data and to non-automated processing held in structured filing systems. It covers processing by any public body or private entity whose activities involve residents of Benin, regardless of where the processing takes place. The law is built around defined data quality principles: personal data must be collected for specified, explicit and legitimate purposes and not processed in an incompatible manner; it must be adequate, relevant and not excessive relative to those purposes; and it must be accurate and kept up to date. Controllers are required to implement appropriate technical and organisational security measures. The law distinguishes between processing requiring a simple declaration to the supervisory authority and processing requiring prior authorisation. Automated processing of sensitive personal data, including racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and health or sexual life, always requires prior authorisation from the supervisory authority. Processing linked to national identification numbers is similarly subject to prior authorisation. Data subjects are granted enforceable rights of access, rectification, opposition, and erasure. They may oppose the processing of their personal data for direct marketing purposes without giving reasons. The right of access entitles a data subject to obtain confirmation of whether their data is being processed and a copy of the information held about them, free of charge. Cross-border transfers of personal data are prohibited unless the destination country ensures an adequate level of protection, or the controller obtains specific prior authorisation from the supervisory authority. Transfers may also proceed on the basis of standard contractual clauses approved by the authority. The supervisory authority responsible for enforcement is the Autorité de Protection des Données à caractère Personnel (APDP), formerly named the Commission Nationale de l'Informatique et des Libertés (CNIL) until 2018. The APDP is an independent administrative authority with powers to receive declarations and authorisation requests, conduct on-site investigations, issue warnings, and refer matters to prosecutorial authorities. Penalties include fines and imprisonment, with aggravated sanctions for processing sensitive data without authorisation or for wilful obstruction of APDP investigations. The 2009 Act was supplemented by Law No. 2017-20 of 20 April 2018 on the Digital Code of Benin, which modernised aspects of the digital regulatory framework and reinforced the APDP's institutional independence. Law No. 2009-09 remains the primary data protection statute. Source language: French.
- Processing must be declared to or authorised by the APDP before commencing, depending on its nature and the categories of data involved.
- Sensitive data (health, ethnic origin, political opinions, biometrics) requires prior authorisation from the APDP; such processing without authorisation is a criminal offence.
- Data subjects have enforceable rights of access, rectification, opposition, and erasure against data controllers.
- Cross-border transfers require an adequacy finding or prior APDP authorisation; standard contractual clauses approved by the APDP may be used as a safeguard.
- Penalties for infringement include fines and imprisonment; aggravated penalties apply for unauthorised sensitive-data processing and for obstruction of APDP inspections.
- Use of national identification numbers in processing requires prior APDP authorisation.
- The APDP may conduct on-site inspections and investigations and refer cases to the procureur for criminal prosecution.
- Special protections apply to processing of personal data relating to children.