Congo (Republic)In ForceData Protection

Loi n° 29-2019 du 10 octobre 2019 portant protection des données à caractère personnel (Law No. 29-2019 of 10 October 2019 on the Protection of Personal Data)

cg-dp-2019 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Loi n° 29-2019 du 10 octobre 2019 portant protection des données à caractère personnel (Law No. 29-2019 of 10 October 2019 on the Protection of Personal Data) is the Republic of Congo's primary legislation governing the collection, processing, storage, and transfer of personal data. The law was published in the Journal Officiel de la République du Congo on 7 November 2019 and entered into force on 25 November 2020. The law applies to any processing of personal data carried out wholly or partly by automated means, as well as to non-automated processing where the data forms part of a structured filing system. It covers data controllers and processors established in the Republic of Congo, as well as those located outside the country where processing relates to persons based in Congo. Personal data is defined as any information relating to a natural person who is identified or identifiable, directly or indirectly, by reference to an identification number or one or more elements specific to their physical, physiological, genetic, psychological, cultural, social, or economic identity. Sensitive categories, including genetic data, data relating to minors, data concerning criminal offences or convictions, biometric data, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, gender, health, and sex life, are afforded heightened protection and may only be processed subject to prior authorisation from the national commission. The law requires that all processing of personal data be notified to the national commission before commencement, with limited exceptions. Processing of sensitive categories and certain high-risk activities requires prior authorisation, which the commission must grant or refuse within two months of receipt. Data controllers must implement appropriate technical and organisational security measures. In the event of a security breach, the controller must notify the commission without delay and no later than 72 hours after identifying the breach. Where the breach poses a significant risk to data subjects' rights, those individuals must also be informed. Data subjects hold rights of access, rectification, and objection. A data protection officer must be designated where processing is carried out by a public entity, where the nature of the processing requires regular and systematic monitoring, or where processing is carried out on a large scale involving sensitive categories. Cross-border transfers are permitted only where the receiving state offers an equivalent level of data protection and the commission is notified in advance. Enforcement sanctions include criminal penalties and fines ranging from approximately USD 1,800 to USD 180,000. The national commission (Commission Nationale pour la Protection des Données à Caractère Personnel, CNPDCP) was formally established by Law No. 5-2025 of 29 March 2025, with commissioners appointed on 31 December 2025 and the commission inaugurated in January 2026. Original language: French.

Key provisions
  1. All processing of personal data must be notified to the CNPDCP before commencement; processing of sensitive categories requires prior authorisation within two months
  2. Sensitive categories, including genetic data, biometric data, health, ethnic origin, political opinions, religious beliefs, trade union membership, gender, and sex life, are subject to heightened protection and prior authorisation requirements
  3. Cross-border transfer permitted only to jurisdictions offering equivalent protection, with prior notification to the commission
  4. Breach notification required within 72 hours of identifying a security breach; significant-risk breaches must also be disclosed to affected data subjects
  5. Data protection officers must be appointed for public entities, large-scale sensitive data processing, and systematic or regular monitoring activities
  6. Criminal sanctions and fines from approximately USD 1,800 to USD 180,000
  7. CNPDCP formally established by Law No. 5-2025 (March 2025); commissioners appointed December 2025; commission operational from January 2026
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from Journal Officiel de la République du Congo No. 45-2019 (SGG.CG) and NATLEX/ILO database record