Côte d'IvoireIn ForceData Protection

Loi N° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel (Côte d'Ivoire Personal Data Protection Act 2013)

ci-dp-2013 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Law No. 2013-450 of 19 June 2013 is Côte d'Ivoire's primary personal data protection statute. Enacted in implementation of the ECOWAS Supplementary Act A/SA.1/01/10 of 16 February 2010 on Personal Data Protection, the law establishes a comprehensive framework applicable to both public and private sector actors. The law applies to all automated processing of personal data and to non-automated processing in structured filing systems, where the processing is carried out by a controller established in Côte d'Ivoire or uses processing equipment located in the country. Processing carried out exclusively for personal or household purposes is excluded from the law's scope. The law designates the Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI) as the competent personal data protection authority. ARTCI exercises this remit alongside its telecoms regulatory functions, giving it the status of an independent administrative authority with regulatory, investigatory, and sanctioning powers over personal data processing. Implementing Decree No. 2015-79 of 11 February 2015 sets out detailed procedural requirements for notifications and authorisations. Controllers are subject to a prior notification or authorisation regime before commencing data processing. Simple processing activities are notified to ARTCI; processing involving sensitive data, biometric data, or national identification numbers requires prior authorisation. The law establishes core data quality principles: purpose specification, data minimisation, accuracy, and time-limited retention. Data controllers must also designate a data protection correspondent (correspondant à la protection des données) in specified circumstances. Data subjects are entitled to: obtain information about processing in an intelligible form; object, for legitimate reasons, to processing of their data; refuse processing for direct marketing purposes without giving reasons; correct, supplement, update or erase inaccurate or incomplete data; and not be subject to solely automated decisions producing significant or adverse legal effects. Cross-border transfers of personal data are prohibited unless the recipient country offers an adequate level of protection or specific derogations apply, including data subject consent or contractual necessity. ARTCI may authorise transfers subject to appropriate safeguards. The law provides criminal sanctions for infringements, including fines and imprisonment, with elevated penalties for violations involving sensitive data or national identification numbers. Carve-outs apply for processing related to national security, criminal investigation, journalism, research, and statistics. Note: the precise date on which the law entered into force (versus its enactment date of 19 June 2013) has not been confirmed from available sources; flagged for reviewer. Source language: French; official English translation available.

Key provisions
  1. Processing requires prior declaration to or authorisation from ARTCI before commencing, depending on the nature and sensitivity of the data; Implementing Decree No. 2015-79 of 11 February 2015 sets out detailed procedures.
  2. Sensitive data (health, biometrics, racial origin, political opinion, sexual life, criminal convictions) may only be processed with prior ARTCI authorisation.
  3. Data subjects have rights of access, rectification, erasure, opposition, and protection against solely automated decision-making, enforceable against controllers.
  4. Cross-border transfers are prohibited unless the destination country provides adequate protection; ARTCI may authorise transfers subject to appropriate safeguards.
  5. Data controllers must designate a data protection correspondent (correspondant à la protection des données) in specified circumstances.
  6. Criminal sanctions include fines and imprisonment; elevated penalties apply to violations involving sensitive data and national identification numbers.
  7. Processing for national security, criminal investigation, journalism, or scientific research is exempt from some requirements or subject to special rules.
  8. ARTCI may conduct on-site inspections, issue injunctions, and refer cases for criminal prosecution.
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from ARTCI official English translation of Law No. 2013-450; precise commencement date flagged for reviewer confirmation