TogoIn ForceData Protection

Loi N° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel (Togo Personal Data Protection Act 2019)

tg-dp-2019 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Law No. 2019-014 of 29 October 2019 is Togo's primary personal data protection statute, published in the Official Journal of the Togolese Republic on the same date. Enacted on the model of the ECOWAS Supplementary Act A/SA.1/01/10 of 2010 and consistent with regional standards, the law establishes a comprehensive framework for the regulation of personal data collection, processing, transmission, storage, and use in Togo. The law applies to all automated processing of personal data and to non-automated processing in structured filing systems, carried out by natural or legal persons, whether public or private, established in Togo. It also covers processing by controllers outside Togo where they use processing equipment or resources located in the country. Core data quality principles govern all processing: data must be collected for specified, explicit and legitimate purposes and not processed in an incompatible manner; must be adequate, relevant and not excessive; must be accurate and kept up to date; and must not be retained for longer than necessary. Controllers are required to implement appropriate technical and organisational security measures proportionate to the risks involved. The law creates a prior notification and authorisation regime. Processing activities are generally subject to prior declaration to the supervisory authority; processing involving sensitive personal data, including health information, racial or ethnic origin, political opinions, religious beliefs, and sexual life, or other high-risk categories requires prior authorisation. Data subjects are granted enforceable rights of access, rectification, erasure, and opposition, including the right to oppose processing for direct marketing purposes without giving reasons. Automated individual decision-making producing significant legal effects requires specific safeguards. Cross-border transfers of personal data are restricted to countries ensuring an adequate level of protection, or may proceed on the basis of appropriate safeguards or specific derogations authorised by the supervisory authority. The supervisory authority established by the law is the Instance de Protection des Données à Caractère Personnel (IPDCP), which is an independent administrative body with its own website (ipdcp.tg). The IPDCP's organisation and functioning were established by a subsequent government decree. Criminal penalties apply for infringements, including fines and imprisonment, with aggravated sanctions for processing of sensitive data without authorisation. Source language: French.

Key provisions
  1. Processing must be declared to or authorised by the IPDCP before commencing, depending on the nature and categories of data involved; sensitive data requires prior IPDCP authorisation.
  2. Data subjects have rights of access, rectification, erasure, and opposition enforceable against controllers, including the right to oppose direct marketing processing without giving reasons.
  3. Sensitive data (health, ethnic origin, political opinions, religious beliefs, sexual life) may only be processed with prior IPDCP authorisation; processing without authorisation is a criminal offence.
  4. Cross-border transfers are restricted to countries ensuring adequate protection; the IPDCP may authorise transfers subject to appropriate safeguards.
  5. Automated individual decision-making producing significant legal effects requires specific safeguards and data subject notification.
  6. The IPDCP is the independent supervisory authority; its organisation and functioning were further established by implementing decree subsequent to the law's enactment.
  7. Criminal sanctions include fines and imprisonment; aggravated penalties apply for unauthorised sensitive-data processing and obstruction of IPDCP investigations.
  8. The law applies to processing by controllers outside Togo where they use equipment or resources located in Togolese territory.
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from Togo Journal Officiel official text and AFAPDP archive; IPDCP established and operational under this law