BJ

Benin

West Africa

3Instruments
0Cases
2Regulators
80%Coverage
Overview

Benin regulates personal data through Law No. 2009-09 of 22 May 2009 on the protection of personal data, drafted on the ECOWAS model and influenced by Convention 108. It applies to automated processing and structured manual files, covering public and private actors whose activities involve residents of Benin regardless of where processing occurs. The law is built on defined data-quality principles (purpose limitation, adequacy, accuracy, security) and distinguishes processing requiring a simple declaration from processing requiring prior authorisation; sensitive data (ethnic origin, political opinions, religious belief, health, sexual life) and use of national identification numbers always require prior authorisation. Data subjects have rights of access, rectification, opposition, and erasure, including a no-reasons right to object to direct marketing. Cross-border transfers are prohibited unless the destination ensures adequate protection or the regulator authorises them, with approved standard contractual clauses available. The framework was reinforced by Law No. 2017-20 of 20 April 2018 (the Digital Code), which modernised the digital regulatory framework and strengthened the regulator's institutional independence; Law No. 2009-09 remains the primary data protection statute. Enforcement rests with the Autorité de Protection des Données à caractère Personnel (APDP), an independent administrative authority, formerly the CNIL until 2018, that receives declarations and authorisation requests, conducts on-site investigations, issues warnings, and refers matters for prosecution, with fines and imprisonment available and aggravated sanctions for unauthorised sensitive-data processing and obstruction. With a long-standing law, a supporting Digital Code, and an active named regulator, Benin runs one of the more established francophone West African regimes.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection20
AI Governance10
Fintech00
Cybercrime10
Digital Rights10
Platform Liability00
Telecoms10

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
Notable gaps

The 2009 law follows the declaration-and-authorisation model and lacks, on its face, a fixed 72-hour breach-notification rule, a general DPO mandate, and a portability right. Both the 2009 Act and the 2018 Digital Code are now recorded as Instruments on file (the Digital Code record is AI-drafted and its specific data protection provisions await confirmation).