Congo (DRC)
Central Africa
The Democratic Republic of the Congo regulates personal data within a broad consolidated statute rather than a freestanding act. Ordonnance-Loi No. 23/010 of 13 March 2023 (the Digital Code), published in April 2023, governs the digital economy, electronic services, cybersecurity, electronic transactions, and personal data protection in a single text; Title III specifically addresses data protection. The data protection provisions apply to automated and partly automated processing, and to non-automated processing in structured systems, conducted in the DRC or relating to data subjects located there, and reach controllers and processors outside the country whose activities are directed at persons in the DRC. Title III establishes the foundational principles, lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, and security, and grants data subjects rights of access, rectification, and erasure, with mandatory breach notification to the supervisory authority and conditions on cross-border transfers requiring equivalent protection in the receiving jurisdiction. In June 2025 the DRC ratified the African Union (Malabo) Convention on Cybersecurity and Personal Data Protection; because ratified treaties take precedence over ordinary domestic law in the Congolese order, this reinforces the obligation to stand up a functional data protection regime. The decisive weakness is institutional. Article 262 of the Code provides for an independent data protection supervisory authority, but as at June 2026 it had not been constituted by the required Prime Ministerial decree. A 2024 ministerial decree provisionally transferred supervisory functions to the Autorité de Régulation du Numérique (ARN), an arrangement some practitioners regard as potentially ultra vires. ATLPF holds an Instrument record for the Digital Code but no Regulator record, reflecting the absence of a properly constituted authority, the principal reason this jurisdiction scores below its single-instrument peers that have an established regulator.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 1 | 0 | ◐ |
| AI Governance | 0 | 0 | ○ |
| Fintech | 3 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 2 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 1 | 0 | ◐ |
● Covered ◐ Partially covered ○ Not yet covered
Constitution of the Democratic Republic of the Congo, 2006 (rev. 2011), Article 31 (Privacy and secrecy of correspondence, telecommunications and communications)
Enacted 18 Feb 2006
Instruction n° 58 de la Banque Centrale du Congo du 4 septembre 2024 relative à l'interopérabilité des systèmes de paiement électronique et à la participation au switch monétaire national (BCC Instruction No. 58 of 4 September 2024 on Interoperability of Electronic Payment Systems and Participation in the National Monetary Switch) (DRC)
Enacted 4 Sept 2024
Instruction n° 24 de la Banque Centrale du Congo relative à l'émission de monnaie électronique et aux établissements de monnaie électronique (BCC Instruction No. 24 on the Issuance of Electronic Money and Electronic Money Establishments) (DRC)
Enacted 1 Jan 2011
Loi du 9 juillet 2018 relative aux systèmes de paiement et de règlement-titres (Law of 9 July 2018 on Payment and Securities-Settlement Systems) (DRC)
Enacted 9 Jul 2018
Ordonnance-Loi n° 23/010 du 13 mars 2023 portant code du numérique (Decree-Law No. 23/010 of 13 March 2023 on the Digital Code)
Enacted 13 Mar 2023
No properly constituted data protection authority: the Article 262 supervisor has not been established by Prime Ministerial decree, and the provisional transfer of functions to the ARN is contested. There is no Regulator record on file, no documented breach-notification deadline detail, and no implementing regulations identified.