CD

Congo (DRC)

Central Africa

5Instruments
0Cases
2Regulators
50%Coverage
Overview

The Democratic Republic of the Congo regulates personal data within a broad consolidated statute rather than a freestanding act. Ordonnance-Loi No. 23/010 of 13 March 2023 (the Digital Code), published in April 2023, governs the digital economy, electronic services, cybersecurity, electronic transactions, and personal data protection in a single text; Title III specifically addresses data protection. The data protection provisions apply to automated and partly automated processing, and to non-automated processing in structured systems, conducted in the DRC or relating to data subjects located there, and reach controllers and processors outside the country whose activities are directed at persons in the DRC. Title III establishes the foundational principles, lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, and security, and grants data subjects rights of access, rectification, and erasure, with mandatory breach notification to the supervisory authority and conditions on cross-border transfers requiring equivalent protection in the receiving jurisdiction. In June 2025 the DRC ratified the African Union (Malabo) Convention on Cybersecurity and Personal Data Protection; because ratified treaties take precedence over ordinary domestic law in the Congolese order, this reinforces the obligation to stand up a functional data protection regime. The decisive weakness is institutional. Article 262 of the Code provides for an independent data protection supervisory authority, but as at June 2026 it had not been constituted by the required Prime Ministerial decree. A 2024 ministerial decree provisionally transferred supervisory functions to the Autorité de Régulation du Numérique (ARN), an arrangement some practitioners regard as potentially ultra vires. ATLPF holds an Instrument record for the Digital Code but no Regulator record, reflecting the absence of a properly constituted authority, the principal reason this jurisdiction scores below its single-instrument peers that have an established regulator.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection10
AI Governance00
Fintech30
Cybercrime10
Digital Rights20
Platform Liability00
Telecoms10

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
cd-const-privacy·Act

Constitution of the Democratic Republic of the Congo, 2006 (rev. 2011), Article 31 (Privacy and secrecy of correspondence, telecommunications and communications)

Congo (DRC)Digital RightsIn Force
Verified

Enacted 18 Feb 2006

cd-fintech-interop-2024·Guidance

Instruction n° 58 de la Banque Centrale du Congo du 4 septembre 2024 relative à l'interopérabilité des systèmes de paiement électronique et à la participation au switch monétaire national (BCC Instruction No. 58 of 4 September 2024 on Interoperability of Electronic Payment Systems and Participation in the National Monetary Switch) (DRC)

Congo (DRC)FintechIn Force
Verified

Enacted 4 Sept 2024

cd-fintech-emoney-2011·Guidance

Instruction n° 24 de la Banque Centrale du Congo relative à l'émission de monnaie électronique et aux établissements de monnaie électronique (BCC Instruction No. 24 on the Issuance of Electronic Money and Electronic Money Establishments) (DRC)

Congo (DRC)FintechIn Force
Verified

Enacted 1 Jan 2011

cd-fintech-paymentsystems-2018·Act

Loi du 9 juillet 2018 relative aux systèmes de paiement et de règlement-titres (Law of 9 July 2018 on Payment and Securities-Settlement Systems) (DRC)

Congo (DRC)FintechIn Force
Verified

Enacted 9 Jul 2018

cd-dc-2023·Act

Ordonnance-Loi n° 23/010 du 13 mars 2023 portant code du numérique (Decree-Law No. 23/010 of 13 March 2023 on the Digital Code)

Congo (DRC)Data ProtectionCybercrimeTelecomsDigital RightsIn Force
Verified

Enacted 13 Mar 2023

Notable gaps

No properly constituted data protection authority: the Article 262 supervisor has not been established by Prime Ministerial decree, and the provisional transfer of functions to the ARN is contested. There is no Regulator record on file, no documented breach-notification deadline detail, and no implementing regulations identified.