CG

Congo (Republic)

Central Africa

3Instruments
0Cases
2Regulators
65%Coverage
Overview

The Republic of Congo regulates personal data through Law No. 29-2019 of 10 October 2019 on the protection of personal data, published in November 2019 and in force from 25 November 2020. The law applies to wholly or partly automated processing and to non-automated processing in structured filing systems, covering controllers and processors established in Congo and those outside the country where the processing relates to persons based there. Personal data is defined broadly by reference to direct or indirect identifiability. The statute runs a notification-and-authorisation model: all processing must be notified to the national commission before it begins, with limited exceptions, while sensitive categories, genetic and biometric data, data on minors, criminal-offence data, ethnic origin, political opinions, religious beliefs, trade union membership, gender, health, and sex life, require prior authorisation, which the commission must grant or refuse within two months. Notably for a francophone instrument of its generation, the law includes a modern 72-hour breach-notification duty (with notice to affected individuals for significant-risk breaches) and a DPO-appointment requirement for public entities, large-scale sensitive-data processing, and regular systematic monitoring. Data subjects have rights of access, rectification, and objection, cross-border transfers require equivalent protection plus prior notification, and penalties range from roughly USD 1,800 to USD 180,000 alongside criminal sanctions. The institutional dimension is recent. The supervisory body, the Commission Nationale pour la Protection des Données à Caractère Personnel (CNPDCP), was only formally established by Law No. 5-2025 of 29 March 2025; commissioners were appointed on 31 December 2025 and the commission was inaugurated in January 2026. The law has therefore operated for several years without an active regulator, a gap that has only just been closed, placing Congo's regime at the very start of meaningful enforcement.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection10
AI Governance00
Fintech00
Cybercrime10
Digital Rights10
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
Notable gaps

Although the law has been in force since 2020, its supervisory commission (CNPDCP) was only inaugurated in January 2026, so there is no enforcement track record and a multi-year supervisory vacuum preceded it. The status of implementing regulations under the 2019 and 2025 laws is unconfirmed on file.