Congo (Republic)
Central Africa
The Republic of Congo regulates personal data through Law No. 29-2019 of 10 October 2019 on the protection of personal data, published in November 2019 and in force from 25 November 2020. The law applies to wholly or partly automated processing and to non-automated processing in structured filing systems, covering controllers and processors established in Congo and those outside the country where the processing relates to persons based there. Personal data is defined broadly by reference to direct or indirect identifiability. The statute runs a notification-and-authorisation model: all processing must be notified to the national commission before it begins, with limited exceptions, while sensitive categories, genetic and biometric data, data on minors, criminal-offence data, ethnic origin, political opinions, religious beliefs, trade union membership, gender, health, and sex life, require prior authorisation, which the commission must grant or refuse within two months. Notably for a francophone instrument of its generation, the law includes a modern 72-hour breach-notification duty (with notice to affected individuals for significant-risk breaches) and a DPO-appointment requirement for public entities, large-scale sensitive-data processing, and regular systematic monitoring. Data subjects have rights of access, rectification, and objection, cross-border transfers require equivalent protection plus prior notification, and penalties range from roughly USD 1,800 to USD 180,000 alongside criminal sanctions. The institutional dimension is recent. The supervisory body, the Commission Nationale pour la Protection des Données à Caractère Personnel (CNPDCP), was only formally established by Law No. 5-2025 of 29 March 2025; commissioners were appointed on 31 December 2025 and the commission was inaugurated in January 2026. The law has therefore operated for several years without an active regulator, a gap that has only just been closed, placing Congo's regime at the very start of meaningful enforcement.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 1 | 0 | ◐ |
| AI Governance | 0 | 0 | ○ |
| Fintech | 0 | 0 | ○ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 1 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Constitution of the Republic of the Congo, 2015, Articles 25 and 26 (Freedom of expression; secrecy of correspondence and telecommunications)
Enacted 6 Nov 2015
Loi n° 27-2020 du 5 juin 2020 portant lutte contre la cybercriminalité (Law No. 27-2020 of 5 June 2020 on combating cybercrime) (Congo, Republic)
Enacted 5 Jun 2020
Loi n° 29-2019 du 10 octobre 2019 portant protection des données à caractère personnel (Law No. 29-2019 of 10 October 2019 on the Protection of Personal Data)
Enacted 10 Oct 2019
Although the law has been in force since 2020, its supervisory commission (CNPDCP) was only inaugurated in January 2026, so there is no enforcement track record and a multi-year supervisory vacuum preceded it. The status of implementing regulations under the 2019 and 2025 laws is unconfirmed on file.