Côte d'Ivoire
West Africa
Côte d'Ivoire regulates personal data through Law No. 2013-450 of 19 June 2013, enacted to implement the ECOWAS Supplementary Act of 2010. The law applies to automated processing and structured manual files where the controller is established in Côte d'Ivoire or uses equipment located there, excluding purely personal or household processing. Implementing Décret n° 2015-79 of 4 February 2015, now recorded as a separate Instrument in the Library, sets out detailed procedures for notifications and authorisations. Controllers are subject to a prior notification or authorisation regime: ordinary processing is notified, while sensitive data, biometrics, or national identification numbers require prior authorisation. Core data-quality principles apply, and controllers must designate a data protection correspondent in specified circumstances. Data subjects are entitled to intelligible information about processing, to object on legitimate grounds, to refuse direct marketing without reasons, to correct or erase inaccurate data, and not to be subject to solely automated decisions with significant or adverse effects. Cross-border transfers are prohibited unless the recipient country offers adequate protection or derogations apply; the regulator may authorise transfers under appropriate safeguards. Criminal sanctions apply, elevated for violations involving sensitive data or national identification numbers, with carve-outs for national security, criminal investigation, journalism, research, and statistics. A distinctive institutional feature is that enforcement is housed in the Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI), the telecoms regulator designated as the data protection authority, which exercises regulatory, investigatory, and sanctioning powers, conducts inspections, and refers matters for prosecution. With an in-force law, a documented implementing decree, and a named operational regulator, Côte d'Ivoire is now a multi-instrument jurisdiction, though data protection supervision sits within the telecoms regulator rather than a dedicated body.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 2 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 3 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 0 | 0 | ○ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Loi n° 2013-451 du 19 juin 2013 relative à la lutte contre la cybercriminalité (Law on Combating Cybercrime) (Côte d'Ivoire)
Enacted 19 Jun 2013
Instruction n°001-01-2024 du 23 janvier 2024 relative aux services de paiement dans l'Union Monétaire Ouest Africaine (Instruction No. 001-01-2024 of 23 January 2024 on Payment Services in WAMU)
Enacted 23 Jan 2024
Règlement n°15/2002/CM/UEMOA du 19 septembre 2002 relatif aux systèmes de paiement dans les États membres de l'UEMOA (Regulation No. 15/2002/CM/UEMOA on Payment Systems in the Member States of WAEMU)
Enacted 19 Sept 2002
Instruction n°008-05-2015 du 21 mai 2015 régissant les conditions et modalités d'exercice des activités des émetteurs de monnaie électronique dans les États membres de l'UMOA (Instruction No. 008-05-2015 governing the conditions for the exercise of electronic money issuer activities in the WAMU member states)
Enacted 21 May 2015
Stratégie Nationale de l'Intelligence Artificielle 2030 (SNIA 2030) (Côte d'Ivoire National Artificial Intelligence Strategy 2030)
Enacted 1 Aug 2024
Décret n° 2015-79 du 4 février 2015 (declaration and authorisation procedures for personal data processing) (Côte d'Ivoire)
Enacted 4 Feb 2015
Loi N° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel (Côte d'Ivoire Personal Data Protection Act 2013)
Enacted 19 Jun 2013
ATLPF now holds both Law No. 2013-450 and its implementing Décret n° 2015-79 of 4 February 2015 (the date corrected from an earlier note giving 11 February). Data protection supervision remains housed within the telecoms regulator (ARTCI) rather than a dedicated authority, and the 2013 architecture predates the GDPR accountability model.