Togo
West Africa
Togo regulates personal data through a comprehensive standalone statute, Law No. 2019-014 of 29 October 2019, published in the Official Journal of the Togolese Republic on the date of enactment. Modelled on the ECOWAS Supplementary Act A/SA.1/01/10 of 2010, the law governs the collection, processing, transmission, storage, and use of personal data by public or private controllers established in Togo, and reaches controllers outside the country that use processing equipment or resources located in Togolese territory. It is built on the standard data-quality principles, purpose limitation, adequacy and relevance, accuracy, and storage limitation, with security measures proportionate to the risks involved. Processing operates under a prior notification and authorisation regime: ordinary processing is generally declared to the supervisory authority, while sensitive data (health, ethnic origin, political opinions, religious beliefs, sexual life) and other high-risk categories require prior authorisation, with criminal liability for unauthorised sensitive-data processing. Data subjects hold enforceable rights of access, rectification, erasure, and opposition, including to direct marketing without giving reasons, and solely automated decisions producing significant legal effects require specific safeguards. Cross-border transfers are restricted to countries ensuring adequate protection or may proceed under authorised safeguards or derogations. Enforcement rests with the Instance de Protection des Données à Caractère Personnel (IPDCP), the independent supervisory authority established by the law, with its own institutional presence; its organisation and functioning were set out in a subsequent implementing decree. The IPDCP receives declarations and authorisations, investigates complaints, advises government, and refers matters for prosecution, with fines and imprisonment available for infringements. Togo thus presents a single, current, in-force statute supported by a constituted regulator, a solid baseline regime consistent with the regional model.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 1 | 0 | ◐ |
| AI Governance | 0 | 0 | ○ |
| Fintech | 0 | 0 | ○ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 1 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Loi n° 2018-026 du 7 décembre 2018 sur la cybersécurité et la lutte contre la cybercriminalité (Law on Cybersecurity and Combating Cybercrime) (Togo)
Enacted 7 Dec 2018
Loi N° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel (Togo Personal Data Protection Act 2019)
Enacted 29 Oct 2019
The 2019 law follows the declaration-and-authorisation model rather than the full GDPR accountability approach; no fixed breach-notification deadline, general DPO mandate, or portability right is recorded on file, and no subsidiary regulations beyond the organisational implementing decree are documented.