§ Dossier · WEST AFRICA · updated 22 July 2026
in force
DP law status
Digital Code (Law No. 2017-20, Book 5: Protection of Personal Data)
Yes
enforcement activity
as of the last landscape verification
Yes
decisions published
collection under way
The law
Digital Code (Law No. 2017-20 of 20 April 2018), Book V: Protection of Personal Data IN FORCE
commenced 2018-04-20 · Official full text ↗
- Scope
- Collection, processing, transmission, storage and use of personal data by natural persons, the state, local authorities and legal persons; covers automated and non-automated processing of data in files, including processing for public security, defence and criminal justice; the older Law 2009-09 on PII overlaps but Book V is the operative general regime.
- Key obligations
- Lawful-basis regime: consent, or necessity for legal obligation, public-interest mission, contract, or the data subject's fundamental interests; Prior declaration to the APDP for automated or non-automated processing (art. 405), with exemptions incl. where a DPO is appointed (art. 408); Records of processing activities for controllers and processors (art. 435); SME exemption unless risky, non-occasional or sensitive-data processing; Extensive data subject rights: access, withdrawal of consent, objection (incl. to prospecting), rectification, erasure, right to be forgotten, compensation for damage
- DPO required
- Yes, in defined cases: state bodies, and controllers/processors whose activities involve monitoring of individuals or large-scale sensitive-data processing (art. 430); appointing a DPO exempts the controller from APDP notification (art. 408).
- Registration
- Yes: prior declaration to the APDP before implementation (art. 405), or entry in a register kept by a designated person; exemptions per arts. 408, 410, 411, 417.
- Cross-border transfers
- Transfers require both an Authority equivalence finding for the destination and PRIOR APDP AUTHORISATION before any effective transfer, with ongoing control (art. 391); non-adequate destinations ride the art. 392 derogations (express consent, contract necessity/pre-contractual measures, contract in the data subject's interest, important public interest, legal claims, vital interests, public register) or a Council-of-Ministers decree on the APDP's conforming opinion where the controller offers sufficient guarantees. (Transfer articles verified from the archived code text 2026-07-11, S27.)
- Breach notification
- Controller must notify the APDP of any breach of security safeguards without delay (art. 427), describing the breach, affected categories and numbers, likely consequences and remedial steps.
- Penalties
- APDP: warning, formal notice (max 8 days to comply), then pecuniary penalty up to XOF 50,000,000 for a first breach; on repeat within 5 years up to XOF 100,000,000 or 5% of turnover (capped at XOF 100,000,000), plus injunctions, withdrawal of authorisation and data blocking. Criminal penalties apply to serious infringements.
- Authority
- Autorité de Protection des Données à Caractère Personnel (APDP)
Verified 2026-07-07
Access to information
Information and Communication Code (Law No. 2015-07) IN FORCE
The regulator
- Authority
- Autorité de Protection des Données à Caractère Personnel (APDP)
- Website
- https://apdp.bj ↗
- Established
- 2018
- Operational
- Yes
- Enforcing
- Yes
- Publishes decisions
- Yes · publication venue ↗
Enforcement record
The authority publishes enforcement outcomes (publication venue ↗). Published decisions are being collected and verified for the tracker; this dossier will carry them as they pass verification.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Benin
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.