Any processing of personal data of any kind and on any medium, including sound and image, relating to an identified or identifiable natural person; filings must be made by a natural person resident in Côte d'Ivoire or an Ivorian legal person (Decree 2015-79).
Key obligations
Prior declaration to the authority for any processing (art. 5), with detailed content requirements (art. 9) and exemptions (art. 10); Prior authorisation for higher-risk processing: genetic data, health research, offence data, national ID numbers and similar identifiers, biometric data, public-interest processing, third-country transfers, and file interconnection (art. 7); State-sector processing decided by legislative or regulatory act after a reasoned opinion of the authority (art. 13); Standard processing principles: lawfulness, purpose limitation, proportionality, accuracy, limited retention, security
DPO required
No: designating a 'correspondant à la protection des données' (CPDCP) is optional; it exempts the controller from declaration except for third-country transfers (arts. 5-6), with the correspondent's profile fixed by Order No. 511/MPTIC/CAB of 11 November 2014.
Registration
Yes: prior declaration for all processing (art. 5) and prior authorisation for the art. 7 categories; the authority must decide within one month (extendable once), and silence amounts to rejection (Decree 2015-79).
Cross-border transfers
Transfers to a 'pays tiers' - defined as any non-ECOWAS state (art. 1) - only where that state ensures a SUPERIOR OR EQUIVALENT level of protection (art. 26), with prior ARTCI authorisation before any effective transfer and ongoing finality control; envisaged third-country transfers also sit on the art. 7 prior-authorisation list. No consent or necessity derogations exist in the text; intra-ECOWAS transfers fall outside the regime. (Verified from the archived JO scan via Vision OCR 2026-07-11, S27.)
Breach notification
No general data-breach notification duty to the authority; the CPDCP must report uncorrected legal breaches to the authority within three months of raising them with the controller.
Penalties
Administrative sanction scale: up to XOF 10,000,000 for a first breach; on repeat, up to XOF 100,000,000 or 5% of pre-tax turnover, capped at XOF 500,000,000; the law also carries criminal provisions. Published decisions (e.g. the 2023-2024 GCB Cocoa series) show the sanction machinery in use.
Authority
Autorité de Protection des Données à Caractère Personnel (dedicated authority operating autoritedeprotection.ci; mandate historically exercised by telecom regulator ARTCI)
Verified 2026-07-07
Access to information
Law No. 2013-867 on Access to Information of Public Interest IN FORCE
The regulator
Authority
Autorité de Protection des Données à Caractère Personnel (spun out of ARTCI)