§ Dossier · CENTRAL AFRICA · updated 22 July 2026
Democratic Republic of the Congo
- Regulator
- Autorité de Protection des Données (APD; created by Digital Code arts. 262-270, not yet constituted: ARPTC exercises interim missions)
- Law
- Digital Code (Ordinance-Law No. 23/010 of 13 March 2023, Book on personal data) ↗
- Status
- Law in force, enforcement not found
- Authority
- Autorité de Protection des Données (APD; created by Digital Code arts. 262-270, not yet constituted: ARPTC exercises interim missions)
in force
DP law status
Digital Code (Ordinance-Law No. 23/010 of 13 March 2023, Book on personal data)
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Digital Code (Ordinance-Law No. 23/010 of 13 March 2023), personal-data provisions (arts. 186 ff.) IN FORCE
commenced 2023-03-13 (ratified by the National Assembly 4 April 2023) · Official full text ↗
- Scope
- Processing of personal data within the Digital Code's framework for digital activities and services in the DRC; consent-first lawfulness principles with purpose limitation and compatibility tests (arts. 186 ff.).
- Key obligations
- Prior declaration to the Autorité de Protection des Données (APD) with a compliance undertaking; processing may start on receipt of the récépissé (art. 186); Prior APD authorisation for genetic/medical/scientific-research data, offence and conviction data, public-interest processing, and transfers to third countries (art. 187); Detailed filing content incl. sub-processor use and envisaged third-country transfers 'subject to reciprocity' (art. 188), with a 15-day gracious-recourse window against refusals (art. 190); Consent withdrawal by the same means it was given; non-binding effect of terms violating the data-protection Book
- DPO required
- The Code contemplates controllers' 'délégués' (representatives/officers) in the APD's supervision provisions: the precise DPO trigger articles should be cited from the archived text before teaching them.
- Registration
- Yes: declaration for ordinary processing, authorisation for the art. 187 categories; conditions and procedure fixed by the APD (filings by electronic, postal or receipted means, art. 191).
- Cross-border transfers
- Transfers to third countries require prior APD authorisation (art. 187(6)); filings must state envisaged transfers subject to reciprocity (art. 188(10)).
- Breach notification
- The Code's security chapter carries breach duties toward the APD: verify the exact articles from the archived text before asserting timelines in course materials.
- Penalties
- APD sanctions follow an adversarial, report-based procedure (art. 259: 15 days for written/oral observations) and may carry injunctions to modify or delete processing within a maximum of 8 days (art. 258); rectification, erasure and destruction orders among its powers; fine quanta to be confirmed from the archived text.
- Authority
- Autorité de Protection des Données (APD; created by the Digital Code with plenary assembly, bureau and standing commissions: arts. 262-270: but not yet constituted; telecom regulator ARPTC exercises interim missions)
Verified 2026-07-07
The regulator
- Authority
- Autorité de Protection des Données (APD; created by Digital Code arts. 262-270, not yet constituted: ARPTC exercises interim missions)
- Operational
- No
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Democratic Republic of the Congo
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.