Research hub / Democratic Republic of the Congo
§ Dossier · CENTRAL AFRICA · updated 22 July 2026

Democratic Republic of the Congo

Regulator
Autorité de Protection des Données (APD; created by Digital Code arts. 262-270, not yet constituted: ARPTC exercises interim missions)
Law
Digital Code (Ordinance-Law No. 23/010 of 13 March 2023, Book on personal data) ↗
Status
Law in force, enforcement not found
Authority
Autorité de Protection des Données (APD; created by Digital Code arts. 262-270, not yet constituted: ARPTC exercises interim missions)
in force
DP law status
Digital Code (Ordinance-Law No. 23/010 of 13 March 2023, Book on personal data)
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Digital Code (Ordinance-Law No. 23/010 of 13 March 2023), personal-data provisions (arts. 186 ff.) IN FORCE

commenced 2023-03-13 (ratified by the National Assembly 4 April 2023) · Official full text ↗

Scope
Processing of personal data within the Digital Code's framework for digital activities and services in the DRC; consent-first lawfulness principles with purpose limitation and compatibility tests (arts. 186 ff.).
Key obligations
Prior declaration to the Autorité de Protection des Données (APD) with a compliance undertaking; processing may start on receipt of the récépissé (art. 186); Prior APD authorisation for genetic/medical/scientific-research data, offence and conviction data, public-interest processing, and transfers to third countries (art. 187); Detailed filing content incl. sub-processor use and envisaged third-country transfers 'subject to reciprocity' (art. 188), with a 15-day gracious-recourse window against refusals (art. 190); Consent withdrawal by the same means it was given; non-binding effect of terms violating the data-protection Book
DPO required
The Code contemplates controllers' 'délégués' (representatives/officers) in the APD's supervision provisions: the precise DPO trigger articles should be cited from the archived text before teaching them.
Registration
Yes: declaration for ordinary processing, authorisation for the art. 187 categories; conditions and procedure fixed by the APD (filings by electronic, postal or receipted means, art. 191).
Cross-border transfers
Transfers to third countries require prior APD authorisation (art. 187(6)); filings must state envisaged transfers subject to reciprocity (art. 188(10)).
Breach notification
The Code's security chapter carries breach duties toward the APD: verify the exact articles from the archived text before asserting timelines in course materials.
Penalties
APD sanctions follow an adversarial, report-based procedure (art. 259: 15 days for written/oral observations) and may carry injunctions to modify or delete processing within a maximum of 8 days (art. 258); rectification, erasure and destruction orders among its powers; fine quanta to be confirmed from the archived text.
Authority
Autorité de Protection des Données (APD; created by the Digital Code with plenary assembly, bureau and standing commissions: arts. 262-270: but not yet constituted; telecom regulator ARPTC exercises interim missions)

Verified 2026-07-07

The regulator

Authority
Autorité de Protection des Données (APD; created by Digital Code arts. 262-270, not yet constituted: ARPTC exercises interim missions)
Operational
No
Enforcing
No enforcement activity found
Publishes decisions
No

Enforcement record

No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Democratic Republic of the Congo

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.