Research hub / Republic of the Congo
§ Dossier · CENTRAL AFRICA · updated 22 July 2026

Republic of the Congo

Regulator
Commission Nationale pour la Protection des Données à Caractère Personnel (created by Law No. 5-2025 of 29 March 2025; being constituted)
Law
Law No. 29-2019 on the Protection of Personal Data ↗
Status
Law in force, enforcement not found
Authority
Commission Nationale pour la Protection des Données à Caractère Personnel (created by Law No. 5-2025 of 29 March 2025; being constituted), established 2025
in force
DP law status
Law No. 29-2019 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Law No. 29-2019 of 10 October 2019 on the Protection of Personal Data IN FORCE

commenced 2019-10-10 (Journal Officiel No. 45-2019) · Official full text ↗

Scope
Any information relating to an identified or identifiable natural person, processed by automated or non-automated means; personal/domestic processing excluded unless systematically communicated or disseminated.
Key obligations
Prior declaration to the commission on its model form, with a compliance undertaking; one-month récépissé before processing may start (art. 33); Authorisation regimes for higher-risk categories (arts. 31, 35, 37-39) and for file interconnection serving different public interests or e-government services (art. 26); Prior information to the commission of any transfer to a third country; inbound foreign data also checked for sufficient protection (art. 23); 72-hour breach notification (art. 74)
DPO required
No general DPO obligation identified in the law's formalities chapters: verify the full text (archived) before asserting the absence in course materials.
Registration
Yes: declaration with récépissé for ordinary processing (art. 33); reasoned-request authorisation for the higher-risk categories; exemption articles 32-33 formalities apply.
Cross-border transfers
Cross-border transfer only where the third country ensures a sufficient level of protection of privacy and fundamental rights; the controller must inform the commission before any transfer (art. 23).
Breach notification
Notify the commission without undue delay and where possible within 72 hours of becoming aware, unless the breach is unlikely to create a risk to rights and freedoms (art. 74).
Penalties
Administrative: warning and formal notice (art. 92); on non-compliance, after adversarial procedure: provisional (max three months) or definitive withdrawal of authorisation / prohibition of processing, injunctions to cease declared processing, and pecuniary fines of XAF 1,000,000 to 100,000,000 recovered as state debts (art. 93); urgency measures (art. 94).
Authority
Commission Nationale pour la Protection des Données à Caractère Personnel (created by Law No. 5-2025 of 29 March 2025; being constituted: the 2019 law's supervisory machinery had no institution for six years)

Verified 2026-07-07

The regulator

Authority
Commission Nationale pour la Protection des Données à Caractère Personnel (created by Law No. 5-2025 of 29 March 2025; being constituted)
Established
2025
Operational
No
Enforcing
No enforcement activity found
Publishes decisions
No

Enforcement record

No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Republic of the Congo

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.