§ Dossier · CENTRAL AFRICA · updated 22 July 2026
Republic of the Congo
- Regulator
- Commission Nationale pour la Protection des Données à Caractère Personnel (created by Law No. 5-2025 of 29 March 2025; being constituted)
- Law
- Law No. 29-2019 on the Protection of Personal Data ↗
- Status
- Law in force, enforcement not found
- Authority
- Commission Nationale pour la Protection des Données à Caractère Personnel (created by Law No. 5-2025 of 29 March 2025; being constituted), established 2025
in force
DP law status
Law No. 29-2019 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 29-2019 of 10 October 2019 on the Protection of Personal Data IN FORCE
commenced 2019-10-10 (Journal Officiel No. 45-2019) · Official full text ↗
- Scope
- Any information relating to an identified or identifiable natural person, processed by automated or non-automated means; personal/domestic processing excluded unless systematically communicated or disseminated.
- Key obligations
- Prior declaration to the commission on its model form, with a compliance undertaking; one-month récépissé before processing may start (art. 33); Authorisation regimes for higher-risk categories (arts. 31, 35, 37-39) and for file interconnection serving different public interests or e-government services (art. 26); Prior information to the commission of any transfer to a third country; inbound foreign data also checked for sufficient protection (art. 23); 72-hour breach notification (art. 74)
- DPO required
- No general DPO obligation identified in the law's formalities chapters: verify the full text (archived) before asserting the absence in course materials.
- Registration
- Yes: declaration with récépissé for ordinary processing (art. 33); reasoned-request authorisation for the higher-risk categories; exemption articles 32-33 formalities apply.
- Cross-border transfers
- Cross-border transfer only where the third country ensures a sufficient level of protection of privacy and fundamental rights; the controller must inform the commission before any transfer (art. 23).
- Breach notification
- Notify the commission without undue delay and where possible within 72 hours of becoming aware, unless the breach is unlikely to create a risk to rights and freedoms (art. 74).
- Penalties
- Administrative: warning and formal notice (art. 92); on non-compliance, after adversarial procedure: provisional (max three months) or definitive withdrawal of authorisation / prohibition of processing, injunctions to cease declared processing, and pecuniary fines of XAF 1,000,000 to 100,000,000 recovered as state debts (art. 93); urgency measures (art. 94).
- Authority
- Commission Nationale pour la Protection des Données à Caractère Personnel (created by Law No. 5-2025 of 29 March 2025; being constituted: the 2019 law's supervisory machinery had no institution for six years)
Verified 2026-07-07
The regulator
- Authority
- Commission Nationale pour la Protection des Données à Caractère Personnel (created by Law No. 5-2025 of 29 March 2025; being constituted)
- Established
- 2025
- Operational
- No
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Republic of the Congo
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.