All data relating to an identified or identifiable individual (art. 4), processed by private or public controllers; state-sector automated processing proceeds by regulatory act after a reasoned CDP opinion (arts. 20-21).
Key obligations
Prior notification of processing to the CDP, with narrow exemptions for non-profit associations and public registers (art. 18); Prior CDP authorisation for genetic data, offence data, file interconnection, national ID numbers, biometric data and public-interest processing (art. 20); Communication to the CDP of the departments and categories of persons with direct access to data (art. 22); Standard processing principles: lawfulness, purpose limitation, proportionality, accuracy, limited retention, security
DPO required
No: appointment of a DPO is discretionary for businesses; ministries must designate CDP focal points for the census and declaration of personal-data files (Directive No. 2757 of 24 June 2014).
Registration
Yes: notification to the CDP for processing generally, prior authorisation for the art. 20 categories, and a reasoned-opinion ('avis') regime for state processing (arts. 18-21).
Cross-border transfers
Transfers to a third country only where it ensures a sufficient level of protection, with prior INFORMATION to the CDP before any transfer (art. 49); punctual non-massive transfers to non-sufficient destinations ride express consent or necessity (life, public interest, legal claims, contract) (art. 50); the CDP may authorise other non-adequate transfers on a reasoned application where the controller offers sufficient guarantees (art. 51). Inbound rule: the CDP verifies protection before processing of data originating abroad (art. 49 al. 3). (Verified from the archived text 2026-07-11, S27.)
Breach notification
No mandatory breach-notification protocol under the 2008 law.
Penalties
CDP administrative fines of XOF 1,000,000 to 100,000,000, plus warning, injunction, provisional (three-month) then definitive withdrawal of authorisation, and urgent measures (processing interruption, data locking, prohibition); criminal sanctions of one to seven years' imprisonment and fines of XOF 500,000 to 10,000,000 (Penal Code art. 431-14).
Authority
Commission de Protection des Données Personnelles (CDP)
Verified 2026-07-10
Access to information
Law No. 2025-15 on Access to Information IN FORCE
The regulator
Authority
Commission de Protection des Données Personnelles (CDP)