Research hub / Togo
§ Dossier · WEST AFRICA · updated 22 July 2026

Togo

Regulator
Instance de Protection des Données à Caractère Personnel (IPDCP) ↗
Law
Law No. 2019-014 on the Protection of Personal Data ↗
Status
Law in force, enforcement not found
Authority
Instance de Protection des Données à Caractère Personnel (IPDCP), established 2024
in force
DP law status
Law No. 2019-014 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Law No. 2019-014 of 29 October 2019 on the Protection of Personal Data IN FORCE

commenced 2019-10-29 (Journal Officiel of 29 October 2019; the IPDCP it creates launched 28 March 2025) · Official full text ↗

Scope
Collection, processing, storage and transmission of personal data by public or private entities in Togo, protecting the privacy of natural persons; the standard francophone-family exclusions apply.
Key obligations
Three prior-formality regimes with the IPDCP: declaration, authorisation, and request-for-opinion ('avis'), by processing category; Prior IPDCP authorisation for sensitive processing incl. biometric data and international transfers; Standard processing principles with data subject rights to information, access, objection, rectification and erasure; First operational workstream: video-surveillance declaration/authorisation (launched July 2025)
DPO required
No general DPO obligation - the 'correspondant a la protection des donnees' (arts. 75-78) is OPTIONAL: designating one (notified to the Instance, art. 77) exempts the controller from certain prior formalities (art. 6 context); the correspondant has protected status (no employer sanction for exercising the role, discharged only via the Instance, arts. 75, 78). Verified from the archived text 2026-07-11.
Registration
Yes: declaration/authorisation/avis formalities with the IPDCP; the video-surveillance regime is the first to be operationalised (July 2025).
Cross-border transfers
CORRECTED from the text 2026-07-11 (the blanket 'prior authorisation' description was imprecise): transfers to a third country require that it ensure a SUFFICIENT level of protection, and the controller must INFORM the Instance beforehand, which issues a reasoned opinion (avis motive) (art. 28). Punctual, non-massive transfers to non-sufficient destinations are allowed with the data subject's express consent or where necessary for vital interests, public interest, legal claims, or contract performance/pre-contractual measures (art. 29). The Instance may AUTHORISE, on a reasoned application, transfers to non-adequate destinations where the controller offers sufficient guarantees (art. 30). Distinctive: before processing personal data ORIGINATING ABROAD, the Instance must verify that the controller ensures sufficient protection (art. 31); envisaged third-country transfers appear in declaration/authorisation filings.
Breach notification
None - the law imposes preventive security obligations only (art. 52: access control, audit trails, backups; art. 51 confidentiality) with NO duty to notify the Instance or data subjects of a personal-data breach. Verified from the archived text 2026-07-11; do not assert a breach-notification duty for Togo.
Penalties
Administrative (arts. 70-73, image-verified): warning and mise en demeure (art. 70); on non-compliance, provisional 3-month withdrawal of authorisation becoming definitive if uncorrected, and a fine of up to XOF 100,000,000 (art. 71); urgent measures - 3-month processing interruption or data blocking, a compliance injunction with a daily astreinte of up to XOF 5,000,000 (not against State processing), and rappel a l'ordre (art. 72); conservatory measures incl. bailiff-sealed equipment for processing without prior formalities (art. 73); appeals to the administrative chamber of the Supreme Court (art. 74). Criminal (arts. 79-93, image-verified): processing without prior formalities, unauthorised national-ID-number processing, security failures, sensitive-data and criminal-record offences, over-retention and harmful disclosure - 1-5 years' imprisonment and/or XOF 1,000,000-10,000,000 (negligent variants 1-3 years and/or XOF 500,000-5,000,000); fraudulent collection and opposition-right violations - 1-5 years and/or XOF 5,000,000-20,000,000 (arts. 84-85); health-research violations and purpose diversion - 1-5 years and/or XOF 5,000,000-25,000,000 (arts. 88, 91); negligent disclosure - 6 months-2 years and/or XOF 500,000-2,000,000; obstruction of the Instance - 6 months-2 years and/or XOF 1,000,000-10,000,000 (art. 93). All figures re-read from page images (contract v1.11) 2026-07-11.
Authority
Instance de Protection des Données à Caractère Personnel (IPDCP; created by the law, organised by 2024 decree, launched 28 March 2025)

Verified 2026-07-11

Access to information

Law No. 2016-006 on Freedom of Access to Information and Public Documentation IN FORCE

The regulator

Authority
Instance de Protection des Données à Caractère Personnel (IPDCP)
Website
https://ipdcp.tg ↗
Established
2024
Operational
Yes
Enforcing
No enforcement activity found
Publishes decisions
No

Enforcement record

No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Togo

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.