§ Dossier · WEST AFRICA · updated 22 July 2026
in force
DP law status
Law No. 2019-014 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 2019-014 of 29 October 2019 on the Protection of Personal Data IN FORCE
commenced 2019-10-29 (Journal Officiel of 29 October 2019; the IPDCP it creates launched 28 March 2025) · Official full text ↗
- Scope
- Collection, processing, storage and transmission of personal data by public or private entities in Togo, protecting the privacy of natural persons; the standard francophone-family exclusions apply.
- Key obligations
- Three prior-formality regimes with the IPDCP: declaration, authorisation, and request-for-opinion ('avis'), by processing category; Prior IPDCP authorisation for sensitive processing incl. biometric data and international transfers; Standard processing principles with data subject rights to information, access, objection, rectification and erasure; First operational workstream: video-surveillance declaration/authorisation (launched July 2025)
- DPO required
- No general DPO obligation - the 'correspondant a la protection des donnees' (arts. 75-78) is OPTIONAL: designating one (notified to the Instance, art. 77) exempts the controller from certain prior formalities (art. 6 context); the correspondant has protected status (no employer sanction for exercising the role, discharged only via the Instance, arts. 75, 78). Verified from the archived text 2026-07-11.
- Registration
- Yes: declaration/authorisation/avis formalities with the IPDCP; the video-surveillance regime is the first to be operationalised (July 2025).
- Cross-border transfers
- CORRECTED from the text 2026-07-11 (the blanket 'prior authorisation' description was imprecise): transfers to a third country require that it ensure a SUFFICIENT level of protection, and the controller must INFORM the Instance beforehand, which issues a reasoned opinion (avis motive) (art. 28). Punctual, non-massive transfers to non-sufficient destinations are allowed with the data subject's express consent or where necessary for vital interests, public interest, legal claims, or contract performance/pre-contractual measures (art. 29). The Instance may AUTHORISE, on a reasoned application, transfers to non-adequate destinations where the controller offers sufficient guarantees (art. 30). Distinctive: before processing personal data ORIGINATING ABROAD, the Instance must verify that the controller ensures sufficient protection (art. 31); envisaged third-country transfers appear in declaration/authorisation filings.
- Breach notification
- None - the law imposes preventive security obligations only (art. 52: access control, audit trails, backups; art. 51 confidentiality) with NO duty to notify the Instance or data subjects of a personal-data breach. Verified from the archived text 2026-07-11; do not assert a breach-notification duty for Togo.
- Penalties
- Administrative (arts. 70-73, image-verified): warning and mise en demeure (art. 70); on non-compliance, provisional 3-month withdrawal of authorisation becoming definitive if uncorrected, and a fine of up to XOF 100,000,000 (art. 71); urgent measures - 3-month processing interruption or data blocking, a compliance injunction with a daily astreinte of up to XOF 5,000,000 (not against State processing), and rappel a l'ordre (art. 72); conservatory measures incl. bailiff-sealed equipment for processing without prior formalities (art. 73); appeals to the administrative chamber of the Supreme Court (art. 74). Criminal (arts. 79-93, image-verified): processing without prior formalities, unauthorised national-ID-number processing, security failures, sensitive-data and criminal-record offences, over-retention and harmful disclosure - 1-5 years' imprisonment and/or XOF 1,000,000-10,000,000 (negligent variants 1-3 years and/or XOF 500,000-5,000,000); fraudulent collection and opposition-right violations - 1-5 years and/or XOF 5,000,000-20,000,000 (arts. 84-85); health-research violations and purpose diversion - 1-5 years and/or XOF 5,000,000-25,000,000 (arts. 88, 91); negligent disclosure - 6 months-2 years and/or XOF 500,000-2,000,000; obstruction of the Instance - 6 months-2 years and/or XOF 1,000,000-10,000,000 (art. 93). All figures re-read from page images (contract v1.11) 2026-07-11.
- Authority
- Instance de Protection des Données à Caractère Personnel (IPDCP; created by the law, organised by 2024 decree, launched 28 March 2025)
Verified 2026-07-11
Access to information
Law No. 2016-006 on Freedom of Access to Information and Public Documentation IN FORCE
The regulator
- Authority
- Instance de Protection des Données à Caractère Personnel (IPDCP)
- Website
- https://ipdcp.tg ↗
- Established
- 2024
- Operational
- Yes
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Togo
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.