Law / Benin

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Loi n°2017-20 du 20 avril 2018 Livre V, Protection des Données à Caractère Personnelle, portant Code du Numérique en République du Bénin, arts. 379-390, 393, 405-414, 424-426 et 428-436 (principes généraux, licité et obligations des responsables de traitement)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 20 April 2018.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain a lawful basis, ordinarily the data subject's consent, before collecting, processing, transmitting, storing, or using their personal data, unless a specific legal exception applies.
  • Collect personal data only for determined, explicit, and legitimate purposes, and do not process it further in a way incompatible with those purposes.
  • Keep personal data accurate, correct or erase inaccurate or incomplete data, and do not keep it in identifiable form beyond what its purpose requires.
  • Choose a processor offering sufficient security and confidentiality guarantees, fix the processor's obligations in a written contract, and ensure the processor acts only on your documented instructions.
  • Where two or more controllers jointly determine the purposes and means of a processing, allocate your respective obligations toward data subjects in a transparent arrangement made available to them.
  • Declare each processing of personal data to the Autorité de Protection des Données Personnelles (APDP) before implementing it, or obtain the Autorité's prior authorization where the processing falls into one of its listed higher risk categories.
  • Implement data protection by design and by default, including pseudonymization and data minimization, so that only the personal data necessary to each specific purpose is processed by default.
  • Implement appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction, or damage, including pseudonymization and encryption where appropriate, and test their effectiveness regularly.
  • Carry out a data protection impact assessment before a processing likely to create a high risk to individuals' rights and freedoms, and consult the Autorité first where the assessment shows a risk you cannot mitigate.
  • Designate a data protection officer where you are a public body, or your core activities require regular and systematic large scale monitoring or large scale processing of sensitive personal data, and publish that officer's contact details.
  • Keep a written record of your processing activities, covering the purposes, the categories of data subjects and data, the recipients, retention periods, and security measures, and make it available to the Autorité on request.

What it reaches

Obligation class

Consent, Governance, Security, DPIA, Retention, Licensing

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Benin's comprehensive personal-data statute, deliberated and adopted by the National Assembly on 13 June 2017 and promulgated by the President on 20 April 2018 after two Constitutional Court conformity decisions, repealing the earlier Loi n°2009-09 du 24 mai 2009.

Articles 379 to 382 set the Book's object and its material and territorial scope, reaching collection, processing, transmission, storage, and use of personal data by a natural person, the State, local governments, and other public or private bodies, subject only to a narrow exclusion for purely personal or domestic processing not intended for communication or diffusion to third parties.

Article 383 requires personal data to be processed lawfully, fairly, and transparently, for determined and legitimate purposes, kept accurate, and retained no longer than those purposes require. Articles 384 and 385 add the transparency and confidentiality and security principles that run through the rest of the Book.

Article 386 requires a controller to choose a processor offering sufficient security and confidentiality guarantees and to fix the processor's obligations in a written contract, Article 387 lists the controller's own accountability duties, and Article 388 requires joint controllers to allocate their respective obligations by a transparent arrangement made available to data subjects.

Articles 389 and 390 make consent the ordinary basis for lawful processing, subject to exceptions for a legal obligation, a public interest task, a contract, or safeguarding vital interests, and set the conditions a valid consent must meet, including that it be freely given, specific, and withdrawable at any time. Article 393 requires that any interconnection of files serve a legitimate legal or statutory objective and respect the relevance of the data interconnected.

Articles 405 to 414 require a controller to declare each processing to the Autorité de Protection des Données Personnelles (APDP) before implementing it, or to obtain the Autorité's prior authorization for the higher risk categories it lists, subject to the simplified declarations and exemptions the Autorité may grant.

Article 424 requires data protection by design and by default, including pseudonymization and data minimization, so that only the data necessary to a specific purpose is processed by default. Articles 425 and 426 require confidential processing and appropriate technical and organizational security measures, including pseudonymization, encryption, and regular testing of their effectiveness.

Articles 428 and 429 require a data protection impact assessment before a processing likely to create a high risk to individuals' rights and freedoms, followed by prior consultation with the Autorité where the risk cannot be mitigated. Articles 430 to 432 require a data protection officer for a public body, or for large scale monitoring or large scale sensitive data processing, and set that officer's independence and functions.

Article 433 bars keeping personal data in identifiable form beyond what its purpose requires, and Article 435 requires a written record of processing activities available to the Autorité on request.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app