Law / Democratic Republic of the Congo

Digital Code, Title III: Personal Data Protection

Code du numérique Titre III, Des données personnelles, Ordonnance-loi n° 23/010 du 13 mars 2023 (arts. 183 à 194, 204, 205, 219, 221 à 233, 243, 245, 246 et 254)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 March 2023.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the data subject's consent before processing their personal data, unless the processing is necessary to perform a legal obligation.
  • File a prior declaration with the Data Protection Authority before processing personal data, or obtain its prior authorization before processing genetic, medical, biometric, offense or conviction, national-identification, or cross-border-transfer data.
  • Keep personal data reliable, adequate, relevant, accurate and not excessive, and correct or erase it once it becomes inaccurate or incomplete.
  • Do not process personal data for historical, statistical or scientific purposes beyond its original collection unless one of the statutory safeguards applies, or process only anonymous data for that further purpose.
  • Implement technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or alteration, confine internal access to what each role requires, and train staff on their data protection duties.
  • Build data protection into the processing by design and by default, including pseudonymization, and process by default only the personal data necessary for each specific purpose.
  • Appoint a data protection officer where your processing is non-occasional, high-risk, or touches special-category or criminal-record data, and keep a written record of your processing activities available to the Data Protection Authority.
  • Govern any processor's engagement by a written contract confining it to your documented instructions, and require the processor not to engage a sub-processor without your prior written authorization.
  • Carry out a data protection impact assessment before processing likely to create a high risk to individuals' rights and freedoms, and consult the Data Protection Authority in advance where that assessment shows a high risk you have not sufficiently mitigated.

What it reaches

Obligation class

Consent, Licensing, Retention, Security, Design code, Governance, DPIA

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 184 subjects to Titre III the collection, processing, transmission, storage and use of personal data by the State, the provinces, decentralised and deconcentrated territorial entities, public or private legal persons and natural persons, whether the processing is automated or not and whether it takes place on national territory or abroad, and reaches processing bearing on public security, defence, and the investigation or prosecution of criminal offences subject to derogations fixed by other statutes.

Article 185 excludes only processing by a natural person for exclusively personal or domestic activities where the data is not destined for systematic communication to third parties or dissemination, temporary caching copies made for network transmission, and processing carried out by competent authorities for the prevention, detection, investigation and prosecution of criminal offences.

Articles 186 to 191 require most processing to be declared in advance to the Data Protection Authority and require its prior authorisation instead for processing bearing on genetic, medical or scientific-research data, offence or conviction data, a national identification number or telephone number, biometric data, or a transfer to a third country, fix what a declaration or authorisation request must contain, exempt a short list of low-risk processing, and give the Authority thirty days to decide, extendable once by thirty more, with silence read as acceptance.

Article 192 makes processing lawful only where the data subject has consented or the processing is necessary to perform a legal obligation, and article 193 states the lawfulness, fairness, transparency, confidentiality and storage-limitation principles, with an exception for data kept solely for public-interest archiving, scientific or historical research, or statistics.

Article 194 requires personal data to be reliable, adequate, relevant, accurate and not excessive, and requires inaccurate or incomplete data to be erased or corrected.

Article 204 bars further processing of personal data for historical, statistical or scientific purposes unless one of five listed safeguards applies, and admits such further processing outright where it uses anonymous data, and article 205 relieves a controller of any duty to identify a data subject solely to comply with Titre III.

Article 219 requires the controller to keep data accurate, confine internal access to what a role requires, train staff, keep processing software consistent with its own declaration, and implement technical and organisational measures against unauthorised or unlawful processing, accidental loss, alteration or disclosure, secure storage, verified access, an audit trail and backups.

Article 221 requires security measures proportionate to the data and the risk and requires that, by default, only the personal data necessary for each specific purpose is processed, and article 243 requires the controller to build in measures such as pseudonymisation from the moment it decides the means of processing, taking into account the state of the art, cost, and the nature, scope, context and purposes of the processing.

Articles 222 to 228 require a data protection officer where a listed condition applies, task the officer with advising the controller, monitoring compliance, and liaising with the Authority, and require a written record of processing activities available to the Authority on request, excusing small and medium enterprises and startups from the register and officer duties unless their processing is high-risk, non-occasional, or touches special-category or criminal-record data.

Articles 229 to 233 require a written contract governing a processor's engagement confining it to the controller's documented instructions, bar a processor from engaging a sub-processor without the controller's prior written authorisation, require the processor to keep its own record of processing, and bind anyone with access to personal data under the controller's or processor's authority to that authority's instructions alone.

Article 245 requires a data protection impact assessment before processing likely to create a high risk to individuals' rights and freedoms, and article 246 requires prior consultation with the Authority where that assessment shows a high risk the controller has not sufficiently mitigated, with the Authority answering within eight weeks, extendable by four more.

Article 254 permits interconnecting personal-data files only for a legitimate purpose and bars it from reducing a data subject's rights, freedoms or safeguards. Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_biometrics

Read the law

Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique
reproduced by the Autorité de Régulation de l'Électricité (are.gouv.cd)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app