Law No. 29-2019 on the Protection of Personal Data
Loi n° 29-2019 du 10 octobre 2019 portant protection des données à caractère personnel articles 2, 3, 5 à 12, 31 à 45, 63 à 70 et 79 à 91 (champ d'application, principes, formalités préalables et obligations du responsable de traitement)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Obtain the data subject's consent before processing their personal data, unless a legal obligation, public-interest mission, vital-interest, or another statutory ground applies.
- File a prior declaration of processing with the national commission, unless the processing is exempt, requires the commission's prior authorization under article 37, or requires a presidential decree issued after the commission's opinion under article 40.
- Choose a processor offering sufficient technical and organisational security guarantees, govern the engagement by a written contract confining the processor to your instructions, and process personal data under your own or the processor's authority only on the controller's instructions.
- Keep processing confidential and take precautions appropriate to the data and the risk to preserve its security, including against unauthorised access, alteration or loss.
- Keep a written register of your processing activities and make it available to the national commission on demand, and cooperate with the commission when it asks.
- Carry out a data protection impact assessment before a type of processing likely to create a high risk to the rights and freedoms of natural persons, and designate a data protection officer where article 83 requires one.
What it reaches
Obligation class
Consent, Licensing, Security, Governance, DPIA
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 2 applies the Law to the collection, processing, transmission, storage or use of personal data by a natural person, the State, decentralised administrative entities, or a legal person of public or private law, whether the controller is established on Congolese territory or uses processing means located there.
Article 3 excludes only processing by a natural person for exclusively personal or domestic activities, where the data is not destined for systematic communication to third parties or dissemination, and temporary copies made for the technical transmission of, and access to, a digital network.
Article 5 conditions processing on the data subject's consent, unless the processing is necessary to comply with a legal obligation, perform a public-interest mission or exercise public authority, perform a contract to which the data subject is party, or safeguard the data subject's vital interests or fundamental rights.
Articles 6 to 10 state the Law's principles: processing is lawful, fair and transparent; personal data is kept no longer than its purpose requires; the data is accurate and updated where necessary; the data subject is given the transparency information the Law requires; and processing is kept confidential, in particular where it involves transmission over a network.
Article 11 requires the controller to choose a processor offering sufficient technical and organisational security guarantees and to govern the engagement by a written contract confining the processor to the controller's instructions, and Article 12 confines anyone who accesses personal data under the controller's or the processor's authority to processing on the controller's instructions alone.
Articles 33 to 36 require most processing to be declared to the national commission, Article 37 requires the commission's prior authorization instead for processing bearing on genetic data or health research, offence, conviction or security-measure data, a file interconnection, a national identification number, or biometric data, and Article 40 requires a decree of the President of the Republic, after the commission's reasoned opinion, for processing carried out on behalf of the State, a public establishment, a decentralised administrative entity, or a private-law legal person managing a public service.
Article 63 requires the controller to keep processing confidential, and Article 64 requires precautions appropriate to the nature of the data and the risks the processing presents to preserve data security. Articles 67 to 69 require a written register of processing activities, made available to the commission on demand, and Article 70 requires cooperation with the commission on request.
Article 79 requires a data protection impact assessment before a type of processing likely to create a high risk to the rights and freedoms of natural persons, and Articles 83 to 91 require the designation of a data protection officer, on the conditions Article 83 sets, given the position Article 87 prescribes and the tasks Article 90 lists.
Article 101 requires the Law's publication in the Journal Officiel de la République du Congo and its execution as law of the State, and it was signed at Brazzaville on 10 October 2019. The Journal Officiel de la République du Congo published the Law in its No. 45-2019 issue of Thursday, 7 November 2019, and no provision of the Law defers its own entry into force to a later date.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Text of Law No. 29-2019
published in the Journal Officiel de la République du Congo No. 45-2019, reproduced by the Secrétariat Général du Gouvernement (sgg.cg)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.