Law / Benin

Benin

11 of 13 named instruments researched to a stage, across five of the six areas of law we track: 11 in force. As of 19 September 2026.

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (338 words)

Benin has not enacted a binding statute imposing an affirmative AI-transparency or output-labeling duty (a duty to disclose that content is AI-generated, to label or watermark synthetic output, or to disclose that a user is talking to a bot).

It does have an outright prohibition adjacent to that question: the Digital Code's Article 576 criminalizes publishing an unauthorized montage of a person's words or image on the internet unless it is evident that it is a montage or this is expressly stated, which functions as a labeling-linked safe harbor for synthetic or manipulated media of a real person rather than an affirmative labeling mandate.

Benin's Council of Ministers adopted a Stratégie Nationale d'Intelligence Artificielle et des Mégadonnées (SNIAM) 2023-2027 on 18 January 2023, a published policy document organized into four programs covering the deployment of AI use cases in priority sectors (education, health, agriculture, and others), human-capacity building, support for training and research, and an AI-and-big-data governance framework; one governance action proposes creating a controlled environment for AI-initiative development grounded in Articles 406 to 408 of the Digital Code, which are the code's prior-declaration and prior-authorization provisions for certain categories of personal-data processing, but none of the strategy's programs states a specific, binding transparency or content-labeling duty on a developer or deployer, and no numbered bill, Journal Officiel citation, or public draft legal text implementing it was located.

Benin's existing binding statutes touching AI-adjacent activity address other duties too: the Digital Code's Article 401 bars a decision that produces legal effects for a person, or otherwise significantly affects them, from resting solely on automated processing, including profiling, and gives the person a right to know and contest the logic behind such a decision, but that is a data-subject right within the personal-data regime the Digital Code's Livre V creates, rather than a content-labeling duty.

As of 2026, Benin has named a Minister for Digital Transformation and Innovation with responsibility for the national AI strategy, reported in secondary coverage as a step toward a dedicated ministry for AI governance.

AI prohibited practices

Digital Code of the Republic of Benin, Livre VI, Article 576 (Unauthorised Image or Voice Montage / Synthetic-Media Prohibition)

Loi n°2017-20 du 20 avril 2018 Livre VI, Article 576 (Atteinte à la représentation de la personne), portant Code du Numérique en République du BéninLoi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

In force since 20 April 2018. Binds public and private bodies.

What this law does

Article 576 of the Digital Code, within Livre VI's cybercriminality title, punishes publishing on the internet, by any means, a montage made with a person's words or image without their consent, by five years' imprisonment and a fine of 25,000,000 CFA francs, cumulatively rather than as alternative penalties.

The prohibition does not reach a montage where it is evident that it is a montage, or where this is expressly stated, which functions as a safe harbor tied to disclosure rather than an affirmative duty to label synthetic content. The provision is not limited to AI-generated media by its own terms: a manually edited composite of a person's words or image falls within it just as a synthetic one does.

What it requires

Privacy law6 instruments, 6 in force

Research summary (377 words)

Benin's comprehensive personal-data statute is Livre V (Protection des Données à Caractère Personnel) of Loi n°2017-20 portant Code du Numérique en République du Bénin, adopted by the National Assembly on 13 June 2017 and promulgated on 20 April 2018, repealing the country's first data-protection statute, Loi n°2009-09 du 24 mai 2009.

It applies to collection, processing, transmission, storage, and use of personal data by a natural person, the State, local governments, and other actors, carries a heightened regime for sensitive categories (racial or ethnic origin, political opinions, religion or beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health data, and sexual life or orientation data), and bars a legal-effect or significantly-affecting decision from resting solely on automated processing, including profiling, while giving the affected person a right to know and contest the underlying logic.

A controller must notify the country's data-protection authority and the affected person without delay of any security breach affecting personal data, and processing a child's personal data in connection with an information-society service offered directly to them requires the child's own consent from age sixteen or a parent's or guardian's consent below that age.

Cross-border transfer requires the Autorité de Protection des Données Personnelles (APDP), the independent administrative authority the law creates, to find that the destination country or organization assures a level of protection equivalent to Benin's own.

Enforcement combines administrative sanctions the APDP can pronounce directly, including a two-tier pecuniary fine capped at 50,000,000 CFA francs for a first violation and 100,000,000 CFA francs (or 5% of turnover, itself capped at that same figure) for a repeat violation within five years, with a private right of action letting a data subject seek damages for the harm suffered.

Livre V itself carries a dedicated criminal-infractions chapter (Art. 460-461) reaching unauthorised processing, processing without required formalities or security measures, unlawful collection, unauthorised cross-border transfer, and disregard of a data subject's rights, punishable by six months' to ten years' imprisonment and a fine of 10,000,000 to 50,000,000 CFA francs (a negligent formalities failure alone draws a fine only, 5,000,000 to 50,000,000 CFA francs), and Livre VI elsewhere in the Code adds standalone criminal offenses for using personal data to deceive people into disclosing further data or to embezzle funds.

Breach notification

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, notification des ruptures de sécurité

Loi n°2017-20 du 20 avril 2018, Livre V, art. 427 (notification des ruptures de sécurité)Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

In force since 20 April 2018. Binds public and private bodies.

What this law does

Article 427 requires a controller to notify the Autorité de Protection des Données Personnelles (APDP) and the affected person without delay of any security breach that has affected their personal data, and requires a processor to warn the controller without delay of any breach affecting data it processes on the controller's behalf.

The notification must describe the nature of the breach, including where possible the categories and approximate number of affected data subjects and personal data records, the contact point for more information, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

Article 427 excuses notice to the affected person only where the controller had already applied protective measures such as encryption that make the data unintelligible, where later measures removed the high risk, or where it would take disproportionate effort and the controller makes an equally effective public communication instead. The Book states no fixed number of hours or days for either notification, so both run only from becoming aware of the breach and without delay.

What it requires

Comprehensive regime

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel)

Loi n°2017-20 du 20 avril 2018 Livre V, Protection des Données à Caractère Personnelle, portant Code du Numérique en République du Bénin, arts. 379-390, 393, 405-414, 424-426 et 428-436 (principes généraux, licité et obligations des responsables de traitement)Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

In force since 20 April 2018. Binds public and private bodies.

What this law does

Benin's comprehensive personal-data statute, deliberated and adopted by the National Assembly on 13 June 2017 and promulgated by the President on 20 April 2018 after two Constitutional Court conformity decisions, repealing the earlier Loi n°2009-09 du 24 mai 2009.

Articles 379 to 382 set the Book's object and its material and territorial scope, reaching collection, processing, transmission, storage, and use of personal data by a natural person, the State, local governments, and other public or private bodies, subject only to a narrow exclusion for purely personal or domestic processing not intended for communication or diffusion to third parties.

Article 383 requires personal data to be processed lawfully, fairly, and transparently, for determined and legitimate purposes, kept accurate, and retained no longer than those purposes require. Articles 384 and 385 add the transparency and confidentiality and security principles that run through the rest of the Book.

Article 386 requires a controller to choose a processor offering sufficient security and confidentiality guarantees and to fix the processor's obligations in a written contract, Article 387 lists the controller's own accountability duties, and Article 388 requires joint controllers to allocate their respective obligations by a transparent arrangement made available to data subjects.

Articles 389 and 390 make consent the ordinary basis for lawful processing, subject to exceptions for a legal obligation, a public interest task, a contract, or safeguarding vital interests, and set the conditions a valid consent must meet, including that it be freely given, specific, and withdrawable at any time. Article 393 requires that any interconnection of files serve a legitimate legal or statutory objective and respect the relevance of the data interconnected.

Articles 405 to 414 require a controller to declare each processing to the Autorité de Protection des Données Personnelles (APDP) before implementing it, or to obtain the Autorité's prior authorization for the higher risk categories it lists, subject to the simplified declarations and exemptions the Autorité may grant.

Article 424 requires data protection by design and by default, including pseudonymization and data minimization, so that only the data necessary to a specific purpose is processed by default. Articles 425 and 426 require confidential processing and appropriate technical and organizational security measures, including pseudonymization, encryption, and regular testing of their effectiveness.

Articles 428 and 429 require a data protection impact assessment before a processing likely to create a high risk to individuals' rights and freedoms, followed by prior consultation with the Autorité where the risk cannot be mitigated. Articles 430 to 432 require a data protection officer for a public body, or for large scale monitoring or large scale sensitive data processing, and set that officer's independence and functions.

Article 433 bars keeping personal data in identifiable form beyond what its purpose requires, and Article 435 requires a written record of processing activities available to the Autorité on request.

What it requires

Cross border transfer

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, transfert transfrontalier de données

Loi n°2017-20 du 20 avril 2018, Livre V, arts. 391-392 (transfert transfrontalier de données)Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

In force since 20 April 2018. Binds public and private bodies.

What this law does

Article 391 permits transferring personal data to a third country or an international organization only once the Autorité has found that the destination assures a level of data protection equivalent to this Book, weighing the rule of law, the data protection rules, and the available remedies there, and requires the Autorité's prior authorization before any actual transfer takes place.

Article 392 lets a transfer proceed despite an inadequate destination where the data subject has expressly consented, the transfer is necessary to perform or negotiate a contract with or for the data subject, it serves an important public interest or a legal claim, it protects vital interests, it comes from a public register open to consultation, or the Council of Ministers has authorized it by decree on the Autorité's opinion after the controller shows sufficient privacy safeguards.

Article 435 requires a controller's register of processing activities to identify every transfer of personal data to a third country or international organization, including its identity and, where relied on, the documents evidencing appropriate safeguards.

What it requires

Data subject rights

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, droits des personnes concernées

Loi n°2017-20 du 20 avril 2018, Livre V, arts. 399-401, 415-423, 437-445 et 447 (droits des personnes concernées)Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

In force since 20 April 2018. Binds public and private bodies.

What this law does

Article 401 bars a court judgment assessing a person's conduct, and any decision producing legal effects for a person or significantly affecting them, from resting solely on automated processing, including profiling, of data meant to evaluate aspects of their personality, unless the decision is authorized by a contract or a legal provision that lets the person put forward their point of view.

Article 415 requires a controller to tell a data subject, no later than when their data is collected, the controller's identity, the purposes of the processing, the recipients, whether the automated decision making Article 401 addresses is in use, the retention period, and the data subject's rights of objection, access, rectification, and erasure.

Article 416 requires the same information within a reasonable time and at most thirty days after obtaining data that was not collected from the data subject, or at the first communication or disclosure of it if that comes sooner.

Article 437 lets a data subject demand confirmation of whether their data is processed, the purposes and categories involved, the recipients, any envisaged transfer to a third country, the retention period, and, where a decision under Article 401 is in play, the logic behind it, answered within sixty days.

Article 438 gives a data subject a right to receive, in a structured, commonly used, and machine readable format, personal data they provided under a consent or a contract, and to have it transmitted directly to another controller where technically possible.

Article 440 lets a data subject object at any time, on legitimate grounds, to processing of their data, and object free of charge and without any justification where the processing is for direct marketing, charitable, or political prospecting.

Article 441 lets a data subject demand rectification, completion, updating, blocking, or erasure of personal data that is inaccurate, incomplete, ambiguous, outdated, irrelevant, or unlawfully processed, and requires the controller to pass the correction on to anyone the data was disclosed to.

Article 443 requires a controller who made a data subject's personal data public to take reasonable steps, including technical measures, to tell third parties processing that data of an erasure request, unless the processing serves free expression, a legal obligation, an important public health reason, archiving, research, or statistical purposes, or a legal claim.

Article 447 lets an incapacitated adult's rights under this Book be exercised by a cohabiting spouse or partner, or in order, an adult child, a parent, or a sibling, or a court appointed guardian, involving the data subject as far as their understanding allows.

What it requires

Enforcement supervision

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, Autorité de Protection des Données Personnelles, sanctions et infractions pénales

Loi n°2017-20 du 20 avril 2018, Livre V, arts. 448-490 et Livre VI, arts. 514-517 (Autorité, sanctions et infractions pénales)Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

In force since 20 April 2018. Binds public and private bodies.

What this law does

Article 462 creates the Autorité de Protection des Données Personnelles (APDP) to oversee this Book and privacy generally in Benin, and Article 463 makes it an independent administrative body with legal personality that receives no instruction from any administrative or political authority.

Article 448 lets a data subject complain to the Autorité about a processing they consider violates this Book, Article 449 gives them an effective judicial remedy against the Autorité if it does not act within ninety days, Article 450 gives them the same remedy against the controller or processor, and Article 451 lets anyone who suffered material or moral harm from a violation of this Book seek reparation from the controller or processor, with joint liability where more than one took part in the same processing.

Article 452 lets the Autorité warn a controller and give formal notice to end a violation within a period of no more than eight days.

Article 454 lets the Autorité, once a controller ignores that notice, impose a pecuniary sanction, an order to stop processing, a withdrawal of authorization, or a lock on the data concerned, and Article 455 caps that pecuniary sanction at fifty million CFA francs for a first violation, rising to one hundred million CFA francs, or five percent of the controller's last closed financial year turnover excluding tax up to that same figure, for a violation repeated within five years.

Article 459 lets the Autorité make a sanction public, and Articles 486 to 489 let it demand information, cooperation, and access to premises in the course of its investigations.

Article 460 makes obstructing the Autorité, processing without required prior formalities or security measures, unlawfully collecting or misappropriating personal data, an unauthorized cross border transfer, and disregarding a data subject's rectification, objection, information, or access rights into offenses, and Article 461 punishes them with six months to ten years' imprisonment and a fine of ten million to fifty million CFA francs, or either penalty alone, reduced to a fine only of five million to fifty million CFA francs for a negligent failure to complete prior formalities.

Elsewhere in the Code, Article 514 fines an unsolicited electronic message sent without an unsubscribe link, Article 515 punishes using a person's or entity's identity to deceive message recipients or website users into disclosing personal or confidential data with five years' imprisonment and a twenty five million CFA franc fine, and Article 516 punishes using personal data or confidential information obtained that way to embezzle public or private funds with ten years' imprisonment and a one hundred million CFA franc fine.

Loi n°2020-35 du 06 janvier 2021 later amended three articles of the Code, including Article 464 within this Titre's composition rules for the Autorité, and the amending law's own content beyond that is not established here.

What it requires

Sensitive categories

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, données sensibles et mineurs

Loi n°2017-20 du 20 avril 2018, Livre V, arts. 394-404, 407 et 446 (données sensibles et mineurs)Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

In force since 20 April 2018. Binds public and private bodies.

What this law does

Article 394 prohibits processing personal data revealing racial or ethnic origin, political opinions, religion or beliefs, trade union membership, genetic data, biometric data used to uniquely identify a person, health data, or data about a person's sex life or sexual orientation, subject to listed exceptions such as the data subject's explicit consent or data the person has manifestly made public.

Article 395 confines processing of personal data about criminal convictions and related security measures to courts, public authorities, and other bodies the law specifically authorizes, and bars a complete register of criminal convictions outside the Autorité's control. Article 402 requires a controller processing the data Articles 394 and 395 cover to designate the categories of staff with access to it, keep that list available to the Autorité, and bind those staff to confidentiality.

Article 403 requires a controller relying solely on the data subject's written consent for that data to tell them beforehand the reasons for the processing and the categories of staff who will access it. Article 404 bars an employer or another party a data subject depends on from relying on that consent where the dependency prevents the data subject from freely refusing, unless the processing grants the data subject a benefit.

Article 407 requires the Autorité's prior authorization before processing the data Article 394 or Article 397 covers, a national identification number, or biometric data. Article 446 makes processing a minor's personal data in connection with an information society service offered directly to them lawful once the minor is at least sixteen years old, and otherwise requires the consent of the holder of parental responsibility, verified as far as available technology allows.

What it requires

Scraping law2 instruments, 2 in force

Research summary (380 words)

Open-web crawling of public pages carries no dedicated Beninese statute.

The applicable authority for unauthorized-access questions is Livre VI, Titre I, Chapitre III of Loi n°2017-20 portant Code du Numérique en République du Bénin, which criminalizes intentionally and without right accessing or remaining present in all or part of a computer system (Art. 507), with an aggravated penalty where the access is accompanied by fraudulent intent, exceeds an authorized level of access, results in data being suppressed or modified, or is committed in violation of the system's security measures; no located Beninese court decision construes how authorization is read for a public, unauthenticated page.

The same Livre separately exempts a search-engine or indexing provider from liability for its search results, and an online host from liability for content stored at a user's request, each conditioned on the provider not originating, selecting the recipient of, or modifying the content in question (Art. 505 and 506), which bears on an aggregator or crawler's own exposure rather than on the underlying access question.

No statute or case law addressing terms-of-service enforceability (browsewrap versus clickwrap), or whether login or acceptance of terms changes the legal picture, was located; ordinary contract-formation principles under Beninese civil law would be the applicable general law for a contract-formation question, but this is unsettled rather than a specific regime.

Copyright protects a database only as a compilation, never through a separate sui generis right: Loi n°2005-30 du 05 avril 2006 protects a collection of works, folklore expressions, or simple facts or data, including encyclopedias, anthologies, and databases, as a protected work when the selection, coordination, or arrangement of its contents constitutes an intellectual creation (Art. 8), while excluding official texts, the news of the day, and bare ideas, facts, or data from copyright protection outright (Art. 9).

Personal-data reach over scraped public personal data is governed by Loi n°2017-20's Livre V, researched in full under the privacy topic; its scope provisions carry no publicly-available-data exemption beyond a narrow one for sensitive-category data the person has manifestly made public, so ordinary personal data scraped from a public source remains within the regime's reach.

No specific unfair-competition or misappropriation doctrine addressed to scraping, and no case law or regulatory statement giving robots.txt legal weight or addressing AI-training-specific access rules, was located.

Computer misuse

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybercriminalité), atteintes aux réseaux et systèmes d'information

Loi n°2017-20 du 20 avril 2018, Livre VI, Atteintes aux Réseaux et Systèmes d'Information, portant Code du Numérique en République du BéninLoi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

In force since 20 April 2018. Binds public and private bodies.

What this law does

Benin's general computer-misuse title, part of the cybercriminality and cybersecurity Book of the Digital Code.

Article 507 punishes intentionally and without right accessing or remaining present in all or part of a computer system with one to five years' imprisonment and a fine of 500,000 to 1,000,000 CFA francs, or either penalty alone; the aggravated form committed with fraudulent intent, and exceeding an authorized level of access to a computer system, are each punished at two to five years' imprisonment and a fine of 500,000 to 2,000,000 CFA francs, or either penalty alone.

Where any of these three forms results in the suppression, obtaining, or modification of the system's data, or an alteration of the system's operation, the penalty just described is doubled; where instead any of the three is committed in violation of the system's own security measures, the offense draws a separate, harsher penalty of ten to twenty years' imprisonment (réclusion criminelle) and a fine of 5,000,000 to 500,000,000 CFA francs (Art. 507).

Article 508 separately punishes intercepting, divulging, using, altering, or misappropriating computer data during its non-public transmission; Article 509 punishes causing an interruption of a computer system's normal operation; Article 510 punishes damaging, deleting, deteriorating, altering, or suppressing computer data; Article 511 punishes producing, selling, obtaining, importing, or distributing a device, program, password, or access code designed to commit any of the above offenses; Article 512 punishes falsifying computer data by introducing, modifying, altering, or erasing it.

Two liability exemptions sit earlier in the same Book: a provider of a search engine or content index is not liable for its search results, and an online host is not liable for information stored at a user's request, each conditioned on the provider not originating the content, not selecting its recipient, and not selecting or modifying it, and on the host acting to remove or disable access to illegal content once notified (Art. 505 and 506).

The title does not define "without right" for a public, unauthenticated web page specifically, and no Beninese court decision construing these articles in that context was located.

What it requires

Database right

Loi n°2005-30 relative à la protection du droit d'auteur et des droits voisins, exclusion des nouvelles du jour et protection des bases de données comme compilations

Loi n°2005-30 du 05 avril 2006 Exclusions des Nouvelles du Jour et des Bases de Données, relative à la protection du droit d'auteur et des droits voisinsLoi n°2005-30 du 05 avril 2006, official text as republished by WIPO Lex

In force since 5 April 2006. Binds public and private bodies.

What this law does

Benin's copyright statute, adopted by the National Assembly on 9 August 2005 and again on 12 January 2006 after a Constitutional Court conformity decision, promulgated on 5 April 2006.

Article 9 excludes official legislative, administrative, or judicial texts and their official translations, the news of the day, and ideas, procedures, systems, methods, concepts, principles, discoveries, or bare data from copyright protection outright, whether or not those are stated, described, explained, illustrated, or incorporated in a work.

Article 8 separately protects, as works, collections of works, folklore expressions, or bare facts or data, such as encyclopedias, anthologies, and databases, whether reproduced on a machine-readable medium or any other form, when the selection, coordination, or arrangement of their contents constitutes an intellectual creation; the protection reaches only that selection, coordination, or arrangement, and not the underlying facts or data themselves, and there is no separate sui generis database right of the EU kind.

Piracy of literary and artistic works, meaning reproduction without the prior authorization of the copyright or related-rights holders and the collective management body, is a criminal offense punished under Art. 108 to 110 by three months to two years' imprisonment and a fine of 500,000 to 10,000,000 CFA francs, or either penalty alone, without prejudice to damages.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (482 words)

Benin's Digital Code (Loi n°2017-20 portant Code du Numérique en République du Bénin, promulgated 20 April 2018) carries a dedicated network-security chapter, Livre VI, Titre I, Chapitre XIII (De la Sécurité des Réseaux).

Its Article 598 requires a vendor of an information and communication technology product to have an independent security expert, accredited by the ministry in charge of electronic communications, carry out a vulnerability test and a security assurance evaluation of the product, and to inform consumers of every vulnerability detected in it along with the solution recommended to remedy it.

The same Chapter separately binds a licensed electronic-communications network or service operator, a narrower defined term than a software or platform provider, to maintain a qualified system for detecting events that could affect its information systems' security, to submit those systems to a security audit performed by the Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI-BENIN) at the operator's own cost, and it fines the failure to maintain a previously established protection measure at 10,000,000 CFA francs (Articles 599-601); because that duty attaches to the licensed operator role rather than to any activity this corpus can flag an app against, it is recorded here rather than raised against a declared activity.

Livre VI, Titre II creates ANSSI-BENIN as the national authority over information-systems and network security across Beninese territory, with a mission running to centralizing requests for assistance after a security incident, maintaining a vulnerability database, and issuing security recommendations it enforces only inside public bodies, so it functions as a coordinating and advisory body over the private sector rather than as the source of a private security-reporting duty with its own clock.

Separately, Livre III (Des Prestataires de Services de Confiance) binds every qualified and non-qualified trust-service provider, an electronic-signature, seal, timestamp or website-authentication certification role, to take risk-proportionate technical and organizational security measures (Article 308), to notify Benin's designated control body of a security breach or integrity loss with a significant impact within 24 hours of becoming aware of it and to notify the affected party as well (Articles 309-310), and to undergo an independent conformity audit at least every 24 months (Articles 317-319); because the trust-service-provider role is likewise a licensed role no declared activity in this corpus expresses, it is recorded here rather than flagged.

No general reasonable-security or information-security-programme statute binding a business with no sector gate was located: the personal-data statute's own security-of-processing duties sit inside Livre V (Protection des Données à Caractère Personnel), the jurisdiction's comprehensive privacy regime already researched under the privacy topic and carrying its own duty to notify the data-protection authority and the affected person of a security breach, which is not repeated here.

No located primary source confirms or rules out whether the regional Banque Centrale des États de l'Afrique de l'Ouest (BCEAO) has issued a cybersecurity or information-technology risk-management directive binding a licensed financial institution in Benin.

Product security requirements

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybersécurité), sécurité des réseaux et essai de vulnérabilité des produits

Loi n°2017-20 du 20 avril 2018, Livre VI, Titre I, Chapitre XIII, Article 598, portant Code du Numérique en République du BéninLoi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

In force since 20 April 2018. Binds private bodies.

What this law does

A vendor of an information and communication technology product must have an independent security expert, accredited by the ministry in charge of electronic communications, carry out a vulnerability test and a security assurance evaluation of the product. The vendor must then inform consumers of every vulnerability detected in the product, along with the solution recommended to remedy it.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (268 words)

Benin has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is Loi n°2005-30 du 05 avril 2006 relative à la protection du droit d'auteur et des droits voisins, which excludes the news of the day and bare ideas, facts, or data from copyright protection outright (Art. 9), so a bare fact or news item is never protectable regardless of who first reported it.

The same Law lets the press, broadcasting, and television, without needing the author's authorization but subject to naming the author and source, reproduce for informational purposes political, economic, or socio-cultural articles and public speeches delivered at political, judicial, administrative, or religious gatherings, provided the reproduction right has not been expressly reserved by the rights holder (Art. 16), and separately lets a photographer, filmmaker, or broadcaster record, reproduce, and communicate to the public works encountered while covering a current event, to the extent justified by the informational purpose (Art. 17).

Neither exception is capped at a headline-length or short-extract threshold, the Art. 16 exception is not confined to the press industry, and no reported Beninese decision applies either to a systematic news aggregator as opposed to a traditional press outlet.

The Law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists either, though Art. 16's own express-reservation proviso functions as an author-side reservation mechanism for the press-reproduction exception specifically.

Snippet reproduction

Loi n°2005-30 relative à la protection du droit d'auteur et des droits voisins, exception de reproduction de presse et de comptes rendus d'actualité, et exclusion des nouvelles du jour

Loi n°2005-30 du 05 avril 2006 Exception de Reproduction de Presse et d'Actualité, relative à la protection du droit d'auteur et des droits voisinsLoi n°2005-30 du 05 avril 2006, official text as republished by WIPO Lex

In force since 5 April 2006. Binds public and private bodies.

What this law does

Article 9 excludes official legislative, administrative, or judicial texts and their official translations, the news of the day, and ideas, procedures, systems, methods, concepts, principles, discoveries, or bare data from copyright protection outright: a bare fact, or the news of the day as such, is never a protected work under Beninese law, whichever outlet reports it first.

Article 16 lets the press, broadcasting, or television reproduce, for informational purposes and subject to naming the author and source, political, economic, or socio-cultural articles published in original or translated form, and public speeches delivered before political, judicial, administrative, or religious assemblies or at public political gatherings and official ceremonies, but only where the copyright holder has not expressly reserved the reproduction right.

Article 17 separately lets a photographer, filmmaker, or sound or visual broadcaster, when covering a current event, lawfully record, reproduce, and communicate to the public the literary works encountered in the course of that coverage, to the extent justified by the informational purpose.

Neither exception is capped at a headline-length or short-extract threshold, and neither is confined to the press industry; whether either reaches a systematic aggregator's reproduction of headlines and snippets, as opposed to a traditional press outlet's own reporting, has not been tested in a reported Beninese decision.

Benin has no separate press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no recognized hot-news or misappropriation doctrine distinct from ordinary copyright and unfair-competition law, and no located case law on hyperlinking or framed display.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.