Law / Democratic Republic of the Congo

Democratic Republic of the Congo

13 of 15 named instruments researched to a stage, across four of the six areas of law we track: 13 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law 5
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (414 words)

The Democratic Republic of the Congo's comprehensive data-protection regime is Titre III (Des données personnelles) of the Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique, signed by President Félix-Antoine Tshisekedi Tshilombo at Kinshasa and in force from its own date of promulgation, 13 March 2023.

It binds the State, provinces, decentralised and deconcentrated territorial entities, and any public or private legal person or natural person, over automated or non-automated processing of personal data carried out on national territory or abroad, subject only to a narrow personal-or-domestic-use exclusion, a temporary-caching exclusion for network transmission, and a separate regime for processing by competent authorities for criminal-law-enforcement purposes.

Processing is lawful only where the data subject has consented or the processing is necessary to perform a legal obligation, and processing of racial, ethnic, political, religious or philosophical, refugee or stateless, trade-union, sex-life or health data is prohibited subject to enumerated exceptions.

A prior declaration to the Data Protection Authority is required for most processing, and prior authorisation is required before processing genetic, medical or research data, offence or conviction data, a national identification number or telephone number, biometric data, or before any cross-border transfer, and the Titre also carries a data protection impact assessment duty, a data protection officer duty, and a set of access, rectification, erasure, objection and portability rights for the data subject.

Titre IV creates the Autorité de Protection des Données (APD), an independent administrative authority with legal personality, to enforce Titre III. Personal data must be stored in the Democratic Republic of the Congo; transfer to a digital embassy, a third-country host, or an international organisation is permitted only where the APD finds an adequate level of protection, which functions as a data-localisation default rather than a merely 'moderate' cross-border-transfer posture.

A data breach must be notified to the APD and to the affected person without delay, with no fixed numerical deadline stated. Administrative sanctions for a Titre III breach range from 8,000,000 to 200,000,000 Congolese francs where the violation caused no serious harm, escalating to 5% of annual turnover or an order to cease processing for the gravest violations, and the State separately reserves the right to bring a criminal action.

Loi n° 20/017 du 25 novembre 2020 relative aux telecommunications et aux technologies de l'information et de la communication was named as a possible source of additional confidentiality duties for the telecommunications sector, but its primary text was not located, so no telecommunications-sector privacy instrument is recorded here.

Breach notification

Digital Code, Title III, personal data breach notification

Code du numérique, Titre III, art. 244 (violation de données à caractère personnel)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 244 requires the controller to notify the Data Protection Authority and the affected data subject, without delay, of any breach that has affected the data subject's personal data, and states no fixed number of hours or days for either notification. The same article requires a processor to warn the controller without delay of any breach of security affecting personal data it processes on the controller's behalf.

The notification must, at a minimum, describe the nature of the breach including, where possible, the categories and approximate number of affected data subjects and of personal data records concerned, give the name and contact details of the data protection officer or another contact point, describe the likely consequences, and describe the measures taken or proposed to address the breach.

Communicating the breach to the affected data subject is not required where the controller had applied protective measures, in particular ones that render the affected data unintelligible to an unauthorised person, such as encryption, where the controller has since taken measures that mean the high risk to the data subject's rights and freedoms is no longer likely to materialise, or where it would require disproportionate effort, in which case a public communication or an equally effective measure is made instead.

Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.

What it requires

Comprehensive regime

Digital Code, Title III: Personal Data Protection

Code du numérique Titre III, Des données personnelles, Ordonnance-loi n° 23/010 du 13 mars 2023 (arts. 183 à 194, 204, 205, 219, 221 à 233, 243, 245, 246 et 254)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 184 subjects to Titre III the collection, processing, transmission, storage and use of personal data by the State, the provinces, decentralised and deconcentrated territorial entities, public or private legal persons and natural persons, whether the processing is automated or not and whether it takes place on national territory or abroad, and reaches processing bearing on public security, defence, and the investigation or prosecution of criminal offences subject to derogations fixed by other statutes.

Article 185 excludes only processing by a natural person for exclusively personal or domestic activities where the data is not destined for systematic communication to third parties or dissemination, temporary caching copies made for network transmission, and processing carried out by competent authorities for the prevention, detection, investigation and prosecution of criminal offences.

Articles 186 to 191 require most processing to be declared in advance to the Data Protection Authority and require its prior authorisation instead for processing bearing on genetic, medical or scientific-research data, offence or conviction data, a national identification number or telephone number, biometric data, or a transfer to a third country, fix what a declaration or authorisation request must contain, exempt a short list of low-risk processing, and give the Authority thirty days to decide, extendable once by thirty more, with silence read as acceptance.

Article 192 makes processing lawful only where the data subject has consented or the processing is necessary to perform a legal obligation, and article 193 states the lawfulness, fairness, transparency, confidentiality and storage-limitation principles, with an exception for data kept solely for public-interest archiving, scientific or historical research, or statistics.

Article 194 requires personal data to be reliable, adequate, relevant, accurate and not excessive, and requires inaccurate or incomplete data to be erased or corrected.

Article 204 bars further processing of personal data for historical, statistical or scientific purposes unless one of five listed safeguards applies, and admits such further processing outright where it uses anonymous data, and article 205 relieves a controller of any duty to identify a data subject solely to comply with Titre III.

Article 219 requires the controller to keep data accurate, confine internal access to what a role requires, train staff, keep processing software consistent with its own declaration, and implement technical and organisational measures against unauthorised or unlawful processing, accidental loss, alteration or disclosure, secure storage, verified access, an audit trail and backups.

Article 221 requires security measures proportionate to the data and the risk and requires that, by default, only the personal data necessary for each specific purpose is processed, and article 243 requires the controller to build in measures such as pseudonymisation from the moment it decides the means of processing, taking into account the state of the art, cost, and the nature, scope, context and purposes of the processing.

Articles 222 to 228 require a data protection officer where a listed condition applies, task the officer with advising the controller, monitoring compliance, and liaising with the Authority, and require a written record of processing activities available to the Authority on request, excusing small and medium enterprises and startups from the register and officer duties unless their processing is high-risk, non-occasional, or touches special-category or criminal-record data.

Articles 229 to 233 require a written contract governing a processor's engagement confining it to the controller's documented instructions, bar a processor from engaging a sub-processor without the controller's prior written authorisation, require the processor to keep its own record of processing, and bind anyone with access to personal data under the controller's or processor's authority to that authority's instructions alone.

Article 245 requires a data protection impact assessment before processing likely to create a high risk to individuals' rights and freedoms, and article 246 requires prior consultation with the Authority where that assessment shows a high risk the controller has not sufficiently mitigated, with the Authority answering within eight weeks, extendable by four more.

Article 254 permits interconnecting personal-data files only for a legitimate purpose and bars it from reducing a data subject's rights, freedoms or safeguards. Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.

What it requires

Cross border transfer

Digital Code, Title III, cross-border transfer of personal data

Code du numérique, Titre III, arts. 201 à 203 (transfert des données personnelles)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 201 requires personal data to be stored or hosted in the Democratic Republic of the Congo, and permits transfer to a digital embassy, a host in a third State, or an international organisation only where the Data Protection Authority finds that the destination offers a level of protection equivalent and sufficient to Titre III's own, assessed against the rule of law and human rights, the general and sector legislation and the remedies available there, the existence of independent supervisory authorities, and the destination's international commitments on data protection; a controller must obtain the Authority's prior authorisation before any actual transfer, and every transfer remains subject to the Authority's regular control.

Article 202 lets a controller transfer personal data to a destination that does not meet that adequacy standard only where the data subject has given informed, explicit consent to the transfer, the transfer is necessary to perform or negotiate a contract with the data subject or in the data subject's interest, an important public interest or a legal claim requires it, the data subject's or another person's vital interests require it and the data subject cannot consent, or the transfer originates from a public register open to legitimate consultation, and it bars public authorities from relying on the first three of those grounds when they exercise their own public powers.

The same article lets the Council of Ministers, on the Authority's conforming opinion, authorise a transfer or a set of transfers to a destination that offers adequate and sufficient protection where the controller offers sufficient guarantees for privacy and fundamental rights, and it keeps the complete register of criminal convictions under the Authority's control and its custodians under professional secrecy.

Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.

What it requires

Data subject rights

Digital Code, Title III, rights of the data subject

Code du numérique, Titre III, arts. 200, 207 à 218, 220, 235 à 237, 240 à 242 et 248 (droits de la personne concernée)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 200 requires a controller communicating personal data to a partner or a processor to disclose its own identity and the data subject's rights, including the right to object to prospecting. Article 207 requires a controller relying solely on the data subject's written consent to disclose, before processing, the reasons the data is processed and the list of categories of staff who will access it, on top of the ordinary information duty.

Article 208 requires a controller to tell the data subject they may set instructions for managing their personal data after death, covering retention, erasure, communication and transmission to a chosen person, and lets the deceased's heirs, absent instructions, pursue those rights and obtain the data concerning the deceased.

Article 209 lets a data subject demand the information needed to know and contest the processing of their data, confirmation of whether it is processed, the purposes, the categories of data and recipients, the existence of automated decision-making including profiling, the data itself in intelligible form and its origin, any transfer to a third country, the retention period, and the existence of rights to rectification, erasure, restriction and complaint.

Article 210 requires an access copy within sixty days of the request, lets the Data Protection Authority grant a response extension or excuse manifestly abusive requests on the controller's contradictory application, and lets a controller defer disclosure of medical-research data where disclosure risks no harm to privacy but could seriously harm the research, until the research concludes.

Article 211 gives a data subject whose processing rests on consent or a contract and uses automated means the right to receive their data in a structured, commonly used, machine-readable format and to have it transmitted directly between controllers where technically possible, a right that does not apply to processing carried out under a public-interest mission or official authority.

Article 212 lets a person who proves their identity contact the Data Protection Authority to learn whether a government body's processing concerns them and obtain that information.

Article 213 gives a data subject the right to object at any time, on legitimate grounds, to processing of their data, requires the controller to offer, expressly and free of charge, the right to object before their data is first communicated to a third party or used for prospecting, and requires an answer within thirty days of the objection.

Article 214 lets a data subject demand rectification, updating or blocking of inaccurate, incomplete, ambiguous, outdated or unlawfully processed data, requires the controller to pass the correction on to every recipient within thirty days, and lets an heir demand the same update to reflect a data subject's death.

Article 215 gives a data subject the right to erasure within thirty days on the listed grounds, including that the data is no longer necessary, was unlawfully processed, or that the data subject withdrew consent with no other legal basis remaining.

Article 216 requires a controller that made a data subject's data public to take reasonable steps, including technical measures, to tell any third party processing it that the data subject has asked for the erasure of every link, copy or reproduction, subject to exceptions for freedom of expression, a legal obligation or public-interest mission, public health, archiving, research or statistics, and legal claims.

Article 217 requires the Data Protection Authority to adopt guidelines fixing the conditions for removing links to personal data and the criteria for restricting processing.

Article 218 routes a request touching data processed for State security, defence or public safety through an Authority member who investigates and orders any needed correction, and requires the Authority to have the relevant information communicated to the requester within thirty days where doing so does not compromise those interests.

Article 220 requires a controller to give the data subject, at the latest at collection, its identity, the purposes and legal basis, the categories of data, the recipients, the right to be delisted, the right to object to prospecting, whether a reply is mandatory or optional and the consequences of not replying, the rights of access and rectification, the right to withdraw consent, the right to complain to the Authority, the retention period, the existence of automated decision-making including profiling, and any transfer to a third country.

Articles 235 and 236 require the same information where the data was not collected from the data subject directly, within a reasonable period and no later than the first communication to the data subject or to another recipient, unless giving it is impossible or disproportionate for a statistical, historical, scientific or public-health purpose, the data subject already has it, or the processing implements a legal or regulatory provision.

Article 237 requires a controller that does not act on a data subject's request to tell them why, without charge and within thirty days, and preserves the data subject's right to complain to the Authority and to bring a judicial action. Article 240 bars any charge for supplying information or making a communication, and article 242 lets a controller use standardised, machine-readable icons to give an intelligible overview of the processing.

Article 248 lets an incapacitated adult's rights under Titre III be exercised by their spouse or another person appointed to protect their interests under the family code, with the data subject associated in the exercise of those rights as far as their understanding allows. Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.

What it requires

Enforcement supervision

Digital Code, Data Protection Authority and sanctions

Code du numérique Titre III, arts. 234, 249 à 261 et Titre IV, arts. 262 à 270 (autorité de protection des données, sanctions et voies de recours)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 234 gives the Data Protection Authority exclusive competence to control a controller's, its delegate's or a processor's compliance with Titre III and to impose the administrative sanctions that follow from it, a competence it may delegate to a third body only where that body shows the Authority its independence and expertise, sets up its own procedures for assessing compliance and handling complaints, and shows no conflict of interest.

Article 249 gives a data subject the right to lodge a complaint with the Authority, which must tell the complainant how the complaint is progressing and how it was resolved, including the possibility of judicial recourse, and article 250 gives the data subject a right of effective recourse before the competent administrative court where the Authority does not process the complaint or inform them of its progress or outcome within sixty days.

Article 251 gives a data subject a right of effective judicial recourse against a controller or its processor before the tribunal de paix of their district where they consider a Titre III right has been violated by processing of their data, and article 252 gives anyone who suffered material or moral harm from a Titre III violation the right to obtain compensation from the controller, holds a processor liable only for its own non-compliance with the duties Titre III places on processors or for acting outside or against the controller's lawful instructions, and holds several controllers or processors responsible for the same processing jointly and severally liable for the whole of the damage.

Article 253 requires joint controllers to allocate their respective duties by transparent agreement, including how they will handle the data subject's rights, lets them name a single point of contact, and requires the essence of that agreement to be made available to the data subject.

Article 255 lists what counts as a breach of Titre III, including unfair collection of personal data, disclosing personal data to an unauthorised third party, collecting sensitive or strategic data, offence-related data or a national identification number without meeting the legal conditions, collecting or using personal data in a way that seriously harms a person's fundamental rights or privacy, and obstructing the Authority's on-site inspection.

Article 256 lets the Authority issue a warning to a non-compliant controller or give formal notice to end the breach within a period it fixes that may not exceed eight days, and article 257 lets the Authority, where the controller does not comply with that formal notice and after adversarial procedure, impose a fine of eight million to two hundred million Congolese francs where the violation caused no serious harm to the State or the persons concerned, a fine of five per cent of the offender's annual turnover excluding tax for the last financial year where the violation caused death or an attempted murder, or an order to cease processing where the violation endangered national security or safety or led to a mass crime or genocide, while reserving the State's separate right to bring a criminal action and claim damages against the controller.

Article 258 lets the Authority attach an injunction to modify or delete the processing within a maximum of eight days to any sanction it imposes, article 259 requires a sanction to rest on a report the Authority notifies to the controller, who has fifteen days to submit written or oral observations and may be assisted or represented, and requires the Authority's decisions to be reasoned and notified, and article 260 gives a right of appeal against a sanction before the competent administrative court, while article 261 requires the Authority to make its sanctions public.

Article 262 creates the Data Protection Authority, an independent administrative authority with legal personality and administrative and financial autonomy, whose organisation and operation a decree of the Prime Minister fixes on the Minister for digital affairs' proposal.

Article 263 gives the Authority a broad list of powers and duties, including answering and issuing its own opinions and recommendations, informing data subjects and controllers of their rights and duties, authorising or refusing processing including of sensitive files, receiving declarations, authorisation requests, petitions and complaints, investigating on its own initiative or on a complaint, informing the judicial authority and the public prosecutor of criminal violations it learns of, ordering rectification, erasure or destruction of unlawfully processed data, authorising and monitoring cross-border transfers and the monetisation of data, and proposing legislative reform.

Articles 264 to 270 organise the Authority into a plenary assembly, a bureau and standing commissions, backed by a technical secretariat and provincial branches, fix the plenary assembly at nine members designated by the President of the Republic, the National Assembly, the judiciary, the bar, the national human rights commission and the digital sector's employers, on a five-year renewable term set by presidential ordinance and subject to parliamentary oversight, give its members immunity for opinions expressed in office while making them answerable before the Cour de Cassation, and bar them from holding government, parliamentary, business-leadership or shareholding roles in the digital, banking or telecommunications sectors.

Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.

What it requires

Sensitive categories

Digital Code, Title III, sensitive personal data and minors

Code du numérique, Titre III, arts. 195 à 199, 206 et 247 (catégories sensibles et mineurs)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 195 prohibits processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, refugee or stateless status, trade union membership, sex life, or more generally a person's state of health, and lifts that prohibition only for data the data subject manifestly made public, the data subject's explicit consent to specific purposes, safeguarding vital interests where the data subject cannot consent, an important public interest, a public-interest mission carried out by or assigned by a public authority, execution of public-statistics legislation, and preventive or occupational medicine carried out under a health professional's supervision.

Further paragraphs the scan does not number require a controller unable to answer a data subject's request within the ordinary period to notify the requester by the next day and to answer within eight days at the latest, and let the Data Protection Authority correspond directly with a controller to obtain the information a judicial inquiry or a national-security investigation needs.

Article 206 requires a controller processing the categories this run of articles covers to designate, by function, the staff with access to the data, keep that list available to the Data Protection Authority, bind those staff to confidentiality by a legal, statutory or contractual duty, and state the legal basis for the processing whenever it informs the data subject or files its declaration.

Article 247 makes processing a minor's personal data for a direct offer of information-society services lawful only where the holder of parental responsibility over the minor has consented, and requires the controller to verify, taking available technology into account, that the consent was given or authorized by that holder.

Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.

What it requires

Scraping law1 instrument, 1 in force

Research summary (198 words)

The Democratic Republic of the Congo has no dedicated scraping or web-crawling statute, but Livre IV (De la securite et de la protection penale des systemes informatiques) of the Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numerique criminalises unauthorised access to, and unauthorised maintenance of access within, a computer system, reaching an automated crawler or agent that accesses a system without authorisation and with fraudulent intent.

There is no reported case construing how 'authorization' is read for a public web page, and no robots.txt-specific or AI-training-specific provision.

Ordonnance-loi n° 86-033 du 5 avril 1986 portant protection des droits d'auteur et des droits voisins (see the aggregation topic for this jurisdiction) contains no text-and-data-mining exception and no database (sui generis) right; its Article 375, read there, separately criminalises a deliberate, commercial-scale infringement of copyright committed by means of a computer system, which reaches large-scale reproduction of copyrighted material by an automated system.

Loi n° 20/017 du 25 novembre 2020 relative aux telecommunications et aux technologies de l'information et de la communication was named as a possible source of network-access offences, but its primary text was not located, so no instrument from that law is recorded here.

Computer misuse

Digital Code, Book IV: Unauthorized Access to a Computer System

Code du numérique Livre IV, Sécurité et protection pénale des systèmes informatiques, Ordonnance-loi n° 23/010 du 13 mars 2023 (arts. 330 à 334)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 330 makes any violation of the Digital Code punishable under a penalty it provides a criminal offence against the digital legislation.

Article 332 punishes with three to five years' penal servitude and a fine of 50,000,000 to 100,000,000 Congolese francs, or either penalty alone, whoever intentionally and without right accesses or maintains access, with fraudulent intent, to all or part of a computer system, and punishes with two to five years' penal servitude and the same fine whoever, with fraudulent intent or intent to harm, exceeds their lawful access authority over a computer system.

Article 333 raises the penalty to five to ten years' penal servitude and a fine of 100,000,000 to 300,000,000 Congolese francs where the access results in the suppression, obtaining, or modification of data in the system, or an alteration of the system's functioning, and to ten to twenty years' penal servitude and a fine of 300,000,000 to 550,000,000 Congolese francs where the same conduct breaches security measures.

What it requires

Cybersecurity law5 instruments, 5 in force

Research summary (406 words)

The Democratic Republic of the Congo's Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique carries several distinct security duties on private information-system operators, layered across different Livres of the same instrument.

Livre II, Titre II binds a qualified or non-qualified trust service provider, an electronic certification service provider, to a risk-based security duty under Article 147, and to a twenty four hour security-incident notification duty running to the Autorité Nationale de Certification Électronique under Articles 148 and 149.

Livre IV binds any natural or legal person operating in the digital sector, and specifically the operator of an information system, public or private, to cooperate with and notify the Agence Nationale de Cybersécurité of a cyberattack, intrusion or other penetration under Articles 276 and 281.

Livre IV further binds a digital services provider generally to implement event-detection systems and submit to Agence Nationale de Cybersécurité security controls under Articles 295 and 296, and lets that agency obtain a vulnerable user's or system holder's contact details to alert them under Article 297.

Livre IV, Titre III, Article 294 imposes a product-security duty on a vendor of information and communication technology products, or a provider of information and communication technology services, requiring a compliance certificate issued after a vulnerability analysis, and a duty to disclose known vulnerabilities and remedies to consumers.

Livre IV, Titre IV of the same ordonnance-loi carries the criminal computer-misuse offenses already recorded under this jurisdiction's scraping topic filing, and Livre III, Titre III carries the personal-data regime already recorded under this jurisdiction's privacy topic filing, so neither is restated here.

Loi n° 20/017 du 25 novembre 2020 relative aux télécommunications et aux technologies de l'information et de la communication was located as a scanned document at the Autorité de Régulation de la Poste et des Télécommunications du Congo, but the file carries no extractable text layer, so whether it imposes a security-maintenance or incident-reporting duty on a licensed telecom operator beyond the Digital Code duties recorded here is not confirmed.

An Instruction n° 43 addressed by the Banque Centrale du Congo to credit establishments and microfinance institutions, on promoting electronic money and easing automated-teller-system operations, was located by title only; its text was not read, so whether it carries a security or cybersecurity duty for a bank or a mobile-money operator is not confirmed, and no other Banque Centrale du Congo circular or instruction addressed to information-system or cybersecurity posture was located.

Product security requirements

Digital Code, Livre IV: ICT Product and Service Vendor Security Certification

Code du numérique, Livre IV, Titre III, Chapitre I, Section 1, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 294)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds private bodies.

What this law does

Article 294 requires a vendor of information and communication technology products, or a provider of information and communication technology services, to apply to the Minister responsible for digital affairs for a compliance certificate. Article 294 conditions issuance of that certificate on a vulnerability analysis and an evaluation of the security guarantee performed by information security experts the Minister has accredited.

Article 294 separately requires the vendor or provider to inform consumers of every vulnerability detected in its information and communication technology products and services, and of the solutions deployed to remedy them. Neither Article 294 nor the other sections of the Digital Code reviewed here state a fixed administrative or criminal penalty specific to a vendor's failure to obtain the certificate or make the disclosure.

What it requires

Sector security regimes

Digital Code, Livre II: Trust Service Provider Security Risk-Management Duty

Code du numérique, Livre II, Titre II, Chapitre III, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 147, et art. 164 pour les sanctions)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 147 requires a qualified or non-qualified trust service provider to take the technical and organizational measures necessary to prevent and manage the risks to the security of the trust services it provides. Article 147 requires those measures to keep the level of security proportional to the degree of risk, given technological developments.

Article 147 requires the measures to prevent and limit the consequences of security incidents, inform the parties concerned of the harmful effects of such incidents, and ensure the continuity of services in the event of technical failures or cessation of activity.

A trust service provider that does not comply with the ordonnance-loi or with the requirements the Autorité Nationale de Certification Électronique sets faces an administrative sanction of a fine, a suspension of up to three hundred sixty five days, or a prohibition on operating in the Democratic Republic of the Congo, depending on the severity and impact of the breach.

What it requires

Security baseline statutes

Digital Code, Livre IV: Digital Services Provider Security Obligations

Code du numérique, Livre IV, Titre III, Chapitre I, Section 2, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 295 à 297)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 295 requires a digital services provider to implement systems qualified to detect events likely to affect the security of its own information systems. Article 296 requires a digital services provider to submit its information system to controls the Agence Nationale de Cybersécurité conducts to verify the system's security level and its compliance with security rules, at the provider's own cost.

Article 297 lets the Agence Nationale de Cybersécurité obtain a provider's users' or system holders' identity, postal address and electronic address when their systems are vulnerable, threatened or attacked, so as to alert them to the vulnerability or compromise. None of the three articles states a fixed administrative or criminal penalty for a digital services provider's noncompliance.

What it requires

Vulnerability and incident reporting

Digital Code, Livre II: Trust Service Provider Security-Incident Notification

Code du numérique, Livre II, Titre II, Chapitre III, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 148 et 149)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 148 requires a qualified or non-qualified trust service provider to notify the Autorité Nationale de Certification Électronique, and where applicable other bodies concerned, within twenty four hours of becoming aware of it, of every breach of security or loss of integrity having a significant impact on the trust service provided or on the personal data it stores.

Article 149 requires the trust service provider to notify the same breach or loss of integrity to an affected user within twenty four hours where it is liable to harm that user. Article 149 requires the Autorité Nationale de Certification Électronique, on receiving a notification concerning a foreign State, to inform the competent authorities of that State beforehand.

Article 149 lets the Autorité Nationale de Certification Électronique inform the public of the breach, or require the trust service provider to do so, whenever the Authority finds the public interest requires it.

What it requires

Digital Code, Livre IV: General Cyberattack Cooperation and Incident-Reporting Duty

Code du numérique Livre IV, Titre II, Chapitre I, et Titre III, Chapitre I, Section 1, Ordonnance-loi n° 23/010 du 13 mars 2023 (art. 276 et 281)Text of Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique

In force since 13 March 2023. Binds public and private bodies.

What this law does

Article 281 requires a natural or legal person operating in the digital sector, or possessing expertise in it, to cooperate in detecting cyberattacks in accordance with the applicable legal and regulatory provisions. Article 276 requires the operator of an information system, public or private, to inform the Agence Nationale de Cybersécurité of every attack, intrusion or other penetration liable to impair the operation of another information system or network.

Article 276 further requires that operator to comply with the measures the Agence Nationale de Cybersécurité prescribes to put an end to the disruption, including isolation of the affected information system. Neither Article 276 nor Article 281 states a fixed numerical deadline for the notification, or a fixed administrative or criminal penalty for a failure to notify or cooperate.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (177 words)

The Democratic Republic of the Congo has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, and no text-and-data-mining opt-out mechanism.

Ordonnance-loi n° 86-033 du 5 avril 1986 portant protection des droits d'auteur et des droits voisins, in force since its own date of promulgation, 5 April 1986, gives an aggregator two free-use provisions instead: a general quotation exception for citations or excerpts of a protected work reproduced for a cultural, scientific, teaching, critical or polemical purpose, and a press-specific exception letting the written or spoken press reproduce an article published in a newspaper or journal, on named-source condition, unless the article or periodical itself states that reproduction is forbidden, plus an unconditional free-use rule for 'news of the day' and miscellaneous facts having the character of mere press information.

Loi n° 23/009 du 3 mars 2023 fixant les regles relatives a l'exercice de la liberte de la presse, which replaced the 1996 press law and was named as a possible source of republication or licensing rules, was not located, so no finding is recorded from it.

Snippet reproduction

Copyright and Neighboring Rights Ordinance, Quotation and Press-Reproduction Exceptions

Ordonnance-loi n° 86-033 du 5 avril 1986 portant protection des droits d'auteur et des droits voisins, arts. 24 et 32Text of Ordonnance-loi n° 86-033 du 5 avril 1986, WIPO Lex record for the Democratic Republic of the Congo

In force since 5 April 1986. Binds public and private bodies.

What this law does

Article 24 makes it lawful to reproduce quotations or excerpts of protected works for a cultural, scientific, teaching, critical or polemical purpose, on condition of naming the source, the title and the author.

Article 32 lets the written or spoken press reproduce an article published in a newspaper or journal, on condition of naming the source, the title and the author, unless the article or the periodical in which it is published itself states that reproduction is forbidden, and separately makes 'news of the day' and miscellaneous facts having the character of mere press information freely usable without any attribution condition.

The Ordinance defines reproduction broadly, as the material fixation of a work by any process letting it be communicated indirectly to the public; a service excerpting DRC news content stands on Articles 24 and 32.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.