What this law does
Article 200 requires a controller communicating personal data to a partner or a processor to disclose its own identity and the data subject's rights, including the right to object to prospecting. Article 207 requires a controller relying solely on the data subject's written consent to disclose, before processing, the reasons the data is processed and the list of categories of staff who will access it, on top of the ordinary information duty.
Article 208 requires a controller to tell the data subject they may set instructions for managing their personal data after death, covering retention, erasure, communication and transmission to a chosen person, and lets the deceased's heirs, absent instructions, pursue those rights and obtain the data concerning the deceased.
Article 209 lets a data subject demand the information needed to know and contest the processing of their data, confirmation of whether it is processed, the purposes, the categories of data and recipients, the existence of automated decision-making including profiling, the data itself in intelligible form and its origin, any transfer to a third country, the retention period, and the existence of rights to rectification, erasure, restriction and complaint.
Article 210 requires an access copy within sixty days of the request, lets the Data Protection Authority grant a response extension or excuse manifestly abusive requests on the controller's contradictory application, and lets a controller defer disclosure of medical-research data where disclosure risks no harm to privacy but could seriously harm the research, until the research concludes.
Article 211 gives a data subject whose processing rests on consent or a contract and uses automated means the right to receive their data in a structured, commonly used, machine-readable format and to have it transmitted directly between controllers where technically possible, a right that does not apply to processing carried out under a public-interest mission or official authority.
Article 212 lets a person who proves their identity contact the Data Protection Authority to learn whether a government body's processing concerns them and obtain that information.
Article 213 gives a data subject the right to object at any time, on legitimate grounds, to processing of their data, requires the controller to offer, expressly and free of charge, the right to object before their data is first communicated to a third party or used for prospecting, and requires an answer within thirty days of the objection.
Article 214 lets a data subject demand rectification, updating or blocking of inaccurate, incomplete, ambiguous, outdated or unlawfully processed data, requires the controller to pass the correction on to every recipient within thirty days, and lets an heir demand the same update to reflect a data subject's death.
Article 215 gives a data subject the right to erasure within thirty days on the listed grounds, including that the data is no longer necessary, was unlawfully processed, or that the data subject withdrew consent with no other legal basis remaining.
Article 216 requires a controller that made a data subject's data public to take reasonable steps, including technical measures, to tell any third party processing it that the data subject has asked for the erasure of every link, copy or reproduction, subject to exceptions for freedom of expression, a legal obligation or public-interest mission, public health, archiving, research or statistics, and legal claims.
Article 217 requires the Data Protection Authority to adopt guidelines fixing the conditions for removing links to personal data and the criteria for restricting processing.
Article 218 routes a request touching data processed for State security, defence or public safety through an Authority member who investigates and orders any needed correction, and requires the Authority to have the relevant information communicated to the requester within thirty days where doing so does not compromise those interests.
Article 220 requires a controller to give the data subject, at the latest at collection, its identity, the purposes and legal basis, the categories of data, the recipients, the right to be delisted, the right to object to prospecting, whether a reply is mandatory or optional and the consequences of not replying, the rights of access and rectification, the right to withdraw consent, the right to complain to the Authority, the retention period, the existence of automated decision-making including profiling, and any transfer to a third country.
Articles 235 and 236 require the same information where the data was not collected from the data subject directly, within a reasonable period and no later than the first communication to the data subject or to another recipient, unless giving it is impossible or disproportionate for a statistical, historical, scientific or public-health purpose, the data subject already has it, or the processing implements a legal or regulatory provision.
Article 237 requires a controller that does not act on a data subject's request to tell them why, without charge and within thirty days, and preserves the data subject's right to complain to the Authority and to bring a judicial action. Article 240 bars any charge for supplying information or making a communication, and article 242 lets a controller use standardised, machine-readable icons to give an intelligible overview of the processing.
Article 248 lets an incapacitated adult's rights under Titre III be exercised by their spouse or another person appointed to protect their interests under the family code, with the data subject associated in the exercise of those rights as far as their understanding allows. Article 390 enters the ordinance-law into force on the date of its own promulgation, and it was signed at Kinshasa on 13 March 2023 by President Félix-Antoine Tshisekedi Tshilombo.
What it requires