Law / Republic of the Congo

Republic of the Congo

9 of 10 named instruments researched to a stage, across four of the six areas of law we track: 9 in force. As of 22 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (236 words)

The Republic of the Congo's comprehensive data-protection statute is Law No. 29-2019 of 10 October 2019 on the Protection of Personal Data, signed by President Denis Sassou-N'Guesso and published in the Journal Officiel of 7 November 2019.

It binds any natural or legal person, public or private, processing personal data on Congolese territory or using processing means located there, conditions processing on the data subject's consent or an enumerated alternative ground, requires a prior declaration or the national commission's authorization for most processing, arms the data subject with rights of information, access, portability, rectification, erasure and objection, imposes a seventy-two-hour breach-notification duty toward the commission, restricts cross-border transfer to countries offering a sufficient level of protection, and backs these duties with administrative fines of one million to one hundred million CFA francs.

Breach of the Law's provisions is separately punished under the Penal Code and under Law No. 27-2020 on combating cybercrime, whose own Chapter 6 criminalises processing without the required formalities, unlawful or undeclared processing, and processing of sensitive-category data with imprisonment of one to five years.

The Law's sensitive-category definition (Article 4) reaches genetic data, data concerning minors, offence and criminal-conviction data, and biometric data, alongside data revealing ethnic or regional origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or health (Article 14), so a service processing a biometric identifier falls within the Law's heightened prior-authorization regime for sensitive data.

Breach notification

Law No. 29-2019, personal-data breach notification

Loi n° 29-2019, articles 74 à 78 (violation de données à caractère personnel)Text of Law No. 29-2019

In force. Binds public and private bodies.

What this law does

Article 74 requires the controller, in the case of a personal-data breach, to notify the national commission without undue delay and, where possible, within seventy-two hours of becoming aware of it, unless the breach is not likely to create a risk to the rights and freedoms of natural persons, and to accompany a notification made after that deadline with the reasons for the delay; the processor notifies the controller of any personal-data breach without undue delay after becoming aware of it.

Article 75 fixes what the notification to the commission must contain: the nature of the breach, including where possible the categories and approximate number of data subjects and of personal-data records concerned, the name and contact details of the data protection officer or another contact point, the likely consequences, and the measures taken or proposed to remedy the breach and mitigate its adverse effects, communicated in stages without further undue delay where they cannot all be given at once.

Article 76 requires the controller to document every personal-data breach, its effects and the remedial measures taken, so the commission can verify compliance. Article 77 requires the controller, where a personal-data breach is likely to create a high risk to the rights and freedoms of a natural person, to communicate the breach to the data subject without undue delay, in clear and simple terms, and to give at least the information Article 75 requires.

Article 78 excuses that communication where the controller had applied protective measures, such as encryption, rendering the affected data unintelligible, where later measures mean the high risk is no longer likely to materialise, or where it would take disproportionate effort, in which case a public communication of equal effect is made instead.

Article 101 requires the Law's publication in the Journal Officiel de la République du Congo and its execution as law of the State, and it was signed at Brazzaville on 10 October 2019. The Journal Officiel de la République du Congo published the Law in its No. 45-2019 issue of Thursday, 7 November 2019, and no provision of the Law defers its own entry into force to a later date.

What it requires

Comprehensive regime

Law No. 29-2019 on the Protection of Personal Data

Loi n° 29-2019 du 10 octobre 2019 portant protection des données à caractère personnel articles 2, 3, 5 à 12, 31 à 45, 63 à 70 et 79 à 91 (champ d'application, principes, formalités préalables et obligations du responsable de traitement)Text of Law No. 29-2019

In force. Binds public and private bodies.

What this law does

Article 2 applies the Law to the collection, processing, transmission, storage or use of personal data by a natural person, the State, decentralised administrative entities, or a legal person of public or private law, whether the controller is established on Congolese territory or uses processing means located there.

Article 3 excludes only processing by a natural person for exclusively personal or domestic activities, where the data is not destined for systematic communication to third parties or dissemination, and temporary copies made for the technical transmission of, and access to, a digital network.

Article 5 conditions processing on the data subject's consent, unless the processing is necessary to comply with a legal obligation, perform a public-interest mission or exercise public authority, perform a contract to which the data subject is party, or safeguard the data subject's vital interests or fundamental rights.

Articles 6 to 10 state the Law's principles: processing is lawful, fair and transparent; personal data is kept no longer than its purpose requires; the data is accurate and updated where necessary; the data subject is given the transparency information the Law requires; and processing is kept confidential, in particular where it involves transmission over a network.

Article 11 requires the controller to choose a processor offering sufficient technical and organisational security guarantees and to govern the engagement by a written contract confining the processor to the controller's instructions, and Article 12 confines anyone who accesses personal data under the controller's or the processor's authority to processing on the controller's instructions alone.

Articles 33 to 36 require most processing to be declared to the national commission, Article 37 requires the commission's prior authorization instead for processing bearing on genetic data or health research, offence, conviction or security-measure data, a file interconnection, a national identification number, or biometric data, and Article 40 requires a decree of the President of the Republic, after the commission's reasoned opinion, for processing carried out on behalf of the State, a public establishment, a decentralised administrative entity, or a private-law legal person managing a public service.

Article 63 requires the controller to keep processing confidential, and Article 64 requires precautions appropriate to the nature of the data and the risks the processing presents to preserve data security. Articles 67 to 69 require a written register of processing activities, made available to the commission on demand, and Article 70 requires cooperation with the commission on request.

Article 79 requires a data protection impact assessment before a type of processing likely to create a high risk to the rights and freedoms of natural persons, and Articles 83 to 91 require the designation of a data protection officer, on the conditions Article 83 sets, given the position Article 87 prescribes and the tasks Article 90 lists.

Article 101 requires the Law's publication in the Journal Officiel de la République du Congo and its execution as law of the State, and it was signed at Brazzaville on 10 October 2019. The Journal Officiel de la République du Congo published the Law in its No. 45-2019 issue of Thursday, 7 November 2019, and no provision of the Law defers its own entry into force to a later date.

What it requires

Cross border transfer

Law No. 29-2019, cross-border transfer of personal data

Loi n° 29-2019, articles 23 à 25 (transfert transfrontalier de données à caractère personnel)Text of Law No. 29-2019

In force. Binds public and private bodies.

What this law does

Article 23 bars a cross-border transfer of personal data unless the third country offers a sufficient level of protection for the privacy and fundamental rights and freedoms of the persons the transferred data does or may concern, measured against the security measures applied, the characteristics of the processing (including its purposes and duration), and the nature, origin and destination of the data, and requires the controller to inform the national commission of any such transfer in advance.

Article 24 lets a controller transfer personal data to a third country that does not meet the article 23 condition where the transfer is a one-off, non-massive transfer and the data subject has expressly consented to it, or the transfer is necessary to protect that person's life, safeguard the public interest, allow the establishment, exercise or defence of a legal claim, or perform a contract between the controller and the data subject.

Article 25 lets the national commission authorize a transfer or a set of transfers to a third country that does not offer a sufficient level of protection where the controller offers sufficient guarantees for the privacy, fundamental rights and freedoms of the data subjects and the exercise of their corresponding rights, on a duly reasoned request from the controller.

Article 101 requires the Law's publication in the Journal Officiel de la République du Congo and its execution as law of the State, and it was signed at Brazzaville on 10 October 2019. The Journal Officiel de la République du Congo published the Law in its No. 45-2019 issue of Thursday, 7 November 2019, and no provision of the Law defers its own entry into force to a later date.

What it requires

Data subject rights

Law No. 29-2019, rights of the data subject

Loi n° 29-2019, articles 13 et 46 à 62 (droits de la personne concernée)Text of Law No. 29-2019

In force. Binds public and private bodies.

What this law does

Article 13 bars a decision producing legal effects for a natural person from resting solely on automated processing intended to define the person's profile or evaluate aspects of their personality, unless the decision arises from concluding or performing a contract on which the person had a chance to comment, or it grants the person's own request.

Article 46 requires the controller, when collecting personal data directly from the data subject, to give them, at the latest at collection, the controller's identity, the purposes of the processing, the categories of data concerned, the recipients or categories of recipients, whether a reply is obligatory or optional and the consequences of not replying, the right to be removed from the file, the rights of access and rectification, the retention period, and any transfer envisaged to a third country.

Article 50 gives a data subject who proves their identity the right to demand, in writing, the information needed to know and contest the processing, confirmation of whether their personal data is processed, the data itself and any available information on its origin, the purposes of the processing and the categories of recipients, and any transfer envisaged to a third country.

Article 56 gives a data subject the right to receive the personal data they provided in a structured, commonly used, machine-readable format, and to transmit it to another controller, and Article 57 gives the right to have it transmitted directly between controllers where technically possible.

Article 59 lets a data subject object to processing of their personal data on legitimate grounds, and gives them the right to be told, before their data is first communicated to a third party or used on a third party's behalf for prospecting, and to be expressly offered a free right to object to that communication or use.

Article 60 lets a data subject who proves their identity demand rectification, completion, updating, blocking or erasure of personal data concerning them that is inaccurate, incomplete, ambiguous, out of date, or whose collection, use, communication or retention is prohibited, and requires the controller to justify, free of charge, that it has carried out the requested operation within one month of registering the request.

Article 62 lets a minor consent alone to processing of their personal data for the offer of information-society services from the age of sixteen; below that age, the processing is lawful only if consent is given jointly by the minor and the holder or holders of parental authority over them, and the controller must write information addressed to the minor in clear, simple terms the minor can readily understand.

Article 101 requires the Law's publication in the Journal Officiel de la République du Congo and its execution as law of the State, and it was signed at Brazzaville on 10 October 2019. The Journal Officiel de la République du Congo published the Law in its No. 45-2019 issue of Thursday, 7 November 2019, and no provision of the Law defers its own entry into force to a later date.

What it requires

Enforcement supervision

Law No. 29-2019, sanctions

Loi n° 29-2019, articles 92 à 98 (sanctions administratives et pénales)Text of Law No. 29-2019

In force. Binds public and private bodies.

What this law does

Article 92 lets the national commission issue a warning to a controller failing to meet the Law's obligations, or a formal notice to remedy a breach within a period the commission fixes.

Article 93 lets the commission, where the controller does not comply with that formal notice and after adversarial procedure, order a provisional withdrawal of authorization or a provisional ban on processing not exceeding three months, a definitive withdrawal of authorization or ban on processing, an injunction to cease processing subject to the declaration regime or the article 32 and 33 exemptions, or an administrative fine of one million to one hundred million CFA francs, recovered under the legislation on the recovery of State debts.

Article 94 lets the commission, in an emergency where a processing operation or the exploitation of personal data violates rights and freedoms, order, after adversarial procedure, the interruption of the processing or the locking of the data concerned for up to three months, or a temporary or permanent prohibition of processing contrary to the Law.

Article 95 requires the commission's sanctions to rest on a report by one of its members, notified to the controller, who may submit observations and be represented or assisted. Article 96 lets the commission's president make its sanctions public and order their publication, at the sanctioned person's expense, in the publications, newspapers or media the president designates. Article 97 opens a right of appeal against the commission's sanctions and decisions before the Supreme Court.

Article 98 provides that breach of the Law's provisions is separately punished under the Penal Code and under Law No. 27-2020 on combating cybercrime, whose own Chapter 6 criminalises processing without the required formalities, unlawful or undeclared processing, and processing of special-category data, each with imprisonment of one to five years.

Article 101 requires the Law's publication in the Journal Officiel de la République du Congo and its execution as law of the State, and it was signed at Brazzaville on 10 October 2019. The Journal Officiel de la République du Congo published the Law in its No. 45-2019 issue of Thursday, 7 November 2019, and no provision of the Law defers its own entry into force to a later date.

What it requires

Sensitive categories

Law No. 29-2019, special categories of personal data

Loi n° 29-2019, articles 4, 14 à 19 et 37 (catégories particulières de données et autorisation préalable)Text of Law No. 29-2019

In force. Binds public and private bodies.

What this law does

Article 4 defines special categories of personal data as genetic data, data concerning minors, data relating to offences, criminal convictions or security measures, and biometric data, and reaches, so far as they are processed for what they reveal, personal data revealing ethnic origin, filiation, political opinions, religious or philosophical beliefs, trade union membership, sex, or data relating to health or sex life.

Article 14 prohibits collecting or processing personal data revealing ethnic or regional origin, filiation, political opinions, religious or philosophical beliefs, trade union membership, sex life, genetic data, or more generally data relating to a natural person's state of health.

Article 15 lifts that prohibition only where the data was manifestly made public by the data subject, the data subject gave written consent, the processing is necessary to protect vital interests, or it is necessary to establish, exercise or defend a legal claim; genetic data itself may then be processed only to verify a genetic link for a person's identification, or for the prevention or repression of a specific criminal offence, in the administration of proof in court.

Article 16 confines processing of data relating to offences, convictions or security measures to courts, public authorities and legal persons managing a public service acting within their legal remit, and to legal auxiliaries acting for the strict needs of a mission the law entrusts to them.

Article 17 permits processing personal data for health purposes only on one of its listed grounds, including the data subject's consent, data the data subject manifestly made public, the protection of vital interests, a purpose fixed by or under the law, and the promotion and protection of public health, and Article 18 requires health data to be collected from the data subject directly, unless collecting it from another source is necessary for the processing's purpose or the data subject cannot supply it.

Article 37 requires the commission's prior authorization before processing personal data bearing on genetic data or health research, offence, conviction or security-measure data, or biometric data. Article 101 requires the Law's publication in the Journal Officiel de la République du Congo and its execution as law of the State, and it was signed at Brazzaville on 10 October 2019.

The Journal Officiel de la République du Congo published the Law in its No. 45-2019 issue of Thursday, 7 November 2019, and no provision of the Law defers its own entry into force to a later date.

What it requires

Scraping law1 instrument, 1 in force

Research summary (239 words)

The Republic of the Congo has no scraping-specific statute.

Law No. 27-2020 of 5 June 2020 on combating cybercrime is the operative computer-misuse law: Article 4 criminalises fraudulently accessing or attempting to access all or part of an information system, Article 5 criminalises fraudulently remaining or attempting to remain connected to one, Article 6 criminalises hindering or attempting to hinder a system's functioning, and Article 63 criminalises fraudulently copying or attempting to copy computer data to a third party's prejudice.

On a plain reading, an unauthenticated read of a public page does not itself defeat any of these provisions, since none turns on the page being public or private; the offence attaches to accessing, remaining connected to, or copying from a system without authorization. The Law applies to any person, of any nationality, who commits an offence through information and communication technology in the Republic of the Congo (Article 2).

No reported Congolese decision applies these provisions to a web crawler or scraper as opposed to a conventional intrusion.

Congo's copyright statute, Law No. 24-82 of 7 July 1982 on Copyright and Related Rights, is named in Law No. 27-2020's own definitions chapter as the source of the legal definition of a database, but its own text could not be located through any reached channel; the cell for a copyright-based or database-right dimension of this topic is accordingly unreached rather than researched, and is noted as a gap below.

Computer misuse

Law on Combating Cybercrime, Unauthorised Access, Interference and Fraudulent Copying of Data

Loi n° 27-2020 du 5 juin 2020 portant lutte contre la cybercriminalité, arts. 4, 5, 6, 63Text of Law No. 27-2020 on combating cybercrime, reproduced by droit-afrique.com, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2023. Publisher's page: https://www.droit-afrique.com/uploads/Congo-Loi-2020-27-lutte-contre-cybercriminalite.pdf

In force. Binds public and private bodies.

What this law does

Article 1 states the Law's object as defining and punishing offences linked to information and communication technology, completing the Penal Code. Article 2 applies the Law to any person, of any nationality, who commits an offence through information and communication technology in the Republic of the Congo.

Article 4 punishes, by six months to three years' imprisonment and a fine of one million to ten million CFA francs, or either penalty, fraudulently accessing or attempting to access all or part of an information system, and separately punishes fraudulently procuring or attempting to procure an advantage by entering a system. Article 5 punishes the same range of penalties for fraudulently remaining or attempting to remain connected to all or part of an information system.

Article 6 punishes, by one to five years' imprisonment and a fine of five million to ten million CFA francs, or either penalty, hindering or attempting to hinder the functioning of an information system. Article 54 separately punishes, by two to five years' imprisonment and a fine of two million to thirty million CFA francs, installing a backdoor to data or an information system without the legitimate user's authorization.

Article 63 punishes, by six months to five years' imprisonment and a fine of four hundred thousand to five million CFA francs, or either penalty, fraudulently copying or attempting to copy computer data to a third party's prejudice. Article 109 provides that the Law is to be published in the Journal Officiel and executed as a law of the State, without stating a separate commencement date.

What it requires

Age gating law1 instrument, 1 in force

Research summary (348 words)

The Republic of the Congo has no adult-content age-verification statute, social-media minor-access law, app-store age-verification requirement, or standalone age-appropriate design code.

Loi n°4-2010 du 14 juin 2010 portant protection de l'enfant en République du Congo, the country's general child-protection statute, defines a child as any person under eighteen at its opening article and, at article 38, prohibits media from disseminating information that could compromise a child's development and requires media to protect the child against pornography, harmful information, and violent scenes disseminated through video clubs, internet sites, advertising, and other documents.

That duty runs to media as a class rather than to a single named platform category, and the law states no age-verification mechanism, enforcement body, or penalty specific to it. Article 66 of the same law separately prohibits producing, distributing, importing, offering, selling, or possessing material depicting a child in explicit or simulated sexual activity, as a general criminal prohibition rather than a gating or access-control duty addressed to a private service.

Loi n°27-2020 du 5 juin 2020 portant lutte contre la cybercriminalité, the country's computer-misuse statute (see the scraping topic for this jurisdiction's access and interference provisions), criminalises the same conduct when committed through an information system at its chapter on child pornography, punishing production, distribution, procurement, or possession of child sexual abuse material by five to ten years' imprisonment.

The same law separately requires every provider of a public electronic-communication service to maintain an accessible mechanism for reporting illicit content, including child pornography, and to inform the competent authorities promptly, on pain of six months to one year's imprisonment and a fine. That reporting duty spans several categories of illicit content rather than addressing age verification or age-appropriate design specifically.

The Sécrétariat Général du Gouvernement's list of eighteen consolidated codes in force names no digital or child-online-protection code, and its title-indexed register of enacted laws, searched under the terms enfant, mineur, réseaux sociaux, and numérique, returns no statute addressing digital age verification, social-media minor access, or app-store age controls beyond Loi n°4-2010 itself and unrelated measures such as tobacco-sales restrictions to minors and juvenile-detention-centre decrees.

Age-appropriate design code

Child Protection Law, Media Duty to Protect Children from Harmful Content

Loi n°4-2010 du 14 juin 2010 portant protection de l'enfant en République du Congo, art. premier et 38Loi n°4-2010 du 14 juin 2010 portant protection de l'enfant en République du Congo

In force since 17 June 2010. Binds public and private bodies.

What this law does

Loi n°4-2010 defines a child as any human being under eighteen who has not otherwise reached majority by special provision (article premier). Article 38 gives the child a right of access to diversified and objective information and prohibits media from disseminating information that could compromise the child's development.

The article requires media to promote children's books, to protect childhood in audiovisual programming, and to protect the child against pornography, harmful information, and scenes of violence disseminated through video clubs, internet sites, advertising, and other documents that could harm the child's harmonious development. No age-verification mechanism, enforcement body, or penalty specific to this duty appears in the law's text.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (200 words)

The Republic of the Congo has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of Law No. 24-82 of 7 July 1982 on Copyright and Related Rights is the only law reaching an aggregator's reproduction of news content. Article 14 places news of the day, published, broadcast, or communicated to the public, entirely outside the Law's scope, so a bare news item is never a protected work.

Article 33(1)(b) permits, without the author's consent, inserting quotations of a lawfully published work in another work, including quotations of newspaper articles and periodicals in the form of press reviews, provided the quotation conforms to fair practice, is justified by its purpose, and names the source and author.

Article 33(2) separately permits reproducing, or communicating to the public, a lawfully published newspaper or periodical article on a current economic, political, or religious topic, or a broadcast work of the same character, provided the source is clearly indicated, unless the article or broadcast carried an express reservation against such use at the time of its publication or broadcast.

No reported Congolese decision applies either provision to a systematic online news aggregator as opposed to a conventional press review.

Snippet reproduction

Copyright and Related Rights Law, News and Press-Review Free Uses

Loi n°24-82 du 7 juillet 1982 sur le droit d'auteur et les droits voisins, arts. 14, 33Text of Law No. 24-82 on Copyright and Related Rights, reproduced by liziba.cg

In force. Binds public and private bodies.

What this law does

Article 14 excludes laws, judicial and administrative decisions, their official translations, and news of the day published, broadcast, or communicated to the public, from the Law's field of application, so bare news is never a protected work regardless of who first reported it.

Article 33(1)(b) permits, without the author's consent, inserting quotations from a lawfully published work into another work, in the original language or in translation, provided the quotation conforms to fair practice, is limited to what its purpose justifies, and names the source and the author, and the provision expressly extends to quotations of newspaper articles and periodicals in the form of press reviews.

Article 33(2) permits reproducing a lawfully published newspaper or periodical article on a current economic, political, or religious topic, or a broadcast work of the same character, in the press, or communicating it to the public, provided the source is clearly indicated; this use is not licit if the article, at the time of its publication, or the broadcast work, at the time of its broadcast, carried an express reservation that such use is prohibited.

Article 107 provides that the Law is to be executed as a law of the State and published in the Journal Officiel, without stating a separate commencement date.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.