Law / Côte d'Ivoire

Côte d'Ivoire

11 of 13 named instruments researched to a stage, across four of the six areas of law we track: 11 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 3
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (244 words)

Côte d'Ivoire's comprehensive personal-data regime is Loi n° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel, which binds any natural person, the State, local authorities, and public or private corporations that collect, process, transmit, store or use personal data, whether the processing is automated or not.

The Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI), acting as the Autorité de Protection, receives a prior declaration for ordinary processing and a prior authorization for processing genetic, medical, biometric, criminal-record or national-identification-number data, or before a cross-border transfer.

Sensitive-category processing revealing racial, ethnic, political, religious, trade-union or health data is prohibited outright, subject to narrow exceptions, and carries the heaviest criminal exposure of the Act. A person has rights of information, access, rectification, erasure, digital oblivion and portability, and the law bars a court, administrative or private decision from resting solely on automated profiling.

Côte d'Ivoire is a member of the Economic Community of West African States, whose Supplementary Act A/SA.1/01/10 of 2010 sets a regional personal-data framework, and Loi n° 2013-450 was adopted three years later without the text itself naming that Supplementary Act as its origin.

Article 54 conditions the Act's entry into force on its publication in the Official Gazette; the text consulted carries only the National Assembly's adoption and the President's promulgation in Abidjan on 19 June 2013, not a dated Journal Officiel issue, so the day the Act actually took effect is not stated.

Comprehensive regime

Law No. 2013-450 on the Protection of Personal Data

Loi n° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel arts. 1-20, 22, 27, 39-44 (lawful basis, registration and security)Official English-language rendering of Law No. 2013-450 published by ARTCI

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 18, 2026. Publisher's page: https://www.artci.ci/images/stories/pdf-english/lois_english/loi_2013_450_english.pdf

In force. Binds public and private bodies.

What this law does

Article 2 states the Act's purpose as governing the protection of personal data, and article 3 subjects to it any collection, processing, transmission, storage or use of personal data by a natural person, the State, local authorities, or a public or private corporation, whether the processing is automated or not, excluding under article 4 only an individual's strictly personal or household processing and a network operator's temporary technical copies.

Article 5 makes ordinary processing subject to a prior declaration to ARTCI as the Autorité de Protection, and article 6 lets the declaration be replaced by an internal correspondent for most processing, though never before a cross-border transfer. Article 7 also requires the Authority's prior authorization before processing on a national identification number or a data set of public-interest research value.

Article 9 lists what a declaration or an application for authorization must contain, including the identity of the person responsible, the purpose, the categories of data and their origin, the retention period, the recipients, the office where access is exercised, the security measures planned, and any subcontractor or cross-border transfer, and article 11 gives the Authority one month, extendable by a further month, to decide, with silence read as a rejection open to appeal.

Article 12 lets the person responsible designate a correspondent for the protection of personal data to oversee compliance independently.

Article 14 makes processing legitimate where the person concerned gives express consent, subject to listed exceptions for a legal obligation, a public-interest task, a contract, or the person's vital interests, and articles 15 to 20 require processing to be lawful and fair, limited to specified and legitimate purposes, kept no longer than those purposes require, accurate, transparent, confidential, and carried out through a subcontractor who gives sufficient guarantees.

Article 22 prohibits direct marketing using a person's personal data without their consent. Article 27 authorizes the interconnection of files only for a legitimate purpose and bars it from causing discrimination or a reduction of rights.

Articles 39 to 41 require the processing to stay confidential, require precautions against distortion, damage or unauthorized access, and list the technical safeguards to install, including preventing unauthorized access to the installations and to the data, guarding against use for money laundering or terrorist financing, and keeping backup copies.

Article 42 requires an annual compliance report to the Authority, article 43 sets the retention period by reference to the Authority's rules for the type of processing, and article 44 requires the data to remain exploitable regardless of the support used. The Act states no separate data-breach notification duty running to the Authority or to the persons affected.

What it requires

Cross border transfer

Law No. 2013-450 on the Protection of Personal Data, cross-border transfer

Loi n° 2013-450, arts. 7, 26 (cross-border transfer)Official English-language rendering of Law No. 2013-450 published by ARTCI

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 18, 2026. Publisher's page: https://www.artci.ci/images/stories/pdf-english/lois_english/loi_2013_450_english.pdf

In force. Binds public and private bodies.

What this law does

Article 7 makes the transfer of personal data to a third country subject to ARTCI's prior authorization before implementation. Article 26 conditions that transfer on the destination state affording a level of protection of privacy, freedoms and fundamental rights equivalent to or higher than Côte d'Ivoire's with regard to the processing concerned, and requires the person responsible for the processing to obtain the Protection Body's permission before any actual transfer.

The transfer of personal data to a third country remains subject to the Protection Body's regular monitoring in light of its purpose.

What it requires

Data subject rights

Law No. 2013-450 on the Protection of Personal Data, rights of the data subject

Loi n° 2013-450, arts. 25, 28-38 (rights of the data subject)Official English-language rendering of Law No. 2013-450 published by ARTCI

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 18, 2026. Publisher's page: https://www.artci.ci/images/stories/pdf-english/lois_english/loi_2013_450_english.pdf

In force. Binds public and private bodies.

What this law does

Article 28 requires the person responsible for the processing to give the person concerned, at the latest when the data are collected, their identity, the purpose, the categories of data, the recipients, the possibility of refusing to appear on the file, the existence of the rights of access and rectification, the retention period, and the possibility of a transfer to a third country.

Article 29 gives a person the right to obtain confirmation of whether their data are being processed, the data themselves and their origin, and the purposes, categories and recipients of the processing, and lets the Protection Body exercise that access on the person's behalf where direct access is impossible.

Article 30 gives a person the right to object to processing on legitimate grounds relating to their situation, to object at no cost to processing for prospecting purposes, and to be told before their data are first disclosed to a third party for prospecting and given the right to object to that disclosure free of charge.

Article 31 gives a person the right to have inaccurate, incomplete, ambiguous or outdated personal data rectified, completed, updated, deleted or locked, and article 32 extends that right to a deceased person's successors.

Article 33 gives a person the right to erasure of their personal data and to the end of its distribution, including data made available while they were a minor, where it is no longer necessary, where consent is withdrawn or the retention period has lapsed with no other legal ground, where the processing lacks a legal ground, or for any other legitimate reason, and articles 34 to 36 require the person responsible to tell any third party the data were disclosed to that the person concerned seeks removal of every link, copy or reproduction, to carry out the erasure without delay unless a listed ground for retention applies, and to establish mechanisms implementing that right and periodically reviewing the need to keep data.

Article 38 gives a person the right to receive their data in a structured, commonly used electronic format and, where the processing rests on consent or a contract, to have it forwarded to another system. Article 25 bars any court, administrative or private decision assessing a person's behavior or personality from resting solely on automated processing of their personal data.

What it requires

Enforcement supervision

Law No. 2013-450 on the Protection of Personal Data, enforcement and the Protection Body

Loi n° 2013-450, arts. 45-52 (enforcement and the Protection Body)Official English-language rendering of Law No. 2013-450 published by ARTCI

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 18, 2026. Publisher's page: https://www.artci.ci/images/stories/pdf-english/lois_english/loi_2013_450_english.pdf

In force. Binds public and private bodies.

What this law does

Article 46 entrusts the mission of personal-data Protection Body to ARTCI, the independent administrative body regulating telecommunications and information and communication technologies, and article 47 gives it the power to receive declarations and grant or withdraw authorizations, receive and resolve claims and complaints, audit any processing through sworn officers, impose administrative and pecuniary penalties, maintain a public directory of processing, authorize cross-border transfers, and issue guidelines for the processing and protection of personal data.

Article 48 bars a cryptologic service provider or a person responsible for processing from invoking professional secrecy against the Protection Body. Article 49 lets the Protection Body issue a warning or a formal notice to stop a deficiency within a set time, and article 50 lets it, after an adversarial procedure, order the interruption of a processing, the locking of some of the data, or a temporary or permanent prohibition where a processing violates human freedoms.

Article 51 lets the Protection Body, after hearing the person responsible or their subcontractor, withdraw an authorization temporarily or finally or impose a financial penalty proportionate to the seriousness of the breach and the benefit derived from it, capped at 10 million CFA francs for a first failure and, for a repeated failure within five years, at 100 million CFA francs or, for a company, 5 percent of the prior financial year's turnover excluding tax up to a maximum of 500 million CFA francs, without prejudice to any criminal penalty.

Article 45 punishes obstructing the Protection Body, by opposing its members' tasks, refusing or concealing information or documents it requests, or supplying inconsistent information, with imprisonment of one month to two years and a fine of 1 million to 10 million CFA francs, and requires the prosecutor or investigating judge to be told without delay of any such obstruction.

What it requires

Sensitive categories

Law No. 2013-450 on the Protection of Personal Data, sensitive categories of personal data

Loi n° 2013-450, arts. 7, 21 (sensitive categories of personal data)Official English-language rendering of Law No. 2013-450 published by ARTCI

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 18, 2026. Publisher's page: https://www.artci.ci/images/stories/pdf-english/lois_english/loi_2013_450_english.pdf

In force. Binds public and private bodies.

What this law does

Article 7 requires ARTCI's prior authorization before processing personal data relating to genetic or medical data and to related scientific research, to an offense, a conviction or a security measure imposed by a court, or to biometric data.

Article 21 prohibits, subject to narrow exceptions, any processing that reveals a person's racial, ethnic or regional origin, political opinion, religious or philosophical belief, trade-union membership, sex life, or, more generally, genetic data concerning health.

The prohibition does not apply where the data were manifestly made public by the person concerned, where processing genetic or health data is necessary to protect a vital interest and the person cannot consent, where genetic data is necessary to establish, exercise or defend a legal claim, where a judicial proceeding or a criminal investigation is under way, or where the processing serves the legitimate, membership-only activities of a foundation, association or other non-profit body with a political, philosophical, religious, fraternal or trade-union purpose.

Every case the exceptions permit remains subject to the Protection Body's authorization and supervision of its design and implementation.

What it requires

Scraping law2 instruments, 2 in force

Research summary (312 words)

Côte d'Ivoire has no scraping-specific statute, so general law governs each dimension separately.

Loi n° 2013-451 du 19 juin 2013 relative à la lutte contre la cybercriminalité punishes anyone who accesses or attempts to access all or part of an information system, without stating a security-circumvention trigger the way some neighbouring cybercrime laws do, so whether reading a public, unauthenticated page without defeating any access control falls inside or outside a plain reading of that article is not settled by the text or by any reported Ivorian decision.

No reported Ivorian decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper has been located.

Loi n° 2016-555 du 26 juillet 2016 relative au droit d'auteur et aux droits voisins permits, once a work has been disclosed, analyses, press reviews and short quotations justified by a critical, polemical, educational, scientific or informational purpose (art. 25), but the country has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on that general quotation ground if it can be so characterised.

The same Act protects a database only as a compilation, by the choice, coordination or arrangement of its contents, expressly excluding the content itself and any computer program used to build, run or consult it from that protection, so there is no sui generis database right of the kind the European Union recognises.

Loi n° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel applies to any collection or processing of personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Ivorian website remains subject to that Act's declaration, authorization and lawful-basis duties.

No Ivorian statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Cybercrime Act, unauthorized access to an information system

Loi n° 2013-451 du 19 juin 2013 relative à la lutte contre la cybercriminalité, art. 4 (accès frauduleux à un système informatique)Official English-language rendering of Law No. 2013-451 published by ARTCI

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 18, 2026. Publisher's page: https://www.artci.ci/images/stories/pdf-english/lois_english/loi_2013_451_english.pdf

In force. Binds public and private bodies.

What this law does

Article 4 punishes by one to two years' imprisonment and a fine of 5 million to 10 million CFA francs anyone accessing or attempting to access all or part of an information system, and article 5 separately punishes fraudulently remaining within all or part of an information system on the same terms.

Article 6 punishes hindering or distorting the functioning of an information system, article 7 punishes introducing data into it, and articles 8 to 10 punish intercepting, altering or fabricating computer data, each with escalating imprisonment terms of up to ten years and fines of up to 60 million CFA francs.

Article 26 separately punishes theft of information, defined as fraudulently becoming aware of, copying, or removing the physical medium carrying information within an information system, by five to ten years' imprisonment and a fine of 3 million to 5 million CFA francs, rising to ten to twenty years and 5 million to 10 million CFA francs where an aggravating circumstance listed in article 27 is present, and article 30 raises the minimum to ten years where the system or data was protected by a secret access code.

None of these articles conditions the offense on defeating a technical security measure, so whether they reach a scraper reading a public, unauthenticated page is not addressed by the text.

What it requires

Database right

Copyright and Neighboring Rights Act, database compilation protection

Loi n° 2016-555 du 26 juillet 2016 art. 8 (protection des bases de données comme compilations), relative au droit d'auteur et aux droits voisinsLaw No. 2016-555 of 26 July 2016

In force since 26 July 2016. Binds public and private bodies.

What this law does

Article 8 protects, as an original work, a collection of works or of mere data or facts, such as an encyclopedia, anthology or database, where the choice, coordination or arrangement of its contents constitutes an original work; the same article states that this protection does not extend to a database's own content or to a computer program used to create, operate or consult it.

Article 10 separately excludes ideas, methods, procedures, concepts or information as such, official legislative, administrative or judicial texts, and mere data and facts as such, from copyright protection altogether. Together the two articles give Côte d'Ivoire compilation-only protection for a database's selection or arrangement, with no separate sui generis database right of the kind the European Union recognises, and with the underlying content always open to reuse.

Article 138 makes any infringement of the moral or economic rights the Act defines a criminal offense, punishable by one to ten years' imprisonment and a fine of 500,000 to 5,000,000 CFA francs, or either penalty alone.

What it requires

Cybersecurity law3 instruments, 3 in force

Research summary (540 words)

Côte d'Ivoire binds a private-sector duty-bearer to cyber-resilience law through two décrets dated 22 December 2021, rather than through a single named cybersecurity statute, both issued under Article 50 of Loi n°2013-546 du 30 juillet 2013 relative aux transactions électroniques, which the décrets' own recitals describe as tasking the telecom and ICT regulator ARTCI (Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire) with auditing and certifying the information systems of persons carrying out electronic-transactions activities.

Décret n°2021-917 widens that audited population well beyond electronic-transactions providers: its Article 3 reaches every public-sector information system and an enumerated set of private-sector categories, a telecommunications or ICT company, a telecommunications or internet service provider, a company whose information system connects through Côte d'Ivoire's public telecommunications networks, a company that automatically processes its customers' personal data in providing its service, an electronic-transactions company, an ARTCI-approved service provider, and an electronic-archiving or record-keeping provider, with a mandatory periodic security audit enforced by a financial penalty.

The same décret's Article 16 separately requires any public or private organization, with no sector or size gate at all, to inform ARTCI immediately of an attack, intrusion or other disruption likely to impede its information system, and its Plan de Protection des Infrastructures Critiques (PPIC) confirms that Côte d'Ivoire operates a national CERT, CI-CERT, as one of the competent authorities a critical-infrastructure operator's cybersecurity focal point liaises with.

Décret n°2021-916 adopts the ISO 27001 and ISO 27002 based content standard, the Référentiel Général de Sécurité des Systèmes d'Information (RGSSI), that Décret n°2021-917's audits check compliance against, together with the PPIC, and makes compliance with both a freestanding duty on every public body and private enterprise.

Décret n°2021-915 (22 December 2021) adopts a parallel security policy, the Politique de Sécurité des Systèmes d'Information de l'Administration Publique (PSSI), and Décret n°2021-918 (22 December 2021) creates an information-systems department inside each ministry, but both bind only public administration and are not filed here, on the same footing as the government-information-security-programme carve-out this topic's profile states for a jurisdiction's FISMA analogue.

Loi n°2013-450 du 19 juin 2013's own security-of-processing articles, among them Article 41's duty to prevent unauthorized access to processing facilities and unauthorized alteration of recorded data, bind the same personal-data processors to a security duty already carried in the privacy topic and are not re-filed here.

Loi n°2013-451 du 19 juin 2013 relative à la lutte contre la cybercriminalité, amended by Loi n°2023-593 to strengthen its penalties, stays a computer-misuse statute whose unauthorized-access, illegal-gambling and content-provider provisions bind an intruder or a content host rather than an operator's own security posture, and is carried in the scraping topic; its text carries no nearby operator-facing security-programme or vulnerability-reporting duty.

The regional central bank BCEAO (Banque Centrale des Etats de l'Afrique de l'Ouest) publishes payment-systems oversight functions, Surveillance des Systèmes de Paiement and Centralisation des Incidents de Paiement, reaching a licensed credit establishment and payment-system participant across the WAEMU/UEMOA member states including Côte d'Ivoire, a role no activity in this vocabulary expresses; direct navigation of BCEAO's own site within this visit's budget confirmed these functions exist but did not locate a specific citable BCEAO cybersecurity or IT-risk instruction text, so this is recorded here as a deferred, unconfirmed lead rather than an instrument.

Sector security regimes

Mandatory Information Systems Security Audit and Certification

Décret n°2021-917 du 22 décembre 2021, Arts. 3-4, 19-21Official décret text, ARTCI document repository

In force since 22 December 2021. Binds public and private bodies.

What this law does

Article 3 subjects every public-sector information system and an enumerated set of private-sector categories, a telecommunications or ICT company, a telecommunications or internet service provider, a company whose information system connects through Côte d'Ivoire's public telecommunications networks, a company that automatically processes its customers' personal data in providing its service, an electronic-transactions company, an ARTCI-approved service provider, and an electronic-archiving or record-keeping provider, to a mandatory periodic security audit.

Article 4 sets a three-year certification audit cycle, performed by ARTCI itself or by an ARTCI-accredited Prestataire d'Audit de Sécurité des Systèmes d'Information (PASSI), with a further mandatory periodic audit eighteen months after a certificate issues. Article 20 caps the financial penalty for failing to complete the audit at 300,000,000 CFA francs, doubled on a repeat breach.

What it requires

RGSSI and PPIC Compliance Duty

Décret n°2021-916 du 22 décembre 2021, Arts. 1-2Official décret text, ARTCI document repository

In force since 22 December 2021. Binds public and private bodies.

What this law does

Article 1 adopts the Référentiel Général de Sécurité des Systèmes d'Information (RGSSI) and the Plan de Protection des Infrastructures Critiques (PPIC) as annexes to this décret. The RGSSI states that it draws heavily on ISO 27001:2013 and ISO 27002:2013. Article 2 requires every public body and private enterprise to comply with the RGSSI and the PPIC. Décret n°2021-917 Article 14 anchors that compliance duty to the same population its own Article 3 lists.

The PPIC requires an organization the State has designated and notified as a critical-infrastructure operator or manager to renew a complete risk analysis of its critical infrastructure at least every six months. The same organization must also designate a cybersecurity focal point who liaises with ARTCI, a sector cybersecurity officer, and CI-CERT, a set of roles no activity in this vocabulary expresses, so this PPIC-specific duty is recorded here rather than flagged.

What it requires

Vulnerability and incident reporting

Mandatory Reporting of Attacks and Intrusions to ARTCI

Décret n°2021-917 du 22 décembre 2021, Arts. 16-17Official décret text, ARTCI document repository

In force since 22 December 2021. Binds public and private bodies.

What this law does

Article 16 requires every public or private organization to inform ARTCI immediately of any attack, intrusion or other disruption likely to impede its information system's proper functioning. Article 17 empowers ARTCI to take all measures it deems necessary to stop a disruption it identifies.

The Plan de Protection des Infrastructures Critiques names CI-CERT, alongside ARTCI and a sector cybersecurity officer, as one of the competent authorities a designated critical-infrastructure operator's cybersecurity focal point liaises with.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (220 words)

Côte d'Ivoire has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is Loi n° 2016-555 du 26 juillet 2016 relative au droit d'auteur et aux droits voisins, which excludes official texts and mere data and facts as such from copyright protection outright (art. 10), so a bare fact or news item is never protectable regardless of who first reported it.

The same Act lets a person, once a work has been disclosed, make analyses, press reviews and short quotations justified by a critical, polemical, educational, scientific or informational purpose, and separately lets a literary work seen or heard during a current event be reproduced and made available by short extracts for the purpose of reporting that event (arts. 25-26); nothing in either article limits its reach to short extracts generally or to the press industry, and no Ivorian court decision applying either to a systematic news aggregator, as opposed to a traditional press review or event report, has been located.

The Act predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Copyright and Neighboring Rights Act, quotation, press-review and current-events exceptions

Loi n° 2016-555 du 26 juillet 2016 Arts. 25-26 (Quotation, Press Review and Current-Events Exceptions), relative au droit d'auteur et aux droits voisinsLaw No. 2016-555 of 26 July 2016

In force since 26 July 2016. Binds public and private bodies.

What this law does

Article 10 excludes ideas, methods, procedures, concepts or information as such, official legislative, administrative or judicial texts and their official translations, and mere data and facts as such, from copyright protection outright, so a bare fact or the news of the day as such is never a protected work under Ivorian law, whichever outlet reports it first.

Article 25 separately lets any person, once a work has been disclosed, make analyses, press reviews and short quotations justified by a critical, polemical, educational, scientific or informational purpose, and use a literary, artistic or scientific work to illustrate teaching, in each case provided the use is not abusive, carries no lucrative purpose, and credits the author's name and the source.

Article 26 lets a literary work seen or heard during a current event be reproduced and made accessible to the public, by short extracts and for an informational purpose, on the occasion of a report of that event, by photography, audiovisual means or broadcast, again subject to crediting the author and source, and provided reproduction or broadcasting rights were not expressly reserved.

Neither article is capped at a headline-length threshold beyond its own critical, educational or informational-purpose test, and neither is confined to the press industry; whether either reaches a systematic aggregator's reproduction of headlines and snippets, as opposed to a traditional press review or a broadcaster's current-events report, has not been tested in a reported Ivorian decision.

Côte d'Ivoire has no separate press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no recognized hot-news or misappropriation doctrine distinct from ordinary copyright and unfair-competition law, and no located case law on hyperlinking or framed display.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.