Comprehensive regime
Loi n° 2019-014, protection des données à caractère personnel
Loi n° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel arts. 1-20, 32-34, 51-54, 75-78 and 94-97 (comprehensive regime, formalities and obligations)Journal Officiel de la République Togolaise
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2020. Publisher's page: https://numerique.gouv.tg/wp-content/uploads/2020/01/Loi-n-2019-014-du-29-octobre-2019-relative-a-la-protection-des-donnees-a-caractere-pers…In force. Binds public and private bodies.
What this law does
Article 1 states the law's object as regulating the collection, processing, transmission, storage, use and protection of personal data, and article 2 extends it to any such processing by a natural person, the State, a local authority, or a public or private legal person, whether automated or not.
Article 6 requires most processing to be declared to the Instance de Protection des Données à Caractère Personnel beforehand, unless article 5 exempts it from formalities, article 8 requires prior authorization, or article 9 requires a reasoned government opinion, and articles 10 to 13 fix the common content, timing and channel for these requests.
Article 14 makes the data subject's consent the general lawful basis for processing, subject to derogations for a legal obligation, a public interest task, contract performance, or the data subject's vital interests, and articles 15 to 19 add the lawfulness, purpose limitation, accuracy, transparency, confidentiality and security principles. Article 20 requires a processor to offer sufficient guarantees and to be bound by a written contract confining it to the controller's instructions.
Articles 32 to 34 require the Instance's authorization before interconnecting files that serve different purposes, on a request stating the data, purpose and duration involved.
Article 51 keeps processing confidential to persons who have signed a written confidentiality undertaking, article 52 requires appropriate technical and organizational security measures, article 53 caps retention at the period necessary for the processing's purpose, and article 54 requires data to remain usable regardless of changes in storage technology.
Where a controller appoints a data protection correspondent to qualify for the article 5 formality exemption, articles 75 to 78 require the appointment to be notified to the Instance and task the correspondent with advising on compliance, cooperating with the Instance, and keeping an accessible list of the processing carried out.
What it requires