Law / Togo

Togo

8 of 11 named instruments researched to a stage, across four of the six areas of law we track: 8 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (129 words)

Togo's comprehensive personal-data regime is Loi n° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel, which binds a natural person, the State, local authorities, and any public or private legal person that collects, processes, transmits, stores, or uses personal data, and creates the Instance de Protection des Données à Caractère Personnel (IPDCP) as the independent supervisory authority.

Processing genetic data, health-research data, a national identifier, biometric data, criminal-record data, or an interconnection of files requires the IPDCP's prior authorization, while most other processing needs only a prior declaration. A due-consideration test, rather than a strict adequacy or prior-authorization requirement, governs a transfer of personal data outside Togo, and the statute imposes no data-breach notification duty to the IPDCP or to the persons affected.

Comprehensive regime

Loi n° 2019-014, protection des données à caractère personnel

Loi n° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel arts. 1-20, 32-34, 51-54, 75-78 and 94-97 (comprehensive regime, formalities and obligations)Journal Officiel de la République Togolaise

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2020. Publisher's page: https://numerique.gouv.tg/wp-content/uploads/2020/01/Loi-n-2019-014-du-29-octobre-2019-relative-a-la-protection-des-donnees-a-caractere-pers…

In force. Binds public and private bodies.

What this law does

Article 1 states the law's object as regulating the collection, processing, transmission, storage, use and protection of personal data, and article 2 extends it to any such processing by a natural person, the State, a local authority, or a public or private legal person, whether automated or not.

Article 6 requires most processing to be declared to the Instance de Protection des Données à Caractère Personnel beforehand, unless article 5 exempts it from formalities, article 8 requires prior authorization, or article 9 requires a reasoned government opinion, and articles 10 to 13 fix the common content, timing and channel for these requests.

Article 14 makes the data subject's consent the general lawful basis for processing, subject to derogations for a legal obligation, a public interest task, contract performance, or the data subject's vital interests, and articles 15 to 19 add the lawfulness, purpose limitation, accuracy, transparency, confidentiality and security principles. Article 20 requires a processor to offer sufficient guarantees and to be bound by a written contract confining it to the controller's instructions.

Articles 32 to 34 require the Instance's authorization before interconnecting files that serve different purposes, on a request stating the data, purpose and duration involved.

Article 51 keeps processing confidential to persons who have signed a written confidentiality undertaking, article 52 requires appropriate technical and organizational security measures, article 53 caps retention at the period necessary for the processing's purpose, and article 54 requires data to remain usable regardless of changes in storage technology.

Where a controller appoints a data protection correspondent to qualify for the article 5 formality exemption, articles 75 to 78 require the appointment to be notified to the Instance and task the correspondent with advising on compliance, cooperating with the Instance, and keeping an accessible list of the processing carried out.

What it requires

Cross border transfer

Loi n° 2019-014, transfert des données vers un pays tiers

Loi n° 2019-014 du 29 octobre 2019, arts. 28-31 (cross border transfer)Journal Officiel de la République Togolaise

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2020. Publisher's page: https://numerique.gouv.tg/wp-content/uploads/2020/01/Loi-n-2019-014-du-29-octobre-2019-relative-a-la-protection-des-donnees-a-caractere-pers…

In force. Binds public and private bodies.

What this law does

Article 28 permits a transfer of personal data to a third country only if that country ensures a sufficient level of protection for privacy, freedoms and fundamental rights, and requires the controller to inform the Instance beforehand for its reasoned opinion.

Article 29 admits a one off, non massive transfer to a country that does not meet that standard where the data subject has expressly consented, or the transfer is necessary to safeguard the person's life, the public interest, a right in court, or a contract with the person.

Article 30 lets the Instance authorize a transfer or set of transfers to a country lacking adequate protection on a reasoned request, where the controller offers sufficient guarantees for privacy, fundamental rights and freedoms and for the exercise of the corresponding rights.

Article 31 requires the Instance, before any processing of personal data received from abroad, to verify that the controller assures a sufficient level of protection, judged by the security measures applied, the processing's purpose and duration, and the nature, origin and destination of the data.

What it requires

Data subject rights

Loi n° 2019-014, droits de la personne concernée

Loi n° 2019-014 du 29 octobre 2019, arts. 26-27, 35-50 (rights of data subjects)Journal Officiel de la République Togolaise

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2020. Publisher's page: https://numerique.gouv.tg/wp-content/uploads/2020/01/Loi-n-2019-014-du-29-octobre-2019-relative-a-la-protection-des-donnees-a-caractere-pers…

In force. Binds public and private bodies.

What this law does

Article 35 requires a controller collecting data directly from the data subject to disclose, at the latest when collecting it, its identity, the purposes of the processing, the categories of data, the recipients, whether an answer is mandatory, the possibility of objecting to inclusion in the file, the rights of access and rectification, the retention period, and any transfer abroad envisaged.

Article 39 gives a data subject the right to demand confirmation of processing, communication of their data in an accessible form together with its origin, and information on the purposes, categories, recipients and any transfer abroad, and article 40 entitles them to a copy at no more than reproduction cost.

Article 45 gives a data subject the right to object, on legitimate grounds, to processing of their data, and the right to be told before their data is first disclosed to or used by a third party for prospecting and to object to that disclosure or use free of charge, subject to the exception for processing required by a legal obligation.

Article 46 lets a data subject demand correction, completion, updating, locking or deletion of data that is inaccurate, incomplete, ambiguous, outdated or unlawfully held, within one month and at no cost, and requires the controller to notify any third party the data was disclosed to.

Article 47 requires a controller who has made a data subject's data public to take reasonable measures, including technical ones, to tell third parties processing that data to erase links to it or any copy, on the data subject's request. Article 26 bars unsolicited direct marketing using a person's data without their prior consent to receive it.

Article 27 bars founding a court decision on a person's conduct, or any decision producing legal effects concerning them, solely on an automated evaluation of their personal characteristics or profile, other than a contractual decision on which they could state their views or a decision granting their own request.

Article 50 lets the heirs of a deceased data subject require the controller to record the death and make the necessary updates, and requires the controller to justify doing so free of charge.

What it requires

Enforcement supervision

Loi n° 2019-014, cadre institutionnel et dispositions pénales

Loi n° 2019-014 du 29 octobre 2019, arts. 55-74, 79-93 (institutional framework, sanctions and offenses)Journal Officiel de la République Togolaise

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2020. Publisher's page: https://numerique.gouv.tg/wp-content/uploads/2020/01/Loi-n-2019-014-du-29-octobre-2019-relative-a-la-protection-des-donnees-a-caractere-pers…

In force. Binds public and private bodies.

What this law does

Article 55 creates the Instance de Protection des Données à Caractère Personnel (IPDCP) as an independent administrative authority tasked with ensuring that processing complies with the law, and article 56 gives it the missions of receiving formalities, receiving and answering complaints, alerting the public prosecutor to offenses it learns of, verifying processing, sanctioning controllers under article 71, answering opinion requests, approving conduct codes, keeping a public register, advising controllers, authorizing cross border transfers, proposing legislative improvements, cooperating internationally, publishing authorizations and opinions, and reporting annually to the President, the Prime Minister and the presidents of the two legislative chambers.

Article 70 lets the Instance issue a warning or a formal notice fixing a deadline to end a breach, and article 71 lets it, after a hearing, provisionally or ultimately withdraw an authorization or impose a fine of up to XOF 100,000,000 where the controller does not comply.

Articles 72 and 73 let the Instance take emergency and conservatory measures, including interrupting a processing operation, locking data, ordering compliance under a daily penalty of up to XOF 5,000,000, or sealing and removing equipment used in an unauthorized processing operation, and article 74 lets the Instance's decisions be appealed before the administrative chamber of the Supreme Court.

Article 93 punishes obstructing the Instance's action, whether by opposing its members' or agents' missions, refusing to communicate the information or documents they request, or supplying information that does not match the records, with six months to two years' imprisonment and a fine of XOF 1,000,000 to XOF 10,000,000.

What it requires

Sensitive categories

Loi n° 2019-014, données sensibles

Loi n° 2019-014 du 29 octobre 2019, arts. 8, 21-25 (sensitive personal data)Journal Officiel de la République Togolaise

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2020. Publisher's page: https://numerique.gouv.tg/wp-content/uploads/2020/01/Loi-n-2019-014-du-29-octobre-2019-relative-a-la-protection-des-donnees-a-caractere-pers…

In force. Binds public and private bodies.

What this law does

Article 8 requires the Instance's prior authorization before processing genetic data, health research data, biometric data, or data on criminal offenses, convictions or security measures. Article 21 prohibits collecting or processing data revealing racial or ethnic origin, filiation, political opinions, religious or philosophical convictions, trade union membership, sex life, genetic data, or health data.

Article 22 lifts that prohibition where the data was manifestly made public by the data subject, where the data subject gave written consent, where the processing safeguards a vital interest the data subject cannot consent to protect, or on a short further list including a judicial, public interest, historical, statistical or scientific purpose.

Article 23 restricts processing of data on offenses, convictions or security measures to courts, public authorities, bodies managing a public service, and legal auxiliaries acting within their legal duties.

Article 24 makes health data processing lawful only on a listed ground such as the data subject's consent, requires it to be carried out under the supervision of a health professional bound by professional secrecy, and requires the data to be collected directly from the data subject except where collection elsewhere is necessary or the data subject cannot provide it.

What it requires

Scraping law1 instrument, 1 in force

Research summary (259 words)

Togo has no scraping-specific statute, so general law governs each dimension separately.

Loi n° 2018-026 du 07 décembre 2018 sur la cybersécurité et la lutte contre la cybercriminalité criminalises fraudulent access to or continued presence in a computer system, but its article 8 requires only that the access be sans droit (without right), with no requirement that a security measure be infringed, so whether reading a public, unauthenticated page without defeating any access control falls inside or outside the provision has not been tested in a reported Togolese decision.

No Togolese court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

Loi n° 91-12 du 10 juin 1991 permits short quotations and analyses and a press review, and lets the press or a broadcaster reproduce current political, social or economic news articles for informational purposes unless the reproduction right was expressly reserved, but Togo has not enacted a text-and-data-mining exception, and its copyright statute confers no sui generis database right, protecting only a compilation that is itself an original creation.

Loi n° 2019-014 du 29 octobre 2019 applies to personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Togolese website remains subject to that law's lawful-basis, purpose-limitation and cross-border-transfer duties; a narrower processing ground exists only for sensitive-category data the data subject has manifestly made public.

No Togolese statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Loi n° 2018-026, accès et maintien frauduleux à un système informatique

Loi n° 2018-026 du 07 décembre 2018 sur la cybersécurité et la lutte contre la cybercriminalité art. 8 (accès et maintien frauduleux à un système informatique)Journal Officiel de la République Togolaise, numéro spécial du 07 décembre 2018

In force. Binds public and private bodies.

What this law does

Article 8 punishes any person who, without right, accesses or attempts to access, or remains or attempts to remain, in all or part of a computer system, with six months to two years' imprisonment and a fine of XOF 5,000,000 to XOF 20,000,000, or either penalty alone. The penalty doubles where the access results in a serious disruption or interruption of the system.

It rises to five years' imprisonment and a fine of XOF 15,000,000 to XOF 60,000,000 where the offense is committed to the detriment of the Togolese State.

The provision's trigger is access without right rather than the circumvention of a security measure, so unlike a statute that requires infringing an access control, its plain text does not on its own resolve whether reading a public, unauthenticated page falls inside or outside the offense, and no reported Togolese decision has addressed the question.

Article 9 of the same law separately punishes destroying, hindering, falsifying, disrupting or interrupting the functioning of a computer system, and article 10 separately punishes introducing, deleting, altering, destroying, extracting or intercepting computerised data, each with three to five years' imprisonment and a fine of XOF 25,000,000 to XOF 100,000,000; both are aimed at interference with or extraction of data from a system rather than passive reading of a page it makes public.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (426 words)

Togo's cybersecurity posture for the private-sector duty-bearer rests on Titre II of Loi n° 2018-026 du 07 décembre 2018 sur la cybersécurité et la lutte contre la cybercriminalité, which binds a designated class of opérateur de services essentiels (operator of essential services) to cybersecurity rules protecting its essential infrastructure, enforced by the Agence nationale de la cybersécurité (ANCy) that the same Act creates.

No product-security or connected-device market-placement duty on a manufacturer was located; ANCy's own power to certify hardware, software and IT services for their cybersecurity capability (Article 6) reads as a voluntary scheme rather than a mandatory gate to market, since the Act states no duty to hold that certification before sale or use.

No instrument establishes an incident-notification duty on an operator with a stated threshold or clock; the Act empowers ANCy to collect technical information about an incident affecting an operator of essential services' essential infrastructure and to audit and inspect its compliance, and whether a decree issued under Article 3 or Article 6 adds a notification deadline is not confirmed in the primary text.

Togo has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is Article 52 of Loi n° 2019-014 du 29 octobre 2019 relative à la protection des données à caractère personnel, the security-of-processing obligation inside Togo's comprehensive privacy law, which sits in the privacy topic rather than here, and a search of that law's full text for a breach-notification duty to the data-protection authority or to data subjects returned no match, so none is described here.

Titre III of Loi n° 2018-026 (Lutte contre la cybercriminalité) criminalizes unauthorized access to and interference with a computer system and adjacent offenses; those are offenses committed against a system rather than duties on an operator or manufacturer, so they belong to the scraping topic's computer_misuse family and are not described here.

Whether a BCEAO (Banque Centrale des Etats de l'Afrique de l'Ouest) directive imposes IT-risk or cybersecurity duties on a bank or financial institution licensed in Togo is not confirmed here; whether ARCEP Togo (the telecommunications regulator, whose own site is unreachable through the path tried) has issued a network-security regulation binding a licensed operator is likewise not confirmed; and whether Togo has ratified the African Union Convention on Cyber Security and Personal Data Protection (the Malabo Convention) is not confirmed either, since its own treaty page on au.int does not name Togo.

None of the three is recorded as an instrument here, and each is an open question rather than a finding of absence.

Sector security regimes

Loi n° 2018-026, opérateurs de services essentiels and the National Cybersecurity Agency (ANCy)

Titre II (Arts. 3, 5-7), Loi n° 2018-026 du 07 décembre 2018 sur la cybersécurité et la lutte contre la cybercriminalitéJournal Officiel de la République togolaise, 63e année n° 24 ter, numéro spécial du 07 décembre 2018

In force since 7 December 2018. Binds public and private bodies.

What this law does

Titre II of Loi n° 2018-026 subjects an operator of essential services to cybersecurity rules that protect its essential infrastructure. The Act defines an operator of essential services as any public or private operator offering a service essential to the functioning of society or the economy whose continuity could be gravely affected by an incident touching the electronic communications networks or information systems needed to provide it.

Article 3 leaves which operators receive that designation, and how essential infrastructure is determined, to a decree in Council of Ministers. The same Article leaves the content of the cybersecurity rules those operators must follow to a decree in Council of Ministers as well. Article 6 creates the Agence nationale de la cybersécurité (ANCy) as a public legal person with financial autonomy. ANCy designates the operators of essential services.

ANCy fixes the protective measures an operator of essential services must implement to secure its essential infrastructure, and controls the operator's compliance with them through inspections. ANCy grants or withholds an operator's accreditation based on that compliance. ANCy collects technical information about an incident affecting an operator's essential infrastructure.

ANCy may impose astreintes or sanctions, including monetary ones, on an operator that does not meet its cybersecurity obligations. The modalities of control and the sanctions applicable for non-compliance are themselves left to a decree in Council of Ministers. ANCy also certifies hardware, software and IT services for their capacity to perform cybersecurity functions.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (196 words)

Togo has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is Loi n° 91-12 du 10 juin 1991 portant protection du droit d'auteur, du folklore et des droits voisins, which lets a person, once a work is lawfully disclosed, make short quotations and analyses for a scientific, critical, polemical, teaching or informational purpose, compile a press review, and reproduce or broadcast current political, social or economic news articles for informational purposes unless the reproduction right was expressly reserved, on condition that the author's name and the source are credited.

Unlike some neighbouring jurisdictions' copyright statutes, Loi n° 91-12 carries no separate exclusion of the news of the day or of bare facts from protection, so a court applying it must reach that question, if at all, through the originality requirement rather than a standalone facts exclusion. The Law predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

Snippet reproduction

Loi n° 91-12, quotation and current-events press-reproduction exception

Loi n° 91-12 du 10 juin 1991 portant protection du droit d'auteur du folklore et des droits voisins, arts. 21-22 (citations et reproduction d'actualité par la presse)Loi n° 91-12 du 10 juin 1991

In force. Binds public and private bodies.

What this law does

Article 21 permits, once a work has been lawfully made accessible to the public and provided the work's title and the author's name are mentioned, short analyses and quotations taken from it, including quotations of newspaper and periodical articles in the form of a press review, where they conform to fair usage and are justified by a scientific, critical, polemical, teaching or informational purpose; such quotations and analyses may be used in the original or in translation.

Article 22 separately permits reproducing by the press, or broadcasting, for informational purposes, political, social or economic news articles published in their original form or in translation, and speeches delivered in public at official ceremonies or at political, judicial, administrative or religious meetings and assemblies. This is on condition that the author's name and the source are mentioned and that the right of reproduction has not been expressly reserved.

Neither article caps the quotation or the reproduction at a headline-length or short-extract threshold beyond the fair-usage and informational-purpose tests, and no reported Togolese decision applies either article to a systematic aggregator's reproduction of headlines and snippets, as opposed to an individual quotation or a traditional press review.

Togo has no separate press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no recognized hot-news or misappropriation doctrine distinct from ordinary copyright and the law's civil seizure remedies, and no located case law on hyperlinking or framed display.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.