Data Protection in Côte d’Ivoire

Collection and processing in Côte d’Ivoire

Data collection

  • Data must be collected in a lawful, fair and non-fraudulent manner Article 15 of Law 2013-450.
  • Data must be collected for specified, explicit and legitimate purposes and may not be further processed in a manner incompatible with those purposes.
  • The controller must inform the data subject, at the latest at the time of collection of the data, of his identity, the purposes of the processing, the categories of data collected, the recipients, the storage period and his rights (Article 28).
  • The consent of the data subject is generally required for the collection and processing of data (Article 14). This consent must be explicit, unequivocal, free, specific and informed.
  • There are exceptions to consent where processing is necessary to comply with a legal obligation, to perform a task in the public interest, to perform a contract, or to safeguard the vital interests of the data subject.

Data processing

  • Data processing must be carried out in accordance with established principles.
  • Data must be adequate, relevant and not excessive in relation to the purposes for which it is collected.
  • Data processing must be confidential and carried out exclusively by persons acting under the authority of the data controller and only on its instructions.
  • The data controller must take all necessary precautions to prevent the data from being distorted, damaged or accessed by unauthorised third parties. He must also choose a processor who provides sufficient guarantees.
  • Sensitive data is subject to specific rules. Their collection and processing are generally prohibited except in certain cases (explicit consent, safeguarding vital interests, etc.).
  • Personal data must not be kept beyond the period necessary for the purposes for which it was collected and processed.
  • The data controller must guarantee that the data can be used regardless of the technical medium used.

Data processing

  • Data processing must be carried out in accordance with the established principles (Articles 14 et seq. of the 2013-450 Law).
  • Data must be adequate, relevant and not excessive with regard to the purposes for which they are collected (Article 15).
  • Data processing must be confidential and carried out exclusively by persons acting under the authority of the data controller and only on its instructions (Article 39).
  • The data controller must take all necessary precautions to prevent the data from being distorted, damaged or accessed by unauthorised third parties. He must also choose a processor who provides sufficient guarantees (Article 40).
  • Sensitive data is subject to specific rules. According to Article 13, Their collection and processing are generally prohibited except in certain cases (explicit consent, safeguarding vital interests, etc.).
  • Personal data must not be kept beyond the period necessary for the purposes for which they were collected and processed (Article 16).
  • The controller must ensure that the data can be used regardless of the technical medium used (Article 44).

Continue reading

  • no results

Previous topic
Back to top