Data Protection in Côte d’Ivoire

Security in Côte d’Ivoire

Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data requires data controllers to implement appropriate security measures to safeguard personal data against any form of breach.

According to Article 39 of the law, the processing of personal data must remain confidential and should only be carried out by individuals acting under the authority of the data controller or their processor, and strictly in accordance with their instructions.

Furthermore, Article 40 specifies that the data controller is required to take all necessary precautions, taking into account the nature of the data and the risks posed by processing, to ensure the security of the data. This includes preventing them from being altered, damaged, or accessed by unauthorised third parties. The controller must also implement technical and organisational measures to protect the data against destruction, loss, alteration, unauthorised disclosure, or access. These measures include securing facilities, controlling access, verifying the identity of third parties, and backing up the data.

In the event of non-compliance with these obligations, the data controller may face various types of sanctions, as provided for in Articles 49 and subsequent of the 2013-450 law on the protection of personal data:

  • Warning: The data protection authority may issue a formal warning to the controller for failing to meet their obligations.
  • Formal Notice: The authority may serve notice on the controller to rectify the identified breaches within a set timeframe.
  • Administrative and Financial Sanctions: If the controller fails to comply with the formal notice, the authority may revoke the authorisation temporarily or permanently and impose a financial penalty proportional to the severity of the breach.
  • Interruption of Processing, Locking of Data, or Prohibition of Processing: In urgent cases where processing causes a violation of rights and freedoms, the authority may order the suspension of data processing, locking of specific data, or a ban on processing activities.
  • Criminal Sanctions: Criminal penalties apply for serious breaches, such as processing sensitive data without authorisation (e.g., racial origin, political opinions, religious beliefs), direct marketing without prior consent, or obstructing the authority's work.
  • Civil Liability: The controller may also be held liable for damages caused to affected individuals due to non-compliance with their obligations, as stipulated in Article 5 of the African Union Convention on Cybersecurity and Personal Data Protection.

Continue reading

  • no results

Previous topic
Back to top