Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
Digital Code (Book III)
Book III of the DRC Digital Code (Ordinance-Law No. 23/010 of 13 March 2023) governs personal data protection through a declaration and authorisation regime supervised by a Data Protection Authority, exercised on an interim basis by the ARPTC.
Personal data protection in the Democratic Republic of the Congo is governed by Book III of Ordinance-Law No. 23/010 of 13 March 2023 establishing the Digital Code, which devotes Articles 183 to 261 to the personal data regime and Articles 262 to 270 to the Data Protection Authority. The regime applies very broadly to the State, provinces, territorial entities and public and private persons, to automated and non-automated processing, and to processing carried out on national territory or abroad. It sets out principles of lawfulness, fairness, transparency, minimisation, accuracy, storage limitation and security, and recognises rights of access, rectification, erasure, limitation, portability and complaint. For ordinary data, only two legal bases are admitted: consent or the necessity of complying with a legal obligation.
Formalities depend on the data: prior authorisation is required for genetic, medical and biometric data, offence-related data, national identification numbers (including telephone numbers), public-interest processing and any transfer to a third country; other processing requires prior declaration, with limited exemptions. Decision No. 039/ARPTC/CLG/2025 of 11 September 2025 sets the procedures and fees (from USD 250 for a declaration to USD 750 for a transfer authorisation, with delivery fees in addition). Pending the effective installation of the independent Data Protection Authority created by Article 262, the telecoms regulator ARPTC exercises its functions on an interim basis. Sanctions include fines of CDF 8 million to 200 million, rising to 5 percent of annual turnover for the most serious violations.
Processing of genetic, medical or biometric data, offence-related data, national identification numbers (including telephone numbers), public-interest processing and any transfer to a third country requires prior authorisation from the authority before implementation.
Any processing not subject to authorisation or expressly exempted must be declared to the authority before implementation; the receipt is valid for three years and substantial changes require an update.
Ordinary personal data may only be processed on the basis of the data subject's consent or the necessity of complying with a legal obligation; sensitive data is prohibited from processing subject to enumerated exceptions such as explicit consent.
Controllers and processors must keep a register of processing activities as the reference document for controls; SMEs and startups are exempt unless processing is risky, non-occasional or involves special categories.
Read more
Anove scans your stack against Digital Code (Book III) and 260+ other frameworks in minutes.
A data protection impact assessment is required for authorisation requests and high-risk processing (large-scale sensitive data, systematic surveillance, automated decisions with legal effects); unresolved high risk requires prior consultation of the authority.