In 2019, the Republic of the Congo adopted a modern legal framework for the protection of personal data. Six years later, the ecosystem is beginning to take shape — but its practical contours still need to be understood. Here are the essentials for leaders of Congolese public administrations and companies.
The legal framework in two stages
Law No. 29-2019 of 10 October 2019
This founding text sets out the general principles:
- Lawfulness, fairness and transparency of processing
- Purpose limitation (no diversion of use)
- Data minimisation
- Accuracy and limited retention
- Security and confidentiality
- Accountability of the controller
The rights of data subjects include: information, access, rectification, erasure, objection and restriction of processing.
Law No. 5-2025 of 29 March 2025
This more recent text establishes the Commission Nationale de Protection des Données personnelles (CNPD, National Personal Data Protection Commission) — the independent regulatory authority. Its mission: to inform, advise, monitor and sanction.
What this concretely changes for you
If you are a public administration
- You must appoint a data protection officer (DPO).
- Your e-services must respect users' rights (informed consent, right of access, etc.).
- Any serious breach must be notified to the CNPD.
- Your subcontractors (software publishers, hosting providers) must be contractually bound by compliance commitments.
If you are a company
- The same goes for the DPO and notification, with a context-dependent materiality threshold.
- You must keep a record of processing activities documenting each purpose.
- Cross-border transfers are regulated — particular vigilance is required for foreign cloud services.
If you are an NGO or an international organisation
The obligations apply as soon as you process the data of persons located in the Congo, regardless of where your head office is.
The classic pitfalls we see
“Our provider is compliant with the European GDPR, so we're fine.”
— No. European compliance does not exempt you from Congolese law. The obligations are similar but not identical (notably on local hosting and CNPD notification).
“We only collect email addresses, it's negligible.”
— False. An email address is personal data. The principle does not depend on volume.
“We have a privacy policy, so we're protected.”
— The policy is necessary but not sufficient. You also need technical measures (encryption, backups, access control) and organisational measures (training, record of processing, procedures).
Our approach at MOKILIX
All our products incorporate the principles of Law 29-2019 by default:
- MOKILIX AUDIT IT includes a compliance component.
- MOKILIX SHIELD deploys the necessary technical measures (encryption, logging, EDR).
- MOKILIX ASSISTANT offers optional sovereign hosting for sensitive deployments.
- Our privacy policy is drafted with reference to these two laws.
To go further
If your organisation is unsure about its actual compliance, we offer a diagnosis as a first step, within the 2-week scoping phase, at a price set according to the analysis of your need. You leave with an actionable assessment, whether or not we work together.
— Rodrigue DEBI, Chairman & Founder, MOKILIX SAS


