Skip to content

Evidence request lists

Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

ARTCI Prior Authorisation + Notification + Public Register

CI-DPL-ARTCI-Prior-Authorisation-Notification-Article-5-Registration-Public-Register
Cote dIvoire Law 2013-450 ARTCI Prior Authorisation + Notification + Registration

Cote dIvoire Law 2013-450 Articles 5-8 + Decree 2017-740 Articles 1-15 ARTCI Prior Authorisation and Notification Regime (NOTE: Cote dIvoire retains French CNIL-style declaration model rather than GDPR accountability model). Standard processing requires prior declaration (declaration prealable) to ARTCI via electronic portal artci.ci + free of charge + within 30 days before processing commencement + describing categories + purposes + recipients + retention + safeguards + Cross-Border transfer destination. Sensitive personal data + interconnection of files + Cross-Border transfer + biometric + criminal record + national identification number + medical research processing require prior authorisation (autorisation prealable) - ARTCI review + 90-day response (deemed approval if no response) + may impose conditions. Public Register of declarations and authorisations maintained by ARTCI + free

Artefacts an auditor will ask for
  • ARTCI prior declaration receipt
  • Authorisation grant evidence
  • Renewal records
  • Exemption documentation
  • Sector-specific Code of Conduct adoption
  • Single-window submission evidence
Where this commonly fails
  • Processing without declaration
  • Sensitive data without authorisation
  • No renewal
  • No Code of Conduct adoption

Cross-Border + Articles 49-50 + ARTCI Adequacy + SCC

CI-DPL-Cross-Border-Data-Transfers-Articles-49-50-ARTCI-Adequacy-Standard-Contractual-Clauses-Convention-108
Cote dIvoire Law 2013-450 Cross-Border + Articles 49-50 + ARTCI + Adequacy + SCC

Cote dIvoire Law 2013-450 Articles 49-50 Cross-Border Data Transfer Regime. Article 49 Transfer of personal data outside Cote dIvoire permitted only where: (1) destination jurisdiction provides adequate level of protection (niveau de protection adequat) - ARTCI publishes White List of adequate jurisdictions including EU/EEA + UK + Switzerland + Convention 108 parties + recognised African jurisdictions; (2) explicit informed consent of data subject; (3) Performance of contract with data subject or in data subject interest; (4) Compelling public interest authorised by law; (5) Vital interests; (6) Legal claims; (7) ARTCI-approved Standard Contractual Clauses (Clauses Contractuelles Types - CCT) + Binding Corporate Rules (Regles Internes dEntreprise - RIE) for intra-group transfers within multinational groups; (8) ARTCI-approved Codes of Conduct + Certification mechanisms. Article 50 Specif

Artefacts an auditor will ask for
  • Cross-border transfer inventory
  • ARTCI authorisation evidence per transfer
  • ARTCI-approved SCC (CCT) executed copies
  • ARTCI-approved BCRs (RIE)
  • Schrems II Transfer Impact Assessment
  • White List reliance documentation
  • Mobile Money BCEAO joint oversight evidence
Where this commonly fails
  • Transfer without ARTCI authorisation
  • Old SCCs not CCT
  • No TIA
  • Missing BCEAO coordination for fintech

DPO + ROPA + ARTCI + Sanctions + Modernisation

CI-DPL-DPO-ROPA-ARTCI-Inspection-Sanctions-Marketing-Cookies-Articles-55-77-Convention-108-Modernisation
Cote dIvoire Law 2013-450 DPO + ROPA + ARTCI + Sanctions + Marketing + Modernisation

Cote dIvoire Law 2013-450 Articles 55-77 + Decree 2017-740 governance + enforcement framework. Article 55 Data Protection Officer (DPO - Delegue a la Protection des Donnees) - mandatory for: (a) public bodies; (b) large-scale sensitive data processors; (c) systematic monitoring + profiling; (d) ARTCI-licensed entities. DPO qualifications + independence + reporting to highest management + sufficient resources + ARTCI register + Association des DPO de Cote dIvoire continuing professional development. Article 65 Records of Processing Activities (ROPA - Registre des Traitements) - maintained for each processing operation including categories + purposes + recipients + transfers + retention + security + made available to ARTCI on request. Article 62 ARTCI Inspection Powers - on-site inspection + production of records + access to systems + interviews + may delegate to qualified experts + sworn

Artefacts an auditor will ask for
  • DPO designation records
  • ROPA per processing operation
  • ARTCI inspection response plan
  • Sanctions exposure register (XOF 5M-50M + criminal 1-5 years)
  • Marketing opt-in evidence
  • Cookies banner compliance
  • Modernisation Bill 2025-2026 readiness gap analysis
  • Tribunal Administratif review procedure
Where this commonly fails
  • No DPO
  • ROPA incomplete
  • No ARTCI response plan
  • No sanctions exposure analysis
  • No marketing opt-in
  • No Modernisation readiness

Lawful Basis + Consent + Notice + Quality Principles

CI-DPL-Lawful-Basis-Consent-Notice-Information-Data-Quality-Articles-13-26-Specific-Informed-Unambiguous
Cote dIvoire Law 2013-450 Lawful Basis + Consent + Notice + Data Quality Principles

Cote dIvoire Law 2013-450 Articles 13-26 + Decree 2017-740 lawful basis for processing. Article 14 consent (consentement) - explicit + specific + informed + free + unambiguous + withdrawable + revocable + special form for minors via legal guardian + verifiable. Alternative lawful bases: (1) Compliance with legal obligation; (2) Performance of contract with data subject; (3) Vital interests of data subject; (4) Public interest task; (5) Legitimate interests of controller not overridden by data subject fundamental rights. Article 26 Information to data subject (devoir dinformation) must cover: identity of controller + Ivorian establishment + purposes + categories + recipients + retention + Cross-Border transfer destinations + safeguards + data subject rights + ARTCI complaint avenue + free French notice + accessible to data subject (Article 26-2 elaborated). Articles 7-13 Principles: (a) L

Artefacts an auditor will ask for
  • Lawful basis register per processing
  • Consent records (granular and withdrawable)
  • French privacy notices
  • Quality control programme
  • Direct collection notification evidence
  • Indirect collection notification
  • Withdrawal mechanism
Where this commonly fails
  • Bundled consent
  • Notice not in French
  • No quality control programme
  • Indirect collection notice missing
  • No withdrawal mechanism

Scope + Loi 2013-450 + ARTCI + Convention 108 + Malabo

CI-DPL-Scope-Application-Loi-2013-450-19-June-2013-Decree-2017-740-ARTCI-Convention-108-Malabo
Cote dIvoire Law 2013-450 Scope and Application + 19 June 2013 + Decree 2017-740 + ARTCI

Republic of Cote dIvoire Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data (Loi No 2013-450 du 19 juin 2013 relative a la protection des donnees a caractere personnel) + Implementing Decree No. 2017-740 of 8 November 2017 (Decret No 2017-740 portant application de la Loi sur la protection des donnees a caractere personnel). Foundational Ivorian data protection statute. Universal application to controllers + processors processing personal data in Cote dIvoire + extraterritorial application where Ivorian data subjects are targeted. Constitutional anchor Cote dIvoire Constitution (2016 revised) Article 13 right to privacy + Article 19 fundamental rights. Autorite de Regulation des Telecommunications/TIC de Cote dIvoire (ARTCI) - independent regulatory authority + Abidjan headquarters + Director General + ARTCI Council + supervisory authority for telecommunications + ICT +

Artefacts an auditor will ask for
  • Applicability assessment
  • Personal data inventory
  • ARTCI engagement records
  • Implementing Decree 2017-740 compliance evidence
  • Constitutional alignment memo
  • Malabo Convention compliance
Where this commonly fails
  • No ARTCI registration
  • Missing French notices
  • No Implementing Decree compliance
  • Treating CI Law same as GDPR without Ivorian provisions

Security + Processor + Breach Notification + Articles 42-58

CI-DPL-Security-Processor-Confidentiality-Breach-Notification-Articles-42-58-Encryption-Logging-Incident
Cote dIvoire Law 2013-450 Security + Processor + Confidentiality + Breach Notification

Cote dIvoire Law 2013-450 Articles 42-58 Security + Processor + Breach Notification. Article 42 Security of Processing (Securite du Traitement) - appropriate technical + organisational measures proportionate to risk + nature of data + state-of-the-art + including: encryption at rest + in transit for sensitive and credit information data + AES-256 minimum + TLS 1.3 + key management + RBAC + least privilege + segregation of duties + PAM + identity and authentication management + comprehensive logging + monitoring + 1-year retention minimum + vulnerability management + patching + pen-testing + secure SDLC + physical security + data centre + biometric access + CCTV + backup + business continuity + disaster recovery. Article 43 Processor Obligations (Sous-Traitant) - written contract specifying categories + purposes + duration + obligations + security + confidentiality + sub-processing prior

Artefacts an auditor will ask for
  • Security baseline configuration
  • Encryption at rest + in transit evidence
  • Processor contracts (Article 43 compliant)
  • Confidentiality + professional secrecy attestations
  • ARTCI breach notification log + 72-hour evidence
  • CIRT-CI + CICS coordination records
  • Incident response runbook
Where this commonly fails
  • No processor contracts
  • Late ARTCI notification
  • Inadequate logging
  • No CIRT-CI liaison
  • Missing encryption

Sensitive Data + Article 19 + Children + Article 21

CI-DPL-Sensitive-Personal-Data-Article-19-Special-Categories-Childrens-Data-Article-21-Minors-Parental-Consent
Cote dIvoire Law 2013-450 Sensitive Personal Data + Article 19 + Children + Article 21

Cote dIvoire Law 2013-450 Articles 19-25 + Decree 2017-740 Sensitive Personal Data and Special Categories. Article 19 Sensitive Data categories (donnees sensibles): racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union or association membership + health + sexual life + sexual orientation + biometric data + genetic data + criminal record + administrative sanctions + offences. Article 20 Sensitive Data processing prohibition - prohibited except: (1) explicit consent of data subject; (2) compelling public interest authorised by specific law; (3) vital interest of data subject + incapacity to consent; (4) medical treatment + healthcare by professional bound by professional secrecy; (5) research with safeguards + anonymisation; (6) processing for legal proceedings; (7) processing for legitimate non-profit activity (religious + philosophical + politica

Artefacts an auditor will ask for
  • Sensitive data inventory + Article 19 categories
  • ARTCI authorisation for sensitive processing
  • Biometric proportionality + alternative + encryption
  • Children parental consent records
  • Public Health Code compliance for health data
  • Ministry of Women + Family coordination evidence
  • DPIA for sensitive processing
Where this commonly fails
  • Sensitive without authorisation
  • Biometric without proportionality
  • Children without parental consent
  • Healthcare without Public Health Code alignment

Subject Rights + Access + Rectification + Articles 29-39

CI-DPL-Data-Subject-Rights-Access-Rectification-Erasure-Object-Articles-29-39-Automated-Decision-Making-30-Day
Cote dIvoire Law 2013-450 Data Subject Rights + Access + Rectification + Erasure + Automated Decisions

Cote dIvoire Law 2013-450 Articles 29-39 Data Subject Rights regime (modeled on French CNIL tradition + EU Directive 95/46/EC era + GDPR alignment via 2020+ ARTCI guidance). Article 29 Right of Access (droit dacces) - to be informed of processing existence + purposes + categories + recipients + Cross-Border destinations + free + first-instance + reasonable subsequent fee + 30-day response standard + judicial review of refusals. Article 32 Right to Rectification (droit de rectification) and Erasure (droit a leffacement) - to correct inaccurate + incomplete + outdated + irrelevant data + to delete data when no longer necessary + consent withdrawn + unlawful processing + 30-day response + propagation to recipients. Article 34 Right to Object (droit dopposition) - to processing on legitimate grounds + absolute right to object to direct marketing + automated decision restriction. Article 39 A

Artefacts an auditor will ask for
  • Rights request handling SLAs (30-day) + log
  • Access response templates
  • Rectification + erasure procedures
  • Automated decision opt-out + human intervention evidence
  • Appeals to ARTCI procedure
  • Tribunal Administratif review path
Where this commonly fails
  • Slow response
  • No automated-decision opt-out
  • No appeals path
  • No identity verification policy
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.