Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
ARTCI Prior Authorisation + Notification + Public Register
Cote dIvoire Law 2013-450 Articles 5-8 + Decree 2017-740 Articles 1-15 ARTCI Prior Authorisation and Notification Regime (NOTE: Cote dIvoire retains French CNIL-style declaration model rather than GDPR accountability model). Standard processing requires prior declaration (declaration prealable) to ARTCI via electronic portal artci.ci + free of charge + within 30 days before processing commencement + describing categories + purposes + recipients + retention + safeguards + Cross-Border transfer destination. Sensitive personal data + interconnection of files + Cross-Border transfer + biometric + criminal record + national identification number + medical research processing require prior authorisation (autorisation prealable) - ARTCI review + 90-day response (deemed approval if no response) + may impose conditions. Public Register of declarations and authorisations maintained by ARTCI + free
- ARTCI prior declaration receipt
- Authorisation grant evidence
- Renewal records
- Exemption documentation
- Sector-specific Code of Conduct adoption
- Single-window submission evidence
- Processing without declaration
- Sensitive data without authorisation
- No renewal
- No Code of Conduct adoption
Cross-Border + Articles 49-50 + ARTCI Adequacy + SCC
Cote dIvoire Law 2013-450 Articles 49-50 Cross-Border Data Transfer Regime. Article 49 Transfer of personal data outside Cote dIvoire permitted only where: (1) destination jurisdiction provides adequate level of protection (niveau de protection adequat) - ARTCI publishes White List of adequate jurisdictions including EU/EEA + UK + Switzerland + Convention 108 parties + recognised African jurisdictions; (2) explicit informed consent of data subject; (3) Performance of contract with data subject or in data subject interest; (4) Compelling public interest authorised by law; (5) Vital interests; (6) Legal claims; (7) ARTCI-approved Standard Contractual Clauses (Clauses Contractuelles Types - CCT) + Binding Corporate Rules (Regles Internes dEntreprise - RIE) for intra-group transfers within multinational groups; (8) ARTCI-approved Codes of Conduct + Certification mechanisms. Article 50 Specif
- Cross-border transfer inventory
- ARTCI authorisation evidence per transfer
- ARTCI-approved SCC (CCT) executed copies
- ARTCI-approved BCRs (RIE)
- Schrems II Transfer Impact Assessment
- White List reliance documentation
- Mobile Money BCEAO joint oversight evidence
- Transfer without ARTCI authorisation
- Old SCCs not CCT
- No TIA
- Missing BCEAO coordination for fintech
DPO + ROPA + ARTCI + Sanctions + Modernisation
Cote dIvoire Law 2013-450 Articles 55-77 + Decree 2017-740 governance + enforcement framework. Article 55 Data Protection Officer (DPO - Delegue a la Protection des Donnees) - mandatory for: (a) public bodies; (b) large-scale sensitive data processors; (c) systematic monitoring + profiling; (d) ARTCI-licensed entities. DPO qualifications + independence + reporting to highest management + sufficient resources + ARTCI register + Association des DPO de Cote dIvoire continuing professional development. Article 65 Records of Processing Activities (ROPA - Registre des Traitements) - maintained for each processing operation including categories + purposes + recipients + transfers + retention + security + made available to ARTCI on request. Article 62 ARTCI Inspection Powers - on-site inspection + production of records + access to systems + interviews + may delegate to qualified experts + sworn
- DPO designation records
- ROPA per processing operation
- ARTCI inspection response plan
- Sanctions exposure register (XOF 5M-50M + criminal 1-5 years)
- Marketing opt-in evidence
- Cookies banner compliance
- Modernisation Bill 2025-2026 readiness gap analysis
- Tribunal Administratif review procedure
- No DPO
- ROPA incomplete
- No ARTCI response plan
- No sanctions exposure analysis
- No marketing opt-in
- No Modernisation readiness
Lawful Basis + Consent + Notice + Quality Principles
Cote dIvoire Law 2013-450 Articles 13-26 + Decree 2017-740 lawful basis for processing. Article 14 consent (consentement) - explicit + specific + informed + free + unambiguous + withdrawable + revocable + special form for minors via legal guardian + verifiable. Alternative lawful bases: (1) Compliance with legal obligation; (2) Performance of contract with data subject; (3) Vital interests of data subject; (4) Public interest task; (5) Legitimate interests of controller not overridden by data subject fundamental rights. Article 26 Information to data subject (devoir dinformation) must cover: identity of controller + Ivorian establishment + purposes + categories + recipients + retention + Cross-Border transfer destinations + safeguards + data subject rights + ARTCI complaint avenue + free French notice + accessible to data subject (Article 26-2 elaborated). Articles 7-13 Principles: (a) L
- Lawful basis register per processing
- Consent records (granular and withdrawable)
- French privacy notices
- Quality control programme
- Direct collection notification evidence
- Indirect collection notification
- Withdrawal mechanism
- Bundled consent
- Notice not in French
- No quality control programme
- Indirect collection notice missing
- No withdrawal mechanism
Scope + Loi 2013-450 + ARTCI + Convention 108 + Malabo
Republic of Cote dIvoire Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data (Loi No 2013-450 du 19 juin 2013 relative a la protection des donnees a caractere personnel) + Implementing Decree No. 2017-740 of 8 November 2017 (Decret No 2017-740 portant application de la Loi sur la protection des donnees a caractere personnel). Foundational Ivorian data protection statute. Universal application to controllers + processors processing personal data in Cote dIvoire + extraterritorial application where Ivorian data subjects are targeted. Constitutional anchor Cote dIvoire Constitution (2016 revised) Article 13 right to privacy + Article 19 fundamental rights. Autorite de Regulation des Telecommunications/TIC de Cote dIvoire (ARTCI) - independent regulatory authority + Abidjan headquarters + Director General + ARTCI Council + supervisory authority for telecommunications + ICT +
- Applicability assessment
- Personal data inventory
- ARTCI engagement records
- Implementing Decree 2017-740 compliance evidence
- Constitutional alignment memo
- Malabo Convention compliance
- No ARTCI registration
- Missing French notices
- No Implementing Decree compliance
- Treating CI Law same as GDPR without Ivorian provisions
Security + Processor + Breach Notification + Articles 42-58
Cote dIvoire Law 2013-450 Articles 42-58 Security + Processor + Breach Notification. Article 42 Security of Processing (Securite du Traitement) - appropriate technical + organisational measures proportionate to risk + nature of data + state-of-the-art + including: encryption at rest + in transit for sensitive and credit information data + AES-256 minimum + TLS 1.3 + key management + RBAC + least privilege + segregation of duties + PAM + identity and authentication management + comprehensive logging + monitoring + 1-year retention minimum + vulnerability management + patching + pen-testing + secure SDLC + physical security + data centre + biometric access + CCTV + backup + business continuity + disaster recovery. Article 43 Processor Obligations (Sous-Traitant) - written contract specifying categories + purposes + duration + obligations + security + confidentiality + sub-processing prior
- Security baseline configuration
- Encryption at rest + in transit evidence
- Processor contracts (Article 43 compliant)
- Confidentiality + professional secrecy attestations
- ARTCI breach notification log + 72-hour evidence
- CIRT-CI + CICS coordination records
- Incident response runbook
- No processor contracts
- Late ARTCI notification
- Inadequate logging
- No CIRT-CI liaison
- Missing encryption
Sensitive Data + Article 19 + Children + Article 21
Cote dIvoire Law 2013-450 Articles 19-25 + Decree 2017-740 Sensitive Personal Data and Special Categories. Article 19 Sensitive Data categories (donnees sensibles): racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union or association membership + health + sexual life + sexual orientation + biometric data + genetic data + criminal record + administrative sanctions + offences. Article 20 Sensitive Data processing prohibition - prohibited except: (1) explicit consent of data subject; (2) compelling public interest authorised by specific law; (3) vital interest of data subject + incapacity to consent; (4) medical treatment + healthcare by professional bound by professional secrecy; (5) research with safeguards + anonymisation; (6) processing for legal proceedings; (7) processing for legitimate non-profit activity (religious + philosophical + politica
- Sensitive data inventory + Article 19 categories
- ARTCI authorisation for sensitive processing
- Biometric proportionality + alternative + encryption
- Children parental consent records
- Public Health Code compliance for health data
- Ministry of Women + Family coordination evidence
- DPIA for sensitive processing
- Sensitive without authorisation
- Biometric without proportionality
- Children without parental consent
- Healthcare without Public Health Code alignment
Subject Rights + Access + Rectification + Articles 29-39
Cote dIvoire Law 2013-450 Articles 29-39 Data Subject Rights regime (modeled on French CNIL tradition + EU Directive 95/46/EC era + GDPR alignment via 2020+ ARTCI guidance). Article 29 Right of Access (droit dacces) - to be informed of processing existence + purposes + categories + recipients + Cross-Border destinations + free + first-instance + reasonable subsequent fee + 30-day response standard + judicial review of refusals. Article 32 Right to Rectification (droit de rectification) and Erasure (droit a leffacement) - to correct inaccurate + incomplete + outdated + irrelevant data + to delete data when no longer necessary + consent withdrawn + unlawful processing + 30-day response + propagation to recipients. Article 34 Right to Object (droit dopposition) - to processing on legitimate grounds + absolute right to object to direct marketing + automated decision restriction. Article 39 A
- Rights request handling SLAs (30-day) + log
- Access response templates
- Rectification + erasure procedures
- Automated decision opt-out + human intervention evidence
- Appeals to ARTCI procedure
- Tribunal Administratif review path
- Slow response
- No automated-decision opt-out
- No appeals path
- No identity verification policy
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.