{
  "node_id": "ci-dp-law-2013",
  "title": "Côte d'Ivoire Personal Data Protection Law No. 2013-450 - ARTCI",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Côte d'Ivoire's Loi No. 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel (Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data) - published in the Journal Officiel de la République de Côte d'Ivoire and promulgated in 2013 - is Côte d'Ivoire's primary personal data protection legislation. The law was enacted in the context of Côte d'Ivoire's broader legal framework for the digital economy and information society, complementing the Law on Electronic Transactions and ICT regulations. The supervisory authority designated under the law is the Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI - Côte d'Ivoire Telecommunications/ICT Regulatory Authority), which exercises data protection oversight functions through a specialised committee or commission. Côte d'Ivoire's law was developed in alignment with the ECOWAS Supplementary Act on Personal Data Protection (adopted by ECOWAS in 2010) and draws on the French CNIL data protection model as a former French colonial territory within the Francophone West Africa legal tradition. Key features of Côte d'Ivoire's Law No. 2013-450: (1) Scope - applies to automated and non-automated processing of personal data by public and private entities established in Côte d'Ivoire or using processing means on Ivorian territory; (2) Data processing principles - processing must comply with: lawfulness (loyauté); purpose limitation (finalité); proportionality and relevance; accuracy (exactitude); storage limitation; security (sécurité); and confidentiality (confidentialité); (3) Sensitive personal data - the law prohibits processing without lawful basis for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual life; genetic data; and criminal history; (4) Lawful processing conditions - consent; legal obligation; contractual necessity; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to object; and right not to be subject to solely automated decisions; (6) Declaration and authorisation regime - controllers must file a declaration (déclaration) with ARTCI for standard processing or obtain an authorisation (autorisation) for sensitive or high-risk processing before commencing; (7) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or subject to ARTCI-approved safeguards; (8) Security obligations - controllers must implement technical and organisational security measures; (9) ARTCI enforcement - investigates complaints; conducts audits; issues formal notices; refers violations to judicial authorities; (10) ECOWAS context - the law aligns with the ECOWAS Supplementary Act on Personal Data Protection to facilitate cross-border data flows within the Economic Community of West African States. Côte d'Ivoire is the largest economy in Francophone West Africa and its data protection framework is significant for the UEMOA/WAEMU regional digital economy.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-27001-2022",
    "iso-27701-privacy-information-management"
  ],
  "primary_citations_count": 7
}