An Innovative Legislative Framework for Privacy in Benin

An Innovative Legislative Framework for Privacy in Benin

Benin’s Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information, also known as the Law for short, is a data privacy law that was passed in Benin 2009. As one of the numerous countries around the world that have drawn influence from the European Union’s landmark General Data Protection Regulation or GDPR, Benin’s Digital Code, a telecommunications and cybersecurity law, promulgated the EU’s GDPR law to supplement the Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information. As such, the Law establishes the legal basis for which personal data may be collected and processed within Benin, as well the principles that individuals and organizations must follow when collecting or processing personal data.

How are data controllers and processors defined under the Law?

Under Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information, a data controller is defined as an individual who “controls the procedures and purpose of data usage. Data controllers are required to file an annual report with the APDP on compliance with the processing principles”. Conversely, the Law defines a data processor as a  “person, company, or other body which processes personal data on the data controller’s behalf”. Moreover, personal data is defined as “any information relating to an identified or identifiable natural person. It makes a direct reference to sound and image. In addition, the APDP considers that this definition applies to the data of a deceased individual authority”.

As it pertains to the scope and application of Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information, the personal scope of the law is applicable to all legal persons, agencies, or public authorities, or any other body that collects or processes personal data, whether said collection or processing is done via a third party or not. Alternatively, the territorial scope of the law applies to all data controllers and processors within Benin, including major social media and Fintech companies. Furthermore, the material scope of the law applies to all collection, processing, storage, use, and transmission of personal data, with certain exceptions, such as personal data that is processed in the context of the offering of staff management services.

What are the responsibilities of data controllers and processors under the law?

The Digital Code of Benin set forth the following data protection principles through the Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information:

As Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information contains many provisions similar to the EU’s GDPR law that were adapted to fit the data protection needs of Benin, the law also mandates that data controllers and processors provide data subjects with data processing notifications, as well as data breach notification in the event that a data breach occurs. Additionally, data controllers and processors are also responsible for maintaining detailed data processing records, as well as following specific requirements set forth by the law as it relates to the collection and processing of both special categories of personal data, as well as children’s data. Organizations and agencies that collect and process personal data are required to appoint a data protection officer or DPO under certain circumstances.

What are the rights of data subjects under Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information?

Under Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information Beninese citizens have the following rights with respect to the protection of their personal data and privacy:

In terms of penalties that can be imposed as a result of failing to comply with the regulations set forth by the law, Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information is enforced by the Beninese Data Protection Authority or APDP for short. As such, the APDP is authorized to levy the following punishments:

Benin’s Digital code and by extension, Law No. 2009-09 of May 22, 2009, Dealing with the Protection of Personally Identifiable Information, is considered to be one of the most innovative and sophisticated legal instruments concerning the protection of personal data in Africa. As such, Benin is a part of a handful of African countries that have been leading the way for comprehensive data protection legislation to be implemented around the continent, including Kenya’s Data Protection Act 2019 and Ghana’s Data Protection Act. To this end, citizens of Benin are afforded a level of data protection that remains largely unrivaled in not only their region, but the world as a whole.

Related Reads