🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CI v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing6 sources retrieved model claude-sonnet-5 · 2026-08-05

Ivory Coast (UEMOA Bloc)

CI schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 8 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
8Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction lead brief

Latest update · 28 September 2026

Lead Signal

Cote d'Ivoire's data-protection regulator, ARTCI, is confirmed this cycle as the operative Autorite de Protection des Donnees a Caractere Personnel under Loi n°2013-450 du 19 juin 2013, correcting an earlier seed reference to a body named ADPP. ARTCI's own publication describes itself in that capacity directly, and the statute itself creates the authority and fixes data-subject rights. This is a naming correction with substantive weight: it fixes the identity of the body an operator or complainant in Cote d'Ivoire must actually deal with.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statute and regulator identity confirmed via secondary sources; primary legal text (Journal Officiel) and full scope/registration detail not directly retrieved in this run.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Traffic-light rationale — AmberCore statute and regulator identity confirmed via secondary sources; primary legal text (Journal Officiel) and full scope/registration detail not directly retrieved in this run.

Sub-modules (5)

Regulator And AuthorityAmber

ARTCI, Côte d'Ivoire's telecoms/ICT regulator, has been documented issuing data-protection-related communiqués and reminders to controllers, consistent with a designated DPA role.

Claims (1):

  • ARTCI (the Telecommunications/ICT Regulatory Authority of Côte d'Ivoire) exercises data-protection oversight functions, including issuing public communiqués addressing personal data/privacy matters.

Act And InstrumentsGreen

Law No. 2013-450 is the primary instrument; a DataGuidance legal-research index confirms its title and existence.

Claims (1):

  • Law No. 2013-450 on the Protection of Personal Data is the primary omnibus data-protection statute of Côte d'Ivoire.

Material ScopeRed

Material scope (what data/processing is caught) was not independently verified from primary text in this run.

Absence provenance: unavailable. Searched: unavailable.

Territorial ScopeRed

No confirmed evidence located on extraterritorial/establishment-based application of the 2013 law to non-established controllers.

Absence provenance: unavailable. Searched: unavailable.

Regulator Registration And FilingAmber

Secondary sources indicate ARTCI issues reminders to data controllers of their obligations, consistent with a declaration/authorisation-style formality regime common to francophone West African DP laws, but the specific CI filing mechanics were not independently confirmed.

Claims (1):

  • ARTCI actively reminds data controllers operating in Côte d'Ivoire of registration/compliance obligations under the personal data protection regime.
Category narrative83 words

Côte d'Ivoire's personal data regime rests on Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, a comprehensive omnibus statute. The Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI) — originally the telecoms/ICT sector regulator — was designated to exercise data-protection regulatory functions, publishing controller-facing reminders and privacy communiqués. Material and territorial scope details, and the precise registration/filing procedure, are only partially confirmed from secondary-source snippets; the operative Journal Officiel text was not directly retrievable in this run.

Periodic update · new data 2026-09-28

Regulator & Framework

ARTCI is confirmed this cycle as the Autorite de Protection des Donnees a Caractere Personnel exercising Cote d'Ivoire's statutory data-protection regulator role, a role fixed by Loi n°2013-450 du 19 juin 2013. This corrects an earlier reference naming a body 'ADPP'; ARTCI is the operative body acting in that capacity, per ARTCI's own published material describing itself in the role. Loi n°2013-450 establishes the legal framework for personal-data protection in Cote d'Ivoire, defining lawful-processing principles and creating the Autorite de Protection itself, and remains the core omnibus statute governing the field.

The principal framework development this cycle is procedural rather than legislative: ARTCI launched CERTINUM in 2026, with a launch ceremony held on 2 July 2026 after having been postponed from an earlier date, as a digital platform intended to accelerate and secure personal-data-processing compliance and authorisation procedures. This is a digitalisation of existing administrative pathways -- registration, notification and authorisation requests -- rather than a change to the substantive obligations the statute already imposes. No amendment to Loi n°2013-450 itself was evidenced this cycle.

Outlook

Watch for CERTINUM's practical effect on processing timelines for authorisation and notification requests once it is in fuller operation, and for whether ARTCI issues further public guidance clarifying its own regulatory identity following the naming correction noted above.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ProbableOneTrust DataGuidance — ARTCI (the Telecommunications/ICT Regulatory Authority of Côte d'Ivoire) exercises data-protection oversight functions, including issuing public communiqués addressing personal data/privacy matters.observed
  2. ConfirmedOneTrust DataGuidance — Law No. 2013-450 on the Protection of Personal Data is the primary omnibus data-protection statute of Côte d'Ivoire.observed
  3. UncertainOneTrust DataGuidance — ARTCI actively reminds data controllers operating in Côte d'Ivoire of registration/compliance obligations under the personal data protection regime.observed

#

No T1/T2 primary-text confirmation retrieved for lawful bases or special-category provisions specific to CI in this run.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — Not assessedNo T1/T2 primary-text confirmation retrieved for lawful bases or special-category provisions specific to CI in this run.

Sub-modules (4)

Lawful BasesRed

Not independently confirmed for CI in this run.

Absence provenance: unavailable. Searched: unavailable.

Special CategoriesRed

Not independently confirmed for CI in this run.

Absence provenance: unavailable. Searched: unavailable.

Pseudonymisation And AnonymisationRed

Not independently confirmed for CI in this run.

Absence provenance: unavailable. Searched: unavailable.

Category narrative66 words

No primary-text confirmation was obtained in this run for Côte d'Ivoire's enumerated lawful bases, consent standards, or special-category rules under Law No. 2013-450. Regional pattern (French-influenced francophone African DP statutes of this era) typically enumerates consent, contract, legal obligation, vital interest and public-interest/legitimate-interest-style bases with heightened protection for health, biometric, and other sensitive data, but this was not independently verified for CI specifically in this run.

#

No direct evidentiary confirmation of specific data-subject-rights provisions for CI obtained in this run.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — Not assessedNo direct evidentiary confirmation of specific data-subject-rights provisions for CI obtained in this run.

Sub-modules (5)

Access RightRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Rectification And ErasureRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Restriction And ObjectionRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Data PortabilityRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Deadlines And Response WindowsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Category narrative50 words

No CI-specific primary or secondary evidence on the subject-access, rectification/erasure, restriction/objection, portability, or response-deadline framework under Law No. 2013-450 was retrieved in this run. Given the omnibus nature of the statute and its designation of ARTCI as regulator, a rights framework analogous to regional peers is plausible but unverified here.

#

Regulator-controller engagement is evidenced; specific duty thresholds (DPO appointment triggers, breach-notification timelines, retention limits) are unverified.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — AmberRegulator-controller engagement is evidenced; specific duty thresholds (DPO appointment triggers, breach-notification timelines, retention limits) are unverified.

Sub-modules (7)

Accountability And DpiaRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Dpo RequirementsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Ropa RequirementsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Security MeasuresRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Breach NotificationRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Retention And DisposalRed

Not confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Category narrative35 words

ARTCI has publicly reminded data controllers of compliance obligations, indicating an active accountability/enforcement posture, but granular DPIA, DPO, ROPA, joint-controller, security, breach-notification and retention provisions specific to CI were not independently verified in this run.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — ARTCI's public reminders to data controllers of their compliance obligations indicate an active accountability-oversight function under Law No. 2013-450, though the specific DPIA/DPO/breach thresholds remain unverified.observed

#

Regional instrument (ECOWAS Supplementary Act) applicability is inferable from ECOWAS membership but CI-specific ratification/ transfer-mechanism detail is unconfirmed; no EU adequacy exists either way.

Primary frameworkLaw No. 2013-450; ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection (regional overlay)
Supervisory authorityARTCI
Traffic-light rationale — AmberRegional instrument (ECOWAS Supplementary Act) applicability is inferable from ECOWAS membership but CI-specific ratification/ transfer-mechanism detail is unconfirmed; no EU adequacy exists either way.

Sub-modules (6)

Transfer MechanismsRed

Specific cross-border transfer mechanisms (consent, contractual clauses, authorisation) under CI's 2013 law were not independently verified.

Absence provenance: unavailable. Searched: unavailable.

Adequacy ReceivedRed

No evidence of any adequacy decision received by Côte d'Ivoire from the EU or other regimes.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedRed

No evidence Côte d'Ivoire operates an outbound adequacy-whitelisting mechanism.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsRed

No CI-specific SCC/BCR uptake data identified.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No TIA obligation identified for CI.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationRed

No data-localisation mandate identified for CI in available sources.

Absence provenance: unavailable. Searched: unavailable.

Category narrative83 words

Côte d'Ivoire has not received or granted any EU adequacy decision. As a founding ECOWAS member state, Côte d'Ivoire is presumptively within scope of the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection (a regional harmonisation instrument referenced by DataGuidance for comparator ECOWAS states such as Ghana and Cape Verde), though direct confirmation of Côte d'Ivoire's own ratification status for this Act and for the African Union Malabo Convention was not obtained in this run. No data-localisation mandate specific to CI was identified.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — As an ECOWAS member state, Côte d'Ivoire falls within the intended scope of the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection within ECOWAS, a regional harmonisation instrument for cross-border data flows among member states.observed

#

No sectoral overlay instrument specific to CI was retrieved; narrative flags a plausible but unverified financial-sector nexus.

Traffic-light rationale — Not assessedNo sectoral overlay instrument specific to CI was retrieved; narrative flags a plausible but unverified financial-sector nexus.

Sub-modules (7)

Financial Sector OverlayRed

Not independently confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Health Sector OverlayRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Telecoms And EprivacyRed

Not confirmed beyond ARTCI's general telecom-regulator identity.

Absence provenance: unavailable. Searched: unavailable.

Employment DataRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Credit And ScoringRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

EducationRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

InsuranceRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Category narrative52 words

No CI-specific sectoral overlay evidence (banking/BCEAO-UEMOA financial data rules, health-sector rules, telecoms/ePrivacy, employment, credit-scoring, education, or insurance) was retrieved in this run. Côte d'Ivoire's membership in the West African Economic and Monetary Union (UEMOA/BCEAO) plausibly implies financial-sector data-handling instructions for mobile-money and banking operators, but this was not independently confirmed via search.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

No adtech/commercial-privacy-specific instrument or guidance for CI was located in this run.

Traffic-light rationale — Not assessedNo adtech/commercial-privacy-specific instrument or guidance for CI was located in this run.

Sub-modules (6)

Cookies And TrackersRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Dark PatternsRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Opt Out SignalsRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Direct MarketingRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Category narrative22 words

No CI-specific evidence was found on cookie/tracker consent regimes, dark-pattern prohibitions, opt-out signal recognition, clean-room rules, cross-context advertising, or direct-marketing suppression frameworks.

#

A national AI-policy study is confirmed; binding profiling/ADM/biometric statutory detail specific to CI is unverified.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — AmberA national AI-policy study is confirmed; binding profiling/ADM/biometric statutory detail specific to CI is unverified.

Sub-modules (6)

Profiling RestrictionsRed

Not independently confirmed for CI's specific statutory text.

Absence provenance: unavailable. Searched: unavailable.

Automated Decision Making TransparencyAmber

Regional pattern across African DP laws generally recognises a right against solely-automated decisions, but CI-specific text unconfirmed.

Claims (1):

  • Among the 39 African countries with data protection laws (a set that includes Côte d'Ivoire), 35 recognize a right not to be subject to solely automated decision-making, indicating a regional pattern that plausibly extends to CI's statute though not independently verified against its specific articles.

Ai Risk AssessmentsAmber

A 2024 Ivorian government-linked study examined AI, 5G and metaverse governance challenges, aiming at ethical and responsible adoption, but this is a policy study rather than a binding AI-risk-assessment regime.

Claims (1):

  • A study initiated in April 2024 examined the challenges and issues of AI, 5G networks and the metaverse for developing Côte d'Ivoire's digital economy, aiming to promote inclusive, ethical and responsible adoption of emerging technologies.

Biometric RegimeRed

Not independently confirmed for CI in this run.

Absence provenance: unavailable. Searched: unavailable.

Genetic DataRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Category narrative92 words

IAPP reporting indicates a 2024-initiated study on the challenges of AI, 5G and the metaverse for Côte d'Ivoire's digital economy, aimed at promoting inclusive, ethical and responsible adoption of emerging technologies, but this reflects a policy study rather than binding profiling/ADM/biometric legislation. Across the 39 African countries with data protection laws generally, the right not to be subject to solely automated decision-making is widely recognised, which — if CI's 2013 law follows the regional pattern — would suggest an Article-22-style analogue, though this was not independently confirmed against CI's specific statutory text.

Sources and claims (2)
  1. UncertainInternational Association of Privacy Professionals — Among the 39 African countries with data protection laws (a set that includes Côte d'Ivoire), 35 recognize a right not to be subject to solely automated decision-making, indicating a regional pattern that plausibly extends to CI's statute though not independently verified against its specific articles.observed
  2. ProbableInternational Association of Privacy Professionals — A study initiated in April 2024 examined the challenges and issues of AI, 5G networks and the metaverse for developing Côte d'Ivoire's digital economy, aiming to promote inclusive, ethical and responsible adoption of emerging technologies.observed

#

No age-of-consent, parental-consent, or minor-specific provision was retrieved for CI in this run.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — Not assessedNo age-of-consent, parental-consent, or minor-specific provision was retrieved for CI in this run.

Sub-modules (5)

Age VerificationRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Minor Profiling BansRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Education SettingsRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Category narrative21 words

No CI-specific evidence was retrieved on age-of-consent thresholds, parental-consent mechanisms, minor-profiling bans, education-setting rules, or dependent-adult protections under Law No. 2013-450.

#

No penalty-cap, enforcement-activity, or redress-mechanism evidence specific to CI was retrieved; only general regulator-engagement signals exist.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — RedNo penalty-cap, enforcement-activity, or redress-mechanism evidence specific to CI was retrieved; only general regulator-engagement signals exist.

Sub-modules (6)

Regulator Powers And PenaltiesRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Enforcement Activity IndexRed

No fines or enforcement decisions attributable to ARTCI in the last 12 months were located.

Absence provenance: unavailable. Searched: unavailable.

Regulator Funding And CapacityRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Private Right Of ActionRed

Not confirmed.

Absence provenance: unavailable. Searched: unavailable.

Recent Developments 180DRed

No CI-specific data-protection developments within the last 180 days (from 2026-08-05) were located.

Absence provenance: unavailable. Searched: unavailable.

Category narrative57 words

ARTCI's documented activity (controller reminders, an app-privacy communiqué) indicates it exercises supervisory and public-facing enforcement-adjacent functions, but no specific fines, investigative-power statutes, penalty caps, collective-redress mechanisms, or private-right-of-action provisions for CI were retrieved. No enforcement decisions or fines in the last 12 months, and no developments in the last 180 days, were located for Côte d'Ivoire specifically.

Periodic update · new data 2026-09-28

Enforcement & Redress

Cote d'Ivoire's data-protection enforcement regime combines administrative and criminal mechanisms. Article 45 of Loi n°2013-450 punishes obstruction of the Autorite de Protection's investigative action with one month to two years' imprisonment and a fine of 1,000,000 to 10,000,000 CFA francs, giving ARTCI's investigative powers a criminal backstop rather than leaving compliance with an investigation purely voluntary.

On the administrative side, ARTCI issued Decision n°2024-0996 on 16 January 2024, a warning and formal notice against the Ministere de l'Enseignement Technique, de la Formation Professionnelle et de l'Apprentissage. This is notable both for its target -- a government ministry rather than a private-sector controller -- and for its form, a warning and formal notice rather than a monetary penalty, suggesting ARTCI's practice to date favours a graduated enforcement approach that begins with formal notice before escalating.

Taken together, the criminal-obstruction provision and the January 2024 ministry decision indicate a regulator with both the statutory teeth and the demonstrated willingness to act against non-compliant bodies across the public and private sectors, though the evidence base for enforcement volume beyond this single 2024 decision remains thin this cycle.

Outlook

Watch for whether ARTCI escalates beyond warnings and formal notices to monetary penalties in future decisions, and for whether enforcement activity against private-sector controllers, not evidenced this cycle, becomes visible in subsequent reporting.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — ARTCI demonstrates an active supervisory posture toward data controllers in Côte d'Ivoire, evidenced by public reminders of compliance obligations and privacy-related communiqués, though the specific statutory penalty regime was not independently verified.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct18.18
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Ivory Coast (UEMOA Bloc)
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 8 claim(s) (8 category placement(s)), 16 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

Only regulator_and_framework, algorithmic_biometric_and_surveillance_governance, and enforcement_and_redress modules carry any populated claims, all sourced from T3 secondary databases (DataGuidance, IAPP) rather than T1 primary legal text — the Journal Officiel text of Law No. 2013-450 and any ARTCI implementing decrees were not directly retrievable via search in this run. The remaining seven modules (lawful_processing_and_special_data, data_subject_rights, controller_processor_duties [partial], cross_border_and_adequacy [partial], sectoral_watch, adtech_and_commercial_privacy, children_and_vulnerable_groups) carry empty claims[] with explicit absent_field_provenance naming the searches performed. No CI-specific enforcement fines, penalty caps, or 180-day developments were located.

Unresolved questions (6):

  • What are the specific lawful bases, consent standards, and special-category rules enumerated in Law No. 2013-450's operative articles?
  • What is Côte d'Ivoire's confirmed ratification status for the ECOWAS Supplementary Act A/SA.1/01/10 and the African Union Malabo Convention?
  • Does ARTCI operate a mandatory pre-processing declaration/authorisation regime, and what are its thresholds and exemptions?
  • What are ARTCI's statutory maximum penalties and investigative powers, and has it issued any sanctions to date?
  • Are there BCEAO/UEMOA financial-sector data-handling instructions applicable to mobile-money and banking operators in Côte d'Ivoire?
  • Does Law No. 2013-450 contain an Article-22-style automated-decision-making right, and are there minor/parental-consent provisions?

Escalate to primary-source review: yes