Other Developments
CERTINUM digital-compliance platform launched. ARTCI launched CERTINUM, a digital platform intended to accelerate and secure personal-data-processing compliance and authorisation procedures, with a launch ceremony held on 2 July 2026 after being postponed from an earlier date. This is a procedural digitalisation of existing compliance pathways rather than a change to the underlying substantive law.
Cross-border transfer practice continues on a case-by-case authorisation model. ARTCI issues individual decisions authorising specific cross-border personal-data transfers rather than operating an adequacy-list or standard-contractual-clause model. Decisions n°2024-1001 and n°2024-1002, both dated 16 January 2024, authorised GCB Cocoa Trading Cote d'Ivoire to transfer personal data to the United Kingdom and to Norway respectively. This ad hoc, per-transfer authorisation model is the operative mechanism an organisation must plan around for any international data flow out of Cote d'Ivoire.
Enforcement activity against a government ministry. ARTCI issued Decision n°2024-0996 on 16 January 2024, a warning and formal notice against the Ministere de l'Enseignement Technique, de la Formation Professionnelle et de l'Apprentissage. This shows the regulator willing to act against state bodies, not only private-sector controllers. Separately, Article 45 of Loi n°2013-450 criminalises obstruction of the Autorite de Protection's investigative action, carrying a penalty of one month to two years' imprisonment and a fine of 1,000,000 to 10,000,000 CFA francs, giving the regulator a criminal backstop behind its administrative investigative powers.
Cross-Monitor Connections
The cross-border transfer authorisation practice evidenced here, and the underlying statute's criminal-penalty regime, sit adjacent to financial-integrity's tracking of Cote d'Ivoire's FATF grey-list status and to world-payments' tracking of BCEAO's regional payment-infrastructure rules; this brief does not extend into either domain and confines itself to ARTCI's data-protection-specific regulatory and enforcement record.
Outlook
Watch for whether CERTINUM's rollout changes the practical timeline or documentary burden of ARTCI's authorisation processes, including the case-by-case cross-border transfer decisions. Watch also for whether further enforcement decisions follow the January 2024 pattern of action against both private controllers and government ministries, which would indicate a sustained rather than episodic enforcement posture.
Standing brief · as of 23 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Côte d'Ivoire's data-protection authority, ARTCI, is in an active modernisation phase this cycle, most visibly through the 2 July 2026 launch of CERTINUM, a digital platform built to dematerialise compliance and authorisation procedures for personal-data processing. ARTCI acts as Côte d'Ivoire's Autorité de Protection des Données Personnelles, supervising compliance with Loi n°2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel, the country's principal data-protection statute. CERTINUM's launch, alongside a completed mandatory registration drive for Correspondants à la Protection des Données (CPD) that closed on 31 January 2026, signals a regulator investing in institutional capacity and digital infrastructure rather than one primarily driving change through enforcement action this cycle. This is a modernisation-not-enforcement cycle for Côte d'Ivoire's data-protection regulator, and it follows a pattern in which the country's decade-old omnibus statute is being operationalised through progressively more specific administrative mechanisms — a CPD-designation and registration regime, and now a dedicated digital-compliance platform — rather than through fresh legislation.
Other Developments
CPD registration drive closes. ARTCI required all designated Correspondants à la Protection des Données to register via an online form, with a 31 January 2026 deadline, under Arrêté n°0099/MTND/CAB of 16 August 2024. This drive operationalises the statutory CPD mechanism by bringing the population of designated data-protection correspondents onto a centralised regulator-facing register.
CERTINUM platform launches after a short delay. ARTCI's CERTINUM launch ceremony was originally scheduled for 25 June 2026 and was postponed to 2 July 2026. The platform is intended to accelerate and secure digital-compliance procedures, and its launch, even delayed by roughly a week, represents a concrete infrastructure delivery rather than a policy announcement alone.
ARTCI hosts a major regional conference. ARTCI hosted the 9th RAPDP (Réseau Africain de Protection des Données Personnelles) international conference in Abidjan starting 18 May 2026, with delegations from more than thirty African and European countries in attendance. Hosting a conference of this scale positions Côte d'Ivoire's regulator as a regionally visible convenor on data-governance issues, distinct from, but complementary to, its domestic compliance-infrastructure work.
Correspondant à la Protection des Données duties confirmed from primary source. ARTCI's own published guidance confirms the designation mechanism for the CPD: the data controller designates a CPD, notifies ARTCI, and ARTCI then has thirty days from notification to oppose the designation if the nominee does not meet the profile set by Article 4 of the 11 November 2014 arrêté. Once in place, the CPD must maintain an up-to-date list of the organisation's processing operations and hold access credentials to related processing systems. Loi n°2013-450 remains the controlling legal instrument for all of this cycle's institutional developments: the CPD designation mechanism, the CERTINUM platform, and ARTCI's supervisory mandate generally all operate under its authority, with no indication this cycle of a legislative amendment or a new omnibus instrument superseding it. The thirty-day objection window itself is a meaningful compliance-timeline detail for organisations appointing a CPD: an organisation cannot treat a CPD appointment as final and unchallengeable until that window has lapsed without ARTCI objection, and the Article 4 profile requirement means the nominee's qualifications are subject to regulator scrutiny rather than being left entirely to the appointing organisation's discretion.
Cross-Monitor Connections
ARTCI's institutional design, combining telecoms/ICT sector regulation with data-protection authority (APDP) responsibilities in a single body, is a structural feature relevant to any monitor tracking Côte d'Ivoire's broader digital-economy regulatory architecture, including the World Payments Monitor's coverage of payment-institution licensing and the Crypto Monitor's coverage of BCEAO's digital-asset policy activity, insofar as all three regulatory tracks intersect with the same digitising economy. No direct instrument-level overlap with those monitors' findings was identified this cycle.
Outlook
The near-term question is whether CERTINUM's rollout translates into measurable changes in authorisation-procedure timelines or compliance uptake, which would be the natural next data point once the platform has been operating for a full reporting cycle. On the institutional side, ARTCI's hosting of the 9th RAPDP conference and its completed CPD registration drive both point toward a regulator building regional standing and domestic administrative capacity in parallel; whether either translates into visible enforcement activity — fines, audits, or published decisions — remains an open question this cycle, since no enforcement action was identified in the current evidence base. Taken together, this cycle's developments describe a regulator whose credibility investment is currently running ahead of its enforcement record — a pattern common among newly digitising African data-protection authorities building administrative capacity before scaling enforcement — and that sequencing is itself a signal worth tracking independently of any single development.