🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CI · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 6 sources retrieved model claude-sonnet-5 ·

Ivory Coast (UEMOA bloc)

CI schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 8 claims · 6 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
8Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statute and regulator identity confirmed via secondary sources; primary legal text (Journal Officiel) and full scope/registration detail not directly retrieved in this run.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Traffic-light rationale — AmberCore statute and regulator identity confirmed via secondary sources; primary legal text (Journal Officiel) and full scope/registration detail not directly retrieved in this run.

Sub-modules (5)

Regulator And AuthorityAmber

ARTCI, Côte d'Ivoire's telecoms/ICT regulator, has been documented issuing data-protection-related communiqués and reminders to controllers, consistent with a designated DPA role.

Claims: CLM-CI-a1b2c301

Act And InstrumentsGreen

Law No. 2013-450 is the primary instrument; a DataGuidance legal-research index confirms its title and existence.

Claims: CLM-CI-a1b2c302

Material ScopeRed

Material scope (what data/processing is caught) was not independently verified from primary text in this run.

Absence provenance: not recorded. Searched: not recorded.

Territorial ScopeRed

No confirmed evidence located on extraterritorial/establishment-based application of the 2013 law to non-established controllers.

Absence provenance: not recorded. Searched: not recorded.

Regulator Registration And FilingAmber

Secondary sources indicate ARTCI issues reminders to data controllers of their obligations, consistent with a declaration/authorisation-style formality regime common to francophone West African DP laws, but the specific CI filing mechanics were not independently confirmed.

Claims: CLM-CI-a1b2c303

Category narrative83 words

Côte d'Ivoire's personal data regime rests on Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, a comprehensive omnibus statute. The Autorité de Régulation des Télécommunications/TIC de Côte d'Ivoire (ARTCI) — originally the telecoms/ICT sector regulator — was designated to exercise data-protection regulatory functions, publishing controller-facing reminders and privacy communiqués. Material and territorial scope details, and the precise registration/filing procedure, are only partially confirmed from secondary-source snippets; the operative Journal Officiel text was not directly retrievable in this run.

Sources and claims (3)
  1. ProbableOneTrust DataGuidanceARTCI (the Telecommunications/ICT Regulatory Authority of Côte d'Ivoire) exercises data-protection oversight functions, including issuing public communiqués addressing personal data/privacy matters.
  2. ConfirmedOneTrust DataGuidanceLaw No. 2013-450 on the Protection of Personal Data is the primary omnibus data-protection statute of Côte d'Ivoire.
  3. UncertainOneTrust DataGuidanceARTCI actively reminds data controllers operating in Côte d'Ivoire of registration/compliance obligations under the personal data protection regime.

#

No T1/T2 primary-text confirmation retrieved for lawful bases or special-category provisions specific to CI in this run.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — RedNo T1/T2 primary-text confirmation retrieved for lawful bases or special-category provisions specific to CI in this run.

Sub-modules (4)

Lawful BasesRed

Not independently confirmed for CI in this run.

Absence provenance: not recorded. Searched: not recorded.

Special CategoriesRed

Not independently confirmed for CI in this run.

Absence provenance: not recorded. Searched: not recorded.

Pseudonymisation And AnonymisationRed

Not independently confirmed for CI in this run.

Absence provenance: not recorded. Searched: not recorded.

Category narrative66 words

No primary-text confirmation was obtained in this run for Côte d'Ivoire's enumerated lawful bases, consent standards, or special-category rules under Law No. 2013-450. Regional pattern (French-influenced francophone African DP statutes of this era) typically enumerates consent, contract, legal obligation, vital interest and public-interest/legitimate-interest-style bases with heightened protection for health, biometric, and other sensitive data, but this was not independently verified for CI specifically in this run.

#

No direct evidentiary confirmation of specific data-subject-rights provisions for CI obtained in this run.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — RedNo direct evidentiary confirmation of specific data-subject-rights provisions for CI obtained in this run.

Sub-modules (5)

Access RightRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Rectification And ErasureRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Restriction And ObjectionRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Data PortabilityRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Deadlines And Response WindowsRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Category narrative50 words

No CI-specific primary or secondary evidence on the subject-access, rectification/erasure, restriction/objection, portability, or response-deadline framework under Law No. 2013-450 was retrieved in this run. Given the omnibus nature of the statute and its designation of ARTCI as regulator, a rights framework analogous to regional peers is plausible but unverified here.

#

Regulator-controller engagement is evidenced; specific duty thresholds (DPO appointment triggers, breach-notification timelines, retention limits) are unverified.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — AmberRegulator-controller engagement is evidenced; specific duty thresholds (DPO appointment triggers, breach-notification timelines, retention limits) are unverified.

Sub-modules (7)

Accountability And DpiaRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Dpo RequirementsRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Ropa RequirementsRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Security MeasuresRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Breach NotificationRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Retention And DisposalRed

Not confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Category narrative35 words

ARTCI has publicly reminded data controllers of compliance obligations, indicating an active accountability/enforcement posture, but granular DPIA, DPO, ROPA, joint-controller, security, breach-notification and retention provisions specific to CI were not independently verified in this run.

Sources and claims (1)
  1. UncertainOneTrust DataGuidanceARTCI's public reminders to data controllers of their compliance obligations indicate an active accountability-oversight function under Law No. 2013-450, though the specific DPIA/DPO/breach thresholds remain unverified.

#

Regional instrument (ECOWAS Supplementary Act) applicability is inferable from ECOWAS membership but CI-specific ratification/ transfer-mechanism detail is unconfirmed; no EU adequacy exists either way.

Primary frameworkLaw No. 2013-450; ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection (regional overlay)
Supervisory authorityARTCI
Traffic-light rationale — AmberRegional instrument (ECOWAS Supplementary Act) applicability is inferable from ECOWAS membership but CI-specific ratification/ transfer-mechanism detail is unconfirmed; no EU adequacy exists either way.

Sub-modules (6)

Transfer MechanismsRed

Specific cross-border transfer mechanisms (consent, contractual clauses, authorisation) under CI's 2013 law were not independently verified.

Absence provenance: not recorded. Searched: not recorded.

Adequacy ReceivedRed

No evidence of any adequacy decision received by Côte d'Ivoire from the EU or other regimes.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

No evidence Côte d'Ivoire operates an outbound adequacy-whitelisting mechanism.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

No CI-specific SCC/BCR uptake data identified.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No TIA obligation identified for CI.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No data-localisation mandate identified for CI in available sources.

Absence provenance: not recorded. Searched: not recorded.

Category narrative83 words

Côte d'Ivoire has not received or granted any EU adequacy decision. As a founding ECOWAS member state, Côte d'Ivoire is presumptively within scope of the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection (a regional harmonisation instrument referenced by DataGuidance for comparator ECOWAS states such as Ghana and Cape Verde), though direct confirmation of Côte d'Ivoire's own ratification status for this Act and for the African Union Malabo Convention was not obtained in this run. No data-localisation mandate specific to CI was identified.

Sources and claims (1)
  1. UncertainOneTrust DataGuidanceAs an ECOWAS member state, Côte d'Ivoire falls within the intended scope of the ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection within ECOWAS, a regional harmonisation instrument for cross-border data flows among member states.

#

No sectoral overlay instrument specific to CI was retrieved; narrative flags a plausible but unverified financial-sector nexus.

Traffic-light rationale — RedNo sectoral overlay instrument specific to CI was retrieved; narrative flags a plausible but unverified financial-sector nexus.

Sub-modules (7)

Financial Sector OverlayRed

Not independently confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Health Sector OverlayRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Telecoms And EprivacyRed

Not confirmed beyond ARTCI's general telecom-regulator identity.

Absence provenance: not recorded. Searched: not recorded.

Employment DataRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Credit And ScoringRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

EducationRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

InsuranceRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative52 words

No CI-specific sectoral overlay evidence (banking/BCEAO-UEMOA financial data rules, health-sector rules, telecoms/ePrivacy, employment, credit-scoring, education, or insurance) was retrieved in this run. Côte d'Ivoire's membership in the West African Economic and Monetary Union (UEMOA/BCEAO) plausibly implies financial-sector data-handling instructions for mobile-money and banking operators, but this was not independently confirmed via search.

#

No adtech/commercial-privacy-specific instrument or guidance for CI was located in this run.

Traffic-light rationale — RedNo adtech/commercial-privacy-specific instrument or guidance for CI was located in this run.

Sub-modules (6)

Cookies And TrackersRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Dark PatternsRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Opt Out SignalsRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Direct MarketingRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative22 words

No CI-specific evidence was found on cookie/tracker consent regimes, dark-pattern prohibitions, opt-out signal recognition, clean-room rules, cross-context advertising, or direct-marketing suppression frameworks.

#

A national AI-policy study is confirmed; binding profiling/ADM/biometric statutory detail specific to CI is unverified.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — AmberA national AI-policy study is confirmed; binding profiling/ADM/biometric statutory detail specific to CI is unverified.

Sub-modules (6)

Profiling RestrictionsRed

Not independently confirmed for CI's specific statutory text.

Absence provenance: not recorded. Searched: not recorded.

Automated Decision Making TransparencyAmber

Regional pattern across African DP laws generally recognises a right against solely-automated decisions, but CI-specific text unconfirmed.

Claims: CLM-CI-a1b2c306

Ai Risk AssessmentsAmber

A 2024 Ivorian government-linked study examined AI, 5G and metaverse governance challenges, aiming at ethical and responsible adoption, but this is a policy study rather than a binding AI-risk-assessment regime.

Claims: CLM-CI-a1b2c307

Biometric RegimeRed

Not independently confirmed for CI in this run.

Absence provenance: not recorded. Searched: not recorded.

Genetic DataRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative92 words

IAPP reporting indicates a 2024-initiated study on the challenges of AI, 5G and the metaverse for Côte d'Ivoire's digital economy, aimed at promoting inclusive, ethical and responsible adoption of emerging technologies, but this reflects a policy study rather than binding profiling/ADM/biometric legislation. Across the 39 African countries with data protection laws generally, the right not to be subject to solely automated decision-making is widely recognised, which — if CI's 2013 law follows the regional pattern — would suggest an Article-22-style analogue, though this was not independently confirmed against CI's specific statutory text.

Sources and claims (2)
  1. UncertainInternational Association of Privacy ProfessionalsAmong the 39 African countries with data protection laws (a set that includes Côte d'Ivoire), 35 recognize a right not to be subject to solely automated decision-making, indicating a regional pattern that plausibly extends to CI's statute though not independently verified against its specific articles.
  2. ProbableInternational Association of Privacy ProfessionalsA study initiated in April 2024 examined the challenges and issues of AI, 5G networks and the metaverse for developing Côte d'Ivoire's digital economy, aiming to promote inclusive, ethical and responsible adoption of emerging technologies.

#

No age-of-consent, parental-consent, or minor-specific provision was retrieved for CI in this run.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — RedNo age-of-consent, parental-consent, or minor-specific provision was retrieved for CI in this run.

Sub-modules (5)

Age VerificationRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Minor Profiling BansRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Education SettingsRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative21 words

No CI-specific evidence was retrieved on age-of-consent thresholds, parental-consent mechanisms, minor-profiling bans, education-setting rules, or dependent-adult protections under Law No. 2013-450.

#

No penalty-cap, enforcement-activity, or redress-mechanism evidence specific to CI was retrieved; only general regulator-engagement signals exist.

Primary frameworkLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Supervisory authorityARTCI
Traffic-light rationale — RedNo penalty-cap, enforcement-activity, or redress-mechanism evidence specific to CI was retrieved; only general regulator-engagement signals exist.

Sub-modules (6)

Regulator Powers And PenaltiesRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Enforcement Activity IndexRed

No fines or enforcement decisions attributable to ARTCI in the last 12 months were located.

Absence provenance: not recorded. Searched: not recorded.

Regulator Funding And CapacityRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Private Right Of ActionRed

Not confirmed.

Absence provenance: not recorded. Searched: not recorded.

Recent Developments 180DRed

No CI-specific data-protection developments within the last 180 days (from 2026-08-05) were located.

Absence provenance: not recorded. Searched: not recorded.

Category narrative57 words

ARTCI's documented activity (controller reminders, an app-privacy communiqué) indicates it exercises supervisory and public-facing enforcement-adjacent functions, but no specific fines, investigative-power statutes, penalty caps, collective-redress mechanisms, or private-right-of-action provisions for CI were retrieved. No enforcement decisions or fines in the last 12 months, and no developments in the last 180 days, were located for Côte d'Ivoire specifically.

Sources and claims (1)
  1. UncertainOneTrust DataGuidanceARTCI demonstrates an active supervisory posture toward data controllers in Côte d'Ivoire, evidenced by public reminders of compliance obligations and privacy-related communiqués, though the specific statutory penalty regime was not independently verified.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Ivory Coast (UEMOA bloc)
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 8 claim(s), 6 source(s) in the cumulative register.