Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity and Compliance in Côte d'Ivoire

Security audits, penetration testing, and compliance services for organizations operating in Côte d'Ivoire, in line with the legal framework set by ARTCI.

Last updatedAugust 22, 2026

The local regulatory framework

In Côte d'Ivoire, personal data protection is governed by Law No. 2013-450, and cybercrime by Law No. 2013-451. The Autorité de régulation des télécommunications/TIC de Côte d'Ivoire (ARTCI) is responsible for implementing and enforcing these texts, as well as coordinating incident response for information systems.

Concrete obligations

Prior declaration of personal data processing activities with ARTCI

Implementation of risk-appropriate technical and organizational measures for personal data processing

Reporting of breaches affecting information systems in line with Law No. 2013-451

Contractual safeguards for data transfers to third parties or subcontractors

Cooperation with ARTCI during inspections or cybercrime-related investigations

Priority sectors

Financial services and mobile moneyTelecommunicationsDistribution and logistics

Delivery modalities

Engagement mode

On-site missions in Abidjan and remote delivery for the rest of the territory

Working language

French, with deliverables available in English on request

Regulatory coordination

Dedicated contact for interactions with ARTCI

Local FAQ

Which authority regulates cybersecurity and personal data in Côte d'Ivoire?

The Autorité de régulation des télécommunications/TIC de Côte d'Ivoire (ARTCI), which enforces Laws No. 2013-450 and No. 2013-451.

Does Law No. 2013-450 apply to foreign companies operating in Côte d'Ivoire?

Yes, whenever personal data processing takes place on Ivorian territory or targets Ivorian residents.

What does the cybercrime Law No. 2013-451 cover?

It addresses offenses related to information systems (unauthorized access, data integrity breaches, computer fraud) and sets out the framework for cooperation with ARTCI.

Does a penetration test require prior authorization from ARTCI?

The test itself is a contractual engagement between your organization and its provider; certain declarations may be required depending on the sector and systems tested, which we assess with you upfront.

Do you work with mobile money providers?

Yes, this sector is a priority for us given its criticality and exposure to fraud.

Do you support compliance with Law No. 2013-450?

Yes, through our governance, risk and compliance service, covering diagnosis, implementation, and ongoing monitoring.

How long does a typical audit engagement take?

Duration depends on scope; it is defined jointly during the initial scoping of each engagement.

Get in touch