Benin's APDP and Togo's IPDCP sign a cooperation agreement: what it changes in practice
On 18 August 2026, a delegation from Togo's Personal Data Protection Authority (IPDCP), led by its chair Colonel Bediani Belei, was received at the headquarters of Benin's Personal Data Protection Authority (APDP) by its chair, Dr Luciano Hounkponou. The two institutions signed a partnership agreement on that occasion.
The IPDCP frames the visit as a continuation of its institutional anchoring among sister authorities in the sub-region. For organisations processing data on both sides of the border, the announcement deserves more than a protocol reading: it says something about how regulation will actually be practised in West Africa over the coming months.
What the agreement provides for
According to the IPDCP's statement, the discussions covered skills development, the sharing of expertise and the progressive harmonisation of regulatory practice. Both authorities also addressed the challenges raised by artificial intelligence and by data transfers. The agreement formalises cooperation intended to "foster exchanges of experience, training activities and capacity building".
"To remain at the service of the human being, of their dignity, their privacy and their freedoms."
Dr Luciano Hounkponou, chair of Benin's APDP
The stated goal is to build "reinforced African cooperation towards a trusted, secure digital environment that respects fundamental rights".
Why this matters
Togo and Benin share far more than a border. They share corporate groups established in both countries, common hosting and digital service providers, regional mobile money operators, and international organisations whose processing spans both territories. In other words: permanent cross-border data flows, governed by two distinct bodies of rules, Togolese Law No. 2019-014 of 29 October 2019 on one side, the Beninese digital code on the other.
Until now, those two regimes largely ran in parallel. A cooperation agreement between authorities shifts that on three fronts.
- Doctrine. "Progressive harmonisation of regulatory practice" means that two authorities in dialogue tend to characterise the same situations in the same way: what counts as valid consent, what amounts to sufficient security, when processing carries a high risk. A position taken in Cotonou becomes an indication of what will be expected in Lomé, and vice versa.
- Complaints and inspections. Two authorities bound by an agreement exchange information. A breach identified on one side of the border is more likely to become known on the other, particularly where the controller operates in both countries.
- Capability. Training and capacity building primarily target the authorities' own staff, but the effect spreads across the ecosystem: data protection officers, lawyers, information security managers. A better-equipped authority inspects more, and inspects better.
What the agreement does not do
The limits matter, because the distinction has immediate operational consequences.
An agreement between two administrative authorities does not create a one-stop shop. An organisation present in both Togo and Benin remains subject to the prior formalities of each country, before each authority. It does not amount to mutual recognition: a filing made in Cotonou exempts you from nothing in Lomé. And it amends no law: only the legislature, or the Community legal order, can do that.
Finally, the text of the agreement is not public at this stage. What is known comes from the two institutions' statements. The precise scope of the commitments, particularly on the exchange of information about individual cases, remains to be clarified.
Part of a wider movement
This bilateral step fits the momentum of the revision of the ECOWAS supplementary act on data protection, adopted on 19 July 2026, which expressly provides for a regional network of protection authorities. We analysed it in our article on the revision of the supplementary act.
Four reflexes for the organisations concerned
- Map your Togo and Benin flows. Which processing crosses the border, in which direction, for what purpose, with which processor? A record of processing that stops at national borders is of no use inside a regional group.
- Check the formalities in each country. Filing, authorisation or request for an opinion depending on the nature of the processing, before the IPDCP in Togo and the APDP in Benin. Do not count on cooperation between authorities to cover a missing formality: the effect will be the opposite.
- Document your transfers. The regime for transfers of data outside Togo under Law No. 2019-014 requires you to justify the basis of the transfer and the level of protection in the destination country. Transfers to Benin are no exception, and the attention both authorities now give the subject will make them more visible.
- Appoint and equip a data protection officer. The announced rise in regulator capability presupposes a counterpart. A data protection officer, internal or external, is the best guarantee against discovering a requirement on the day of an inspection.
Our reading
Data regulation in West Africa is leaving its declaratory phase. After the IPDCP became operational, after the compliance deadlines expired and after the Community framework was revised, this agreement marks a further step: the authorities are no longer content to exist, they are organising among themselves. For organisations, the window of tolerance is closing, and it is now closing on both sides of the border at once.
Source: IPDCP statement, "L'IPDCP poursuit son ancrage institutionnel auprès des autorités sœurs de la sous-région", 18 August 2026.
Does your processing cross the border?
AMELEGAL supports businesses, institutions and organisations on compliance with Law No. 2019-014, mapping of processing activities, formalities before the IPDCP and the framing of data transfers.
This article provides general information and does not constitute legal advice. AMELEGAL