← Back to the blog
Compliance

5 steps to comply with the law on the protection of personal data (in Togo)

14 July 2026 · AMELEGAL

The Togolese law on the protection of personal data, adopted on 29 October 2019, sets at article 95 a compliance period of one to two years for all entities falling within its scope.

That deadline expired several years ago.

It is therefore imperative, for public and private bodies alike, to take the necessary measures in order to avoid the heavy penalties provided for by the law.

AMELEGAL sets out 5 key steps to put you concretely on the path to compliance with the law.

Step 1

Identify the processing operations you carry out

To begin your compliance work properly, you must first draw up a precise inventory of the personal data processing you carry out (HR, commercial prospecting, client management, etc.), the data subjects involved (clients, patients, pupils, employees, partners, etc.) and the categories of data collected.

To do so with confidence, it is important to rely on a specialist.
Step 2

Appoint a personal data protection officer, if you are able to

To take your compliance work further, the law recommends appointing a personal data protection officer, able to advise you and to ensure that you comply with the applicable data protection texts. That appointment also relieves you of certain obligations (article 5 of Law 2019-014).

If you are unsure how to appoint such an officer, AMELEGAL is at your disposal to guide you through the process.

Step 3

Train your teams

Lasting compliance rests on well-trained and well-informed teams. Train your staff so that they understand their obligations and adopt good practice in personal data protection. With the support of your data protection officer, run sessions tailored to your organisation.

Step 4

Put a personal data protection policy in place

Set out your commitments formally by drawing up a clear policy on the handling of personal data. That document guides your teams, reassures your partners and meets the expectations of the supervisory authority.

Your data protection officer will help you draft the policy and circulate it within your organisation.

Step 5

Keep oversight

Compliance is a continuing process: it is essential to check regularly that your practices comply with the law and evolve alongside it. Schedule internal audits and update your procedures so as to remain in order at all times. Your data protection officer plays a key role in this monitoring and continuous improvement.

To remain compliant, every processing operation must be justified, secure and transparent.

AMELEGAL can support you through this process.

Thank you ! A confirmation email has just been sent to you. Click the link it contains to confirm your subscription, and do check your spam folder if it does not appear in your inbox.
Newsletter

AMENEWS

Your African legal and digital newsletter.

Each month, a selection of analysis and practical resources : personal data protection, the Malabo Convention, cybersecurity, artificial intelligence and digital governance in Africa.

Add a comment