5 steps to comply with the law on the protection of personal data (in Togo)
The Togolese law on the protection of personal data, adopted on 29 October 2019, sets at article 95 a compliance period of one to two years for all entities falling within its scope.
That deadline expired several years ago.
It is therefore imperative, for public and private bodies alike, to take the necessary measures in order to avoid the heavy penalties provided for by the law.
AMELEGAL sets out 5 key steps to put you concretely on the path to compliance with the law.
Identify the processing operations you carry out
To begin your compliance work properly, you must first draw up a precise inventory of the personal data processing you carry out (HR, commercial prospecting, client management, etc.), the data subjects involved (clients, patients, pupils, employees, partners, etc.) and the categories of data collected.
Appoint a personal data protection officer, if you are able to
To take your compliance work further, the law recommends appointing a personal data protection officer, able to advise you and to ensure that you comply with the applicable data protection texts. That appointment also relieves you of certain obligations (article 5 of Law 2019-014).
If you are unsure how to appoint such an officer, AMELEGAL is at your disposal to guide you through the process.
Train your teams
Lasting compliance rests on well-trained and well-informed teams. Train your staff so that they understand their obligations and adopt good practice in personal data protection. With the support of your data protection officer, run sessions tailored to your organisation.
Put a personal data protection policy in place
Set out your commitments formally by drawing up a clear policy on the handling of personal data. That document guides your teams, reassures your partners and meets the expectations of the supervisory authority.
Your data protection officer will help you draft the policy and circulate it within your organisation.
Keep oversight
Compliance is a continuing process: it is essential to check regularly that your practices comply with the law and evolve alongside it. Schedule internal audits and update your procedures so as to remain in order at all times. Your data protection officer plays a key role in this monitoring and continuous improvement.
To remain compliant, every processing operation must be justified, secure and transparent.
AMELEGAL can support you through this process.