A central bank reading the DRC's Code du numérique as a text to enforce will miss the first thing it does: it makes the central bank itself a supervised entity, audited by another agency.

Central banks read new legislation the way supervisors read anything: for what it will require of the institutions they oversee. It is a professional reflex, and usually correct.
The Code du numérique defeats it. Ordonnance-loi n° 23/010 puts a central bank in three positions at once — as an entity subject to the Code, as an operator of infrastructure the State considers vital, and as a co-regulator of its own sector. The three come with different authorities, different timelines and different consequences. Read only the third, and the first arrives as a surprise.
Article 280 is the provision most likely to be missed. Public-sector information systems are subject to a mandatory, periodic security audit. The National Cybersecurity Agency, or the experts it designates, hold the right to consult “all databases, documents, files and records relating to information security”. Its sworn agents carry the status of judicial police officers with restricted competence, and alongside their administrative report they file a judicial report with the public prosecutor.
For an institution built on confidentiality and operational independence, that is a change of nature rather than degree. It means a second organisation, outside the central bank's hierarchy, with a statutory right of access to its systems and a channel to the prosecution.
Around it sits a wider control regime. Article 19 subjects every supplier of digital services to the State or to any public entity to a homologation requirement, certified by the Minister after the Agency's opinion — which reaches the core platform, the payment infrastructure, the supervision tooling, not merely office software. Articles 295 and 296 require qualified detection systems and submit the institution's systems to Agency-conducted security controls, at the controlled party's expense. Article 298 restricts cryptology used for confidentiality functions to approved providers, with one exception that matters a great deal: encryption performed on one's own data. Where the keys sit, and who holds them, becomes a legal question and not only a technical one.
The obligations that apply to commercial banks apply here without discount.
Article 201 establishes local storage and hosting as the principle, with export permitted only to an adequate destination and only with the authority's prior authorisation. For a central bank this lands first on the disaster recovery site, then on remote vendor support, then on any analytics hosted abroad.
Article 245 requires an impact assessment before high-risk processing — including automated evaluation producing legal effects, large-scale biometric identification, and large-scale systematic monitoring of publicly accessible areas. That is the credit registry, the payment incidents register, biometric access control, and branch video surveillance. Where residual risk remains high, Article 246 requires prior consultation, with eight weeks for a response, extendable by four.
Article 244 requires breach notification without delay to the authority and to the data subjects, unless the data was rendered unintelligible to unauthorised parties. Article 199 gives a controller two days to answer a judicial requisition, eight at the outside — a capability for targeted extraction that few institutions actually have. Article 222 requires a data protection officer who, under Article 225, receives no instructions, cannot be penalised for doing the job, and reports directly to the highest level of management. In a central bank, that is a reporting line to the Governor, not to the CIO.
Article 278 gives the Cybersecurity Agency the task of identifying vital organisations and essential services “in collaboration with the ministries and the sectoral regulators”. The central bank therefore helps decide which banks and which market infrastructures fall inside that perimeter. That is real authority, available early, and it expires quietly if it is not exercised.
Two consequences follow.
The first is coordination. Banks now answer to three supervisors on overlapping ground: the central bank on governance and internal control, the data protection authority on processing, the Cybersecurity Agency on resilience and incidents. Each will want to be told first when something breaks. Absent an articulated sequence, institutions will build three incident processes, three audit responses and three reporting formats — and the supervisory value of all three will fall.
The second is harder, and unavoidable. Almost every core banking platform in the country is hosted abroad. Applying Article 201 to the letter, immediately, is not realistic. Ignoring it manufactures general legal insecurity across the sector. A doctrinal position taken by the central bank, articulated with the authority — what constitutes an acceptable derogation, on what evidence, over what transition — is better than a rule discovered case by case through refusals.
There is a constructive version of that position. A domestically hosted national payment infrastructure is the structural answer to Article 201. Framed that way, the sovereignty requirement stops being a constraint on the interoperability programme and becomes its justification.
They converge on a single dependency: knowing where data sits, how it moves, and who answers for it. The audit under Article 280 asks it. The register under Article 227 asks it. The transfer authorisation under Article 201 asks it. The designation of vital operators asks it of the whole sector.
An institution that builds that view once — as an architectural artefact maintained by change control, not a document reconstructed for each inspection — answers all three. An institution that treats them as three compliance programmes will build three partial answers and pay for all of them.
Regulation rarely slows an institution down. Discovering the constraint late does — and a central bank has less room than most to be surprised by its own supervisor.
HKONNECT advises central banks, banks and financial market infrastructures on translating strategy into technology direction. If your institution is setting its position on hosting, resilience or supervisory coordination this year, we would be glad to be part of that conversation.