The DRC's Code du numérique makes local hosting the default rule for personal data and every export a derogation. That is not a legal question — it is an architecture constraint, and it has been in force since 2023.

Three years after the Democratic Republic of the Congo adopted its Code du numérique, the conversation inside most banks in Kinshasa still happens in the legal department. A note is drafted. A clause is added to supplier contracts. The file is closed until the regulator asks.
That reading is understandable. It is also expensive — and, on the calendar, late. Article 390 brought the Code into force on the day of its promulgation, 13 March 2023, and Article 388 gave providers already operating six months to bring themselves into conformity. That window closed in September 2023.
Ordonnance-loi n° 23/010 contains a great deal of law across five books — digital services, electronic writings and trust services, digital content and personal data, cybersecurity and cybercrime. But the obligations that bite for a bank, a microfinance institution or a payment provider are not obligations of drafting. They are obligations of design. They determine where customer data may physically sit, what it takes to move it, who is accountable for a processing decision, and how quickly the institution can prove any of it. None of that lives in a legal file. It lives in the architecture.
Article 201 opens with one sentence: personal data is stored and hosted in the Democratic Republic of the Congo.
Everything after that sentence is derogation. Data may be transferred to a host in a third State or to an international organisation where the data protection authority has established that the destination offers an adequate and sufficient level of protection, judged against the rule of law, the presence of an effective independent supervisor and binding international commitments. And the controller must obtain the authority's prior authorisation before any actual transfer, with the transfer then subject to ongoing supervision. Article 202 provides the fallback grounds when adequacy is absent: explicit informed consent, necessity for the performance of a contract with the data subject, an important public interest, vital interests.
Now hold that against the real estate of a Congolese bank. The core banking platform hosted in Johannesburg or Paris. Card processing and the switch, offshore by design. The group data lake, the consolidated risk models, the fraud engine, the shared service centre — all sitting with a parent abroad. Every one of those is a transfer under Article 201, and the default answer of the Code is no, unless.
Article 222 requires every controller to designate a data protection officer — not conditionally, as under the GDPR, but as a rule — and Article 227 defines the register that officer must maintain: purposes, categories of data subjects and data, recipients including those in third countries, transfers and their destinations, retention periods, and a description of the technical and organisational security measures.
Article 245 requires a data protection impact assessment before processing that presents a high risk — explicitly including automated evaluation of personal aspects producing legal effects, and large-scale processing of biometric data used to identify a person. That is credit scoring. That is biometric onboarding. Where the assessment shows residual high risk, Article 246 requires prior consultation with the authority, which has eight weeks to respond and may extend by four.
Article 244 requires notification of a personal data breach without delay, to the authority and to the data subject — with one exemption worth noting for architects: the subject need not be informed where the data was rendered unintelligible to unauthorised parties, encryption being the example the Code itself gives.
Article 257 sets the tariff: administrative fines from 8 million to 200 million Congolese francs, and in the gravest cases 5% of prior-year turnover, alongside an injunction to stop processing.
Ask the question a supervisor will eventually ask: list every processing operation, its purpose, its recipients, and every border it crosses. Most institutions cannot produce that list in a week — not through negligence, but because no one has ever needed a single, current view of where data goes. It exists in fragments: in middleware, in vendor contracts, in a warehouse nobody decommissioned, in the analytics extract someone set up in 2019. Compliance did not create that problem. Architecture did.
Three decisions follow.
Map the flows before writing the policy. A map naming every system, every recipient and every border crossing turns an open-ended legal exposure into a finite work list — and reliably surfaces two or three flows nobody can justify.
Treat hosting location as a first-order design constraint. Under Article 201 the burden runs the other way from what most architecture boards assume: local is the default, export is the exception you must document, justify and have authorised. An institution that establishes its residency posture before its next core banking or cloud decision keeps its options. One that decides afterwards inherits the vendor's default and negotiates from behind.
Give the DPO a place in the change process, not the org chart. The Code already insists on this: Article 225 requires that the officer receive no instructions in the exercise of their duties, cannot be penalised for performing them, and reports directly to the highest level of management. An officer who reviews finished projects is a formality. One who sits where new processing is designed is a control — and the register stays current because change keeps it current.
The institutional machinery is still being assembled. The independent data protection authority is not yet standing on its own — the ARPTC exercises its functions in the interim, and it is in that capacity that it issued Decision n° 039/ARPTC/CLG/2025 of 11 September 2025 establishing the declaration and authorisation procedures. The national cybersecurity agency provided for at Articles 274 and following is still being built.
That gap is the opportunity. The obligations are already in force; the supervision is arriving. Institutions that fold data location, data lineage and accountability into the same decision as cost, latency and resilience will make one set of choices and use them three times. Those that wait will retrofit — and retrofitting where data lives is the most expensive change a bank can make.
HKONNECT advises banks, central banks and financial market infrastructures on translating strategy into technology direction. If your institution is making core platform, hosting or data decisions in the coming year, the Code du numérique belongs in that conversation now — not after it.