AngolaIn ForceData Protection

Law 22/11 on the Protection of Personal Data

ao-dp-2011 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Angola's Law 22/11 on the Protection of Personal Data, enacted on 17 June 2011, is the primary statutory framework governing the collection, processing, storage, and disclosure of personal data in Angola. The law applies to automated and non-automated processing of personal data by public bodies and private organisations established in Angola, operating within Angolan territory, or using means located in Angola for processing purposes. The law establishes core data processing principles requiring that personal data be collected for specified, explicit, and legitimate purposes; processed fairly and lawfully; kept accurate and up to date; and retained only for as long as necessary for the original purpose. Data controllers must inform data subjects of the identity of the controller and the purposes of processing at the time of collection. Sensitive categories of personal data, including data relating to racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, and sexual life, are subject to heightened protection and are, as a general rule, prohibited from processing without explicit consent or a specific authorisation from the Agência de Protecção de Dados (APD). Data controllers are required to notify the APD before commencing processing operations. Certain higher-risk categories of processing additionally require prior authorisation rather than mere notification. Data subjects hold rights of access, rectification, and erasure of their personal data against the controller, and the controller must respond to such requests within defined timeframes. Cross-border transfers of personal data to third countries are permitted only where the destination country ensures an adequate level of protection, or where a specific exemption applies, such as the unambiguous consent of the data subject, the necessity of the transfer for the performance of a contract, or the protection of vital interests. The APD, formally established in October 2019, is the national supervisory authority responsible for enforcing the law, administering the notification regime, conducting investigations, and imposing administrative sanctions for violations. Penalties for non-compliance range from the equivalent of approximately USD 65,000 to USD 150,000 depending on the nature and gravity of the breach. A draft revision of Law 22/11 was published for public consultation between March and April 2025, with the stated aim of updating the framework to align with contemporary data protection standards. That revision had not been enacted as of the date of this entry.

Key provisions
  1. Prior notification to the APD required before commencing personal data processing operations; certain higher-risk processing categories require prior APD authorisation
  2. Sensitive data categories (racial/ethnic origin, health, sexual life, religious/political beliefs, trade union membership) subject to heightened restrictions and generally prohibited without explicit consent or APD authorisation
  3. Data subjects hold rights of access, rectification, and erasure against the data controller
  4. Cross-border transfers permitted only to countries offering adequate protection or on the basis of specified exemptions including data subject consent
  5. Data controllers must implement appropriate technical and organisational security measures
  6. Administrative sanctions for violations range from approximately USD 65,000 to USD 150,000
  7. A 2025 draft revision is under public consultation but not yet enacted as of June 2026
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from APD.ao official legislation page, CMS Expert Guide to Data Protection and Cyber Security Laws (Angola), DLA Piper Data Protection Laws of the World (Angola)