Lei n.º 133/V/2001 de 22 de Janeiro relativa à protecção de dados pessoais (Cabo Verde Data Protection Act 2001, as amended)
cv-dp-2001 · Act
Cabo Verde's Law No. 133/V/2001 of 22 January 2001 is Africa's first comprehensive data protection statute. Enacted a full decade before most continental peers, it established foundational principles for personal data processing and created the Comissão Nacional de Protecção de Dados (CNPD) as the competent supervisory authority. The law has been progressively modernised by amendments in 2013 and 2021 and remains in force. In its original form, the law established principles of purpose limitation, data minimisation, accuracy, and security. It required prior notification to or authorisation from the CNPD before personal data processing could commence, depending on the nature of the processing. Processing of sensitive data, including health information, racial or ethnic origin, political opinions, religious beliefs, and sexual life, required prior authorisation. Law No. 42/VIII/2013 of 17 September 2013 substantially reformed the law, restructuring the CNPD's institutional framework and refining the categories of processing subject to prior authorisation. The CNPD, originally established by the 2001 Act, became fully operational in 2015 following the 2013 reform. Law No. 121/IX/2021 of 17 March 2021, which entered into force on 17 April 2021, introduced the most significant updates, aligning the law with the EU GDPR and Convention 108+. Key changes included: extension of the law's extraterritorial scope to controllers outside Cabo Verde processing data of individuals located within the country; introduction of the rights to data portability and to erasure; mandatory breach notification to the CNPD within 72 hours; the obligation to notify affected data subjects of high-risk breaches; and the requirement to appoint a DPO in certain circumstances, including where core activities involve large-scale systematic monitoring or sensitive-data processing at scale. The law applies to automated processing and to non-automated processing in structured files, covering all natural and legal persons established in Cabo Verde. The CNPD is empowered to receive notifications and authorisation requests, carry out inspections, decide on complaints, and impose sanctions including administrative fines and referrals for criminal prosecution. Cross-border transfers are restricted and require either an adequacy assessment or appropriate safeguards. Note: the Enacted Date reflects the original 2001 Act; the Effective Date reflects the entry into force of the 2021 amendment consolidating current rights. Reviewer should confirm whether a formally consolidated text has been published. Source language: Portuguese.
- Prior notification to or authorisation by the CNPD is required before commencing personal data processing, depending on the nature and sensitivity of the data involved.
- Data subjects have rights of access, rectification, erasure, portability, restriction, and opposition enforceable against controllers, as strengthened by the 2021 amendment.
- Breach notification to the CNPD is required within 72 hours of discovery; high-risk breaches must also be communicated to affected data subjects without undue delay.
- Cross-border transfers require an adequacy determination or appropriate safeguards; prior CNPD authorisation may be required.
- Processing of sensitive data (health, biometrics, racial origin, criminal convictions, sexual life) requires prior CNPD authorisation.
- DPO appointment is mandatory for certain controllers, including those engaged in large-scale systematic monitoring or large-scale sensitive-data processing.
- The law applies extraterritorially to controllers outside Cabo Verde who process personal data of individuals located in the country (introduced by 2021 amendment).
- Sanctions include administrative fines and criminal penalties; the CNPD may conduct on-site inspections.