Personal Data Protection Law No. 1/2016 of 22 July 2016 (Equatorial Guinea)
gq-pdpl-2016 · Act
Equatorial Guinea has a comprehensive data protection statute, the Personal Data Protection Law No. 1/2016 of 22 July 2016. According to comparative legal sources, the law governs the protection of personal data in Equatorial Guinea and applies across sectors. This resolves earlier uncertainty in ATLPF's records, where conflicting reporting had made it unclear whether the country had a recognised comprehensive law; the 2016 law is now confirmed. Under the law, a General Data Protection Registry is responsible for the registration of public and private personal data files, and data controllers and processors must adopt the necessary technical and organisational measures to ensure the security of the personal data they process. This registration-and-security architecture reflects the Spanish/Ibero-American data protection tradition on which Equatorial Guinea's framework draws. Beyond the registration regime and security obligations, the detailed substantive provisions, lawful bases, the data-subject rights catalogue, sensitive-data categories, cross-border transfer mechanisms, and the penalty schedule, are not well documented in available English-language sources; the law is published in Spanish only. The status, powers, and operational capacity of the General Data Protection Registry as a supervisory body are likewise unconfirmed, so no Regulator record is linked to this instrument at this stage. This entry was created from a June 2026 verification search rather than from a pre-existing ATLPF research file. Reviewer should obtain the Spanish primary text, confirm the substantive provisions, and determine whether the General Data Protection Registry functions as an operational supervisory authority. Source language: Spanish.
- Equatorial Guinea has a comprehensive data protection statute: Personal Data Protection Law No. 1/2016 of 22 July 2016 (resolving earlier uncertainty over whether a law existed).
- A General Data Protection Registry is responsible for registration of public and private personal data files.
- Controllers and processors must adopt necessary technical and organisational security measures.
- Draws on the Spanish/Ibero-American data protection tradition.
- Detailed provisions (rights, transfers, penalties) are not well documented; the law is in Spanish only.
- The status and powers of the General Data Protection Registry as a supervisory body are unconfirmed.
- Reviewer action: obtain the Spanish primary text, confirm substantive provisions, and determine whether a functioning supervisory authority exists.