Lei n.º 15/2017, de 6 de outubro, Lei do Cibercrime (Law No. 15/2017 of 6 October 2017, Cybercrime Law) (São Tomé and Príncipe)
st-cyber-2017 · Act
Law No. 15/2017 of 6 October 2017, the Cybercrime Law (Lei do Cibercrime), is São Tomé and Príncipe's dedicated cybercrime statute. Published in the Diário da República No. 147 of 6 October 2017, it follows the Portuguese-language legal tradition and is closely modelled on Portugal's Cybercrime Law (Lei n.º 109/2009), which itself transposes the Council of Europe (Budapest) Convention on Cybercrime. The law was adopted alongside other 2017 digital and security legislation as part of the country's effort to modernise its legal framework for the digital environment. The law establishes the catalogue of substantive cyber-offences in which the computer system or data is the target of the criminal conduct. These include computer-related forgery / false computer data (falsidade informática); damage to programs or other computer data (dano relativo a programas ou outros dados informáticos); computer sabotage (sabotagem informática); illegitimate access (acesso ilegítimo) to computer systems; illegitimate interception (interceção ilegítima) of computer communications; and the unlawful insertion of false personal data. Consistent with the Budapest model, the law also addresses the misuse of devices and tools designed to commit such offences and provides for the criminal liability of legal persons in defined circumstances. Beyond substantive offences, the law sets out procedural rules for the collection of electronic evidence. Following the Portuguese template, it provides for the expedited preservation of stored computer data, the production and disclosure of traffic data, search and seizure of computer data, and the interception of communications under judicial authorisation, together with provisions supporting international cooperation in cybercrime matters. These powers are exercised within the ordinary criminal-justice system through the Public Prosecutor's Office and the courts. The Cybercrime Law operates alongside São Tomé and Príncipe's personal data protection regime (Law No. 3/2016 and Decree-Law No. 4/2017). Together they provide the country with a Budapest-aligned legal basis for prosecuting offences against the confidentiality, integrity and availability of computer systems and data and for gathering electronic evidence.
- Dedicated cybercrime statute (Diário da República No. 147, 6 October 2017), modelled on Portugal's Lei n.º 109/2009 and the Budapest Convention
- Criminalises computer-related forgery/false computer data (falsidade informática) and damage to programs or computer data (dano informático)
- Criminalises computer sabotage (sabotagem informática), illegitimate access (acesso ilegítimo) and illegitimate interception (interceção ilegítima)
- Addresses misuse of devices/tools for committing offences and the unlawful insertion of false personal data; provides for liability of legal persons
- Procedural powers for electronic evidence: expedited preservation of stored data, production of traffic data, search and seizure, and interception under judicial authorisation
- International cooperation provisions; enforced through the Public Prosecutor's Office and the courts