São Tomé and PríncipeIn ForceData Protection

Lei n.º 3/2016 and Decreto-Lei n.º 4/2017 on Personal Data Protection (São Tomé and Príncipe)

st-pdp-2016 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

São Tomé and Príncipe has a personal data protection framework built around Lei n.º 3/2016 on the protection of personal data, supplemented by Decreto-Lei n.º 4/2017, which establishes measures for personal data protection in connection with the processing of information. The country adopted these instruments alongside Law No. 15/2017 on cybercrime, giving this small Lusophone island state a dedicated data protection regime earlier than many larger continental peers. Drawing on the Portuguese and Lusophone data protection tradition, the framework is understood to establish core data-quality principles, conditions for lawful processing, data-subject rights, and restrictions on the processing of sensitive data, consistent with the Convention 108 / pre-GDPR model prevalent at the time of adoption. The country has also established a supervisory authority, the Agência Nacional de Protecção de Dados Pessoais (National Agency for Personal Data Protection), which has had a publicly identified president, indicating an intention to operationalise the framework rather than leave it purely on paper. This entry was created from a June 2026 verification search rather than from a pre-existing ATLPF research file, and the available public sourcing is thin. The precise relationship between Lei n.º 3/2016 and Decreto-Lei n.º 4/2017, the detailed substantive provisions (lawful bases, rights, transfers, penalties), and the Agency's statutory powers and current operational capacity should all be confirmed against the primary texts (available via the Diário da República and REDIPD), and primary-source URLs added. Source language: Portuguese.

Key provisions
  1. Data protection framework built on Lei n.º 3/2016, supplemented by Decreto-Lei n.º 4/2017, adopted alongside Law No. 15/2017 on cybercrime.
  2. Establishes data-quality principles, lawful-processing conditions, data-subject rights, and sensitive-data restrictions on the Convention 108 / pre-GDPR model.
  3. A supervisory authority, the Agência Nacional de Protecção de Dados Pessoais, has been established, with a publicly identified president.
  4. Sourcing is thin; substantive detail is not fully confirmed.
  5. Reviewer action: confirm the relationship between the 2016 law and 2017 decree-law, the substantive provisions, and the Agency's powers against primary texts; add primary-source URLs.