Angola
Southern Africa
Angola regulates personal data through Law 22/11 on the Protection of Personal Data, enacted on 17 June 2011, one of the earlier comprehensive data protection statutes in the Southern African region. The law applies to automated and non-automated processing by public bodies and private organisations established in Angola, operating in Angolan territory, or using means located in Angola. It sets the standard data-quality principles, purpose specification, fair and lawful processing, accuracy, and storage limitation, and requires controllers to inform data subjects of the controller's identity and the purposes of processing at collection. Processing operates under a notification-and-authorisation regime: controllers must notify the supervisory authority before commencing operations, and higher-risk categories require prior authorisation rather than mere notification. Sensitive data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, and sexual life, is generally prohibited without explicit consent or specific authorisation. Data subjects hold rights of access, rectification, and erasure, and cross-border transfers are permitted only to countries with adequate protection or under specified exemptions such as unambiguous consent, contractual necessity, or protection of vital interests. Administrative sanctions range from roughly USD 65,000 to USD 150,000. Enforcement rests with the Agência de Protecção de Dados (APD), the national supervisory authority, though notably the APD was formally established only in October 2019, some eight years after the law, leaving an extended period in which the statute lacked an active regulator. A draft revision of Law 22/11 was published for public consultation between March and April 2025 to modernise the framework, but had not been enacted as of June 2026. Angola thus has a long-standing law and an established (if belatedly created) regulator, with modernisation now on the horizon.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 2 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 2 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 1 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 1 | 0 | ◐ |
● Covered ◐ Partially covered ○ Not yet covered
Lei n.º 1/17, de 23 de Janeiro, Lei de Imprensa (Press Law) (Angola)
Enacted 23 Jan 2017
Lei n.º 7/17, de 16 de Fevereiro, Lei de Protecção das Redes e Sistemas Informáticos (Angola)
Enacted 16 Feb 2017
Aviso n.º 11/2022, Requisitos e Procedimentos para a Autorização de Constituição de Instituições Financeiras Não Bancárias
Enacted 1 Jan 2022
Lei n.º 40/20, de 16 de Dezembro, Lei do Sistema de Pagamentos de Angola (LSPA)
Enacted 16 Dec 2020
Proposta de Lei sobre a Inteligência Artificial (Draft Law on Artificial Intelligence)
Law 22/11 on the Protection of Personal Data
Enacted 17 Jun 2011
The 2011 law predates the GDPR accountability model, no fixed breach-notification deadline, general DPO mandate, or portability right is recorded, and the supervisory authority operated only from 2019. A 2025 draft revision is pending but unenacted; implementing regulations are not documented on file.