GQ

Equatorial Guinea

Central Africa

3Instruments
0Cases
1Regulators
50%Coverage
Overview

Equatorial Guinea has a comprehensive data protection law, a position now confirmed, resolving the earlier uncertainty in ATLPF's records. The Personal Data Protection Law No. 1/2016 of 22 July 2016 governs personal data protection across sectors and is now recorded in ATLPF's Instruments database (AI-draft). Under the law, a General Data Protection Registry is responsible for the registration of public and private personal data files, and controllers and processors must adopt appropriate technical and organisational security measures, a registration-and-security architecture reflecting the Spanish/Ibero-American data protection tradition. Beyond this, the detailed provisions (lawful bases, rights, transfers, penalties) are not well documented in available sources, and the law is published in Spanish only. The status and powers of the General Data Protection Registry as an operational supervisory body are unconfirmed, so no Regulator record is on file. With an instrument on file but no confirmed operational regulator, Equatorial Guinea scores in the one-instrument-without-an-operational-regulator band, a substantial increase from its previous near-zero score, which had reflected uncertainty over whether any law existed at all. The record is AI-drafted from a June 2026 verification search.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection10
AI Governance00
Fintech00
Cybercrime10
Digital Rights20
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
Notable gaps

The detailed substantive provisions are poorly documented (the text is in Spanish only), and it is unconfirmed whether the General Data Protection Registry functions as an operational supervisory authority. The Instrument record is AI-drafted and awaits confirmation against the Spanish primary text.