ST

São Tomé and Príncipe

Central Africa

3Instruments
0Cases
2Regulators
60%Coverage
Overview

São Tomé and Príncipe has a data protection framework built around Lei n.º 3/2016, supplemented by Decreto-Lei n.º 4/2017, adopted alongside Law No. 15/2017 on cybercrime, giving this small Lusophone island state a dedicated regime earlier than many larger continental peers. The framework is now recorded in ATLPF's Instruments database (AI-draft). Drawing on the Lusophone Convention 108 tradition, the framework is understood to establish data-quality principles, lawful-processing conditions, data-subject rights, and sensitive-data restrictions, though detailed provisions are thinly sourced. The country has established a supervisory authority, the Agência Nacional de Protecção de Dados Pessoais (with a publicly identified president), now recorded in ATLPF's Regulators database. With an instrument and a named authority now documented, but with genuinely thin public sourcing and unconfirmed operational capacity, São Tomé is scored slightly below the standard single-instrument-plus-regulator level. The records are AI-drafted from a June 2026 verification search and require confirmation against the Portuguese primary texts.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection10
AI Governance00
Fintech00
Cybercrime10
Digital Rights10
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
Notable gaps

Public sourcing is thin. The relationship between Lei n.º 3/2016 and Decreto-Lei n.º 4/2017, the substantive provisions (rights, transfers, penalties), and the National Agency's statutory powers and operational capacity all await confirmation against primary texts.