Law / Angola

Penal Code, Unauthorised Access to an Information System

Código Penal de Angola, art. 438.º (Acesso Ilegítimo a Sistema de Informação), Lei n.º 38/20 de 11 de Novembro de 2020

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A computer misuse rule binding public and private bodies.

As of 7 September 2026.

What it requires

  • Do not access, without authorisation, all or part of an information system of which you are not the holder.
  • Do not defeat a security measure or access a conditional-access ('protegido') service to reach a system without authorisation, which draws a substantially heavier penalty.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Unauthorised access to all or part of an information system draws imprisonment of up to two years or a fine of up to 240 days (Article 438(1)); imprisonment of two to eight years applies where the access defeats a security measure, targets a conditional-access service, exposes a protected secret, or yields an elevated-value benefit (Article 438(2) and (3)).

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 438(1) punishes any person who, without authorisation, accesses all or part of an information system of which they are not the holder, with imprisonment of up to two years or a fine of up to 240 days.

Article 438(2) raises the penalty to imprisonment of two to eight years where the access is achieved by defeating security measures, or is directed at a 'serviço protegido' (a service whose access is conditional on a subscription or other prior individual authorisation, as Lei n.º 7/17 art. 4(a) defines the term).

Article 438(3) applies the same heavier tier where the actor learns a commercial or industrial secret or confidential data protected by law, or obtains a benefit or advantage of elevated value. Article 438(4) extends the base penalty to a person who, without due authorisation, processes individually identifiable data or transmits it to a third party for a purpose other than the one authorised.

Article 437 defines 'sistema informático' broadly as any device or set of interconnected devices that automates the processing of computer data, together with the network supporting communication between them.

The offence draws no distinction based on whether the accessed system or page is public and unauthenticated, so a plain reading exposes web crawling that accesses a system without the holder's authorisation, regardless of whether a technical barrier was defeated, though the enhanced tier under Article 438(2) requires either a security-measure violation or a conditional-access service.

Lei n.º 7/17 (Lei de Protecção das Redes e Sistemas Informáticos) imposes separate security and data-retention duties on network operators, but its own Article 44 states that, for information systems and data, subsidiarily the legal regime provided by the criminal legislation and criminal procedure legislation in force applies, referring unauthorised-access liability back to this Penal Code article rather than creating a second offence.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Text of Lei n.º 38/20 (Código Penal de Angola), reproduced by AngoLex

Back to the example  ·  Lint your app