Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and Databases
Lei n.º 7/17, Artigos 12.º, 13.º, 14.º, 17.º, 18.º e 19.º
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A sector security regimes rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This binds a provider, operator or service provider of an information-society system under Lei n.º 7/17, a class Article 4(ff) defines as broadly as any service normally provided at a distance, by electronic means, at the individual request of a recipient; operates_social_platform is flagged here as this vocabulary's nearest available proxy for that broader class, not as the actual limit of who the duty reaches.
- Guarantee the security of any device or set of devices, and the network supporting communication between them, that stores, processes, retrieves, receives or transmits data in execution of a computer program (Article 12).
- Where you are responsible for managing, operating or providing services for a computer infrastructure, apply the measures and techniques needed to secure and protect the assets essential to that infrastructure's proper functioning (Article 13).
- Where you operate or provide an internet service, promote user registration and carry out the measures and instruments needed to anticipate, detect, react to and recover from security risk situations on your networks (Article 14).
- Apply this Law's security measures and techniques to any computer program you make available; the text states no separate support period, update or vulnerability-disclosure-channel duty for the program itself (Article 18).
- Where you use a database, follow technical rules and specialised procedures adequate to protect its access, storage, file duplication, treatment and the recovery of automated information (Article 19).
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 42 makes a violation of Articles 12, 13, 14 or 18 a contravenção (an administrative infraction) rather than a crime; Article 42(7) states that where the same fact is simultaneously a crime and a contravenção, the agent is always punished as a crime instead, so the contravenção itself carries no criminal exposure.
Penalty structure
Article 42(1)(a) sets this range (Kz 7,000,000 to Kz 150,000,000) for non-compliance with the requirements of Articles 12, 13, 14 or 18; Article 42(1)(b) sets the identical range for non-compliance with Article 17 or 19. Article 42(3) doubles this range for a legal person only where the violation falls under Article 42(2), which does not include these articles, so no doubling applies here.
- Rule
- Fixed only
- As of
- 18 September 2026
- Minimum
- 7,000,000
- Currency
- AOA
- Fixed cap
- 150,000,000
Who enforces it
Enforcement body
Agência de Protecção de Dados Pessoais (the Personal Data Protection Agency), which investigates the contravenção proceedings under this Law, with fines applied by the Agency's President following the Agency's own deliberation (Article 43).
Settledness
- As of
- 18 September 2026
- Open questions
- Does Article 2's extraterritorial reach in paragraph 2 bind a foreign legal person with no domicile in Angola whose information-society service targets Angolan cyberspace, given paragraph 2(a) requires a legal person's domicile in Angola and paragraph 2(d) names only a foreign citizen, not a foreign legal person, with no residence requirement?
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 12 requires the body responsible for promoting the information society, and every provider, operator and service provider of information-society-system services, to guarantee the security of any device or set of devices, and the network supporting communication between them, that stores, processes, retrieves, receives or transmits data in execution of a computer program.
Article 13 requires the entity responsible for management, or the operators and service providers, of a computer infrastructure to apply the measures and techniques needed to secure and protect the assets essential to that infrastructure's proper functioning. Article 14 requires an internet operator or service provider to promote user registration and to carry out the measures and instruments needed to anticipate, detect, react to and recover from security risk situations on its networks.
Article 18 extends this Law's measures and techniques to computer programs, without stating a separate support-period, update or vulnerability-disclosure-channel duty for the program itself, and Article 19 requires database use to follow technical rules and specialised procedures adequate to protect access, storage, file duplication, treatment and the recovery of automated information.
Article 4(ff) defines the bound information-society-service class as broadly as the EU's information-society-service concept: any service normally provided at a distance, by electronic means, at the individual request of a recipient, excluding television and radio broadcasting, automatic note or ticket dispensing, and payment-gated road, parking or similar access even where an electronic device controls or verifies the payment.
When LexLint raises it
operates_social_platform
Read the law
AngoLex (Portal da Legislação Angolana), full text of Lei n.º 7/17