Law / Angola

Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination Duties

Lei n.º 7/17, Artigos 15.º, 16.º, 40.º e 41.º

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A vulnerability and incident reporting rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This binds the same class as this jurisdiction's companion security-duties row, a provider, operator or service provider of Angola's cyberspace or of an information-society system; operates_social_platform is flagged here for the same reason, as this vocabulary's nearest available proxy for that broader class.
  • Before starting your activity, submit an accident-and-incident management plan to Angola's data protection regulator and to the body responsible for promoting the information society, for use in a computer emergency (Article 15(1)).
  • On an attack, computer theft or any computer incident, disseminate alerts and warnings; the text does not state to whom or within what deadline (Article 15(2)).
  • Equip your service with devices capable of issuing an alert on an event or a request, and of sending a technical report on a compromised server, widely disseminated malicious code, a software vulnerability or anything an intrusion-detection system or event log identifies (Article 16(1)).
  • Expect this reactive alerting function to sit alongside the CERT-equivalent Equipa de Monitorização e Respostas aos Incidentes Informáticos, whose own organisation, functioning and reporting channel Article 40 leaves to a separate decree not located here (Article 16(2), Article 40).

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 42 makes a violation of Article 15 or 16 a contravenção (an administrative infraction) rather than a crime; Article 42(7) states that where the same fact is simultaneously a crime and a contravenção, the agent is always punished as a crime instead, so the contravenção itself carries no criminal exposure. Articles 40 and 41, the CERT team's own organisation and cooperation duties, carry no fine under Article 42 at all.

Penalty structure

Article 42(1)(a) sets this range (Kz 7,000,000 to Kz 150,000,000) for non-compliance with the requirements of Article 15; Article 42(1)(b) sets the identical range for non-compliance with Article 16. Articles 40 and 41 are not listed in Article 42 and carry no stated fine.

Rule
Fixed only
As of
18 September 2026
Minimum
7,000,000
Currency
AOA
Fixed cap
150,000,000

Who enforces it

Enforcement body

Agência de Protecção de Dados Pessoais (the Personal Data Protection Agency), which investigates the contravenção proceedings under this Law, with fines applied by the Agency's President following the Agency's own deliberation (Article 43).

Settledness

As of
18 September 2026
Open questions
Has the decree required by Article 40 to establish the Equipa de Monitorização e Respostas aos Incidentes Informáticos's own organisation and functioning been issued, and does it specify the reporting channel and clock Articles 15 and 16 leave unstated?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 15(1) requires a provider, operator or service provider of cyberspace, before starting its activity, to submit an accident-and-incident management plan to the entity that regulates data protection and to the body responsible for promoting the information society, for use in a computer emergency, and Article 15(2) requires alerts and warnings to be disseminated in the event of an attack, computer theft or any computer incident.

Article 16(1) requires the relevant services to be equipped with devices capable of issuing an alert on an event or a request, and of sending a technical report on a compromised server, widely disseminated malicious code, a software vulnerability or anything an intrusion-detection system or event log identifies, and Article 16(2) ties that reactive service to the central work of the CERT-equivalent Equipa de Monitorização e Respostas aos Incidentes Informáticos (Computer Incident Monitoring and Response Team).

Article 40 leaves that team's own organisation and functioning, which would be the natural place a reporting channel and clock could sit, to a separate decree ("diploma próprio") not located here, and Article 41 requires the team to maintain institutional cooperation with public and private bodies. Unlike the General Data Protection Regulation (GDPR)'s 72-hour or the Cyber Resilience Act's 24-hour clock, no article reviewed here states a deadline for any of these notifications.

When LexLint raises it

  • operates_social_platform

Read the law

AngoLex (Portal da Legislação Angolana), full text of Lei n.º 7/17

Back to the example  ·  Lint your app