Law / Angola

Law on the Protection of Personal Data, rights of data subjects

Lei n.º 22/11, de 17 de Junho de 2011, arts. 25-29 (direitos dos titulares dos dados)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A data subject rights rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Tell a data subject at least your identity and address, the purposes of processing and the file's existence, the recipients or categories of recipients, whether a reply is mandatory or voluntary and the consequences of not replying, and the existence and conditions of the rights of access, rectification, updating, elimination and objection, when you collect their data or, if collected elsewhere, at the latest thirty days after collection.
  • Publish an easily accessible privacy policy carrying the article 25 disclosures, including that data on an open network may circulate without security guarantees and could be seen or used by unauthorised third parties, wherever data is collected over an open network.
  • Give a data subject, free of charge, without restriction and without excessive delay, confirmation of whether you process their data, the purposes, categories and recipients, the specific data itself and any available information on its origin, and let them exercise access to health or sex-life data, including genetic data, through a doctor of their choice.
  • Let a data subject object at any time, on compelling and legitimate grounds tied to their particular situation, to processing carried out under a public-interest or legitimate-interest ground, and exclude their data from that processing once the objection is justified.
  • Rectify, update or eliminate a data subject's personal data within sixty business days of a request where its processing does not comply with this law, and notify any recipient the data was previously disclosed to of the correction, update or elimination unless that is demonstrably impossible.
  • Do not base a decision that produces legal effects on, or significantly affects, a person solely on automated processing evaluating personal aspects such as their professional capacity, creditworthiness, trustworthiness or conduct, unless it occurs in performing a contract at the data subject's request with safeguards for their legitimate interests, or the APD has authorised it with safeguards.

What it reaches

Obligation class

Data subject rights, Disclosure, Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 25 requires the controller to give a data subject at least the controller's identity and address, the purposes of processing and the file created for it, the recipients or categories of recipients, whether replying is mandatory or voluntary and the consequences of not replying, and the existence and conditions of the rights of access, rectification, updating, elimination and objection, at the time of collection or, where the data came from elsewhere, at the latest thirty days after collection, in language that is clear, precise and objective for a minor or a person with special needs.

Article 25 treats the right to information as fulfilled, for data collected over open networks, by publishing an easily accessible privacy policy carrying that same information together with a warning that personal data may circulate on the network without security guarantees and risk being seen or used by unauthorised third parties.

Article 26 gives a data subject the right to obtain from the controller, freely and without restriction, delay or excessive cost, confirmation of whether their data are processed, the purposes and categories of that processing, the recipients, the specific data itself, and any available information on its origin, and lets a data subject exercise access to health or sex-life data, including genetic data, through a doctor of their choice.

Article 27 lets a data subject object at any time, on compelling and legitimate grounds tied to their particular situation, to processing carried out under Article 12's public-interest or legitimate-interest grounds, obliging the controller to exclude their data from that processing once the objection is justified.

Article 28 requires the controller to rectify, update or eliminate a data subject's personal data within sixty business days of a request where its processing does not comply with this law, and to notify any recipient the data were previously disclosed to of the correction, update or elimination, unless that is demonstrably impossible.

Article 29 gives a data subject the right not to be subject to a decision that produces legal effects on them or significantly affects them, taken solely on automated processing evaluating personal aspects such as professional capacity, creditworthiness, trustworthiness or conduct, unless the decision is taken in forming or performing a contract at the data subject's request with safeguards for their legitimate interests including a right of representation and expression, or the APD has authorised it with safeguards for the data subject.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • generates_content

Read the law

Text of Lei n.º 22/11 (Lei da Protecção de Dados Pessoais), reproduced by AngoLex

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app