Law / Angola

Law on the Protection of Personal Data, enforcement and supervision

Lei n.º 22/11, de 17 de Junho de 2011, arts. 44-62 (Agência de Protecção de Dados, contravenções e crimes)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect the Agência de Protecção de Dados, a public legal person with administrative, financial and asset autonomy composed of seven members, to supervise compliance with this law, issue guidance, decide complaints, register and publish processing files, and exercise its sanctioning function.
  • Register a code of conduct with the APD before relying on it, and expect the APD to reject a code that conflicts with this law or other applicable legislation.
  • Expect any person to be able to pursue an administrative or judicial remedy for a breach of this law's data protection rules, in addition to filing a complaint with the APD, and expect an APD decision to be appealable to the administrative courts.
  • Expect to face judicial liability for reparation of moral or patrimonial harm caused to a person by misuse of their personal data, with the amount set by a judge.
  • Expect an administrative fine, in national currency equivalent, of USD 75,000 to USD 150,000 for violating the security, professional secrecy, or special category duties in Articles 14, 15, 16, 17, 20, 30, 31 or 32, or of USD 65,000 to USD 130,000 for violating the general principles in Articles 6 to 11 or the consent, communication, or interconnection duties in Articles 18, 19 and 21 to 24, tripled for a company or association.
  • Expect criminal liability of three to eighteen months' imprisonment or a corresponding fine, doubled for sensitive category data, for omitting a required APD authorisation request, giving false information in a notification or authorisation request, carrying out an illegal data interconnection, or failing to comply with the APD's own deadline for a required action.
  • Do not access personal data whose access is barred to you without authorisation, on pain of six months' to two years' imprisonment or a corresponding fine, aggravated where achieved by defeating security rules or for a benefit.
  • Do not erase, destroy, damage, suppress or modify personal data without due authorisation, on pain of eighteen months' to three years' imprisonment or a corresponding fine, aggravated for particularly serious damage.
  • Interrupt, cease or block processing once the APD has notified you to do so, and cooperate with an APD request, on pain of up to three years' imprisonment or a corresponding fine for qualified disobedience.
  • Keep personal data confidential once bound by professional secrecy, on pain of imprisonment of up to eighteen months, rising to two years for a public official, a financial gain motive, or harm to the data subject's reputation or privacy.
  • Expect a court to add, alongside a fine, a temporary or permanent processing ban, an order to block, erase or destroy data, or publication of the conviction at your expense in a widely circulated periodical.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Failing to seek the APD's required authorisation, giving false information in a notification or authorisation request, carrying out an illegal data interconnection, or missing an APD compliance deadline draws imprisonment of three to eighteen months or a corresponding fine, doubled for sensitive category data under Articles 13 to 16 (Article 55). Unauthorised access to personal data whose access is barred to the actor draws imprisonment of six months to two years or a corresponding fine, aggravated for defeating security rules or for a benefit, and prosecuted only on the victim's complaint (Article 56). Erasing, destroying, damaging, suppressing or modifying personal data without authorisation draws imprisonment of eighteen months to three years or a corresponding fine, doubled for particularly serious damage, or up to two years for negligence (Article 57). Failing to interrupt, cease or block processing after APD notice, or otherwise disobeying an APD requirement, draws imprisonment of up to three years or a corresponding fine (Article 58). Violating the duty of professional secrecy over personal data draws imprisonment of up to eighteen months or a corresponding fine, rising to two years for a public official, a financial gain motive, or harm to the data subject's reputation, honour or privacy (Article 59). An attempt of any of these crimes draws imprisonment of up to six months or a corresponding fine (Article 60).

Penalty structure

Administrative fines run from USD 65,000 to USD 130,000 for violating the general principles in Articles 6 to 11, the consent requirement, or the communication and interconnection duties in Articles 18, 19 and 21 to 24, and from USD 75,000 to USD 150,000 for violating the security, professional secrecy, or special category duties in Articles 14 to 17, 20, 30, 31 or 32 (Article 51(1)), tripled to a maximum of USD 450,000 for a company, corporation or unincorporated association (Article 51(2)). Separate criminal penalties in Articles 55 to 60 run up to three years' imprisonment or a corresponding fine, with no separate monetary ceiling stated for the fine beyond the amount corresponding to the prison term.

Rule
Fixed only
As of
19 September 2026
Minimum
65,000
Currency
USD
Fixed cap
450,000

Who enforces it

Enforcement body

Agência de Protecção de Dados (APD)

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 44 establishes the Agência de Protecção de Dados as a public legal person with administrative, financial and asset autonomy, composed of seven members, three designated by the President of the Republic including the Agency's President, three elected by the National Assembly, and one judicial magistrate elected by the Superior Council of Judicial Magistracy, and gives it functions including supervising this law, issuing guidance, deciding complaints, registering and publishing processing files, cooperating internationally, exercising its sanctioning function, and reporting annually to the Executive.

Article 46 lets the APD stimulate, register, and reject codes of conduct that conflict with this law. Article 47 lets any person pursue an administrative or judicial remedy for a breach of this law's rules in addition to a complaint to the APD, and makes an APD decision appealable through administrative litigation. Article 48 entitles a person who suffers moral or patrimonial harm from misuse of their personal data to seek judicial reparation, with the judge setting the harm's value.

Article 51 fines a violation of Articles 14 to 17, 20, 30, 31 or 32 from USD 75,000 to USD 150,000, and a violation of Articles 6 to 11's principles, the consent requirement, or Articles 18, 19 and 21 to 24 from USD 65,000 to USD 130,000, tripling the applicable limits for a company, corporation or unincorporated association, and makes both attempt and negligence punishable.

Article 55 makes omitting a required APD authorisation request, giving false information in a notification or authorisation request, an illegal data interconnection, or missing an APD compliance deadline a crime punishable by three to eighteen months' imprisonment or a corresponding fine, doubled for Article 13 to 16 sensitive data.

Article 56 makes unauthorised access to personal data whose access is barred to the actor a crime punishable by six months to two years' imprisonment or a corresponding fine, aggravated for defeating security rules or for a benefit, and prosecuted only on complaint.

Article 57 makes erasing, destroying, damaging, suppressing or modifying personal data without authorisation a crime punishable by eighteen months to three years' imprisonment or a corresponding fine, doubled for particularly serious damage, or up to two years for negligence. Article 58 makes failing to interrupt, cease or block processing after APD notice, or otherwise disobeying an APD requirement, a crime punishable by up to three years' imprisonment or a corresponding fine.

Article 59 makes violating the duty of professional secrecy over personal data a crime punishable by up to eighteen months' imprisonment or a corresponding fine, rising to two years for a public official, a financial-gain motive, or harm to the data subject's reputation, honour or privacy.

Article 61 lets a court add, alongside a fine, a temporary or permanent processing ban, an order to block, erase or destroy data, or publication of the conviction at the convicted party's expense in a widely circulated periodical.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions
  • is_listed_company

Read the law

Text of Lei n.º 22/11 (Lei da Protecção de Dados Pessoais), reproduced by AngoLex

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app