Law / Cape Verde

Law No. 133/V/2001 on the Protection of Personal Data

Lei n.º 133/V/2001, de 22 de Janeiro (Lei de Protecção de Dados Pessoais), Assembleia Nacional da República de Cabo Verde

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A comprehensive regime rule binding public and private bodies.

As of 7 September 2026.

What it requires

  • Do not process personal data revealing philosophical, ideological or political beliefs, religion, political party or trade union affiliation, racial or ethnic origin, or health and sex life including genetic data, without the data subject's express consent or another statutory authorization.
  • Do not base a decision producing legal effects on, or significantly affecting, a person solely on automated processing that evaluates their work performance, creditworthiness, reliability, or conduct.
  • Notify the CNPD before carrying out an automated personal-data processing operation, and obtain the CNPD's prior authorization for processing of sensitive data, credit and solvency data, combined data across filing systems, or data reused for a new purpose.
  • Do not transfer personal data to a foreign state that the CNPD has not found to ensure an adequate level of protection, unless the data subject has given unequivocal consent or another CNPD-recognized derogation applies.
  • Compensate a data subject for damage caused by an unlawful processing operation or another act incompatible with this law, unless able to show the damage is not attributable to the controller.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Intentional non-compliance with the notification or authorisation duties draws up to one year's imprisonment or a fine of up to 120 days, doubled to the maximum where the data is Article 8 or 9 sensitive data (Article 40); undue access to prohibited personal data draws the same range, doubled for a security-rule violation or an obtained benefit (Article 41); invalidation or destruction of personal data draws up to two years' imprisonment or a fine of up to 240 days, doubled for particularly serious damage (Article 42); and violation of professional secrecy over personal data draws imprisonment from six months to three years or a fine of 80 to 200 days, increased by half for a civil servant or a material-advantage motive (Article 44). These are day-fine terms; the statute does not itself state the escudo value of a day-fine unit.

Penalty structure

Administrative offences: omitting the Article 23/24 notification or authorisation, or giving false information in it, draws a fine of CVE 50,000 to 500,000 for a single individual or CVE 300,000 to 3,000,000 for a group or unincorporated entity, doubled to the maximum for data subject to Article 24 prior authorisation (Article 33); other listed omissions draw a fine of CVE 100,000 to 1,000,000 (Article 34). Separately, Articles 40 to 44 create day-fine and imprisonment crimes for the same and related conduct; see criminal_exposure_note.

Rule
Fixed only
As of
7 September 2026
Minimum
50,000
Currency
CVE
Fixed cap
3,000,000

Who enforces it

Enforcement body

Comissão Nacional de Protecção de Dados (CNPD)

What it reaches

Obligation class

Consent, Disclosure, Data subject rights, Transfer, Licensing

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 2 applies the law to processing of personal data wholly or partly by automated means and to manual filing systems, reaching a controller established in Cabo Verde, a controller to whom Cabo Verdean law applies by international public law, or a controller outside the territory using equipment located there other than for transit, and separately to video surveillance and other capture, processing, and dissemination of sound and images permitting identification of a person.

Article 8 prohibits processing personal data revealing philosophical, ideological or political beliefs, religion, political party or trade union affiliation, racial or ethnic origin, or health and sex life including genetic data, unless the data subject has expressly consented with a guarantee of non-discrimination, or another legal authorization applies.

Article 14 gives every person the right not to be subject to a decision producing legal effects or significantly affecting them that is based solely on automated processing intended to evaluate personal aspects such as work performance, creditworthiness, reliability, or conduct, subject to Article 14(2)'s exceptions for contract-related automated decisions with safeguards.

Article 19 conditions transfer of personal data to a foreign state on the CNPD's assessment that the state ensures an adequate level of protection, and Article 20 permits the CNPD to authorize a transfer to a state that does not meet that standard where the data subject has given unequivocal consent or another enumerated derogation applies.

Article 23 requires the controller to notify the CNPD before carrying out an automated processing operation, subject to simplification or exemption the CNPD may grant, including for a filing system open to public consultation. Article 24 requires the CNPD's prior authorization for processing of the most sensitive data categories, data on credit and solvency, combination of personal data across filing systems, and use of data for a purpose other than that for which it was collected.

Article 31 entitles a person who has suffered damage from an unlawful processing operation or another act incompatible with the law to compensation from the controller, who may be exempted in whole or in part on proving he is not responsible for the fact giving rise to the damage.

Offences are backed by a graduated schedule: Article 33 fines the offence of omitting the Article 23 or 24 notification or authorisation, or providing false information in it, from CVE 50,000 to 500,000 for a single individual and from CVE 300,000 to 3,000,000 for a group of people or an entity without legal personality, doubled to the maximum for data subject to Article 24 prior authorisation; Article 34 fines other listed omissions from CVE 100,000 to 1,000,000.

Articles 40 to 44 create crimes for intentional non-compliance with the notification and authorisation duties (up to one year's imprisonment or a fine of up to 120 days, doubled to the maximum for Article 8 and 9 data), undue access to prohibited personal data (up to one year's imprisonment or a fine of up to 120 days, doubled for security-rule violations or a benefit obtained), invalidation or destruction of personal data (up to two years' imprisonment or a fine of up to 240 days), qualified non-compliance after CNPD notification, and violation of professional secrecy (imprisonment from six months to three years or a fine of 80 to 200 days).

Article 45 makes an attempt of any of these crimes always punishable.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • high_risk_decisions
  • processes_biometrics
  • processes_voice

Read the law

Official English translation of Law No. 133/V/2001 of 22 January
on the Protection of Individuals with Regard to the Processing of Personal Data, published by the Comissão Nacional de Protecção de Dados (CNPD)

Back to the example  ·  Lint your app