Law / Sao Tome and Principe

Lei n.º 03/2016, enforcement, offenses and the NAPPD

Lei n.º 03/2016, arts. 14, 27-44 (compensation, complaints, administrative offenses, crimes and the NAPPD)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect a person who suffered damage from your unlawful processing, or from any other act breaching this Law, to have the right to obtain compensation from you, unless you can prove the act causing the damage is not attributable to you.
  • Expect a data holder to be able to complain to NAPPD, and to pursue administrative or judicial recourse, including appeal to the Court of last instance, for a violation of the rights this Law guarantees.
  • Expect an administrative fine reaching 1,000,000,000 Dobras, doubled for a violation involving data subject to prior checking under Article 22, for omitting or defectively fulfilling a notification or authorization duty, and a separate, lower fine for breaching another provision of this Law.
  • Expect negligent conduct to be punished the same as intentional non-compliance for the administrative offenses in Articles 31 and 32, and an attempt to be punished the same as a completed offense for the crimes in this Law.
  • Expect an accessory penalty, such as a temporary or permanent ban on processing, publication of the conviction, or NAPPD's public warning or censure, in addition to any fine or criminal penalty NAPPD or a court imposes.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Arts. 36-41 punish, among other things, omitting the required NAPPD notification or authorization request, providing false information in one, diverting personal data from its collection purpose, illegal interconnection of personal data, unauthorized access to personal data, and breach of professional secrecy, each with imprisonment of up to one or two years or a fine of up to 120 or 150 days depending on the offense; penalties double where the data involved falls under arts. 7 or 8 (sensitive categories or criminal-suspect records), or where unauthorized access was achieved by defeating a technical security measure.

Penalty structure

Art. 31 sets administrative fines, for omitting or defectively fulfilling the NAPPD notification duty, of 50,000,000 to 120,000,000 Dobras for a natural person, 100,000,000 to 200,000,000 for a group of persons without legal personality, and 250,000,000 to 500,000,000 for a legal person, doubled where the violation concerns data subject to Art. 22 prior checking (sensitive data, credit data, interconnection, or repurposing), giving a true ceiling of 1,000,000,000. Art. 32 sets separate, lower administrative fines for other omissions: 25,000,000 to 50,000,000 for breach of arts. 5, 10-13, 16-17 or 25(3), and 45,000,000 to 90,000,000 for breach of arts. 6-9, 19 or 20. The amounts are stated in the Law's own 2016 text in Dobras (the pre-2018 redenomination currency, ISO code STD); whether they have since been restated in the redenominated New Dobra (STN) is not established here.

Rule
Fixed only
As of
19 September 2026
Currency
STD
Fixed cap
1,000,000,000

Who enforces it

Enforcement body

National Agency for the Protection of Personal Data (NAPPD), commonly cited as the ANPDP

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 14 gives a person who suffered damage from unlawful processing, or from any other act breaching this Law or its regulations, the right to compensation from the controller, who is exonerated only by proving the damaging act is not attributable to it.

Article 27 preserves a data holder's right to complain to NAPPD alongside administrative or judicial recourse for a violation of this Law, and Article 28 makes a court decision on that violation appealable, on an urgent, breach-only basis, to the Court of last instance.

Articles 31 and 32 set administrative fines for a legal, natural or unincorporated-group violator, up to 1,000,000,000 Dobras, doubled for data subject to Article 22 prior checking, for omitting or defectively fulfilling the notification or authorization duty, and a separate, lower fine of 25,000,000 to 90,000,000 Dobras for breaching another listed provision; Article 34 punishes negligence the same as intentional non-compliance for these administrative offenses, and Article 41 punishes an attempt the same as a completed offense for the crimes below.

Articles 36 to 40 punish, with imprisonment or a day-fine doubled for Article 7 or 8 data, intentionally omitting a required NAPPD notification or authorization, providing false information in one, diverting or misusing personal data, illegally interconnecting personal data, unauthorized access to personal data, damaging or destroying personal data without authorization, defying a NAPPD order to stop, block or destroy processing, and breaching professional secrecy over personal data.

Article 42 lets NAPPD or a court add an accessory penalty, a temporary or permanent ban on processing, publication of the conviction, or NAPPD's public warning or censure, and Article 43 requires a conviction to be advertised in a widely circulated Portuguese-language periodical and by public notice for at least 30 days.

Article 44 has the National Assembly approve NAPPD's own organic law and the status of its members, guaranteeing their independence, and gives NAPPD its own technical and administrative support.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions

Read the law

Lei n.º 03/2016 sobre a Protecção de Dados Pessoais, reproduced by the Network of African Data Protection Authorities (NADPA-RAPDP)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2023. Publisher's page: https://www.nadpa-rapdp.org/sites/default/files/2020-11/Law_3_2016_protection_of_personal_data.pdf

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app