Law / Sao Tome and Principe

Lei n.º 03/2016, Protecção de Dados Pessoais

Lei n.º 03/2016, de 15 de Fevereiro de 2016, sobre a Protecção de Dados Pessoais

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A comprehensive regime rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Obtain the data holder's unequivocal authorization before processing their personal data, or rely on one of the Law's specific grounds: performing a contract with them, a legal obligation you face, protecting their vital interests, a public-interest mission, or your own legitimate interest weighed against their rights.
  • Before processing a sensitive category of data (political, religious, trade-union or philosophical affiliation, racial or ethnic origin, private life, health, sex life, or genetic data), obtain the holder's explicit authorization, rely on a specific legal provision, or obtain NAPPD authorization for an important public interest.
  • Notify the National Agency for the Protection of Personal Data (NAPPD) in writing at least eight days before starting a wholly or partly automated processing operation.
  • Obtain NAPPD's prior authorization before processing sensitive data, processing credit or solvency data, interconnecting personal-data files, or using collected data for a purpose other than the one it was collected for.
  • Inform the data holder, at collection, of your identity, the purpose of the processing, and their right of access and rectification.
  • Before transferring personal data outside São Tomé and Príncipe, confirm the destination legal order offers an adequate level of protection or rely on a stated derogation, and notify NAPPD of a transfer that relies on one.
  • Put in place the special safety measures the Law requires for sensitive or credit data: control of premises entry, data-carrier handling, unauthorized disclosure, system access, transmission, and data-entry logging.
  • If you are not established in São Tomé and Príncipe but use means located there to process personal data, designate a representative established in the country and notify NAPPD of that designation.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Arts. 36-41 punish, among other things, omitting the required NAPPD notification or authorization request, providing false information in one, diverting personal data from its collection purpose, illegal interconnection of personal data, unauthorized access to personal data, and breach of professional secrecy, each with imprisonment of up to one or two years or a fine of up to 120 or 150 days depending on the offense; penalties double where the data involved falls under arts. 7 or 8 (sensitive categories or criminal-suspect records), or where unauthorized access was achieved by defeating a technical security measure.

Penalty structure

Art. 31 sets administrative fines, for omitting or defectively fulfilling the NAPPD notification duty, of 50,000,000 to 120,000,000 Dobras for a natural person, 100,000,000 to 200,000,000 for a group of persons without legal personality, and 250,000,000 to 500,000,000 for a legal person, doubled where the violation concerns data subject to Art. 22 prior checking (sensitive data, credit data, interconnection, or repurposing), giving a true ceiling of 1,000,000,000. Art. 32 sets separate, lower administrative fines for other omissions: 25,000,000 to 50,000,000 for breach of arts. 5, 10-13, 16-17 or 25(3), and 45,000,000 to 90,000,000 for breach of arts. 6-9, 19 or 20. The amounts are stated in the Law's own 2016 text in Dobras (the pre-2018 redenomination currency, ISO code STD); whether they have since been restated in the redenominated New Dobra (STN) is not established here.

Rule
Fixed only
As of
6 September 2026
Currency
STD
Fixed cap
1,000,000,000

Who enforces it

Enforcement body

National Agency for the Protection of Personal Data (NAPPD), commonly cited as the ANPDP

What it reaches

Obligation class

Consent, Data subject rights, Transfer, Licensing, Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Lei n.º 03/2016 sets São Tomé and Príncipe's general rules for processing personal data by automated or manual means, applying to a controller established in the country, one targeting activities there, one using means located there, or one whose processing engages São Toméan private or public international law.

Processing needs the holder's unequivocal authorization or one of the Law's specific grounds: contract performance, a legal obligation, the holder's vital interests, a public-interest mission, or the controller's own legitimate interest balanced against the holder's rights.

A narrower list of sensitive categories, philosophical or political belief, trade-union or religious affiliation, racial or ethnic origin, private life, health or sex life including genetic data, needs the holder's explicit authorization, a specific legal provision, or NAPPD authorization for an important public interest; biometric identifiers as such are not named among these categories.

A controller or its representative must notify the National Agency for the Protection of Personal Data (NAPPD) in writing at least eight days before starting a wholly or partly automated processing operation, and obtain NAPPD's prior authorization before processing sensitive data, credit or solvency data, interconnecting personal-data files, or repurposing data collected for another end.

Chapter III gives the data holder a right to information at collection and a right of access and rectification. A transfer of personal data outside the country needs the destination legal order to ensure an adequate level of protection, as NAPPD assesses it, unless a derogation applies (contract necessity, an important public interest, the holder's vital interests, or a public register open to consultation) or NAPPD authorizes the transfer on the strength of adequate contractual safeguards. The Law's own final provision defers its entry into force to general law without stating a day.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice

Read the law

Lei n.º 03/2016 sobre a Protecção de Dados Pessoais, reproduced by the Network of African Data Protection Authorities (NADPA-RAPDP)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2023. Publisher's page: https://www.nadpa-rapdp.org/sites/default/files/2020-11/Law_3_2016_protection_of_personal_data.pdf

Back to the example  ·  Lint your app