Law on the Protection of Personal Data
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Obtain the data subject's unequivocal, express consent before processing their personal data, or notify the Agência de Protecção de Dados, unless a contract-performance, legal-obligation, vital-interest, public-interest, or legitimate-interest ground applies.
- Obtain the data subject's consent or the APD's authorisation before processing personal data on their creditworthiness or solvency, unless the information comes from a publicly accessible source, and notify the data subject within sixty days of entering their data in a debtor file.
- Notify the Agência de Protecção de Dados, or obtain the recipient's express consent, before sending postal or electronic marketing messages or recording a call for commercial purposes, and let the recipient object to further messages free of charge at any time.
- Treat a recipient who processes communicated personal data for its own purposes as a controller in its own right, and one who processes it on your behalf and under your instructions as a subcontractor bound by a written contract, and obtain the APD's authorisation before interconnecting personal data held in different files unless a legal provision already permits it.
- Implement technical and organisational measures adequate to the risk presented by the processing and the nature of the data, and keep a document describing the security measures, standards and procedures applied.
- Keep personal data confidential, both as a data controller and as anyone who learns of it in the course of their duties, including after the relationship ends.
- Notify the Agência de Protecção de Dados before processing personal data, or obtain its authorisation where notification is not enough, and give it the particulars the law requires about the processing.
What it reaches
Obligation class
Consent, Disclosure, Security, Licensing
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 3 subjects to the law any processing of personal data by any person or entity in the public, private, or cooperative sector, including a controller not established in Angola who uses means located there.
Article 12 requires the data subject's unequivocal, express consent before most processing, or notification to the APD, unless the processing falls under one of Article 12's enumerated exceptions such as contract performance, a legal obligation, vital interests, a public interest mission, or the controller's legitimate interest.
Article 16 conditions processing of credit and solvency data on the data subject's consent or the APD's authorisation unless the information comes from a publicly accessible source, and requires the data subject to be notified within sixty days once their data enters a debtor file.
Articles 18 to 20 require notification to the APD, or the recipient's consent, before sending postal or electronic marketing messages or recording a call for commercial purposes, and require the sender to let the recipient object to further messages at any time free of charge.
Articles 21 to 24 allocate responsibility for communicated data between the discloser, a fellow controller, a subcontractor acting on the discloser's behalf and instructions, or a third party, and require the APD's authorisation for interconnecting personal data held in different files unless a legal provision already permits it.
Article 30 requires technical and organisational measures adequate to the risks presented by the processing and the nature of the data, documented in a security procedures record, and Article 32 binds a data controller and anyone who learns of the data in the course of their duties to professional secrecy, including after those duties end.
Articles 35 to 38 require notification to the APD, or its authorisation where notification is not enough, before processing personal data, fix the particulars a notification or authorisation request must contain, and require processing subject to authorisation or notification to appear in a public APD register.
Articles 39 to 43 apply this law to the public sector subject to further rules on creating, modifying and eliminating files and on inter-agency data sharing, and to the private and cooperative sectors subject to further legislation for specific activities. Article 67 enters the law into force on the date of its publication, following approval by the National Assembly on 24 May 2011 and promulgation by the President on 8 June 2011, so these provisions bind today.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Text of Lei n.º 22/11 (Lei da Protecção de Dados Pessoais), reproduced by AngoLex
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.