Law / Sao Tome and Principe

Lei n.º 03/2016, Protecção de Dados Pessoais

Lei n.º 03/2016, de 15 de Fevereiro de 2016, sobre a Protecção de Dados Pessoais, arts. 1-6, 9, 15, 17-18, 21-26, 45, 47

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the data holder's unequivocal authorization before processing their personal data, or rely on one of the Law's specific grounds: performing a contract with them, a legal obligation you face, protecting their vital interests, a public-interest mission, or your own legitimate interest weighed against their rights.
  • Notify the National Agency for the Protection of Personal Data (NAPPD) in writing at least eight days before starting a wholly or partly automated processing operation.
  • Obtain NAPPD's prior authorization before processing credit or solvency data, interconnecting personal-data files, or using collected data for a purpose other than the one it was collected for.
  • If you are not established in Sao Tome and Principe but use means located there to process personal data, designate a representative established in the country and notify NAPPD of that designation.
  • Process personal data lawfully and in good faith, collect it only for specified, explicit and legitimate purposes tied to your activity, keep it adequate, relevant and not excessive, accurate and updated, and retain it in identifiable form no longer than the collection purpose requires.
  • Implement appropriate technical and organizational measures against accidental or unlawful destruction, loss, unauthorized alteration, disclosure or access to personal data, choose a subcontractor offering sufficient guarantees, bind it by contract to your instructions and the same measures, and record that contract in a document with legally recognized probative value.
  • Do not process personal data you access as a subcontractor, or on the controller's authority, beyond the controller's instructions except under a legal obligation, and keep confidential any personal data you learn of in the course of your duties, including after those duties end.
  • Obtain NAPPD's authorization before interconnecting personal data unless a legal or organic provision already authorizes it, and include in any notification or authorization request to NAPPD your identity, the processing's purposes, the categories of data and data holders, the recipients, the retention period, how holders can access or correct their data, any planned interconnection or transfer abroad, and a description of your security measures.
  • Where your processing is exempt from notification, still give any person who asks your identity, the processing's purposes, and the data holder's rights of access and rectification.

What it reaches

Obligation class

Consent, Licensing, Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 applies the Law to processing personal data by automated means, wholly or partly, and to non-automated processing of data held in or intended for a manual file, reaching a controller established in Sao Tome and Principe, one whose activities are carried out there, one whose processing falls under São Toméan law by public or private international law, or one using means located in the country, in which case it must designate a representative there and notify NAPPD of that designation; it also reaches video surveillance and other capture of sound or image that identifies a person, and it exempts only a private individual's exclusively personal or domestic activity that is not meant for systematic communication or diffusion.

Article 5 requires personal data to be treated lawfully and in good faith, collected for specified, explicit and legitimate purposes tied to the controller's activity, kept adequate, relevant, not excessive, accurate and updated, and preserved in identifiable form no longer than those purposes need.

Article 6 permits processing only with the holder's unequivocal authorization or on one of the Law's specific grounds: contract performance, a legal obligation, the holder's vital interests, a public-interest mission, or the controller's own legitimate interest weighed against the holder's rights.

Article 9 subjects interconnecting personal data to NAPPD's authorization unless a legal or organic provision already authorizes it, and requires it to serve a legitimate purpose, avoid a discriminatory effect, and carry appropriate security measures.

Article 15 requires appropriate technical and organizational measures against accidental or unlawful destruction, loss, unauthorized alteration, disclosure or access, a subcontractor chosen for sufficient guarantees and bound by contract to the controller's instructions and the same measures, and that contract recorded in a document with legally recognized probative value; Article 17 bars a subcontractor or anyone else with access to personal data from processing it beyond the controller's instructions except under a legal obligation, and Article 18 binds anyone who learns personal data in the course of their duties to professional secrecy, including after those duties end.

Article 21 requires the controller or its representative to notify NAPPD in writing at least eight days before starting a wholly or partly automated processing operation, and Article 22 requires NAPPD's prior authorization before processing credit or solvency data, interconnecting personal-data files, or using collected data for a purpose other than the one it was collected for.

Articles 23 and 24 fix what a notification or authorization request, and any NAPPD record of it, must state, including the controller's identity, the processing's purposes, the categories of data and recipients, the retention period, how a holder can access or correct their data, any planned interconnection or transfer abroad, and a description of the security measures applied.

Article 25 registers non-exempt processing with NAPPD for public consultation and requires a controller exempt from notification to give any person who asks, at minimum, its identity, the processing's purposes, and the holder's rights of access and rectification. Article 47 defers the Law's own entry into force to general law without stating a day.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_voice

Read the law

Lei n.º 03/2016 sobre a Protecção de Dados Pessoais, reproduced by the Network of African Data Protection Authorities (NADPA-RAPDP)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2023. Publisher's page: https://www.nadpa-rapdp.org/sites/default/files/2020-11/Law_3_2016_protection_of_personal_data.pdf

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app