Angola's dedicated cybersecurity statute is Lei n.º 7/17, Lei de Protecção das Redes e Sistemas Informáticos (Law on the Protection of Networks and Information Systems), approved by the National Assembly on 18 November 2016 and promulgated by the President on 31 December 2016; Article 47 states it enters into force on the date of its publication, but the text read here does not show the Diário da República gazette date, so the exact commencement day is left unconfirmed rather than guessed.
Article 1 sets the Law's object as establishing the legal regime on measures for the protection of networks and information systems, and Article 2 applies it to Angola's cyberspace against any act of attack, computer theft, cyber-attack and computer incidents, with an extraterritorial reach whose paragraph 2(a) requires a legal person's domicile in Angola but whose paragraph 2(d) names only a foreign citizen, not a foreign legal person, with no residence requirement, a gap raised as an open question below rather than resolved here.
Chapter II Section I (Articles 6 through 11) binds operators and service providers of public electronic-communications networks to network-security, encryption, incident-response and security-management duties, and Article 7 separately assigns operators and service providers of critical infrastructure a duty to secure the assets essential to critical social functions; both classes are a sector-licensed telecommunications operator or a government-designated critical-infrastructure operator, a role no activity in this fifteen-value vocabulary expresses, so neither is flagged here and both are recorded as law the lint does not yet reach rather than flagged on a guess.
Chapter II Section II (Articles 12 through 14 and 17) and Section III (Articles 18 and 19) bind a provider, operator or service provider of an information-society system, a class Article 4(ff) defines as broadly as the EU's information-society-service concept (any service normally provided at a distance, by electronic means, at the individual request of a recipient), to the equivalent security duties plus specialised protection rules for computer programs and databases; that class is broad enough to file here, flagged on operates_social_platform as this vocabulary's nearest available proxy, while the row's own summary and requires say plainly that the real reach is broader than a social platform.
Articles 15, 16, 40 and 41 add a pre-activity incident-management-plan filing duty, an alert-dissemination duty on attack or incident, and a central coordinating role for the CERT-equivalent Equipa de Monitorização e Respostas aos Incidentes Informáticos, but no article reviewed here states a reporting clock the way the General Data Protection Regulation (GDPR)'s 72 hours or the Cyber Resilience Act's 24 hours do, and Article 40 leaves the team's own organisation and reporting channel to a decree not located here.
Chapter V Article 42 punishes non-compliance with Articles 12 through 19 with a contravenção (an administrative infraction, not a criminal penalty) of Kz 7,000,000 to Kz 150,000,000, enforced by the Agência de Protecção de Dados Pessoais; Articles 6 through 11 and Article 7 carry no fine under Article 42 at all.
No article of Lei n.º 7/17 sets a security requirement a software product or connected device must meet before being placed on the market, nor a support-period, update or vulnerability-disclosure-channel duty on a manufacturer as such, so this jurisdiction has no product_security_requirements row.
Angola also has no general, no-sector-gate reasonable-security statute reaching any business that holds covered data; Lei n.º 7/17's duties are scoped to communications and information-society-service providers rather than to a business by reason of the data it holds.
A Wayback Machine search of the Banco Nacional de Angola's domain for a bank-specific cybersecurity circular returned only numerically-identified article pages with no descriptive title, so no such circular is confirmed here; regardless, a licensed bank is a role no activity in this vocabulary expresses, so any such circular would be deferred rather than filed even if located.
Two nearby security clauses stay with the privacy topic rather than being held twice here: Lei n.º 22/11 (Lei de Protecção de Dados Pessoais) Articles 30 and 31, the comprehensive privacy law's own security-of-processing and special-security-measures articles, and Lei n.º 23/11 (Lei das Comunicações Electrónicas e dos Serviços da Sociedade de Informação) Title III Article 55, the electronic-communications sector's own integrity-and-security clause and its personal-data breach-notification duty for operators of publicly accessible electronic-communications networks.
Lei n.º 38/20 (Código Penal) stays with the scraping topic's computer-misuse family.