Law / Cabo Verde

Cabo Verde

8 of 9 named instruments researched to a stage, across four of the six areas of law we track: 8 in force. As of 19 September 2026.

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (190 words)

Cabo Verde has no AI-transparency, AI-risk-obligations, AI-training-data, AI-governance, or AI-sector-rules statute in force.

Since April 2025 the Ministry of Digital Economy and Innovation has been developing a National Data Strategy and a companion National Artificial Intelligence Strategy for public administration, with European Union partnership support; as of the 6th Cape Verde Internet Governance Forum in April 2026 officials of the National Directorate of State Modernization confirmed the work remained in progress with no adoption date set, and as of August 2026 neither document had been adopted as binding policy.

Both instruments are strategic planning documents addressed to public administration rather than enacted law binding any person, so neither is recorded as an instrument here.

Cabo Verde does have an ai_prohibited_practices instrument: Article 9(6)(c) of the Cybercrime Law (Lei n.º 8/IX/2017, de 20 de Março) defines child pornography to include any representation, by any means, of a child under 18 in real OR SIMULATED explicit sexual activity, or any representation of a child's sexual organs for a predominantly sexual purpose, so the offence reaches an AI-generated or otherwise synthetic depiction on the same terms as a depiction of a real child.

AI prohibited practices

Cybercrime Law, Child Pornography Including Simulated Representations

Lei n.º 8/IX/2017, art. 9.º (pornografia infantil), de 20 de Março (Lei do Cibercrime)Text of Lei n.º 8/IX/2017 de 20 de Março (Lei do Cibercrime)

In force. Binds public and private bodies.

What this law does

Article 9 criminalises, through a computer system: producing child pornography with the purpose of disseminating it (2 to 8 years' imprisonment, paragraph 1); offering or making it available (1 to 5 years, paragraph 2); disseminating or transmitting it (1 to 5 years, paragraph 3); obtaining it for oneself or another (1 to 4 years, paragraph 4); and possessing it in any way (1 to 4 years, paragraph 5).

Paragraph 6 defines child pornography for these purposes as any pornographic material that visually represents: (a) a person under 14 years of age, or an incapable person, for exhibitionist purposes or involved in sexually explicit conduct; (b) a person 14 to 18 years of age involved in sexually explicit conduct; or (c) any representation, by any means, of a child under 18 performing real or simulated explicit sexual activities, or any representation of a child's sexual organs for a predominantly sexual purpose.

Paragraph 6(c)'s inclusion of a simulated representation reaches a computer-generated, AI-synthesised, or otherwise fabricated depiction of a child in sexually explicit activity on the same terms as a depiction of a real child, without requiring that an actual child be shown or that the material derive from a real event. Paragraph 6(d) sets a reduced penalty of up to three years' imprisonment where the victim depicted is 14 to 18 years of age.

Article 9 binds any person ("Quem"), not only an online service or platform. The Law was approved by the Assembleia Nacional on 25 January 2017, promulgated by the President of the Republic on 3 March 2017, and published in the Boletim Oficial of 20 March 2017; its own Article 33 provides that it enters into force 30 days after publication.

What it requires

Privacy law5 instruments, 5 in force

Research summary (346 words)

Cabo Verde's comprehensive data-protection statute is Law No. 133/V/2001 of 22 January, on the Protection of Individuals with Regard to the Processing of Personal Data, approved by the Assembleia Nacional on 20 December 2000 and enforced by the Comissão Nacional de Protecção de Dados (CNPD), an independent administrative authority operating within the National Assembly.

The law applies to processing wholly or partly by automated means and to manual filing systems, reaches a controller established in Cabo Verde, a controller applying Cabo Verdean law by virtue of international public law, or a controller outside the country using equipment located there for purposes other than transit, and separately extends to video surveillance and other capture, processing, and dissemination of sound and images permitting identification of a person.

It bars processing of sensitive data (philosophical, ideological or political beliefs, religion, political party or trade union affiliation, racial or ethnic origin, health and sex life including genetic data) absent the data subject's consent or another statutory ground, requires prior notification or authorization from the CNPD before most processing begins, arms the data subject with rights of access, rectification, objection, and a right not to be subject to a purely automated decision with legal or significant effect, restricts cross-border transfer to states the CNPD finds adequate, and entitles a person who suffers damage from unlawful processing to compensation from the controller.

The statute does not name a biometric identifier such as a voiceprint or faceprint among its sensitive-data categories, so a service processing one falls under the law's ordinary consent and notification duties rather than a heightened prior-authorization regime, though its video-surveillance provision independently reaches capture and dissemination of identifying sound and images.

Cabo Verde's cybercrime statute, Law No. 8/IX/2017 of 20 March, separately provides at its Article 32 that personal data processed under that law follows Law No. 133/V/2001 as amended by Law No. 41/VIII/2013 of 17 September, confirming that at least one amendment to the 2001 statute exists; no copy of the amendment's own text has been located, so the family rows below record only the 2001 enactment's provisions.

Comprehensive regime

Law No. 133/V/2001 on the Protection of Personal Data

Lei n.º 133/V/2001, de 22 de Janeiro (Lei de Protecção de Dados Pessoais), arts. 1-7, 10, 15, 17-18, 23-27 and 47-49Official English translation of Law No. 133/V/2001 of 22 January

In force. Binds public and private bodies.

What this law does

Article 6 requires personal data to be processed lawfully and in good faith, collected for specific, explicit and legitimate purposes, kept adequate, relevant and not excessive for those purposes, kept accurate and up to date, and kept identifiable for no longer than those purposes require, with the CNPD able to authorise longer retention for historical, statistical or scientific purposes.

Article 7 permits processing only where the data subject has unambiguously consented or where processing is necessary for a contract, a legal obligation, the data subject's vital interests, a public interest task, or the controller's or a third party's legitimate interest that does not override the data subject's rights.

Article 10 subjects combining personal data held in different filing systems, where no legal provision already covers it, to the authorisation of the supervisory authority under article 23, and requires the combination to serve a legitimate purpose, avoid discrimination, and carry adequate security measures.

Article 15 requires the controller to implement technical and organisational measures appropriate to the risk of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, to choose a processor offering sufficient security guarantees, and to bind that processor by a written contract limiting it to the controller's instructions.

Article 17 bars anyone with access to personal data under the controller's or processor's authority from processing it except on the controller's instructions, unless the law requires otherwise, and Article 18 binds a controller and anyone who learns of the data in the course of their functions to professional secrecy, including after those functions end.

Article 23 requires the controller to notify the CNPD before carrying out an automated personal data processing operation, and Article 24 additionally requires the CNPD's prior authorisation for processing of the most sensitive data categories, credit and solvency data, combined data across filing systems, or data reused for a new purpose.

Article 27 requires processing that must be authorised or notified to appear in a CNPD register open to consultation, and requires a controller exempt from notification to make the article 26 particulars available to anyone who asks.

Existing manual and automated filing systems had six months from the law's entry into force to come into conformity with its sensitive data and rights provisions, and the law itself entered into force thirty days after its publication, following approval by the Assembleia Nacional on 20 December 2000 and enactment by the President on 10 January 2001.

What it requires

Cross border transfer

Law No. 133/V/2001 on the Protection of Personal Data, cross border transfer

Lei n.º 133/V/2001, de 22 de Janeiro, arts. 19-20 (transferência internacional de dados)Official English translation of Law No. 133/V/2001 of 22 January

In force. Binds public and private bodies.

What this law does

Article 19 permits transfer of personal data undergoing or intended for processing only in compliance with this law and other applicable data protection legislation, and to a State that has an adequate level of data protection, leaving it for the CNPD to decide whether a foreign State ensures that adequate level.

Article 20 lets the CNPD allow a transfer to a State that does not ensure an adequate level of protection where the data subject has given unequivocal consent, or where the transfer is necessary for a contract with or for the benefit of the data subject, for an important public interest or a legal claim, to protect the data subject's vital interests, or is made from a public register open to consultation by the general public or a person with a legitimate interest.

Article 20 also lets the CNPD authorise an ongoing transfer to a State without an adequate level of protection for as long as the controller provides adequate contractual guarantees for the privacy and fundamental rights of individuals.

What it requires

Data subject rights

Law No. 133/V/2001 on the Protection of Personal Data, rights of data subjects

Lei n.º 133/V/2001, de 22 de Janeiro, arts. 11-14 (direitos dos titulares dos dados)Official English translation of Law No. 133/V/2001 of 22 January

In force. Binds public and private bodies.

What this law does

Article 11 requires the controller or their representative to provide a data subject, from whom data is collected, with at least their identity and address, the purposes of processing, the recipients or categories of recipients, whether replying is mandatory or voluntary and the consequences of not replying, and the existence and conditions of the rights of access and rectification, at the time of collection or, where data comes from elsewhere, no later than its first disclosure to a third party.

Article 11 also requires the data subject to be warned, when their data is collected over an open network and unless they already know it, that it may circulate without security measures and risk being seen or used by unauthorised third parties.

Article 12 gives a data subject the right to obtain from the controller, without constraints, at reasonable intervals and without excessive delay or expense, confirmation of whether their data is processed, the purposes, categories and recipients, an intelligible copy of the data and its source, and lets the data subject exercise access to health data, including genetic data, through a doctor of their own choosing.

Article 13 lets a data subject object, on compelling legitimate grounds relating to their particular situation, to processing carried out for a public interest or legitimate interest ground, and object free of charge and without needing a reason to processing, or a first disclosure to a third party, for direct marketing or other research purposes.

Article 14 gives every person the right not to be subject to a decision that produces legal effects concerning them or significantly affects them, based solely on automated processing intended to evaluate personal aspects such as their performance at work, creditworthiness, reliability or conduct, subject to Article 14(2)'s exception for a contract related automated decision with safeguards or the CNPD's own authorisation.

What it requires

Enforcement supervision

Law No. 133/V/2001 on the Protection of Personal Data, enforcement and supervision

Lei n.º 133/V/2001, de 22 de Janeiro, arts. 21-22 e 28-46 (CNPD, recursos, contra-ordenacoes e crimes)Official English translation of Law No. 133/V/2001 of 22 January

In force. Binds public and private bodies.

What this law does

Article 21 has the CNPD follow up, evaluate and control the activities of legally competent organs or services processing personal data, safeguarding the Constitution, this Law, and the fundamental rights, freedoms and guarantees of citizens, and Article 22 establishes the CNPD as an independent administrative authority operating within the National Assembly.

Article 29 has the CNPD help draft codes of conduct and declare whether a submitted draft complies with the data protection laws and regulations in force.

Article 30 lets any individual seek legal recourse for a violation of their rights under this law, in addition to a complaint to the CNPD, and Article 31 entitles a person who suffers damage from an unlawful processing operation or another act incompatible with this law to compensation from the controller, who may be exempted in whole or in part on proving they are not responsible for the damage.

Article 33 fines an entity that negligently omits, falsifies, or otherwise fails the article 23 or 24 notification or authorisation duty from CVE 50,000 to CVE 500,000 for a single individual or CVE 300,000 to CVE 3,000,000 for a group or unincorporated entity, doubled to the maximum for data subject to article 24 prior authorisation, and Article 34 fines another listed omission, including failing to designate a representative or to observe the article 6, 11, 12, 13, 14, 16 or 17 obligations, from CVE 100,000 to CVE 1,000,000, doubled for a failure touching articles 7, 8, 9, 10, 19 or 20.

Article 40 makes it a crime, punishable by up to one year's imprisonment or a fine of up to 120 days and doubled for article 8 or 9 sensitive data, to intentionally omit a required CNPD notification or authorisation, give false information in one, misappropriate personal data, or carry out an illegal combination of personal data.

Article 41 makes undue access to prohibited personal data a crime punishable the same way, doubled where achieved by violating a technical security rule or for a benefit, and prosecutable only on complaint. Article 42 makes invalidating or destroying personal data without authorisation a crime punishable by up to two years' imprisonment or a fine of up to 240 days, doubled for particularly serious damage.

Article 43 makes failing to interrupt, cease or block processing after notice, refusing to cooperate with the CNPD, or failing to erase or destroy personal data once its retention period under article 6 has elapsed, punishable as qualified non-compliance.

Article 44 makes violating the duty of professional secrecy over personal data a crime punishable by imprisonment from six months to three years or a fine of eighty to two hundred days, increased by half for a civil servant, a material advantage motive, or harm to the data subject's reputation, honour or privacy.

Article 46 lets a court order, in addition to a fine or penalty, a temporary or permanent prohibition of processing, blocking, erasure or destruction of data, or publication of the judgement at the convicted party's expense.

What it requires

Sensitive categories

Law No. 133/V/2001 on the Protection of Personal Data, sensitive data categories

Lei n.º 133/V/2001, de 22 de Janeiro, arts. 8-9 e 16 (dados sensíveis)Official English translation of Law No. 133/V/2001 of 22 January

In force. Binds public and private bodies.

What this law does

Article 8 prohibits processing personal data revealing philosophical, ideological or political beliefs or penalty, religion, political party or trade union affiliation, racial or ethnic origin, privacy, or health and sex life including genetic data, except where the data subject has expressly consented with a guarantee of non-discrimination and adequate assurance, a legal authorisation with the same guarantee applies, the processing is purely statistical and not individually identifiable, the data subject was physically or legally incapable of consenting and processing protects vital interests, a nonprofit political, philosophical, religious or trade union body processes only its own members' or regular contacts' data with their consent, the data subject has manifestly made the data public, or the processing serves the establishment, exercise or defence of a legal claim.

Article 8 additionally permits processing health and sex life data, including genetic data, for preventive medicine, medical diagnosis, medical care or treatment, or health service management, provided a health professional bound by professional secrecy carries it out, it is notified to the CNPD under article 23, and adequate information security measures are in place.

Article 9 restricts central registers on persons suspected of illegal activities, criminal and administrative offences, and decisions applying penalties, security measures, fines or additional penalties to public services vested with that specific responsibility by law, with the CNPD's prior opinion, and lets the CNPD separately authorise such processing subject to the data protection and information security rules, limiting processing for police investigation purposes to what preventing a specific danger or prosecuting a particular offence requires.

Article 16 requires the controllers of sensitive, credit and solvency, and criminal record data to take special security measures, including controlling entry to processing premises, controlling who may read, copy, alter or transmit personal data, and logically separating health and sex life data, including genetic data, from other personal data.

What it requires

Scraping law1 instrument, 1 in force

Research summary (184 words)

Cabo Verde has no scraping-specific statute. Article 6 of the Cybercrime Law (Lei n.º 8/IX/2017, de 20 de Março) criminalises intentionally and without legal permission or authorization from the system's owner or another rights holder accessing a computer system in any way, which on a plain reading reaches unauthorised access to a system but not the ordinary reading of a public, unauthenticated page a system's own operator has made available.

Cabo Verde's Data Protection Law No. 133/V/2001 separately reaches personal data collected by any method, including scraping, under the privacy topic's seam rule rather than this one. A further named lead for this topic, the Código do Direito de Autor (Decreto-Legislativo n.º 1/2009 de 27 de Abril), and its database and text-and-data-mining provisions, has not been located.

The Assembleia Nacional's own compiled 2016-2017 legislation volume carries the Cybercrime Law's full text; the Boletim Oficial's digital kiosk (boe.incv.cv) requires a paid subscription to view a law's articles beyond its title and summary, and the ICT Policy Africa mirror of the Cybercrime Law returns a server error, with its only archived capture ending before Article 3.

Computer misuse

Cybercrime Law, Unauthorised Access to a Computer System

Lei n.º 8/IX/2017, art. 6.º (acesso ilícito), de 20 de Março (Lei do Cibercrime)Text of Lei n.º 8/IX/2017 de 20 de Março (Lei do Cibercrime)

In force. Binds public and private bodies.

What this law does

Article 6(1) punishes with imprisonment of up to one year or a fine of up to 120 days anyone who, intentionally and without legal permission or without being authorised for that purpose by the owner or another rights holder of the system or part of it, in any way accesses a computer system.

Article 6(2) punishes the same conduct where a person produces, sells, distributes, disseminates, or introduces into one or more computer systems a device, program, executable set of instructions, code, or other computer data intended to produce that unauthorised access.

Article 6(3) raises the penalty to up to three years' imprisonment or a fine where the access is achieved through violation of security rules, and Article 6(4) raises it to one to five years' imprisonment where the agent thereby learns a commercial or industrial secret or legally protected confidential data, or obtains a considerably high patrimonial benefit or advantage.

Article 6(5) makes an attempt punishable, and Article 6(6) makes criminal proceedings for the base offences under paragraphs 1, 3 and 5 dependent on a complaint. Article 2 defines a computer system as any device or interconnected set of devices carrying out automated processing of computer data, together with the network supporting communication between them and the data stored, processed, retrieved, or transmitted by them.

The Law was approved by the Assembleia Nacional on 25 January 2017, promulgated by the President of the Republic on 3 March 2017, and published in the Boletim Oficial of 20 March 2017; its own Article 33 provides that it enters into force 30 days after publication.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (398 words)

Cabo Verde has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of Decree-Law No. 1/2009 of April 27, 2009 (Decreto-Legislativo n.º 1/2009, de 27 de Abril de 2009, sobre a Revisão da Lei do Direito de Autor), which revised and replaced Law No. 101/III/90 of December 29, 1990, is the law reaching an aggregator's reproduction of news content.

Article 10(a) places news of the day and reports of different events given simply for information, however disclosed, entirely outside the Law's protected subject matter, so a bare news item is never a protected work regardless of who first reported it.

Article 62(1)(f) permits, without the author's authorization and without remuneration, citing short excerpts of another author's work, in written, sound, or visual form, where justified for scientific, critical, or didactic reasons or for information, as long as the excerpts are not so extensive as to lessen interest in the work.

Article 62(1)(c) separately permits reproducing works included in filmed or televised news reports, or works permanently exhibited in public places or in places where representatives of social communication bodies have access. Article 62(2) permits an author who reproduces his own articles or letters published in newspapers or periodicals in argument with another person to also reproduce the adversary's replies, binding the latter to the same right.

Neighbouring rights under the Act protect performers, producers of phonograms and videograms, and broadcasting organisations (Article 4) rather than news publishers, so there is no publisher-side right of the kind the European Union's Digital Single Market Directive Article 15 creates.

The Act protects a database as a compilation (Article 8(b)) rather than through a separate sui generis right, and Article 64(c) expressly excludes reproducing all or a significant part of a database from the private-use exception. No machine-readable text-and-data-mining opt-out mechanism is stated, and no reported Cabo Verdean decision applies the quotation or news-reporting exception to a systematic online news aggregator as opposed to a traditional press review.

Decree-Law No. 1/2009 was itself amended by Decree-Law No. 2/2017 of November 16, 2017, which WIPO Lex records as relating to the WIPO Performances and Phonograms Treaty, the Beijing Treaty on Audiovisual Performances, and the Marrakesh VIP Treaty; no English translation of that amendment is available, and its recorded subject matter (neighbouring rights and access for the print-disabled) does not reach the Title II free-use provisions this instrument records.

Snippet reproduction

Copyright Law Revision, News-Reporting and Quotation Exceptions

Decreto-Legislativo n.º 1/2009, de 27 de Abril de 2009 (Revisão da Lei do Direito de Autor), arts. 10.º, 62.ºOfficial English translation of Decree-Law No. 1/2009 of April 27

In force since 27 April 2009. Binds public and private bodies.

What this law does

Article 10(a) provides that news of the day and reports of different events given simply for information, however disclosed, may not be protected, placing bare news reporting entirely outside the Law's subject matter.

Article 62(1) permits, without authorization from the author and without compensation, several uses of works already lawfully published or disclosed, provided the authenticity and integrity of the title and the author's name are respected: alínea (c) covers reproduction of works included in news reports, filmed or televised, or of works permanently exhibited in public places or in places where representatives of social communication bodies have access; alínea (f) covers citation of short excerpts of another author's work, in written, audio, or visual form, when justified for scientific, critical or didactic reasons or for information, as long as those excerpts are not so extensive as to lessen interest in the work.

Article 62(2) separately permits an author who reproduces his own articles or letters published in newspapers or periodicals in argument with another person to also reproduce the replies of his adversary, binding the latter to the same right. Article 4 confines related (neighbouring) rights to performers, producers of phonograms and videograms, and broadcasting organisations, so the Law creates no press-publisher right.

Article 8(b) protects a database as a compilation where its selection or arrangement is an intellectual creation. Article 64(c) excludes reproduction of all or a significant part of a database from the private-use exception at Article 62(1)(l), rather than creating a separate sui generis database right. Article 139 revoked the prior copyright statute, Law No. 101/IV/90 of December 29, and Article 140 provides that the Law enters into force immediately.

The Law was published in the Boletim Oficial I Série No. 17 Supplement of April 27, 2009, the date WIPO Lex also records as the date of entry into force.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.