What Is Personal Data Protection Law, Law No. 22/11 of 17 June 2011?
In the 28 August 2026 review, Angola’s operative general statute remains Law No. 22/11 of 17 June 2011, the Personal Data Protection Law. It entered into force on publication, remains listed in the APD’s current legislation inventory, and continues to be applied in APD enforcement notices. No enacted amending or repealing instrument was located in the official-source review; the APD modernization effort is labeled only as a "Projecto de Revisão." The APD was created by Article 44 of Law No. 22/11, received an organic statute in 2016, and began operating on 8 October 2019 according to its institutional history. The law provides information, access, rectification, updating, erasure, blocking, objection, automated-decision protections, and administrative and judicial remedies. The statute has important exceptions for personal or domestic processing, State security, secrecy of justice, specified military processing, journalism, art, literature, research, and criminal investigations. No fixed deadline for filing an individual APD complaint, for APD investigation or decision, or for an access request was located.
At a glance
- Full name
- Personal Data Protection Law, Law No. 22/11 of 17 June 2011
- Short code
- Law No. 22/11
- Jurisdiction
- Angola
- Enacted
- 2011
- Last major update
- No enacted amending or repealing instrument was located; the APD modernization effort remains labeled "Projecto de Revisão," and APD enforcement notices in 2026 continue to apply Law No. 22/11
- Regulator
- Agência de Protecção de Dados (APD)
- Private right of action
- Yes
- Statutory citation
- Law No. 22/11 of 17 June 2011, Personal Data Protection Law
Scope, who Law No. 22/11 covers
Protected data
Data subject rights
Right to information about the controller’s identity and address, processing purposes, recipients, mandatory or optional responses, consequences, and available rights
Right to notice of indirect collection at registration or within 30 days
Right of access to confirmation of processing, purposes, categories, recipients, specific data, and available source information
Right to rectification, updating, erasure, and blocking where data are unlawful, incomplete, or inaccurate
Right to free objection at any time for compelling legitimate reasons related to the person’s situation
Protection against decisions based exclusively on profiling-type automated processing that legally or significantly affects the person
Right to complain to APD and to pursue administrative or judicial remedies
No express standalone portability or GDPR-style restriction right was established in the reviewed statute and APD materials
Notable features
Angola’s law combines a broad 2011 statutory rights framework with an APD that began operating in 2019 and continues enforcement in 2026. The statute does not establish an express standalone portability or GDPR-style restriction right in the reviewed materials. Credit and solvency processing, sensitive data, public sources, and State-security or criminal-investigation contexts have distinct rules and limits.
Enforcement & penalties
Regulator: Agência de Protecção de Dados (APD)
Penalties: Law No. 22/11 provides contravention fines of USD 75,000-150,000 equivalent in national currency for specified breaches involving sensitive data, security, notification, and APD-order obligations, and USD 65,000-130,000 for other breaches of core processing principles, consent requirements, and specified communications or interconnection rules. For legal persons, the statutory limits are aggravated threefold: USD 225,000-450,000 and USD 195,000-390,000. Crimes include imprisonment of 3-18 months for specified authorization, false-information, unlawful-interconnection, and non-compliance conduct; 6 months-2 years for unauthorized access; 18 months-3 years for data alteration or destruction. Published APD outcomes include USD-equivalent fines of 525,000 against BPC, 225,000 against ENDE, 150,000 against MAXAM, and 115,000 against Lizíria/Hotel Diamante; these are case outcomes, not single-offense tariff figures.
Private right of action: The law preserves administrative and judicial remedies and provides judicial compensation for damage. A person may first exercise rights directly with the controller and then complain to APD if there is non-compliance. No fixed deadline for filing an individual APD complaint, for an APD investigation or decision, or for an access request was located.
Relevance to data brokers
The closest data-broker analogue is the regulated Central Privada de Informação de Crédito, which may collect credit, specified judicial and bankruptcy information, and public information from company, intellectual-property, commercial, property, and court records. Consumers have access and contest-related routes, but no dedicated CPIC deletion form or fixed deletion deadline was located. A named general commercial data-broker or public-record takedown route was not located; the available route is the general controller request followed, if necessary, by an APD complaint.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
What data-protection law is currently in force in Angola?+
Law No. 22/11 of 17 June 2011 remains the operative general statute in the 28 August 2026 review. No enacted amending or repealing instrument was located, and the APD modernization effort is still labeled "Projecto de Revisão."
What rights does Angola’s data-protection law provide?+
The law provides information, access, rectification, updating, erasure, blocking, objection, direct-marketing objection, automated-decision protections, APD complaints, judicial remedies, and compensation. The reviewed materials do not establish an express standalone portability or GDPR-style restriction right.
Can a credit-information bureau or data broker be required to delete data in Angola?+
The CPIC framework supports access and contest-related rights for credit information, and the general law provides erasure and blocking rights where statutory conditions apply. However, no dedicated CPIC deletion form, fixed deletion deadline, or named general commercial data-broker takedown route was located.
Official sources & citations
Other international privacy regimes
Law No. 22/11 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
