What Is Lei n.º 133/V/2001, de 22 de Janeiro, as amended by Lei n.º 41/VIII/2013 and Lei n.º 121/IX/2021?
Cabo Verde’s operative general privacy statute is Lei n.º 133/V/2001, de 22 de Janeiro, as amended by Lei n.º 41/VIII/2013 and Lei n.º 121/IX/2021. The 2013 amendment substantially revised and republished the statute, while the 2021 amendment added modern concepts and obligations including extraterritorial coverage, consent withdrawal, erasure, restriction, portability, breach notification, privacy by design, data-protection officers, and revised criminal provisions. A June 2026 CNPD internal regulation expressly identifies the statute as amended by both instruments. No later amending act was located in the reviewed official Boletim Oficial and CNPD materials. The framework provides information, access, rectification, erasure, restriction, portability, objection, consent withdrawal, automated-decision safeguards, judicial recourse, and compensation. The CNPD may investigate, issue binding decisions, order blocking or erasure, prohibit processing, apply fines and ancillary sanctions, and refer criminal matters to the Public Prosecutor. No fixed deadline for a general complaint or ordinary rights request was located.
At a glance
- Full name
- Lei n.º 133/V/2001, de 22 de Janeiro, as amended by Lei n.º 41/VIII/2013 and Lei n.º 121/IX/2021
- Short code
- Lei n.º 133/V/2001
- Jurisdiction
- Cabo Verde
- Enacted
- 2001
- Last major update
- Substantially revised and republished by Lei n.º 41/VIII/2013; amended and republished by Lei n.º 121/IX/2021, which entered into force 30 days after publication; no later amending act was located
- Regulator
- Comissão Nacional de Protecção de Dados (CNPD)
- Private right of action
- Yes
Scope, who Lei n.º 133/V/2001 covers
Protected data
Data subject rights
Right to information about the controller and representative, DPO where applicable, data categories, purposes and legal basis, recipients, mandatory or optional collection, consequences of non-provision, and rights
Right to access confirmation, purposes, categories, recipients, a copy of the data, intelligible data, available source information, and the logic behind automated decisions or profiling
Right to rectification and completion of inaccurate or incomplete data
Right to erasure or destruction where data are no longer necessary, consent is withdrawn without another legal basis, justified objection succeeds, or processing was unlawful
Right to restriction where accuracy is contested, processing is unlawful but erasure is opposed, data are needed for legal claims, or objection is pending
Right to portability in a structured, commonly used, machine-readable format where processing is automated and based on consent or contract
Right to object on compelling legitimate grounds related to the subject’s situation
Free right to object to direct marketing or prospecting and to first disclosure to third parties for those purposes
Right to withdraw consent at any time, easily and without detriment, without affecting prior lawful processing
Right not to be subject to a decision producing legal or similarly significant effects based exclusively on automated processing, including profiling, subject to statutory exceptions
Right to court recourse for statutory-rights violations and compensation for injury
Notable features
The 2021 amendment modernised the framework with extraterritorial coverage, consent withdrawal, erasure, restriction, portability, breach notification, privacy by design, data-protection officers, and revised criminal provisions. The CNPD has broad investigative and corrective powers, but no fixed general complaint-resolution or ordinary rights-response deadline was located.
Enforcement & penalties
Regulator: Comissão Nacional de Protecção de Dados (CNPD)
Penalties: Administrative fines for notification or procedural failures range from CVE 50,000–500,000 for an individual and CVE 300,000–3,000,000 for a legal or non-person entity; the limits double for processing subject to prior CNPD control. Other administrative offences range from CVE 100,000–1,000,000, with limits doubling for specified failures. Non-compliance with an individualized CNPD decision may attract a compulsory daily sanction of CVE 5,000 per day for an individual and CVE 10,000 per day for a legal entity. Criminal penalties vary by offence and include imprisonment up to 1 or 2 years or fines up to 120 or 240 days; unauthorised disclosure by a person bound by professional secrecy carries 6 months to 3 years’ imprisonment or an 80–200 days’ fine.
Private right of action: Court recourse is available for statutory-rights violations, and an injured person may claim compensation. CNPD decisions may be challenged administratively or before the competent courts. No fixed compensation amount was located.
Relevance to data brokers
A broker may use the generic controller-facing access, rectification, erasure, restriction, and objection routes, followed by a CNPD complaint. CNPD forms reference credit-risk assessment, marketing, consumer profiling, and public-register-based transfers. Not located: a Cabo Verde data-broker-specific complaint, deletion, suppression, opt-out registry, or public-record-specific removal procedure.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
What privacy rights exist in Cabo Verde?+
The current framework provides information, access, rectification, erasure, restriction, portability, objection, consent withdrawal, direct-marketing objection, automated-decision safeguards, court recourse, and compensation, subject to statutory exceptions.
Is there a fixed deadline for a Cabo Verde privacy complaint?+
No fixed deadline located: no statutory deadline was located for filing a CNPD complaint, for the CNPD to decide a general complaint, or for a controller to answer an ordinary rights request. A qualifying personal-data breach must generally be notified to the CNPD within 72 hours.
Does Cabo Verde have a data-broker deletion route?+
Not located: no Cabo Verde data-broker-specific complaint, deletion, suppression, opt-out registry, or public-record-specific removal procedure was located in the reviewed official primary sources.
Official sources & citations
Other international privacy regimes
Lei n.º 133/V/2001 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
