Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
LPDP
Angola's 2011 data protection law subjects all personal data processing to prior notification to or authorisation from the APD, with special regimes for sensitive data and international transfers. Enforcement has hardened since the APD became operational in 2019.
Law No. 22/11 of 17 June 2011 regulates personal data protection in Angola alongside the Electronic Communications Law (23/11) and the Information Systems Protection Law (7/17). It applies to natural and juristic persons, public and private, and requires prior express consent plus prior notice to the APD for ordinary processing, and prior APD authorisation with a legal enabling provision for sensitive data (beliefs, politics, religion, private life, ethnicity, health, sex life, genetic data). International transfers to countries with adequate protection require prior notification to the APD; transfers to non-adequate countries require prior authorisation, including intra-group and cloud transfers.
Although the law dates from 2011, the APD only became operational after its board was appointed in September 2019 (Presidential Decree 277/2019), and its organic statute was set by Presidential Decree 214/2016. Enforcement has since hardened: in deliberations 003/2026 and 004/2026 of 18 June 2026, the APD fined one company the kwanza equivalent of USD 505,000 for processing clients' data and storing data in a foreign cloud without notification or authorisation, and another the equivalent of USD 112,000 for inadequate security measures and failure to notify. A draft revision of Law 22/11 underwent public consultation from 17 March to 17 April 2025. There is no DPO requirement under the current law, though the APD has announced a forthcoming DPO registration scheme.
Entities must notify the APD before processing personal data, or obtain prior authorisation depending on the data type and purpose; skipping this formality has drawn fines up to the kwanza equivalent of USD 505,000.
Processing sensitive data (beliefs, politics, religion, private life, ethnicity, health, sex life, genetic data) requires an enabling legal provision and prior APD authorisation.
Transfers to adequate countries require prior APD notification; transfers to non-adequate countries require prior APD authorisation. Storing customer data in a foreign cloud without authorisation has been sanctioned.
Controllers must implement technical and organisational measures against destruction, loss, alteration, unauthorised disclosure or access, proportionate to the risks and the nature of the data.
Read more
Anove scans your stack against LPDP and 260+ other frameworks in minutes.
Processing must respect transparency, legality, good faith and proportionality; data must be used only for the collection purpose and not kept longer than necessary.