Skip to content

Legal compliance

Compliance for your organization starts in Angola — and goes further if you need it to.

Most compliance guides start with GDPR. Ours doesn't: we start with what always applies to an organization operating in Angola, then look at Europe — and at when that exposure is yours too.

First, what applies in Angola

The Angolan legal framework

This applies to any organization that processes personal data or operates digital infrastructure in Angola — regardless of any link to Europe.

  1. Law No. 22/11, of June 17

    Personal Data Protection Law

    Regulates the collection, processing, and retention of personal data in Angola. It is supervised by the Data Protection Agency (APD) — an active regulator: it fined five companies in 2024 and currently has a public consultation open to revise the law itself.

  2. Law No. 7/17, of February 16

    Protection of Networks and Information Systems

    Establishes the legal regime for protecting Angola's cyberspace — response to computer attacks, data theft, and information security incidents.

  3. Presidential Decree No. 256/25, of December 2025

    National Cybersecurity Strategy

    Approves the National Cybersecurity Strategy and provides for a revision of Law No. 7/17. A new cybersecurity bill was reviewed by the Council of Ministers in October 2025 — this framework is, right now, in motion.

The APD is an active regulator, not a law on paper: the 2024 fines and the ongoing public consultation are a sign of real enforcement, not just words.

Then, if you have European exposure

GDPR and NIS2, explained from first principles

Why would a company based in Angola need to care about European law? For two reasons, neither of them hypothetical:

  • If your organization has an operation, customers, or suppliers in the European Union, that part of your activity falls under GDPR and, in some sectors, NIS2 — even while headquartered in Angola.
  • GDPR has become the de facto standard that the revision of Law No. 22/11 tends to follow; NIS2, in turn, is the clearest map of what Angola's National Cybersecurity Strategy is building. Understanding both helps anticipate where Angolan law is heading.

What GDPR is

The General Data Protection Regulation — Regulation (EU) 2016/679, in force since May 2018 — is the EU's personal data protection law. It applies to any organization, wherever it is based, that processes the personal data of people in the EU, or that has an operation established there.

What NIS2 is

Directive (EU) 2022/2555, known as NIS2, requires entities in essential and important sectors — energy, health, transport, digital infrastructure, and others — established in the European Union to adopt cybersecurity risk management measures and notify incidents to national authorities.

Scope self-assessment

Three questions, no personal data saved — the result stays on this screen.

Does your organization operate in one of these sectors — public administration, banking or finance, energy, health, water, transport, telecommunications — or provide digital infrastructure (cloud, data center, DNS)?
Does your organization have 50 or more employees, or annual turnover or balance sheet above €10 million?
Does your organization process personal data belonging to customers, users, or employees?

An indicative self-assessment, not legal advice. No answer is saved — the result stays on this screen.

Want to confirm the result with a real assessment?

Talk to our team for a scope assessment and an action plan with realistic timelines.

Book a compliance assessment