Legal compliance
Compliance for your organization starts in Angola — and goes further if you need it to.
Most compliance guides start with GDPR. Ours doesn't: we start with what always applies to an organization operating in Angola, then look at Europe — and at when that exposure is yours too.
First, what applies in Angola
The Angolan legal framework
This applies to any organization that processes personal data or operates digital infrastructure in Angola — regardless of any link to Europe.
Law No. 22/11, of June 17
Personal Data Protection Law
Regulates the collection, processing, and retention of personal data in Angola. It is supervised by the Data Protection Agency (APD) — an active regulator: it fined five companies in 2024 and currently has a public consultation open to revise the law itself.
Law No. 7/17, of February 16
Protection of Networks and Information Systems
Establishes the legal regime for protecting Angola's cyberspace — response to computer attacks, data theft, and information security incidents.
Presidential Decree No. 256/25, of December 2025
National Cybersecurity Strategy
Approves the National Cybersecurity Strategy and provides for a revision of Law No. 7/17. A new cybersecurity bill was reviewed by the Council of Ministers in October 2025 — this framework is, right now, in motion.
The APD is an active regulator, not a law on paper: the 2024 fines and the ongoing public consultation are a sign of real enforcement, not just words.
Then, if you have European exposure
GDPR and NIS2, explained from first principles
Why would a company based in Angola need to care about European law? For two reasons, neither of them hypothetical:
- If your organization has an operation, customers, or suppliers in the European Union, that part of your activity falls under GDPR and, in some sectors, NIS2 — even while headquartered in Angola.
- GDPR has become the de facto standard that the revision of Law No. 22/11 tends to follow; NIS2, in turn, is the clearest map of what Angola's National Cybersecurity Strategy is building. Understanding both helps anticipate where Angolan law is heading.
What GDPR is
The General Data Protection Regulation — Regulation (EU) 2016/679, in force since May 2018 — is the EU's personal data protection law. It applies to any organization, wherever it is based, that processes the personal data of people in the EU, or that has an operation established there.
What NIS2 is
Directive (EU) 2022/2555, known as NIS2, requires entities in essential and important sectors — energy, health, transport, digital infrastructure, and others — established in the European Union to adopt cybersecurity risk management measures and notify incidents to national authorities.
Scope self-assessment
Three questions, no personal data saved — the result stays on this screen.
An indicative self-assessment, not legal advice. No answer is saved — the result stays on this screen.
Want to confirm the result with a real assessment?
Talk to our team for a scope assessment and an action plan with realistic timelines.
Book a compliance assessment