Skip to content

Evidence request lists

Angola Personal Data Protection Law (Law No. 22/11)

Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Awareness

AO-PDPL-23
Training and Awareness

Personnel processing personal data must receive training on Law 22/11 obligations.

Artefacts an auditor will ask for
  • Data-protection training records
Where this commonly fails
  • Staff untrained on data protection

CCTV

AO-PDPL-14
Video Surveillance and Location Data

Use of CCTV and location data is subject to proportionality, signage, retention limits and APD notification or authorisation.

Artefacts an auditor will ask for
  • CCTV policy, signage and retention limits
Where this commonly fails
  • CCTV without lawful basis or notice

Documentation

AO-PDPL-19
Records of Processing

Maintain documented records of processing activities to demonstrate compliance to the APD.

Artefacts an auditor will ask for
  • Register/records of processing activities
Where this commonly fails
  • No record of processing activities

Enforcement

AO-PDPL-20
APD Cooperation and Audits

Cooperate with APD inspections, provide requested information and implement corrective measures.

Artefacts an auditor will ask for
  • Cooperation with APD inspections
Where this commonly fails
  • Obstructing APD supervision

Incident Response

AO-PDPL-18
Breach Response

Controllers must respond to personal data breaches and may be required to notify the APD and affected individuals.

Artefacts an auditor will ask for
  • Breach detection, recording and notification procedure
Where this commonly fails
  • No breach response process

Legal Basis

AO-PDPL-3
Lawful Basis

Processing requires consent or another lawful basis such as contractual necessity, legal obligation, vital interest, public interest or legitimate interest.

Artefacts an auditor will ask for
  • Lawful-basis register
  • Consent records
Where this commonly fails
  • No legal basis for processing

Marketing

AO-PDPL-15
Direct Marketing and Cookies

Direct marketing requires consent with a clear opt-out mechanism; electronic tracking technologies require informed consent.

Artefacts an auditor will ask for
  • Marketing opt-out and cookie consent
Where this commonly fails
  • Marketing without consent/opt-out

Principles

AO-PDPL-2
General Processing Principles

Processing must be lawful, transparent, for specified and legitimate purposes, accurate, proportionate, and retained only as long as necessary.

Artefacts an auditor will ask for
  • Mapping of processing to the law's principles
  • Retention limits
Where this commonly fails
  • Excessive/indefinite processing

Processors

AO-PDPL-12
Processor Agreements

Engagement of processors requires a written contract specifying purposes, instructions, security and confidentiality.

Artefacts an auditor will ask for
  • Processor agreement imposing the law's duties
Where this commonly fails
  • Processor engaged without binding obligations

Registration

AO-PDPL-5
APD Notification and Authorisation

Processing operations must be notified to the Data Protection Agency (APD); certain categories require prior authorisation.

Artefacts an auditor will ask for
  • APD notification/authorisation records
Where this commonly fails
  • Processing without required APD notification

Rights

AO-PDPL-7
Right of Access

Data subjects have a right to obtain confirmation, copy and information on the processing of their data.

Artefacts an auditor will ask for
  • Access-request handling procedure
Where this commonly fails
  • No access mechanism
AO-PDPL-8
Right of Rectification, Erasure and Blocking

Data subjects may have inaccurate data corrected, excessive or unlawful data erased or blocked.

Artefacts an auditor will ask for
  • Rectification/erasure/blocking process
Where this commonly fails
  • Inaccurate data not corrected
AO-PDPL-9
Right to Object

Data subjects can object to processing including direct marketing and to decisions based on automated processing.

Artefacts an auditor will ask for
  • Objection-handling process
  • Automated-decision safeguards
Where this commonly fails
  • No objection mechanism

Sanctions

AO-PDPL-21
Sanctions and Liability

Violations may result in administrative fines, criminal penalties and civil liability for damages.

Artefacts an auditor will ask for
  • Awareness of sanction/liability exposure
Where this commonly fails
  • Not applicable as a control objective; enforcement

Scope

AO-PDPL-1
Scope and Application

The law applies to processing of personal data in Angola or by controllers using means located in Angola.

Artefacts an auditor will ask for
  • Scoping determination under the law
Where this commonly fails
  • Processing wrongly treated as out of scope

Sectoral

AO-PDPL-22
Sectoral Rules Health and Financial

Processing of health, financial and telecommunications data is subject to sector-specific rules and supervisory oversight.

Artefacts an auditor will ask for
  • Sector-specific data-protection controls (health/financial)
Where this commonly fails
  • Sectoral obligations unmet

Security

AO-PDPL-10
Security Measures

Controllers and processors must implement technical and organisational security measures appropriate to the risk.

Artefacts an auditor will ask for
  • Technical & organisational security measures
Where this commonly fails
  • Inadequate security for the risk
AO-PDPL-11
Confidentiality Obligations

Persons processing personal data are bound by confidentiality obligations that survive employment.

Artefacts an auditor will ask for
  • Confidentiality undertakings for staff handling PI
Where this commonly fails
  • Disclosure by staff bound to secrecy

Special Categories

AO-PDPL-17
Children's Data

Processing of minors' data requires consent of the legal representative and age-appropriate safeguards.

Artefacts an auditor will ask for
  • Age-verification / parental-consent controls
Where this commonly fails
  • Children's data processed without safeguards
AO-PDPL-4
Sensitive Data

Processing of sensitive data (philosophical, political beliefs, party affiliation, religion, private life, ethnicity, health, sexual life, genetic data) requires explicit consent or APD authorisation.

Artefacts an auditor will ask for
  • Sensitive-data conditions
  • APD authorisation where required
Where this commonly fails
  • Sensitive data processed without a lawful condition

Transfers

AO-PDPL-13
Cross-Border Transfers

Transfers outside Angola require APD authorisation unless the recipient country provides adequate protection or specific derogations apply.

Artefacts an auditor will ask for
  • Transfer assessment (adequacy/APD authorisation)
Where this commonly fails
  • Transfer without required safeguards/authorisation

Transparency

AO-PDPL-6
Information to Data Subjects

Data subjects must be informed at collection of the controller, purposes, recipients, retention and their rights.

Artefacts an auditor will ask for
  • Privacy notice to data subjects
Where this commonly fails
  • Data subjects not informed

Workplace

AO-PDPL-16
Employee Monitoring

Employer monitoring of employee communications and activity is restricted, requires notice, proportionality and APD authorisation in defined cases.

Artefacts an auditor will ask for
  • Proportionality assessment for workplace monitoring
Where this commonly fails
  • Excessive employee monitoring
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.