Angola Personal Data Protection Law (Law No. 22/11)
Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Awareness
Personnel processing personal data must receive training on Law 22/11 obligations.
- Data-protection training records
- Staff untrained on data protection
CCTV
Use of CCTV and location data is subject to proportionality, signage, retention limits and APD notification or authorisation.
- CCTV policy, signage and retention limits
- CCTV without lawful basis or notice
Documentation
Maintain documented records of processing activities to demonstrate compliance to the APD.
- Register/records of processing activities
- No record of processing activities
Enforcement
Cooperate with APD inspections, provide requested information and implement corrective measures.
- Cooperation with APD inspections
- Obstructing APD supervision
Incident Response
Controllers must respond to personal data breaches and may be required to notify the APD and affected individuals.
- Breach detection, recording and notification procedure
- No breach response process
Legal Basis
Processing requires consent or another lawful basis such as contractual necessity, legal obligation, vital interest, public interest or legitimate interest.
- Lawful-basis register
- Consent records
- No legal basis for processing
Marketing
Direct marketing requires consent with a clear opt-out mechanism; electronic tracking technologies require informed consent.
- Marketing opt-out and cookie consent
- Marketing without consent/opt-out
Principles
Processing must be lawful, transparent, for specified and legitimate purposes, accurate, proportionate, and retained only as long as necessary.
- Mapping of processing to the law's principles
- Retention limits
- Excessive/indefinite processing
Processors
Engagement of processors requires a written contract specifying purposes, instructions, security and confidentiality.
- Processor agreement imposing the law's duties
- Processor engaged without binding obligations
Registration
Processing operations must be notified to the Data Protection Agency (APD); certain categories require prior authorisation.
- APD notification/authorisation records
- Processing without required APD notification
Rights
Data subjects have a right to obtain confirmation, copy and information on the processing of their data.
- Access-request handling procedure
- No access mechanism
Data subjects may have inaccurate data corrected, excessive or unlawful data erased or blocked.
- Rectification/erasure/blocking process
- Inaccurate data not corrected
Data subjects can object to processing including direct marketing and to decisions based on automated processing.
- Objection-handling process
- Automated-decision safeguards
- No objection mechanism
Sanctions
Violations may result in administrative fines, criminal penalties and civil liability for damages.
- Awareness of sanction/liability exposure
- Not applicable as a control objective; enforcement
Scope
The law applies to processing of personal data in Angola or by controllers using means located in Angola.
- Scoping determination under the law
- Processing wrongly treated as out of scope
Sectoral
Processing of health, financial and telecommunications data is subject to sector-specific rules and supervisory oversight.
- Sector-specific data-protection controls (health/financial)
- Sectoral obligations unmet
Security
Controllers and processors must implement technical and organisational security measures appropriate to the risk.
- Technical & organisational security measures
- Inadequate security for the risk
Persons processing personal data are bound by confidentiality obligations that survive employment.
- Confidentiality undertakings for staff handling PI
- Disclosure by staff bound to secrecy
Special Categories
Processing of minors' data requires consent of the legal representative and age-appropriate safeguards.
- Age-verification / parental-consent controls
- Children's data processed without safeguards
Processing of sensitive data (philosophical, political beliefs, party affiliation, religion, private life, ethnicity, health, sexual life, genetic data) requires explicit consent or APD authorisation.
- Sensitive-data conditions
- APD authorisation where required
- Sensitive data processed without a lawful condition
Transfers
Transfers outside Angola require APD authorisation unless the recipient country provides adequate protection or specific derogations apply.
- Transfer assessment (adequacy/APD authorisation)
- Transfer without required safeguards/authorisation
Transparency
Data subjects must be informed at collection of the controller, purposes, recipients, retention and their rights.
- Privacy notice to data subjects
- Data subjects not informed
Workplace
Employer monitoring of employee communications and activity is restricted, requires notice, proportionality and APD authorisation in defined cases.
- Proportionality assessment for workplace monitoring
- Excessive employee monitoring
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.