§ Dossier · WEST AFRICA · updated 22 July 2026
in force
DP law status
Data Protection Law (Lei No. 133/V/2001, as amended by Lei No. 121/IX/2021)
Yes
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Data Protection Law (Lei No. 133/V/2001 of 22 January 2001, as amended by Lei No. 121/IX/2021) IN FORCE
commenced 2001-01-22 (2021 amendment modernised the regime) · Official full text ↗
- Scope
- Any information, regardless of nature or medium, relating to an identifiable natural person, processed by public or private controllers; the sensitive-data list notably includes 'private life' as its own category alongside convictions, ethnicity, health, sex life, genetic and biometric data.
- Key obligations
- Prior registration/notification with the CNPD before processing, with written prior authorisation for sensitive data, creditworthiness/solvency data, interconnection, and purpose changes; GDPR-style DPO triggers introduced by the 2021 amendment (public bodies; large-scale regular and systematic monitoring; large-scale sensitive or offence data); 72-hour breach notification to the CNPD; Civil liability for pecuniary and non-pecuniary loss from misuse of personal data
- DPO required
- Yes, in defined cases: public authorities/bodies (except courts acting judicially), and controllers/processors whose core activities involve large-scale regular and systematic monitoring or large-scale processing of sensitive or offence data.
- Registration
- Yes: prior authorisation or registration with the CNPD depending on the data category; written authorisation for sensitive data, solvency data, interconnection, and secondary purposes.
- Cross-border transfers
- Transfers abroad only to countries ensuring adequate protection, with the CNPD deciding adequacy (art. 35 as renumbered by Law 121/IX/2021); non-adequate destinations may be permitted by the CNPD on unequivocal consent or necessity grounds (contract, important public interest/legal claims, vital interests, public register), or authorised on sufficient guarantees, notably adequate contractual clauses (art. 36); state-security transfers ride specific laws/treaties (art. 36(3)). (Verified from the archived B.O. texts 2026-07-11, S27.)
- Breach notification
- Notify the CNPD no later than 72 hours after becoming aware of a breach, unless the breach poses no risk to data subjects' rights, freedoms and guarantees.
- Penalties
- Criminal offences (processing without notification/authorisation, false information in filings, misuse, unauthorised interconnection, unlawful access, refusing to stop processing): up to 2 years' imprisonment or a fine of up to 240 day-fines; ancillary sanctions include temporary or permanent processing bans, publication of the sentence, and public warning or reproach.
- Authority
- Comissão Nacional de Proteção de Dados (CNPD)
Verified 2026-07-10
The regulator
- Authority
- Comissão Nacional de Proteção de Dados (CNPD)
- Website
- https://www.cnpd.cv ↗
- Established
- 2015
- Operational
- Yes
- Enforcing
- Yes
- Publishes decisions
- No
Enforcement record
Enforcement activity is documented for this jurisdiction, but the authority does not publish its decisions. The tracker records only what can be verified against a public document, so no decision pages exist here; the publication gap itself is measured in Enforcement in the Dark.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Cape Verde
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.