Research hub / Cape Verde
§ Dossier · WEST AFRICA · updated 22 July 2026

Cape Verde

Regulator
Comissão Nacional de Proteção de Dados (CNPD) ↗
Law
Data Protection Law (Lei No. 133/V/2001, as amended by Lei No. 121/IX/2021) ↗
Status
Enforces without publishing
Authority
Comissão Nacional de Proteção de Dados (CNPD), established 2015
in force
DP law status
Data Protection Law (Lei No. 133/V/2001, as amended by Lei No. 121/IX/2021)
Yes
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Data Protection Law (Lei No. 133/V/2001 of 22 January 2001, as amended by Lei No. 121/IX/2021) IN FORCE

commenced 2001-01-22 (2021 amendment modernised the regime) · Official full text ↗

Scope
Any information, regardless of nature or medium, relating to an identifiable natural person, processed by public or private controllers; the sensitive-data list notably includes 'private life' as its own category alongside convictions, ethnicity, health, sex life, genetic and biometric data.
Key obligations
Prior registration/notification with the CNPD before processing, with written prior authorisation for sensitive data, creditworthiness/solvency data, interconnection, and purpose changes; GDPR-style DPO triggers introduced by the 2021 amendment (public bodies; large-scale regular and systematic monitoring; large-scale sensitive or offence data); 72-hour breach notification to the CNPD; Civil liability for pecuniary and non-pecuniary loss from misuse of personal data
DPO required
Yes, in defined cases: public authorities/bodies (except courts acting judicially), and controllers/processors whose core activities involve large-scale regular and systematic monitoring or large-scale processing of sensitive or offence data.
Registration
Yes: prior authorisation or registration with the CNPD depending on the data category; written authorisation for sensitive data, solvency data, interconnection, and secondary purposes.
Cross-border transfers
Transfers abroad only to countries ensuring adequate protection, with the CNPD deciding adequacy (art. 35 as renumbered by Law 121/IX/2021); non-adequate destinations may be permitted by the CNPD on unequivocal consent or necessity grounds (contract, important public interest/legal claims, vital interests, public register), or authorised on sufficient guarantees, notably adequate contractual clauses (art. 36); state-security transfers ride specific laws/treaties (art. 36(3)). (Verified from the archived B.O. texts 2026-07-11, S27.)
Breach notification
Notify the CNPD no later than 72 hours after becoming aware of a breach, unless the breach poses no risk to data subjects' rights, freedoms and guarantees.
Penalties
Criminal offences (processing without notification/authorisation, false information in filings, misuse, unauthorised interconnection, unlawful access, refusing to stop processing): up to 2 years' imprisonment or a fine of up to 240 day-fines; ancillary sanctions include temporary or permanent processing bans, publication of the sentence, and public warning or reproach.
Authority
Comissão Nacional de Proteção de Dados (CNPD)

Verified 2026-07-10

The regulator

Authority
Comissão Nacional de Proteção de Dados (CNPD)
Website
https://www.cnpd.cv ↗
Established
2015
Operational
Yes
Enforcing
Yes
Publishes decisions
No

Enforcement record

Enforcement activity is documented for this jurisdiction, but the authority does not publish its decisions. The tracker records only what can be verified against a public document, so no decision pages exist here; the publication gap itself is measured in Enforcement in the Dark.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Cape Verde

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.