§ Dossier · CENTRAL AFRICA · updated 22 July 2026
Equatorial Guinea
- Regulator
- Órgano Rector for the Protection of Personal Data (provided for; not operational)
- Law
- Law No. 1/2016 on the Protection of Personal Data ↗
- Status
- Law in force, enforcement not found
- Authority
- Órgano Rector for the Protection of Personal Data (provided for; not operational)
in force
DP law status
Law No. 1/2016 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 1/2016 on the Protection of Personal Data IN FORCE
commenced 2016 (exact promulgation date to confirm against the archived text) · Official full text ↗
- Scope
- Any information, testimony or review concerning a specifically identified or identifiable person (art. 4), in public and private personal-data files; the law follows the Spanish (LOPD 1999) model.
- Key obligations
- Registration of public and private personal-data files with the General Data Protection Registry under the governing body's Technical Secretariat (art. 33); Express authorisation of the data subject required for processing data touching conscience, political affiliation/ideology, health, sex life, race, tribe or religion: unauthorised processing is a major infringement (art. 41(d)); Tiered infringement system (minor/major/severe, arts. 39-41) enforced through administrative procedure (art. 45); Disciplinary proceedings mandated for infringements in public files
- DPO required
- No: no DPO figure; supervision runs through the governing body's Technical Secretariat.
- Registration
- Yes: file-based registration (creation, modification and suppression of personal-data files recorded in authorised books) with the General Data Protection Registry (art. 33).
- Cross-border transfers
- Chapter III (arts. 27-28), verified from the archived scan 2026-07-11: personal data may not be communicated, ceded or transferred to countries that do not provide legal protection EQUIVALENT to this law, except with PRIOR AUTHORISATION of the Organo Rector (art. 27(1)); destination-country protection assessed on all transfer circumstances - data nature, purpose/duration, origin and final destination, law in force and security measures (art. 27(2)). Exceptions (art. 28): international treaties, unequivocal consent, international judicial assistance/legal claims/medical purposes, public interest (especially tax and customs), monetary transfers under their own legislation, legitimate-interest requests from a public register, and contract necessity (including pre-contractual measures and third-party contracts in the data subject's interest). Unauthorised transfer to a non-adequate country is a very grave infraction (art. 41(h)).
- Breach notification
- No mandatory breach-notification duty; failures of the law's notification formalities are graded minor (data obtained from the subject, art. 39) or major (data not obtained from the subject, art. 40).
- Penalties
- Three-tier infraction regime (arts. 38-44), fines image-verified 2026-07-11: minor infractions (art. 39) - admonition, written warning, or fine of FCFA 200,000-500,000; grave infractions (art. 40) - fine of FCFA 500,001-5,000,000, suspension of the file/processing activity, or sealing of premises for up to 15 working days; very grave infractions (art. 41, incl. fraudulent collection, sensitive-data processing without express written consent, obstruction, and unauthorised international transfer to non-adequate countries) - fine of FCFA 5,000,001-15,000,000, equipment seizure, definitive closure, disqualification for one year or definitively, and revocation of the authorisation/registration (art. 42). Graduation criteria in art. 43. The two-step sanctioning procedure (sanctioning organ resolves, higher authority verifies) is arts. 44-45. All fine figures re-read from the page images (pp. 38-39 of the scan; contract v1.11 rule). No authority has ever been constituted, so none has been applied.
- Authority
- Órgano Rector for the Protection of Personal Data (provided for; never operational)
Verified 2026-07-11
The regulator
- Authority
- Órgano Rector for the Protection of Personal Data (provided for; not operational)
- Operational
- No
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Equatorial Guinea
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.