Research hub / São Tomé and Príncipe
§ Dossier · CENTRAL AFRICA · updated 22 July 2026

São Tomé and Príncipe

Regulator
Agência Nacional de Protecção de Dados Pessoais (ANPDP) ↗
Law
Law No. 3/2016 on the Protection of Personal Data ↗
Status
Law in force, enforcement not found
Authority
Agência Nacional de Protecção de Dados Pessoais (ANPDP), established 2019
in force
DP law status
Law No. 3/2016 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Law No. 3/2016 on the Protection of Personal Data (Diário da República No. 39, 10 May 2016) IN FORCE

commenced 2016-05-10 (Diário da República publication; adopted 15 February 2016, promulgated 18 March 2016) · Official full text ↗

Scope
Processing by controllers seated in São Tomé and Príncipe, in the context of an establishment there, or abroad where São-Tomean law applies via international law; foreign controllers using means in the territory must appoint a local representative notified to the ANPDP (art. 4); personal/domestic processing excluded unless systematically communicated or disseminated.
Key obligations
Written notification to the ANPDP at least eight days before starting any wholly or partly automated processing (art. 21); ANPDP authorisation for sensitive-data processing on important-public-interest grounds (art. 8) and for file interconnection not provided for by law (arts. 17, 22); Portuguese-family sensitive-data prohibition (art. 7): philosophical/political convictions, political or union membership, religious faith, PRIVATE LIFE, racial/ethnic origin, health, sex life and genetic data: processable only with non-discrimination guarantees; Detailed security-measures catalogue (entry, access, transmission and input controls); public register of notified/authorised processing at the ANPDP (art. 25)
DPO required
No: the law predates the DPO model; foreign controllers must instead designate a local representative (art. 4).
Registration
Yes: prior written notification to the ANPDP (8-day lead, art. 21), with authorisation regimes for sensitive data and interconnection; filings must disclose planned third-country transfers (art. 23).
Cross-border transfers
Transfers outside the territory only where the destination ensures an adequate level of protection, assessed by the ANPDP against the transfer's circumstances (art. 19); non-adequate destinations require notification to the ANPDP plus the data subject's unequivocal authorisation or contract/pre-contract necessity and similar derogations (art. 20).
Breach notification
No breach-notification duty: the law follows the pre-GDPR Portuguese model; third parties who received data must be notified of rectification, erasure or blocking (art. 12-family duty).
Penalties
The law carries its own sanctions regime (contraordenações and crimes in the Portuguese tradition) plus referral to sanctions in other laws; specific quanta not yet verified: confirm against the archived official text (pages at the sanction chapters) before quoting figures.
Authority
Agência Nacional de Protecção de Dados Pessoais (ANPDP)

Verified 2026-07-07

The regulator

Authority
Agência Nacional de Protecção de Dados Pessoais (ANPDP)
Website
https://anpdp.st ↗
Established
2019
Operational
Yes
Enforcing
No enforcement activity found
Publishes decisions
No

Enforcement record

No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track São Tomé and Príncipe

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.