§ Dossier · CENTRAL AFRICA · updated 22 July 2026
in force
DP law status
Law No. 3/2016 on the Protection of Personal Data
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Law No. 3/2016 on the Protection of Personal Data (Diário da República No. 39, 10 May 2016) IN FORCE
commenced 2016-05-10 (Diário da República publication; adopted 15 February 2016, promulgated 18 March 2016) · Official full text ↗
- Scope
- Processing by controllers seated in São Tomé and Príncipe, in the context of an establishment there, or abroad where São-Tomean law applies via international law; foreign controllers using means in the territory must appoint a local representative notified to the ANPDP (art. 4); personal/domestic processing excluded unless systematically communicated or disseminated.
- Key obligations
- Written notification to the ANPDP at least eight days before starting any wholly or partly automated processing (art. 21); ANPDP authorisation for sensitive-data processing on important-public-interest grounds (art. 8) and for file interconnection not provided for by law (arts. 17, 22); Portuguese-family sensitive-data prohibition (art. 7): philosophical/political convictions, political or union membership, religious faith, PRIVATE LIFE, racial/ethnic origin, health, sex life and genetic data: processable only with non-discrimination guarantees; Detailed security-measures catalogue (entry, access, transmission and input controls); public register of notified/authorised processing at the ANPDP (art. 25)
- DPO required
- No: the law predates the DPO model; foreign controllers must instead designate a local representative (art. 4).
- Registration
- Yes: prior written notification to the ANPDP (8-day lead, art. 21), with authorisation regimes for sensitive data and interconnection; filings must disclose planned third-country transfers (art. 23).
- Cross-border transfers
- Transfers outside the territory only where the destination ensures an adequate level of protection, assessed by the ANPDP against the transfer's circumstances (art. 19); non-adequate destinations require notification to the ANPDP plus the data subject's unequivocal authorisation or contract/pre-contract necessity and similar derogations (art. 20).
- Breach notification
- No breach-notification duty: the law follows the pre-GDPR Portuguese model; third parties who received data must be notified of rectification, erasure or blocking (art. 12-family duty).
- Penalties
- The law carries its own sanctions regime (contraordenações and crimes in the Portuguese tradition) plus referral to sanctions in other laws; specific quanta not yet verified: confirm against the archived official text (pages at the sanction chapters) before quoting figures.
- Authority
- Agência Nacional de Protecção de Dados Pessoais (ANPDP)
Verified 2026-07-07
The regulator
- Authority
- Agência Nacional de Protecção de Dados Pessoais (ANPDP)
- Website
- https://anpdp.st ↗
- Established
- 2019
- Operational
- Yes
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track São Tomé and Príncipe
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.