Key Obligations & Consequences
Applicability: The personal data protection law applies to.
- The processing of personal data carried out by any person in the public sector, the private sector or the cooperative sector, namely, when the data controller is based in Angola.
- The "data controller" is the entity that determines the purpose and means of the processing of personal data. "Personal data" is any information relating to an identified natural person or identification, such as name, address, telephone number, etc.
Collection and Processing:
In general terms, personal data collection and processing of personal data is subject to express and prior consent from the data subject and prior notification to the DPA. However, data subject consent is not required in certain circumstances provided by law.
With respect to sensitive data processing, collection and processing is only allowed where there is a legal provision allowing such processing or prior authorization from the DPA is obtained (please note that the authorization may only be granted in specific cases provided by law). If the sensitive personal data processing results from a legal provision, the same shall be notified to DPA.
There are specific rules applicable to the processing of personal data relating to:
- Sensitive data on health and sexual life.
- Illicit activities, crimes and administrative offenses.
- Solvency and credit data.
- Video surveillance and other electronic means of control
- Advertising by email
- Advertising by electronic means (direct marketing)
- Call recording.
Specific rules for the processing of personal data within the public sector also apply.
- The data subject shall be provided with.
- The identity and address of the controller.
- The purposes of the processing and of the creation of a file for such purposes.
- The recipients or categories of personal data recipients.
- The conditions under which the right of access, rectification, deletion, opposition and updating may be exercised.
- The consequences of the collection of personal data without consent of the data subject.
Data Security:
The data controller must implement appropriate technical and organizational measures and to adopt adequate security levels in order to protect personal data against accidental or unlawful total or partial destruction, accidental loss, total or partial alteration, unauthorized disclosure or access (in particular where the processing involves the transmission of data over a network) and against all other unlawful forms of processing.
Having regard to the state of the art and the cost of their implementation, such measures shall ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected. Specific security measures shall be adopted regarding certain types of personal data and purposes (notably, sensitive data, call recording and video surveillance).