Subscribe to PLMJ’s newsletters to receive the most up-to-date legal insights and our invitations to exclusive events.
Subscribe to PLMJ’s newsletters to receive the most up-to-date legal insights and our invitations to exclusive events.
Learn more about all the changes introduced by the new law.
Law No. 9/26 of 28 September (the “Cybersecurity Law”) was recently published in the Official Gazette, fully repealing Law No. 7/17 of 16 February (Law on the Protection of Computer Networks and Systems). The Law establishes the legal framework applicable to the protection of citizens and public and private entities against cyber threats and cyberattacks, as well as to the security of the country’s networks, information systems, critical infrastructure and essential services.
Compared with the previous regime, the Law has a significantly broader scope, covering all natural and legal persons, public and private, that use or operate in Angolan cyberspace. It also applies to acts carried out within and outside the national territory, whenever such acts are directed at, or produce effects in, Angolan cyberspace.
The main changes introduced include:
The main duties of covered providers include:
The duties that actually apply will depend on the nature, size, risk and criticality of the activity carried out, and each entity should assess its regulatory position in light of the services provided, the networks and systems used and its relationships with customers, subscribers and third-party providers.
Failure to comply with the obligations set out in the Law may constitute a minor, serious or very serious administrative offence, punishable by fines and, in certain cases, by additional penalties of temporary suspension of activities and a ban on participating in public procurement procedures for a period of up to 3 years. For legal persons, fines for very serious offences may reach 2,000 to 4,000 national minimum wages, without prejudice to the other consequences provided for in the Law. Oversight and the application of penalties are the responsibility of the National Cybersecurity Centre.
The Law entered into force on its date of publication, 28 September 2026. Entities subject to registration have 180 days from the entry into force to register.
Entities potentially covered are advised to: