Content with real demand

Digital and data law in Cabo Verde

The legal framework for the digital world in Cabo Verde: personal data protection (Law No. 133/V/2001 as amended) and the CNPD, digital services and e-commerce, cybercrime, electronic justice and the .cv domain, with the gaps still to fill.

Last checked: Oct 5, 2026Company and commercial law · Human rights and equality

Digital and data law brings together the rules governing personal data processing, services provided online, crimes committed by or against computer systems, and electronic means before the administration and the courts. In Cabo Verde this framework exists and has been modernised step by step (from a 2001 law modelled on the European framework of its time to recent amendments aligned with Convention 108+), but it is more developed in data protection than in newer fields such as artificial intelligence.

Constitutional foundation

The Constitution enshrines personal data protection among fundamental rights: citizens have the right of access to computerised data concerning them, the right to require its rectification and updating, the right to know the purpose for which it is kept, and habeas data to enforce it (arts. 45 and 46 of the 2010 consolidated text available on the National Parliament portal). Ordinary legislation was built on this basis.

Personal data protection: the general regime

The core of the framework is Law No. 133/V/2001 of 22 January, which establishes the general legal regime for the protection of natural persons’ personal data, with two later amendments:

  • Law No. 133/V/2001: applies to processing carried out wholly or partly by automated means and to manual files, including video surveillance, and also reaches controllers established abroad who use means located in Cabo Verde. It imposes the classic principles: transparency, collection for specified and legitimate purposes, adequate and non-excessive data, and time-limited retention. Processing requires the data subject’s unequivocal consent or another legal basis (contract, legal obligation, public interest, legitimate interests). Sensitive data (political or religious convictions, party or trade-union membership, racial origin, health, sex life and genetic data) are in principle prohibited, with exhaustive exceptions. It grants the rights to information, access and objection (including against direct marketing) and the right not to be subject to individual automated decisions. Transfers abroad are allowed only to countries ensuring an adequate level of protection or under authorised derogations;
  • Law No. 41/VIII/2013 of 17 September: first amendment. It replaces the original «Parliamentary Oversight Commission» with the National Data Protection Commission (CNPD) and gives it prior control over sensitive processing, credit and solvency data and data interconnections, in addition to prior notifications of automated processing;
  • Law No. 121/IX/2021 of 17 March: second amendment, aligning the regime with the Council of Europe’s Convention 108+ (its preamble records that Cabo Verde has been Party to Convention 108 since 1 October 2018). It extends application to controllers located outside Cabo Verde who process data of people present here, introduces the concepts of pseudonymisation, biometric data, personal data breach and profiling, prohibits profiling that leads to discrimination, and sets 16 as the minimum age for valid consent, with the legal representatives of minors stepping in.

The CNPD, supervisory authority

The National Data Protection Commission is an independent administrative entity operating alongside the National Assembly (Law No. 42/VIII/2013, as amended by Law No. 120/IX/2021, which gave it public-law legal personality and administrative and financial autonomy, and composed the commission of three members elected by the Assembly by a two-thirds majority). It authorises or registers processing, investigates and inquiries, orders the blocking, erasure or destruction of data, prohibits processing (including on open networks from servers located in Cabo Verde), issues opinions and directives, imposes fines, promotes codes of conduct, hears complaints from individuals and publishes an annual report. It is headquartered in Praia and maintains an official website with forms, guidance and its activities: www.cnpd.cv.

Digital services and e-commerce

Law No. 41/X/2024 of 12 August approves the legal regime for digital services and electronic commerce, applicable to information society services, in particular intermediary service providers and online trade. Points verified in the text: it defines electronic signature (art. 4); removes any general monitoring obligation on intermediaries (art. 7); requires intermediary service providers to register with the supervisory authority (art. 12); regulates information duties, order confirmation (art. 31) and the consumer’s right of withdrawal with reimbursement within 14 days (art. 41); provides that the privacy policy is governed by the general data protection regime (art. 15); and makes the Multi-Sectoral Economic Regulatory Agency (ARME) the central supervisory authority (art. 68). It entered into force 60 days after publication, that is, from October 2024.

Cybercrime

Law No. 8/IX/2017 of 20 March is Cabo Verde’s cybercrime law: it criminalises computer forgery, damage to programs and data, computer sabotage (aggravated where it gravely disrupts critical social functions such as health, supply chains or public services), illegal access to systems, illegal interception of communications, misuse of devices, online child pornography and «revenge pornography», and it provides for the criminal liability of legal persons. On the procedural side it creates tools such as expedited data preservation, production orders for data, search and seizure of computer data and interception of communications, and organises international cooperation with a permanent contact point, with the Judicial Police as the competent authority. The same law requires personal data protection to be respected in the use of these powers (art. 32).

Electronic justice and digital identity

Law No. 33/VIII/2013 of 16 July regulates the use of electronic means in the processing of judicial cases, the communication of acts and the filing of procedural documents (known through the rectification published in Official Gazette No. 50, Series I, of 24 September 2013). For identification, Law No. 43/VIII/2013, adopted the same day as the data protection reform, created the National Civil Identification and Authentication System (SNIAC), the infrastructure supporting citizens’ digital authentication.

The .cv domain

The national top-level domain .cv was registered with IANA on 21 October 1996, with registry information pointing to the operator listed at dns.cv and a redelegation to the national communications agency recorded by IANA in 2009. The national legal framework for domain names was not verified in this research, and Law No. 41/X/2024 contains no domain-name rules; domain disputes are in practice handled through the operator’s mechanisms and the courts.

Honest gaps

  • Artificial intelligence: full-text searches of the Official Electronic Gazette found no Cabo Verde instrument dedicated to AI; the occurrences of the term are incidental (higher education, public procurement). The subject is captured, if at all, by the general data protection rules: notably the prohibition of discriminatory profiling and the right not to be subject to automated decisions;
  • Cybersecurity: no dedicated framework act was verified; the law governing computer attacks is the cybercrime law (Law No. 8/IX/2017). Recent organisational instruments mention cybersecurity, but no general regime of its own was identified in this research;
  • The ratification of the African Union Convention on Cybersecurity and Data Protection (Malabo) was not verified in the Official Gazette in this research.

When to speak with a lawyer

Businesses processing customer or employee data (notification to the CNPD, authorisations, data breaches), online shops and service providers (terms, order confirmation, right of withdrawal), victims of cybercrime or non-consensual intimate disclosure, and data subjects who wish to exercise access, rectification or objection rights should seek advice. The directory lists corporate and commercial lawyers; data protection complaints go to the CNPD.

This page is general information, not legal advice.