Personal data protection: what applies to your website

If your site has a contact form, a newsletter, a client area or a shop, you are processing personal data. This article explains what that means in Angola, what is expected of you, and where our part ends and yours begins.

We are not lawyers. This is practical guidance from people who host websites, written to help you ask the right questions. For a decision with legal consequences — a contract, a fine, a formal request — talk to a lawyer.

What counts as personal data

It is any information that identifies a person, directly or by cross-referencing. The list is wider than intuition suggests:

Category Examples
The obvious Name, ID number, tax number, phone, address, e-mail address
The less obvious IP address, cookies, location, photographs where the person is recognisable, buying habits
The kind needing extra care Health, ethnic origin, political or religious convictions, sexual life, biometric data

“Processing” is also more than collecting: it includes storing, consulting, altering, sharing with third parties and deleting. A form that lands in your inbox and stays there for years is data processing.

The law in Angola: Lei n.º 22/11

Angola has its own law, in force since 2011: Lei n.º 22/11, of 17 June, the Personal Data Protection Act. It applies to any entity processing personal data in Angola — companies, institutions and professionals, whatever their size.

The supervising authority is the APD — Agência de Protecção de Dados. It is where you seek an opinion, where you notify processing when the law requires it, and it is the body that applies sanctions.

What the law requires In practice
Consent As a rule the person must expressly consent before you collect their data. A pre-ticked box is not consent
Stated purpose Say what you are collecting it for. Collecting for one thing and using it for another is not covered by the first consent
The person’s rights To access their data, correct it and object to the processing. You need a way to answer those requests
Sensitive data Health, sexual life, racial origin, political views, religious faith and affiliation have reinforced protection and, as a rule, are not processed
Non-compliance Can bring a fine and, in cases set out in the law, criminal liability

What to do on your site, concretely

1 Make the list. What data you collect, in which forms, where it is stored, who has access to it and for how long. Without that list, the rest is guesswork.
2 Publish a privacy policy in language people understand, saying what you collect, what for, who you share it with and how someone asks to be deleted. Link it in the footer and next to every form.
3 Ask only for what you need. If the contact form does not need a postal address, remove the field. Every extra field is one more risk and one fewer conversion.
4 Treat subscription as consent. An unticked box, never pre-ticked, and separate from the send button. And keep a record of when and how they consented.
5 Close the door. Active SSL certificate, strong passwords, two-factor authentication where available, and a review of who has access to the panel — see how to enable two-factor authentication.
6 Know how to go back. A backup is not only against failures: it is what lets you prove what was there and recover after an incident — see how to restore your data with JetBackup.

Mind what leaves your house

Many sites hand data to third parties without noticing: the form that posts to a newsletter service abroad, the embedded map, the share button, the analytics tool, the support chat.

And artificial intelligence tools. Pasting your client list, a contract or a patient’s details into an AI assistant is sharing with a third party — even if nobody reads it on the other side. If you use AI at work, see what makes sense to send in which AI tool suits which task.

What we do and what is yours

Ours Yours
Keeping the server updated and protected Deciding what data you collect and what for
Storing the data on the server and taking backups Writing and publishing the privacy policy
Providing SSL, firewall and access logs Answering people who ask for access, correction or deletion
Warning and helping if there is an incident on our side Controlling who on your team has the panel password

The full line between what we fix and what stays on your side is in how far our support goes.

Need to know where your site’s data is stored, or need an access log?

Ask us
  • 0 Users Found This Useful
Was this answer helpful?