A Real Problem, Legislated in a Hurry
On August 12, 2026, Angola's National Assembly passed the Cybersecurity Law by a party-line vote of 104 in favour (MPLA) to 56 against (UNITA), with no abstentions (allAfrica). The bill had cleared specialised committees just five days earlier with 23 votes in favour, none against, and 10 abstentions (INACOM) — a compressed timeline that opposition MP Joaquim Nafoia argued left too little room for scrutiny of a law that, in his words, would "weaken rights, concentrate powers and threaten transparency" (e-Global).
The steelman case for the law is not hard to make, and it is worth making honestly. Angola's own bill text, submitted by the Ministry of Telecommunications, Information Technologies and Social Communication in February 2025, cites the ITU's 2024 Global Cybersecurity Index ranking Angola in the bottom quartile globally, with a score of 39.5 out of 100 — a genuinely weak starting point for a country pushing digital-transformation policy across banking, government services and telecoms. The same document notes Angola has lacked a dedicated national incident-response authority and that its existing framework, the 2017 Law on the Protection of Networks and Information Systems, predates the ransomware and critical-infrastructure attacks that have since become routine across the region. A country integrating its economy online without a functioning incident-response capability is exposed in ways that are not hypothetical — Angola's own telecom sector has already had close calls, which is part of why the legislative debate resumed as urgently as it did this summer.
Where the Design Goes Wrong
The trouble is not that Angola regulates cybersecurity — nearly every functioning digital economy does — but how it has structured who enforces that regulation. The law creates a National Cybersecurity Centre (CNC) that combines regulatory rule-making, supervisory, inspection and sanctioning powers inside a single body, with no separation between the entity that writes the rules and the one that polices and punishes violations of them (analysis via Maka Angola). That is a structural defect independent of who is in government: a regulator that is simultaneously legislator, investigator and judge has no external check on how aggressively — or selectively — it applies the law.
Two further provisions compound the concern. First, the law's scope is not limited to designated critical infrastructure; it extends to "any other entities that use data communication networks and information systems," a catch-all that could sweep in ordinary businesses and civil-society organisations far outside the power, telecoms and finance sectors the law's own justification focuses on. Second, and more serious, is the communications-access provision: critical-infrastructure operators can be compelled to hand over communications data by "judicial or administrative decision" — meaning an executive authority can authorise access without going through a court at all. Removing judicial sign-off from a compulsory-disclosure power is precisely the kind of procedural shortcut that turns an incident-response law into a surveillance one.
UNITA's objection should be read against that backdrop rather than dismissed as reflexive opposition-party noise. The party argues the law gives the executive "discretionary powers... to cut the Internet signal whenever they want" and frames the bill as part of an "electoral securitisation doctrine" ahead of Angola's 2027 general election (e-Global). Vague statutory language around "state security" and "cyber threat" — undefined with any precision in the bill — gives that concern real teeth: the same clause that lets regulators respond to a genuine ransomware incident can just as easily be pointed at an inconvenient news site or opposition messaging app in an election year.
What Proportionate Regulation Would Look Like
None of this means Angola should have left its 2017 framework untouched. It means the fix should have paired new enforcement capacity with new institutional checks, not stripped them away. A proportionate version of this law would split rule-making from enforcement across two bodies, require judicial authorisation for any compelled access to private communications, and confine mandatory compliance obligations to a defined list of critical-infrastructure sectors rather than an open-ended catch-all. Business-risk analysts have already flagged the practical cost of skipping this step: multinational operators face "enforcement unpredictability" from a regulator that writes and applies its own rules, with no clear channel for recourse when a sanction looks more political than technical (Horizon Engage).
Angola's cybersecurity gap was real. The law that closes it should not have been the one that also hands the executive an administrative backdoor into private communications, on the eve of an election, with no independent body positioned to say no.