Ley 1/2016 art. 13(b) — impugnación de valoraciones: disclose the program, challenge any decision, but nothing forbids the machine
Binds Responsables del fichero o del tratamiento, defined at art. 4(i) as any natural or legal person, public or private, engaged in the processing of personal data, and encargados del tratamiento through the art. 8 processor-contract regime. Art. 2 makes the scope explicitly dual-sector: the Law applies to the personal data of all citizens recorded on any kind of medium, in the public sector as much as in the private, that make them susceptible of processing or of later use by other natural or legal persons or by public and private entities, where that processing is carried out or used on means situated in the national territory, or where Equatoguinean legislation applies to a controller not established in the country. Art. 2(2) additionally brings electoral, statistical, civil-registry and criminal-registry files, and images and sounds obtained by security video cameras, within the Law subject to their specific rules. Art. 3 excludes files kept by natural persons in the exercise of exclusively personal or domestic activities, files established for organised crime and terrorism, and files relating to classified matters — an unusually broad security carve-out that removes the whole of the state-security sector from art. 13(b). Art. 14 further disapplies the rights: controllers of files held for police or tax purposes may deny access, rectification, opposition or cancellation having regard to the gravity and danger that might follow for the defence of the State or public security, the protection of third-party rights, or ongoing investigations; and where the information could affect national defence, national security, or the prevention and investigation of criminal and administrative offences and delinquency in general, the controller is not merely permitted but obliged to refuse. A refused data subject must first lodge a queja or reposición with the controller who decided the processing, and only after exhausting that internal route may they claim to the Órgano Rector de Protección de Datos Personales, which resolves with reasons. No ex ante gate attaches to automated decision-making or to profiling: there is no impact assessment, no prior authorisation for scoring, and no notification duty specific to automated processing. Public files are created by Decree under art. 19 and entered in the Registro General de Protección de Datos, whose contents any person may consult under art. 13(c). Impact tier: all entities.. Article 13(b) of Ley núm. 1/2016, de 22 de julio, de Protección de Datos Personales is Equatorial Guinea's automated-decision provision, and it is the Spanish LOPD form, not the Directive 95/46/EC form that every other Central African row on the tracker carries. Título III, Garantía y protección de los derechos de las personas, opens at art. 13 with a single article listing the citizen's rights, and the second of them is headed Impugnación de valoraciones: El interesado tendrá derecho a obtener información del responsable del fichero sobre los criterios de valoración de sus datos personales y de su comportamiento, y el programa utilizados en el tratamiento de los mismos, pudiendo impugnar todo acto administrativo o decisión que implique una valoración de su conducta o comportamiento y definición de sus características o personalidad — the data subject has the right to obtain from the file controller information on the criteria used to evaluate their personal data and their behaviour, and on the program used in processing them, and may challenge any administrative act or decision that involves an evaluation of their conduct or behaviour and a definition of their characteristics or personality. Two features make it wider than the templates around it. First, the disclosure limb reaches el programa utilizado — the program itself, not merely the logic involved — which is the most explicit software-disclosure wording of any statute on the tracker. Second, the challenge limb carries no solely-automated trigger and no legal-effects threshold: it bites on todo acto administrativo o decisión involving a profiling-style evaluation, whether a machine or a human reached it, where the GDPR art. 22 family and the Directive art. 15 family both require that the decision be based solely on automated processing and produce legal or similarly significant effects. What Equatorial Guinea does not have is a prohibition. There is no rule anywhere in the Law that a decision may not be taken on the sole basis of automated processing, no human-intervention right, no right to express a point of view, and no obligation to disclose the existence of automated decision-making up front: art. 13(b) is exercised after the fact, by an interesado who already suspects they were scored. The Law is otherwise LOPD-lineage throughout — arts. 5 to 12 carry consent, purpose limitation, data quality, processor contracts, security and secrecy, and art. 13 gathers access, the impugnación limb, consultation of the Registro General de Protección de Datos, rectification and cancellation within fifteen days, and a damages right into one article. It is the first Hispanophone row in the African block and the first anywhere on the tracker to place the challengeable object at acto administrativo o decisión rather than at automated decision.
Force. The Disposición Final is a twenty-day vacatio: La presente Ley entrará en vigor a los veinte (20) días de su publicación en el Boletín Oficial del Estado, sin perjuicio de su publicación en los demás Medios Informativos Nacionales. The Law was given at Malabo on 22 July 2016 over the signature of President Obiang Nguema Mbasogo, and the date recorded on this entry is that date, the one the instrument carries on its face and cites itself by (Ley Núm. 1/2016, de fecha 22 de Julio). The Boletín Oficial del Estado issue in which it was published is not stated in the official copy read and the Equatoguinean BOE is not published online, so the exact day on which the twenty days expired cannot be pinned to a primary source; the entry is marked medium for that reason alone. Nothing turns on it for a 2026 reader — the vacatio ran out in 2016 on any publication date and the Law has been in force for a decade — but the in-force date is a range in August or September 2016, not a verified day, and it is recorded as such rather than assumed. One structural condition does remain open. Art. 15 provides that the Órgano Rector de Protección de Datos Personales, que será creado mediante Decreto, is the body that protects the rights derived from the Law; the Law itself does not constitute it, and no creating Decree was found on the Equatoguinean government hosts. Art. 35 covers the gap on the enforcement side: the Ministro de Telecomunicaciones y Nuevas Tecnologías exercises the sanctioning power under the Law against any infringer, on a procedure opened and instructed by the Dirección General de Nuevas Tecnologías, or where applicable by the Órgano Rector, with an appeal by recurso de alzada to the Consejo de Ministros within thirty days. So art. 13(b) is enforceable today through the Ministry whether or not the Órgano Rector exists; what the missing Decree affects is the art. 14(3) claim route, which names the Órgano Rector as the body that resolves a refusal. Supersession: none. Equatorial Guinea had no dedicated data-protection statute before Ley 1/2016 and no AI-specific statute is in force; the Law does not define artificial intelligence, and Gabon's Loi 025/2023 remains the only data-protection statute in the African block that does. Text read in the official scanned copy published by the Ministerio de la Función Pública y la Reforma Administrativa, which satisfies Primary Source First on the same basis as the Nigeria, Burkina Faso, Gabon and Chad copies; the WorldLII mirror Cloudflare-blocks automated retrieval and was not relied on. The copy is a 45-page image-only scan with no text layer and was read as page images. Coverage of the read: arts. 1 to 15 in full (object, scope, exclusions, definitions, the Título II principles, the whole of the art. 13 rights list, the art. 14 exceptions and the art. 15 tutela article), art. 19 on public files, and the whole of the Título VI sanctioning regime — art. 35 competence, arts. 39 to 41 the three infringement classes, art. 42 the penalty scale, art. 43 the graduation criteria, art. 44 procedure — plus the Disposición Final. The intervening arts. 16 to 34, on the police-file regime, public and private files, the Registro General, international transfers and the authority's inspection powers, were read by heading and spot-check; no automated-decision or profiling rule appears in them, and art. 13(b) is the Law's only evaluation-and-challenge provision.
Stated maximum penalty — Administrative, and the route to art. 13(b) is explicit. Art. 40 makes it an infracción grave to obstruct, impede or hinder the exercise of the rights of access, rectification, cancellation and opposition by the interested or affected person (art. 40(b)), and separately to fail to attend to the requests, complaints and claims of interested or affected persons (art. 40(g)) — either limb catches a controller who refuses an art. 13(b) request for the valuation criteria or the program used. Art. 42(1)(b) sets the grave scale: a fine of 500,001 to 5,000,000 FCFA, suspension of the file's activity and of the processing of personal data, and sealing of the premises or installations for a period not exceeding fifteen (15) working days. Below that, art. 42(1)(a) puts leves at amonestación, written warning, or a fine of 200,000 to 500,000 FCFA; art. 39(f) sweeps any other breach of the Law that is not grave or muy grave into that class. Above it, art. 42(1)(c) puts muy graves at fines of 5,000,001 to 15,000,000 FCFA together with one or more of seizure of equipment and other material, definitive closure of the premises and installations, disqualification of the infringer from the activity of file-keeping and personal-data processing for one year or definitively, and cancellation and revocation of the administrative resolution, authorisation or concession creating the file and of its entry in the Registro General de Protección de Datos. Art. 42(2) adds that in grave or muy grave cases where the processing, communication, transfer or international transfer could impair the fundamental rights of those affected, the sanctioning body may require public and private controllers alike to cease the unlawful use, and art. 42(3) lets it immobilise the files by reasoned resolution if that requirement is not met. Art. 43 grades the sanction by the proportionality of the harm and its social or economic repercussion, intentionality, continuity, the volume of processing, the unlawful benefit obtained, the degree of participation, recidivism, and the nature of the harm caused to the interested and to third parties. Separately from the sanctioning regime, art. 13(e) gives the data subject a damages right — before the ordinary courts against private files, and under the State responsibility rules against public ones.