On August 15, 2026, the Angolan Data Protection Agency (Agência de Protecção de Dados, APD) published Deliberation 006/2026, dated August 10, 2026, fining Lizíria, Lda, trading as Hotel Diamante, the equivalent of USD 115,000 for breaches of the Personal Data Protection Law (Lei n.º 22/11 de 17 de Junho). The hotel processed client personal data without the prior notification and authorisation that Articles 30 and 31 of Lei 22/11 require, and failed to adopt adequate technical and organisational measures to protect that data. The sanction was issued under Article 51(1)(a)(i) read with Article 51(2) of the same law.

The fine is the APD's first publicly named hospitality-sector sanction and confirms that the agency's enforcement net now reaches any controller processing customer data in Angola without the required legalisation, not only technology and telecoms firms. For compliance counsel at hotels, tourism operators, banks, insurers and healthcare providers operating in Angola, the deliberation turns what was until recently a theoretical notification duty into a concrete, USD-scale financial exposure.

What exactly did Hotel Diamante fail to do?

The APD identified two cumulative failures. First, the hotel did not notify the APD of its client-data processing and did not obtain the agency's prior authorisation before treating that data, a duty anchored in Articles 30 (notification) and 31 (prior authorisation) of Lei 22/11. Second, it did not implement technical and organisational measures sufficiently adequate to protect the personal data of its clients, a general security obligation that the law pairs with the authorisation regime.

Under Lei 22/11, controllers must legalise their processing with the APD before it begins: high-risk categories (including sensitive data and certain biometric or health processing) require express prior authorisation, while other processing requires notification. Hotel guest data, encompassing identity documents, payment details and stay records, falls squarely within the regime, and the APD treated the absence of both steps as a single infracting course of conduct.

How was the USD 115,000 figure set, and can it be reduced?

The deliberation records that the penalty corresponds to an "extraordinary attenuation". The APD applied the reduction because the hotel promptly cooperated in clarifying the facts and demonstrated commitment and effort to improve its internal processes and procedures with a view to the effective protection of the personal data in its possession. The cooperation did not eliminate the fine, but it lowered it materially, signalling that controllers who self-correct and engage with the agency can expect a lower sanction than those who do not.

The legal ceiling for this category of infringement sits in Article 51 of Lei 22/11, which sets administrative fines expressed in Kwanzas against both the controller and, where applicable, the individuals responsible. Controllers should read the published amount as an attenuated, not a maximum, figure: an uncooperative respondent facing comparable violations could face a higher penalty.

Who else is exposed, and what should controllers do now?

The sanction follows a broader APD enforcement phase. In June 2026 the agency had already imposed fines totalling roughly USD 617,000 on Crescer Tech and Fast Digital Center, and specialist commentary has tracked a deliberate shift from awareness-building to active fining. The hospitality sector is simply the latest to be named; any Angolan controller processing personal data without legalisation is exposed on the same legal basis.

Compliance stepLei 22/11 basisAction
Notify APD of processingArticle 30Submit a notification for each non-authorised processing operation
Obtain prior authorisationArticle 31Apply before starting high-risk or sensitive-data processing
Implement security measuresArticle 30 / Article 31 dutiesDocument technical and organisational measures proportionate to the data processed
Respond to APD enquiriesArticle 51(2) cooperationDesignate a contact and engage promptly to access attenuation

Controllers that have not yet legalised their processing should treat the Hotel Diamante fine as a deadline signal rather than a wait-and-see data point: the APD is publishing named sanctions under Article 53(3), and the next deliberation could name any sector. Continuous, per-jurisdiction real-time monitoring surfaces an enforcement notice like this the moment it publishes, before it becomes a pattern.

Take advantage of this real-time watch

Angola: AI and personal-data rulemaking, APD and MINTTICS supervisionLive
Monitor Angolan digital-governance regulation for the AI, data and digital governance industry.
Hourly Email 7 news
This live monitoring job detected the news you are reading.
Activate this watch free now

For the immediate next steps: verify whether your Angola processing has been notified or authorised with the APD; if not, file the notification or authorisation application before the next enforcement cycle; document the technical and organisational measures you rely on; and brief the team that handles guest, client or patient records on the new, concrete cost of inaction. The official notice and the full text of the deliberation are available on the APD website.