Data Protection Act, 2024 (Act No. 18 of 2024)
Data Protection Act, 2024 (Act No. 18 of 2024)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 14 January 2025.
A comprehensive regime rule binding public and private bodies.
As of 4 September 2026.
What it requires
- Obtain a lawful basis before processing personal data of a person in Botswana, or of a person elsewhere if the processing is by a controller or processor established in Botswana.
- Do not process racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health data, or sex-life or sexual-orientation data, unless a listed exception applies, such as the data subject's explicit consent or data the person has manifestly made public.
- Obtain parental or guardian consent before processing the personal data of a child under sixteen in connection with an information-society service offered directly to them; a child of sixteen or older may consent themselves.
- Do not base a decision that produces legal or similarly significant effects on a person solely on automated processing, including profiling, unless a listed exception applies, and where it does, provide a way for the person to obtain human intervention and to contest the decision.
- Notify the Information and Data Protection Commission of a personal-data breach within 72 hours of becoming aware of it where feasible, unless the breach is unlikely to result in a risk to the affected person's rights and freedoms, and communicate a high-risk breach to that person without undue delay.
- Before transferring personal data to a third country or an international organisation, obtain an adequacy finding from the Commission, put in place approved appropriate safeguards or binding corporate rules, or rely on a listed derogation, and keep a copy of the transferred data in Botswana for the period of processing.
- Respond to a data subject's request to access, rectify, erase, restrict the processing of, or port their personal data, and to their objection to processing.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Section 84 creates criminal offences on top of the administrative-fine and compensation regime: a data controller who does not implement the security safeguards required under Part XI is liable to a fine of P500,000 or imprisonment for up to nine years, or both; a person who sells personal data commits the same offence at the same penalty; and a person who contravenes any other provision of the Act, where no other penalty is provided, is liable to a fine not exceeding P500,000 or imprisonment for a term not exceeding nine years, or both.
Penalty structure
Section 83(3) sets the higher administrative-fine tier: up to P50,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, for a contravention of the core processing principles and consent conditions (Parts IV to VI), data-subject rights (Part VIII), cross-border transfer rules (Part XIV), obligations under a restricting law (Part VII), or an order of the Commission. Section 83(2) sets a narrower lower tier, up to P10,000,000 or 2 percent of worldwide annual turnover, whichever is higher, for a contravention of the children's-consent duty (section 29) or the data-protection-by-design and by-default duty (section 52) specifically. Separately, section 84's criminal offences (failing to implement required security safeguards, selling personal data, or any other contravention with no other penalty provided) carry a fine of up to P500,000 alongside imprisonment of up to nine years; neither criminal track exceeds the P50,000,000 fixed_cap recorded here.
- Rule
- Higher of
- As of
- 4 September 2026
- Currency
- BWP
- Fixed cap
- 50,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Information and Data Protection Commission
What it reaches
Obligation class
Consent, Data subject rights, Biometric, Transfer, Breach notice, Governance, DPIA, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Botswana's comprehensive personal-data statute, passed by the National Assembly on 19 August 2024, assented to on 24 October 2024, published in Government Gazette Extraordinary Vol. LXII, No. 144 of 29 October 2024, and brought into force on 14 January 2025 by Statutory Instrument 4 of 2025, repealing the earlier Data Protection Act, 2018 (Cap. 43:14).
It continues the Information and Data Protection Commission and applies to automated and non-automated processing of personal data by a controller or processor established in Botswana, reaching a foreign controller or processor that offers goods or services to, or monitors the behaviour of, people in Botswana; it binds the State.
It prohibits processing sensitive categories of personal data (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health data, and sex-life or sexual-orientation data) subject to listed exceptions.
A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, subject to narrow exceptions and safeguards including a right to human intervention and to contest the decision.
A controller must notify the Commission of a personal-data breach within 72 hours where feasible, unless the breach is unlikely to risk a person's rights and freedoms, and must communicate a high-risk breach to the affected person without undue delay. Processing a child's personal data for an information-society service offered directly to them needs parental or guardian consent unless the child is at least sixteen.
A transfer of personal data to a third country or an international organisation needs an adequacy finding by the Commission, appropriate safeguards, approved binding corporate rules, or a listed derogation, and a copy of the transferred data must additionally remain in Botswana for the period of processing.
Enforcement combines two tiers of administrative fine the Commission can impose directly (up to P10,000,000 or 2 percent of worldwide annual turnover, whichever is higher, for a contravention of the children's-consent and privacy-by-design duties in sections 29 and 52; up to P50,000,000 or 4 percent of worldwide annual turnover, whichever is higher, for a contravention of the core processing principles, data-subject rights, cross-border transfer rules, or a Commission order) with a private right to compensation for a data subject who suffers material or non-material damage, and criminal offences of up to P500,000 or nine years' imprisonment, or both, for failing to implement required security safeguards, selling personal data, or otherwise contravening the Act where no other penalty is specified.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minors
Read the law
Data Protection Act, 2024, Botswana Government Gazette listing (Botswana Laws bulletin)
provisions verified against the Government Gazette Extraordinary Vol. LXII, No. 144 of 29 October 2024 as mirrored by a third-party host, dpo-india.com, since no official Botswana government host of the full text is cited here