Law / Lesotho

Data Protection Act, 2011, notification of security compromises

Data Protection Act, 2011, s. 23 (notification of security compromises)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 22 February 2012.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Data Protection Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person, unless the data subject's identity cannot be established.
  • Take into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise when timing your notification, but do not use that as a reason to delay beyond what is reasonably possible.
  • Delay notification to the data subject only where the Lesotho Mounted Police Service, the National Security Service, or the Commission determines that notification would impede a criminal investigation.
  • Communicate the notification to the data subject in writing, by mail, email, a prominent website posting, publication in the news media, or as the Commission directs, and include enough information to let the data subject take protective measures, including the identity of the unauthorised person if known.
  • Publicise the compromise in the manner the Commission specifies, where the Commission has reasonable grounds to believe publicity would protect an affected data subject.

What it reaches

Obligation class

Breach notice, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 23(1) requires a data controller, on reasonable grounds to believe a data subject's personal information has been accessed or acquired by an unauthorised person, to notify the Commission and the data subject unless the data subject's identity cannot be established.

Section 23(2) requires that notification to be made as soon as reasonably possible after discovery of the compromise, taking into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise and restore the integrity of the controller's information system.

Section 23(3) requires the controller to delay notification to the data subject where the Lesotho Mounted Police Service, the National Security Service or the Commission determines that notification would impede a criminal investigation.

Section 23(4) requires the notification to the data subject to be in writing, delivered by post, email, a prominent website posting, publication in the news media, or another method the Commission directs, and section 23(5) requires it to contain enough information for the data subject to take protective measures, including the identity of the unauthorised person if known.

Section 23(6) lets the Commission direct a data controller to publicise a compromise where the Commission has reasonable grounds to believe publicity would protect an affected data subject.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot

Read the law

Data Protection Act, 2011 (Act No. 5 of 2012), official text reproduced by LesLII, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app