Law / Lesotho

Data Protection Act, 2011, rights of data subjects

Data Protection Act, 2011, ss. 25-27, 50-51 (rights of data subjects)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 22 February 2012.

A data subject rights rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Give a data subject notice, before or as soon as practicable after collecting personal information about them, of your name and address, the purpose of the collection, whether supply is mandatory, and the consequences of not providing it.
  • Confirm free of charge, on request from a data subject who proves their identity, whether you hold personal information about them, and provide it in a reasonable manner, format and prescribed time.
  • Give a data subject written reasons where you deny an access request, and let them challenge those reasons.
  • Correct, destroy, or delete personal information on a data subject's request within 14 days where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained, and tell anyone the changed information was disclosed to within 7 working days of the correction where it affects a decision about the data subject.
  • Stop processing a data subject's personal information for direct marketing as soon as they give you notice requiring you to cease or not begin such processing.
  • Do not base a decision that has a legal effect on a person, or that significantly affects them, solely on automated processing of their personal information intended to profile their personality or habits, except where taken under a contract at their request or under a law with safeguards in place.

What it reaches

Obligation class

Data subject rights, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 25 requires a data controller that collects personal information directly from a data subject to take reasonably practicable steps, before or as soon as practicable after collection, to make the data subject aware of the information being collected, the controller's name and address, the purpose of collection, whether the supply of the information is mandatory, the consequences of not providing it, and the existence of the rights of access and rectification.

Section 26 gives a data subject who proves their identity the right to request free confirmation of whether a controller holds personal information about them and to request that information, including the identity of third parties who have had access to it, and gives a right to written reasons and a right to challenge those reasons where a request is denied.

Section 27 gives a data subject a free right to have inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained personal information corrected or deleted, requires the controller to answer the request within 14 days, and requires the controller to tell every party the changed information had been disclosed to within 7 working days where a correction affects a decision about the data subject.

Section 50 entitles a data subject to require a controller by notice to cease, or not begin, processing their personal data for direct marketing, and lets the Commission order compliance where the controller fails to observe that notice.

Section 51 bars a decision that has a legal effect on a person, or that significantly affects them, from being based solely on automated processing of their personal information intended to profile their personality or habits, unless the decision is taken in connection with a contract at the data subject's request with appropriate safeguards, or is governed by a law or code that specifies appropriate protective measures.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • high_risk_decisions

Read the law

Data Protection Act, 2011 (Act No. 5 of 2012), official text reproduced by LesLII, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app