Electronic Transactions and Cyber Security Act, 2016, unauthorized access to data
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 June 2017.
A computer misuse rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not access, intercept, or interfere with data without authority or permission to do so, or beyond the access you are authorized for.
- Reading a public, unauthenticated page without defeating any access control has not been tested against this section in a reported decision.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
A fine of K2,000,000 and imprisonment for five years on conviction (s. 84(3)); imprisonment of not less than ten and not more than fifteen years, with no separate fine, where the data concerns national security or an essential service (s. 84(10)).
Penalty structure
Base offence under s. 84(3); the same subsection also allows imprisonment of up to five years. A separate, more severe imprisonment-only tier of ten to fifteen years applies under s. 84(10) where the data concerns national security or an essential service.
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- MWK
- Fixed cap
- 2,000,000
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 84(1) prohibits a person from gaining unauthorized access to, or intercepting, or interfering with data. Section 84(3) makes it an offence for a person to intentionally access or intercept any data without authority or permission to do so, or to exceed authorized access, punishable on conviction by a fine of K2,000,000 and imprisonment for five years; unlike Kenya's neighbouring provision, the offence does not require defeating a security measure to gain access.
Section 84(10) raises the penalty to imprisonment of not less than ten and not more than fifteen years, with no separate fine stated, where the data concerned is data connected with national security or the provision of an essential service. Because the offence turns on accessing data without authority rather than on circumventing a technical control, its reach to a scraper reading a public, unauthenticated page is unsettled.
When LexLint raises it
crawls_webtrains_models
Read the law
official consolidated Act text, Malawi Legal Information Institute (MalawiLII)