Electronic Transactions and Cyber Security Act, 2016, rights of a data subject and information notice (Part VII)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 June 2017.
A data subject rights rule binding public and private bodies.
As of 19 September 2026.
What it requires
- When collecting personal data from a data subject, tell them who the data controller is, together with any representative, the purpose of the processing, and that they have rights of access, rectification and objection.
- Let a data subject obtain, without constraint or unreasonable delay and at no expense, confirmation of whether their data is being processed, communication of the data being processed and its source, and communication of the purposes of the processing and the recipients it is disclosed to.
- Honor a data subject's objection, made at any time on legitimate grounds relating to their situation, to the processing of their data, and stop processing that data once the objection is justified.
- Give a data subject, on request, the rectification, erasure or blocking of data whose processing does not comply with the Act, in particular because it is incomplete or inaccurate.
What it reaches
Obligation class
Disclosure, Data subject rights
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 72 entitles a data subject to obtain from a data controller, without constraint or unreasonable delay and at no expense, confirmation of whether data about him is being processed, communication of the data undergoing processing and its source, and communication of the purposes of the processing and the recipients the data is disclosed to.
The same section entitles a data subject to object at any time, on legitimate grounds relating to their situation, to the processing of data about them, and where the objection is justified the data controller may no longer process that data. It also entitles a data subject to obtain, as appropriate, the rectification, erasure or blocking of data whose processing does not comply with the Act, in particular because it is incomplete or inaccurate.
Section 73 requires a data controller, when collecting data from a data subject, to give them the identity of the controller and any representative, the purpose of the processing, and the existence of the rights of access, rectification and objection.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisions
Read the law
Malawi Electronic Transactions and Cyber Security Act
Chapter 74:02, consolidated to 31 December 2017, Laws.Africa text hosted by MalawiLII (CC BY)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.