Law / Eswatini

Data Protection Act, 2022 (Act No. 5 of 2022)

Data Protection Act, 2022 (Act No. 5 of 2022)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 4 March 2022.

A comprehensive regime rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Obtain a lawful basis, such as the data subject's explicit consent, contractual necessity, or compliance with a legal obligation, before processing personal data of an identifiable individual, whether by automated or non-automated means.
  • Do not process sensitive personal information, including biometric data, genetic data, and data revealing race, political opinion, religion, trade-union membership, gender, health, or sex life, unless a listed exemption applies, and obtain prior parental consent where the data subject is a child.
  • Notify the Eswatini Communications Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person.
  • Do not base a decision that has a legal effect on a person, or that significantly affects them, solely on automated processing of their personal information intended to profile aspects of their personality or habits, except in narrow contract or statutory circumstances.
  • Before transferring personal information outside Eswatini, confirm the recipient is in a SADC Member State that has transposed the SADC data protection requirements, or, for a non-SADC recipient, confirm an adequate level of protection or rely on a listed derogation such as consent.
  • Give a data subject notice, before collecting personal information about them, of who is responsible for the processing and its purpose, and let them access, correct, and challenge the personal information held about them.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Section 53 makes it an offence, on conviction, to hinder, obstruct or unlawfully influence the Commission, breach confidentiality rules, unlawfully obtain or receive personal information, hinder execution of a search warrant, or violate the Act's obligations without reasonable cause, punishable by a fine of up to E100,000,000 or five percent of the data controller's annual turnover, or imprisonment of up to ten years, or both; where the offender is a juristic person, the sentence is served by the head of the data controller.

Penalty structure

Section 53's text lists the fine, the turnover percentage, and imprisonment as alternative penalties on conviction (a fine not exceeding E100,000,000, or five percent of the data controller's annual turnover, or imprisonment not exceeding ten years, or both) without itself stating a comparison rule between the fixed and percentage figures; higher_of is recorded here as the worst-case exposure a court could impose under either cap, not as a rule the text states in those words. Separately, section 6(3)(b) lets the Commission impose a narrower administrative fine, not exceeding E5,000,000 or two percent of annual turnover, where a data controller fails to comply with a compliance notice; neither track exceeds the fixed_cap recorded here.

Rule
Higher of
As of
6 September 2026
Currency
SZL
Fixed cap
100,000,000
Turnover percentage cap
5

Who enforces it

Enforcement body

Eswatini Communications Commission (ESCCOM)

What it reaches

Obligation class

Consent, Biometric, Data subject rights, Transfer, Breach notice, Disclosure, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Data Protection Act, 2022 (Act No. 5 of 2022) provides for the collection, processing, disclosure, and protection of personal data, and applies to a data controller or data processor, whether or not domiciled in Eswatini, that uses automated or non-automated means in Eswatini to process personal information, and to processing performed wholly or partly by automated means (s. 3), subject only to narrow exemptions for purely personal or household activity, de-identified information, and specified State functions such as national security, defence, and public safety (s. 4).

Processing needs a lawful basis, most often the data subject's explicit consent, contractual necessity, or compliance with a legal obligation (s. 9), and sensitive personal information, which includes biometric data alongside genetic data, health data, and data revealing race, political opinion, religion, trade-union membership, or sex life, may not be processed unless a listed exemption applies, including prior parental consent where the data subject is a child (ss. 22, 29).

A data controller must notify the Commission and the affected data subject, as soon as reasonably possible after discovery, of unauthorised access to or acquisition of a data subject's personal information, unless the data subject cannot be identified (s. 17).

A person may not be subjected to a decision that has a legal effect on them, or significantly affects them, based solely on automated processing intended to profile aspects of their personality or habits, except where taken in connection with a contract at the data subject's request or under another law with safeguards in place (s. 45).

Transferring personal information outside Eswatini requires the recipient to be in a SADC Member State that has transposed the SADC data-protection requirements, or, for a non-SADC recipient, an adequacy assessment or a listed derogation such as consent (ss. 32, 33).

Enforcement combines the Commission's power to impose an administrative fine of up to E5,000,000 or two percent of annual turnover for non-compliance with a compliance notice (s. 6(3)(b)), a data subject's civil right of action for damages for breach of any provision of the Act (s. 43), a Commission-run class-action system (s. 50), and a criminal offence, on conviction, for hindering the Commission, breaching confidentiality, unlawfully obtaining personal information, or violating the Act's obligations without reasonable cause, carrying a fine of up to E100,000,000 or five percent of the data controller's annual turnover, or imprisonment of up to ten years, or both (s. 53).

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • high_risk_decisions
  • processes_biometrics

Read the law

Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)

Back to the example  ·  Lint your app