Data Protection Act, 2022 (Act No. 5 of 2022)
Data Protection Act, 2022 (Act No. 5 of 2022)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 4 March 2022.
A comprehensive regime rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Obtain a lawful basis, such as the data subject's explicit consent, contractual necessity, or compliance with a legal obligation, before processing personal data of an identifiable individual, whether by automated or non-automated means.
- Do not process sensitive personal information, including biometric data, genetic data, and data revealing race, political opinion, religion, trade-union membership, gender, health, or sex life, unless a listed exemption applies, and obtain prior parental consent where the data subject is a child.
- Notify the Eswatini Communications Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person.
- Do not base a decision that has a legal effect on a person, or that significantly affects them, solely on automated processing of their personal information intended to profile aspects of their personality or habits, except in narrow contract or statutory circumstances.
- Before transferring personal information outside Eswatini, confirm the recipient is in a SADC Member State that has transposed the SADC data protection requirements, or, for a non-SADC recipient, confirm an adequate level of protection or rely on a listed derogation such as consent.
- Give a data subject notice, before collecting personal information about them, of who is responsible for the processing and its purpose, and let them access, correct, and challenge the personal information held about them.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Section 53 makes it an offence, on conviction, to hinder, obstruct or unlawfully influence the Commission, breach confidentiality rules, unlawfully obtain or receive personal information, hinder execution of a search warrant, or violate the Act's obligations without reasonable cause, punishable by a fine of up to E100,000,000 or five percent of the data controller's annual turnover, or imprisonment of up to ten years, or both; where the offender is a juristic person, the sentence is served by the head of the data controller.
Penalty structure
Section 53's text lists the fine, the turnover percentage, and imprisonment as alternative penalties on conviction (a fine not exceeding E100,000,000, or five percent of the data controller's annual turnover, or imprisonment not exceeding ten years, or both) without itself stating a comparison rule between the fixed and percentage figures; higher_of is recorded here as the worst-case exposure a court could impose under either cap, not as a rule the text states in those words. Separately, section 6(3)(b) lets the Commission impose a narrower administrative fine, not exceeding E5,000,000 or two percent of annual turnover, where a data controller fails to comply with a compliance notice; neither track exceeds the fixed_cap recorded here.
- Rule
- Higher of
- As of
- 6 September 2026
- Currency
- SZL
- Fixed cap
- 100,000,000
- Turnover percentage cap
- 5
Who enforces it
Enforcement body
Eswatini Communications Commission (ESCCOM)
What it reaches
Obligation class
Consent, Biometric, Data subject rights, Transfer, Breach notice, Disclosure, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Data Protection Act, 2022 (Act No. 5 of 2022) provides for the collection, processing, disclosure, and protection of personal data, and applies to a data controller or data processor, whether or not domiciled in Eswatini, that uses automated or non-automated means in Eswatini to process personal information, and to processing performed wholly or partly by automated means (s. 3), subject only to narrow exemptions for purely personal or household activity, de-identified information, and specified State functions such as national security, defence, and public safety (s. 4).
Processing needs a lawful basis, most often the data subject's explicit consent, contractual necessity, or compliance with a legal obligation (s. 9), and sensitive personal information, which includes biometric data alongside genetic data, health data, and data revealing race, political opinion, religion, trade-union membership, or sex life, may not be processed unless a listed exemption applies, including prior parental consent where the data subject is a child (ss. 22, 29).
A data controller must notify the Commission and the affected data subject, as soon as reasonably possible after discovery, of unauthorised access to or acquisition of a data subject's personal information, unless the data subject cannot be identified (s. 17).
A person may not be subjected to a decision that has a legal effect on them, or significantly affects them, based solely on automated processing intended to profile aspects of their personality or habits, except where taken in connection with a contract at the data subject's request or under another law with safeguards in place (s. 45).
Transferring personal information outside Eswatini requires the recipient to be in a SADC Member State that has transposed the SADC data-protection requirements, or, for a non-SADC recipient, an adequacy assessment or a listed derogation such as consent (ss. 32, 33).
Enforcement combines the Commission's power to impose an administrative fine of up to E5,000,000 or two percent of annual turnover for non-compliance with a compliance notice (s. 6(3)(b)), a data subject's civil right of action for damages for breach of any provision of the Act (s. 43), a Commission-run class-action system (s. 50), and a criminal offence, on conviction, for hindering the Commission, breaching confidentiality, unlawfully obtaining personal information, or violating the Act's obligations without reasonable cause, carrying a fine of up to E100,000,000 or five percent of the data controller's annual turnover, or imprisonment of up to ten years, or both (s. 53).
When LexLint raises it
crawls_webtrains_modelsautomated_outreachhigh_risk_decisionsprocesses_biometrics