Law / Eswatini

Data Protection Act, 2022, notification of security compromises

Data Protection Act, 2022, s. 17 (notification of security compromises)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 4 March 2022.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Eswatini Communications Commission and the affected data subject as soon as reasonably possible after discovering that a data subject's personal information has been accessed or acquired by an unauthorised person, unless the data subject's identity cannot be established.
  • Take into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise when timing your notification, but do not use that as a reason to delay beyond what is reasonably possible.
  • Delay notification to the data subject only where the Police or the Commission determines that notification would impede a criminal investigation.
  • Communicate the notification to the data subject in writing, by mail, email, a prominent website posting, publication in the news media, or as the Commission directs, and include enough information to let the data subject take protective measures, including the identity of the unauthorised person if known.
  • Publicise the compromise in the manner the Commission specifies, where the Commission has reasonable grounds to believe publicity would protect an affected data subject.

What it reaches

Obligation class

Breach notice, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 17(1) requires a data controller, on reasonable grounds to believe a data subject's personal information has been accessed or acquired by an unauthorised person, to notify the Commission and the data subject unless the data subject's identity cannot be established.

Section 17(2) requires that notification to be made as soon as reasonably possible after discovery of the compromise, taking into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise and restore the integrity of the controller's information system.

Section 17(3) requires the controller to delay notification to the data subject where the Police or the Commission determines that notification would impede a criminal investigation.

Section 17(4) requires the notification to the data subject to be in writing, delivered by post, email, a prominent website posting, publication in the news media, or another method the Commission directs, and section 17(5) requires it to contain enough information for the data subject to take protective measures, including the identity of the unauthorised person if known.

Section 17(6) lets the Commission direct a data controller to publicise a compromise where the Commission has reasonable grounds to believe publicity would protect an affected data subject.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot

Read the law

Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app