Data Protection Act, 2022, enforcement and offences
Data Protection Act, 2022, ss. 6, 34-43, 49-50, 52-53 (enforcement and offences)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 4 March 2022.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Expect the Commission to be able to warn you or issue a formal compliance notice, and, if you fail to comply, to limit, suspend or terminate your authorisation to process personal information or impose an administrative fine of up to five million Emalangeni or two percent of your annual turnover.
- Expect a data subject to be able to complain to the Commission alleging a contravention of the Act, and expect the Commission to investigate, conciliate, or take enforcement action.
- Comply with an enforcement notice the Commission serves within the period it specifies, whether to take steps or to stop processing personal information, and know that you may apply to the Commission or a court to cancel, vary, or appeal it.
- Cooperate with a Commission investigation, including giving evidence on summons and not obstructing entry and search of premises it reasonably suspects are connected with regulated activities.
- Expect a data subject to be able to bring a civil action for damages against you in a court having jurisdiction, and expect the Commission's class action system to assist data subjects in exercising that right.
- Expect criminal liability, on conviction, of a fine of up to E100,000,000 or five percent of your annual turnover, or imprisonment of up to ten years, or both, for hindering the Commission, breaching confidentiality, obstructing a warrant, or violating the Act without reasonable cause, with a juristic person's sentence served by the head of the data controller.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Section 53 makes it an offence, on conviction, to hinder, obstruct or unlawfully influence the Commission, breach confidentiality rules, unlawfully obtain or receive personal information, hinder execution of a search warrant, or violate the Act's obligations without reasonable cause, punishable by a fine of up to E100,000,000 or five percent of the data controller's annual turnover, or imprisonment of up to ten years, or both; where the offender is a juristic person, the sentence is served by the head of the data controller.
Penalty structure
Section 53's text lists the fine, the turnover percentage, and imprisonment as alternative penalties on conviction (a fine not exceeding E100,000,000, or five percent of the data controller's annual turnover, or imprisonment not exceeding ten years, or both) without itself stating a comparison rule between the fixed and percentage figures; higher_of is recorded here as the worst-case exposure a court could impose under either cap, not as a rule the text states in those words. Separately, section 6(3)(b) lets the Commission impose a narrower administrative fine, not exceeding E5,000,000 or two percent of annual turnover, where a data controller fails to comply with a compliance notice; neither track exceeds the fixed_cap recorded here.
- Rule
- Higher of
- As of
- 6 September 2026
- Currency
- SZL
- Fixed cap
- 100,000,000
- Turnover percentage cap
- 5
Who enforces it
Enforcement body
Eswatini Communications Commission (ESCCOM)
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 6 lets the Commission issue a warning or a formal compliance notice to a data controller. Section 34 lets a person complain to the Commission alleging a contravention of the Act, and sections 35 to 40 give the Commission power to investigate, conciliate, decline to act on specified grounds, and inform the parties of the outcome.
Section 38 lets the Commission summon witnesses, administer oaths, receive evidence, and enter and search premises it reasonably suspects are connected with activities it regulates. Section 41 lets the Commission serve a data controller found to have contravened the Act with an enforcement notice requiring it to take specified steps or stop processing personal information within a stated period, and sections 42 and 49 let the controller apply to cancel or vary the notice or appeal it to a court.
Section 43 lets a data subject bring a civil action for damages against a data controller in a Court having jurisdiction for breach of any provision of the Act. Section 50 requires the Commission to set up a class action system to assist data subjects in exercising their rights.
Section 52 lets the Commission impose a warning as a sanction and, in a case of serious and immediate violation of individual rights, rule in summary proceedings to limit or cease processing or restrict access to the data processed.
Section 53 makes it an offence, on conviction, to hinder, obstruct or unlawfully influence the Commission, breach confidentiality rules made under the Act, obstruct execution of a warrant, or violate the Act's obligations without reasonable cause, punishable by a fine of up to one hundred million Emalangeni or five percent of the data controller's annual turnover, or imprisonment of up to ten years, or both, with a juristic person's sentence served by the head of the data controller.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsis_listed_company
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.