Comprehensive regime
Data Protection Act, 2011 (Act No. 5 of 2012)
Data Protection Act, 2011 (Act No. 5 of 2012)Data Protection Act, 2011 (Act No. 5 of 2012), official text reproduced by LesLII, read through an Internet Archive capture
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22In force since 22 February 2012. Binds public and private bodies.
What this law does
The Data Protection Act, 2011 (Act No. 5 of 2012) establishes the Data Protection Commission and provides for principles regulating the processing of personal information, applying to a data controller domiciled or having its principal place of business in Lesotho, and to a controller outside Lesotho that uses automated or non-automated means in Lesotho or uses such means only for forwarding personal information (s. 3), subject to exemptions for purely personal or household activity, de-identified information, specified State national-security, defence or public-safety functions, and journalistic, artistic or literary expression necessary to reconcile privacy with freedom of expression (s. 4).
A data controller must give a data subject notice of the information being collected and its purpose before or as soon as practicable after collection (s. 25), and may not process spiritual, religious or philosophical beliefs, race or ethnic origin, trade union membership, political affiliation, health, sexual life or criminal behaviour unless a listed exemption applies (s. 29); biometric identifiers are defined in the Act (s. 2) but are not among this enumerated list, so they carry no heightened processing restriction beyond the Act's general lawfulness and security duties.
A data subject may request access to, and free of charge challenge the correctness of, personal information a controller holds about them (ss. 26-27). Where there are reasonable grounds to believe a data subject's personal information has been accessed or acquired by an unauthorised person, the data controller must notify the Commission and, unless the data subject cannot be identified, the data subject as well (s. 23(1)).
Notification to the data subject may be delayed where the Lesotho Mounted Police Service, the National Security Service or the Commission determines that it would impede a criminal investigation (s. 23(3)).
A person may not be subjected to a decision with a legal or significant effect on them based solely on automated processing intended to profile their personality or habits, except where taken in connection with a contract at the data subject's request or under another law with safeguards in place (s. 51).
Transferring personal information outside Lesotho requires the foreign recipient to be subject to a law, code of conduct or contract that effectively upholds substantially similar processing principles, or another listed condition such as the data subject's consent (s. 52). Enforcement combines the Commission's complaint-investigation-and-enforcement-notice process (ss.
39-48) with a data subject's own civil action for damages for breach of any provision of the Act (s. 49), and a criminal offence, on conviction, for hindering the Commission, breaching confidentiality rules, obstructing execution of a warrant, or violating the Act's provisions without reasonable cause, carrying a fine of up to M50,000 or imprisonment of up to five years, or both, with the sentence served by the Chief Executive Officer where the offender is a juristic person (s. 55).
What it requires