Comprehensive regime
Data Protection Act, 2022 (Act No. 5 of 2022)
Data Protection Act, 2022 (Act No. 5 of 2022)Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)
In force since 4 March 2022. Binds public and private bodies.
What this law does
The Data Protection Act, 2022 (Act No. 5 of 2022) provides for the collection, processing, disclosure, and protection of personal data, and applies to a data controller or data processor, whether or not domiciled in Eswatini, that uses automated or non-automated means in Eswatini to process personal information, and to processing performed wholly or partly by automated means (s. 3), subject only to narrow exemptions for purely personal or household activity, de-identified information, and specified State functions such as national security, defence, and public safety (s. 4).
Processing needs a lawful basis, most often the data subject's explicit consent, contractual necessity, or compliance with a legal obligation (s. 9), and sensitive personal information, which includes biometric data alongside genetic data, health data, and data revealing race, political opinion, religion, trade-union membership, or sex life, may not be processed unless a listed exemption applies, including prior parental consent where the data subject is a child (ss. 22, 29).
A data controller must notify the Commission and the affected data subject, as soon as reasonably possible after discovery, of unauthorised access to or acquisition of a data subject's personal information, unless the data subject cannot be identified (s. 17).
A person may not be subjected to a decision that has a legal effect on them, or significantly affects them, based solely on automated processing intended to profile aspects of their personality or habits, except where taken in connection with a contract at the data subject's request or under another law with safeguards in place (s. 45).
Transferring personal information outside Eswatini requires the recipient to be in a SADC Member State that has transposed the SADC data-protection requirements, or, for a non-SADC recipient, an adequacy assessment or a listed derogation such as consent (ss. 32, 33).
Enforcement combines the Commission's power to impose an administrative fine of up to E5,000,000 or two percent of annual turnover for non-compliance with a compliance notice (s. 6(3)(b)), a data subject's civil right of action for damages for breach of any provision of the Act (s. 43), a Commission-run class-action system (s. 50), and a criminal offence, on conviction, for hindering the Commission, breaching confidentiality, unlawfully obtaining personal information, or violating the Act's obligations without reasonable cause, carrying a fine of up to E100,000,000 or five percent of the data controller's annual turnover, or imprisonment of up to ten years, or both (s. 53).
What it requires