Law / Eswatini

Eswatini

All 4 named instruments researched to a stage, across four of the six areas of law we track: 4 in force. As of 6 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (283 words)

Eswatini's comprehensive personal-data statute is the Data Protection Act, 2022 (Act No. 5 of 2022), published in the Government Gazette Extraordinary of 4 March 2022 and, under its own citation and commencement clause, in force from that same publication date; it is administered and enforced by the Eswatini Communications Commission (ESCCOM).

The Act binds any data controller or data processor, whether or not domiciled in Eswatini, that processes personal data by automated or non-automated means in the country, and reaches both public and private bodies, carving out only purely personal or household processing, de-identified data, and processing by or on behalf of the State for national security, defence, or public safety.

It classifies biometric data (fingerprinting, DNA analysis, retinal scanning, and voice recognition) as sensitive personal information alongside genetic data, health data, and data revealing race, political opinion, religion, trade-union membership, or sex life, and prohibits processing any of it unless a listed exemption applies.

A data controller must notify the Commission and the affected data subject, as soon as reasonably possible after discovering unauthorised access to or acquisition of a data subject's personal information, and may not base a legally or significantly consequential decision solely on automated profiling except in narrow circumstances with a right to human intervention.

Cross-border transfer is conditioned on the recipient being in a SADC Member State that has transposed the SADC data-protection requirements or, for a non-SADC recipient, on an adequacy assessment or a listed derogation.

Enforcement combines the Commission's own administrative fines with a data subject's civil right of action for damages and a criminal offence, on conviction, for hindering the Commission, breaching confidentiality, unlawfully obtaining personal information, or violating the Act's obligations without reasonable cause.

Comprehensive regime

Data Protection Act, 2022 (Act No. 5 of 2022)

Data Protection Act, 2022 (Act No. 5 of 2022)Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)

In force since 4 March 2022. Binds public and private bodies.

What this law does

The Data Protection Act, 2022 (Act No. 5 of 2022) provides for the collection, processing, disclosure, and protection of personal data, and applies to a data controller or data processor, whether or not domiciled in Eswatini, that uses automated or non-automated means in Eswatini to process personal information, and to processing performed wholly or partly by automated means (s. 3), subject only to narrow exemptions for purely personal or household activity, de-identified information, and specified State functions such as national security, defence, and public safety (s. 4).

Processing needs a lawful basis, most often the data subject's explicit consent, contractual necessity, or compliance with a legal obligation (s. 9), and sensitive personal information, which includes biometric data alongside genetic data, health data, and data revealing race, political opinion, religion, trade-union membership, or sex life, may not be processed unless a listed exemption applies, including prior parental consent where the data subject is a child (ss. 22, 29).

A data controller must notify the Commission and the affected data subject, as soon as reasonably possible after discovery, of unauthorised access to or acquisition of a data subject's personal information, unless the data subject cannot be identified (s. 17).

A person may not be subjected to a decision that has a legal effect on them, or significantly affects them, based solely on automated processing intended to profile aspects of their personality or habits, except where taken in connection with a contract at the data subject's request or under another law with safeguards in place (s. 45).

Transferring personal information outside Eswatini requires the recipient to be in a SADC Member State that has transposed the SADC data-protection requirements, or, for a non-SADC recipient, an adequacy assessment or a listed derogation such as consent (ss. 32, 33).

Enforcement combines the Commission's power to impose an administrative fine of up to E5,000,000 or two percent of annual turnover for non-compliance with a compliance notice (s. 6(3)(b)), a data subject's civil right of action for damages for breach of any provision of the Act (s. 43), a Commission-run class-action system (s. 50), and a criminal offence, on conviction, for hindering the Commission, breaching confidentiality, unlawfully obtaining personal information, or violating the Act's obligations without reasonable cause, carrying a fine of up to E100,000,000 or five percent of the data controller's annual turnover, or imprisonment of up to ten years, or both (s. 53).

What it requires

Scraping law1 instrument, 1 in force

Research summary (335 words)

Eswatini has no scraping-specific statute, so general law governs each dimension separately.

The Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022) criminalizes illegal access to a computer system without lawful excuse or justification (s. 3), but "access" is defined, for that section only, as "logging into a computer system" (s. 2), so reading a public, unauthenticated page without logging in falls outside a plain reading of the offence; where a person does log in without lawful excuse, that is itself an offence even without defeating a security measure, and infringing a security measure to obtain data escalates the penalty; no reported Eswatini case construes either subsection's application to a web scraper.

Part V of the same Act grants a liability safe harbor to an access, hosting, caching, hyperlink, or search-engine provider, including a search engine that automatically indexes third-party content, where the provider does not initiate the transmission, select the receiver, or modify the content, or expeditiously acts once notified of illegal material (ss. 41-46); the Act assigns no legal weight to a robots.txt directive and states no AI-training-specific rule.

No Eswatini court has ruled on the enforceability of a browsewrap or clickwrap terms of service against a scraper. The Copyright and Neighbouring Rights Act, 2018 (Act No. 4 of 2018) permits fair dealing for research or private study and for criticism, review, or news reporting (ss.

16, 21), and a quotation exception (s. 23), but enacts no text-and-data-mining exception; its definition of "literary work" extends to "tables and compilations" (s. 2), so a database is protected only as a compilation-type literary work rather than through a separate sui generis database right.

Personal-data reach over scraped public personal data is governed by the Data Protection Act, 2022, researched in full under the privacy topic; its scope provisions carry no publicly-available-data exemption, and processing that reveals a sensitive category, biometric data included, is prohibited unless a listed exception applies. No Eswatini statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine.

Computer misuse

Computer Crime and Cybercrime Act, 2022, Illegal Access

Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022), s. 3 (Illegal Access)Computer Crime and Cybercrime Act

In force since 4 March 2022. Binds public and private bodies.

What this law does

Section 3(1) makes it an offence, without needing to defeat any security measure, for a person to intentionally access the whole or any part of a computer system "without lawful excuse or justification," carrying a fine of up to E300,000 or imprisonment of up to three years, or both; "access" is defined at s. 2, in relation to this section only, as "logging into a computer system," so a plain reading does not reach merely retrieving a public, unauthenticated page without logging in.

Section 3(2) raises the penalty to a fine of up to E500,000 or imprisonment of up to five years, or both, where the person accessing under subsection (1) also infringes a security measure with intent to obtain computer data.

What it requires

Age gating law1 instrument, 1 in force

Research summary (206 words)

Eswatini has no social-media minor-access statute, app-store age-verification requirement, or age-appropriate design code, but the Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022) carries an adult-content labeling and distribution duty at section 15: a person who publishes or exhibits pornographic material without printing prescribed identification particulars or indicating its age restriction or consumer advice, who distributes, publishes, advertises, or exposes pornographic material to a child or to a non-consenting adult, or who broadcasts a pornographic film to children or non-consenting adults, commits an offence.

The same Act's section 14 separately criminalizes producing, distributing, procuring, possessing, or knowingly accessing child pornography through a computer system, and making pornography available to a child or facilitating a child's access to it; these are content and offender-focused criminal offences rather than a duty on a service to verify a user's age before granting access.

The Sexual Offences and Domestic Violence Act, 2018 similarly criminalizes making, and other conduct involving, pornographic material involving a child, again as an offender-focused offence rather than an age-verification duty on a publisher or platform; its own citation and commencement clause leaves its Act number and commencement date to be filled in, and no numbered Act citation or commencement notice has been located.

Adult content age verification (AV)

Computer Crime and Cybercrime Act, 2022, Pornography Distribution and Labeling

Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022), s. 15 (Prohibition of Distribution or Publication of Pornography)Computer Crime and Cybercrime Act

In force since 4 March 2022. Binds public and private bodies.

What this law does

Section 15(1) makes it an offence for a person to distribute, publish, advertise, or expose pornographic material to a child or to an adult without that adult's consent; to publish or exhibit pornographic material without printing the publisher's name and prescribed address particulars, or without indicating the material's age restriction or consumer advice; or to broadcast a pornographic film, publicly or privately, to children or non-consenting adults.

Each of these is punishable, on conviction, by a fine of up to E100,000 or imprisonment of up to one year, or both; section 15(2) applies the same penalty where the offender has parental power or control over the child concerned. "Child" is defined, for the whole Act, as a person under the age of eighteen years (s. 2).

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (295 words)

Eswatini has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Copyright and Neighbouring Rights Act, 2018 (Act No. 4 of 2018) is the only enacted law reaching an aggregator's reproduction of news content.

Section 22(2) lets a newspaper or periodical, or a broadcast or cable programme, reproduce an article on a current economic, political, or religious topic published in a newspaper, periodical, or broadcast, without the author's authorisation, if the right of reproduction has not been expressly reserved and sufficient acknowledgement is given; this express-reservation proviso is the closest the Act comes to an author-side opt-out, though it predates the concept of a machine-readable reservation and is not framed as one.

Section 21 separately excuses fair dealing for the purposes of criticism, review, or reporting current events, subject to sufficient acknowledgement, except by means of an audio-visual work, sound recording, broadcast, or programme-carrying signal, and except a photograph used to report current events; section 23 excuses a quotation from a literary or musical work, including a quotation from a journal article that summarizes the work, where the quotation is compatible with fair practice, does not exceed the extent justified by the purpose, and is sufficiently acknowledged.

The Act's neighbouring-rights part reaches only performers, producers of sound recordings, and broadcasting organisations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or reported case addresses whether a hyperlink is a communication to the public or whether framing or inline display changes the answer, and the Act predates the concept of a machine-readable text-and-data-mining opt-out; no reported Eswatini decision applies section 21 or 23 to a systematic news aggregator rather than a traditional newspaper or broadcaster.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.