BotswanaIn ForceData Protection

Data Protection Act, 2024

bw-dpa-2024 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Data Protection Act, 2024 (Act No. 18 of 2024) is Botswana's primary data protection legislation, passed by the National Assembly on 29 October 2024 and brought into force on 14 January 2025 by ministerial notice in the Official Gazette. It repeals and replaces the Data Protection Act 2018, which faced repeated implementation difficulties and enforcement gaps. The 2024 Act significantly modernises and strengthens Botswana's data protection framework, aligning it more closely with international standards including the GDPR. The Act applies to the processing of personal data in Botswana and extends extraterritorially to data controllers and processors based outside Botswana where they offer goods or services to individuals in Botswana or monitor their behaviour. Both public and private bodies are within scope. Data controllers must comply with principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality. The Act grants data subjects comprehensive rights: the right to access personal data held about them, to have inaccurate data rectified, to request erasure, to restrict processing, to data portability, and to object to automated decision-making and profiling. Controllers are required to notify the Information and Data Protection Commission within 72 hours of discovering a personal data breach that poses a risk to the rights and freedoms of data subjects. The Act establishes heightened protections for special categories of personal data, including health data, biometric data, genetic data, racial and ethnic origin, and data concerning children. The Information and Data Protection Commission is the independent supervisory authority under the Act. The 2024 Act substantially enhances the Commission's powers compared to its 2018 predecessor, including authority to conduct searches, seizure, and detention; advisory functions; and a greater role in guiding data controllers. Commissioners are now appointed for fixed terms, and the Commission is required to operate with full independence from the Minister. Maximum administrative fines are set at BWP 50 million or 4% of global annual turnover, whichever is higher, representing a significant increase from the 2018 Act's maximum of BWP 10 million. Cross-border data transfers require adequate protection in the destination country or appropriate safeguards such as standard contractual clauses or binding corporate rules.

Key provisions
  1. Extraterritorial application to non-Botswana controllers and processors who target or monitor individuals in Botswana
  2. Data subjects granted rights of access, rectification, erasure, restriction, portability, and objection to automated decision-making and profiling
  3. Controllers must notify the Information and Data Protection Commission within 72 hours of a personal data breach posing risk to data subjects' rights
  4. Special categories of data (health, biometric, genetic, racial origin, children's data) subject to enhanced protections and restricted lawful bases
  5. Administrative fines up to BWP 50 million or 4% of global annual turnover, whichever is higher
  6. Mandatory Data Protection Officers required for certain controllers and processors
  7. Cross-border transfers require adequate protection or appropriate safeguards such as standard contractual clauses
  8. Repeals and replaces the Data Protection Act 2018
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from BotswanaLaws.com (ACT 18 of 2024), ITLawCo (Data Protection Act 18 of 2024 Botswana), TechHive Advisory (Understanding Botswana's New Data Protection Act)