LesothoIn ForceData Protection

Data Protection Act, 2011 (Act No. 5 of 2012) (Lesotho)

ls-dpa-2011 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Lesotho's Data Protection Act, 2011 (published as Act No. 5 of 2012 in the Government Gazette on 22 February 2012) is the country's comprehensive data protection statute. It has been in force since enactment and applies to every organisation that collects, stores, or processes personal information in Lesotho. The Act draws on the pre-GDPR / Convention 108 model and establishes data-protection principles, obligations on those handling personal information, and a supervisory Commission. The decisive feature of Lesotho's regime is an enforcement vacuum. The Act establishes a Data Protection Commission as the supervisory authority, but that Commission has never been appointed. As a result, the law is technically in force, and, on some readings, fully enforceable once a Commission exists, with enforcement potentially extending to past conduct, but in practice there is no operational regulator and the statute goes largely unenforced. This combination of a binding statute without an enforcing body is the defining characteristic of the regime and a material consideration for assessing real-world compliance risk in the market. Because the Commission has never been constituted, no Regulator record is linked to this instrument. This entry was created from a June 2026 verification search rather than from a pre-existing ATLPF research file. The primary text is available via LesothoLII. Reviewer should confirm the detailed substantive provisions (data-subject rights, sensitive-data categories, cross-border transfer rules, penalties) against that text and monitor whether the Data Protection Commission is finally appointed. Source language: English.

Key provisions
  1. Lesotho's comprehensive data protection statute: Data Protection Act 2011 (Act No. 5 of 2012), gazetted 22 February 2012, in force since enactment.
  2. Applies to every organisation collecting, storing, or processing personal information in Lesotho.
  3. Establishes data-protection principles and a Data Protection Commission as supervisory authority.
  4. The Commission has never been appointed, leaving the in-force law without an operational regulator and largely unenforced.
  5. On some readings, enforcement could extend to past conduct once a Commission is constituted.
  6. Reviewer action: confirm substantive provisions against the LesothoLII text; monitor for appointment of the Data Protection Commission and create a Regulator record if/when constituted.