Data Protection Act, 2024
mw-dpa-2024 · Act
The Data Protection Act, 2024 (Act No. 3 of 2024) is Malawi's first standalone data protection statute, gazetted in May 2024 and brought into force on 3 June 2024. The Act replaces the data protection provisions formerly contained in Part IV of the Electronic Transactions and Cyber Security Act 2016 (No. 33 of 2016), marking a shift from embedded data protection rules within a broader cyber-statute to a dedicated, comprehensive regime aligned with contemporary international standards. Note for ATLPF editors: the Brief for this batch identified Malawi as a jurisdiction where data protection provisions sit within the ETCSA 2016 rather than a standalone law. Current research confirms that the 2024 standalone Data Protection Act has been enacted and is in force, superseding Part IV of the 2016 Act. A separate ETCSA 2016 entry may be warranted for completeness; this has been flagged in the batch report. The Act applies to the processing of personal data wholly or partly by automated means, and to non-automated processing forming part of a filing system. It covers both public and private bodies processing personal data in Malawi, and extends to organisations outside Malawi that process data relating to Malawian data subjects. The Act establishes data processing principles of lawfulness, transparency, fairness, purpose limitation, data minimisation, accuracy, storage limitation, and data integrity and confidentiality. Special categories of personal data, including health data, biometric and genetic data, racial and ethnic origin, religious belief, trade union membership, and political opinions, attract enhanced safeguards and may be processed only on specific grounds enumerated in the Act. Data subjects are granted rights of access, rectification, erasure, restriction, portability, and objection to automated decision-making. Data controllers must implement appropriate technical and organisational security measures and are required to notify the Malawi Communications Regulatory Authority (MACRA) and affected data subjects within 72 hours of a breach posing high risk to individuals' rights and freedoms. MACRA is designated as the national data protection authority, responsible for maintaining the register of data controllers and processors, investigating complaints, enforcing compliance, and providing guidance to regulated entities. The Act provides for administrative penalties proportionate to the nature and severity of violations.
- Supersedes data protection provisions in Part IV of the Electronic Transactions and Cyber Security Act 2016, establishing Malawi's first standalone data protection regime
- Data controllers required to register with MACRA and comply with data processing principles including purpose limitation and data minimisation
- Special categories of personal data (health, biometric, genetic, racial/ethnic origin, religious belief, trade union membership, political opinions) subject to heightened protections and restricted lawful bases
- Data subjects granted rights of access, rectification, erasure, restriction, portability, and objection to automated decision-making
- Controllers must notify MACRA and affected individuals within 72 hours of a data breach posing high risk to data subjects' rights and freedoms
- MACRA designated as the data protection authority with investigative, enforcement, and administrative penalty powers
- Cross-border transfers restricted to countries with adequate protection or on the basis of appropriate safeguards