Electronic Transactions and Cyber Security Act, 2016 (No. 33 of 2016) (Malawi)
mw-etcsa-2016 · Act
The Electronic Transactions and Cyber Security Act, 2016 (No. 33 of 2016) is Malawi's principal statute governing electronic transactions, cyber security and computer crime. Assented to on 20 October 2016 and published in the Malawi Gazette on 4 November 2016, it remains in force. Its data-protection provisions (Part IV) were, however, replaced as Malawi's primary data-protection regime by the standalone Data Protection Act, 2024 (Act No. 3 of 2024, in force 3 June 2024); the Act's electronic-transactions and cybercrime provisions continue to operate. For cybercrime purposes, Part X (Offences) criminalises a broad range of conduct: unauthorised access to, interception of, or interference with computer data and systems; hacking, cracking and the introduction of viruses; unlawfully disabling a computer system; child pornography; cyber harassment; offensive communication; cyber stalking; spamming; illegal trade and commerce conducted electronically; and attempting, aiding or abetting these offences. The Act sets out corresponding penalties and provides investigative and procedural mechanisms to support enforcement against computer-enabled crime. On the Telecoms dimension, the Act is administered by the Malawi Communications Regulatory Authority (MACRA), Malawi's converged communications regulator, and regulates activity carried over electronic communications networks. It governs electronic transactions and electronic signatures and provides for the accreditation and supervision of certification (cryptography) service providers whose services depend on telecom infrastructure; it regulates aspects of information-society and value-added services; and it imposes duties on electronic communications service providers, including in relation to lawful interception of and access to communications and traffic data (ss.83 - 84) and cyber-security obligations on network and service operators. It does not, however, contain the sector's core licensing, spectrum-allocation, interconnection or universal-service framework: those functions sit in the companion Communications Act, 2016 (Act No. 34 of 2016), also administered by MACRA, to which this entry is cross-referenced. The two 2016 statutes (Acts Nos. 33 and 34) were enacted together as Malawi's modern communications and cyber package. Institutionally, MACRA is responsible for implementing the Act, and the Act establishes the Malawi Computer Emergency Response Team (MCERT/CERT) to coordinate incident response and national cyber-security functions. MACRA also serves as the designated data-protection authority under the successor 2024 Act, linking the instruments institutionally. For the ATLPF library this entry is retained as the combined electronic-transactions/cyber-security instrument first catalogued during the Data Protection sweep and subsequently enriched for the Cybercrime, Digital Rights and now Telecoms topics. Its Topics are Data Protection, Cybercrime, Telecoms and Digital Rights; its status is recorded as In Force on the basis that the cybercrime and electronic-transactions provisions remain operative, while Part IV (data protection) has been superseded by the Data Protection Act, 2024. It is cross-referenced to that Act and to the Communications Act, 2016. Researchers requiring Malawi's current data-protection rules should rely on the 2024 Act, and those requiring its telecoms licensing/spectrum framework on the Communications Act, 2016, rather than on this statute.
- Part X offences: unauthorised access, interception and interference with computer data/systems; hacking, cracking and introduction of viruses; unlawfully disabling a computer system
- Content and communication offences: child pornography; cyber harassment; offensive communication; cyber stalking; spamming
- Illegal electronic trade and commerce; attempting, aiding or abetting offences
- Establishes the Malawi Computer Emergency Response Team (MCERT/CERT) for incident response and coordination
- MACRA designated as implementing authority for the Act
- Telecoms nexus: administered by MACRA (the converged communications regulator); regulates electronic transactions, electronic signatures and certification/cryptography service providers carried over telecom networks, and imposes lawful interception/access duties on service providers (ss.83 - 84), while sector licensing, spectrum and universal service sit in the companion Communications Act 2016 (Act 34 of 2016)
- Part IV (data protection) superseded by the Data Protection Act, 2024 (Act No. 3 of 2024); electronic-transactions and cybercrime provisions remain in force
- Provides procedural mechanisms for investigation and enforcement of computer-enabled crime