NamibiaDraftData Protection

Data Protection Bill

na-dpb-2025 · Draft Bill

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Namibia does not yet have an enacted data protection law. The Data Protection Bill has been developed through a consultative process that began with a public call for comment by the Ministry of Information and Communication Technology (MICT) in October 2022. The Bill was revised and tabled in the National Assembly in September/October 2025, but had not been enacted as of the date of this entry (June 2026). Important note for ATLPF editors: the Brief for this batch stated that Namibia's law 'is recent (2024)' and asked for confirmation of the effective date. Current research confirms this assumption was incorrect, as of June 2026, Namibia's Data Protection Bill remains under parliamentary consideration and has not been enacted. This entry should be updated promptly if and when the Bill receives presidential assent and comes into force. The Bill, as tabled, proposes a rights-based framework drawing on international standards including the GDPR and the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention). It would apply to the processing of personal information by both public and private bodies in Namibia, establishing the first comprehensive statutory regime for data protection in the country. Key proposed provisions include data processing principles (lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, and confidentiality), comprehensive data subject rights (access, correction, erasure, and data portability), and requirements for data protection impact assessments in relation to higher-risk processing activities. The Bill proposes the creation of an independent supervisory authority, the Information Commissioner, with powers to investigate complaints, conduct audits, and impose administrative sanctions. Cross-border data transfer restrictions are included in the Bill's draft text, requiring transfers to jurisdictions with adequate data protection standards or on the basis of appropriate safeguards. Breach notification obligations for data controllers are also proposed.

Key provisions
  1. Proposes creation of an independent Information Commissioner as supervisory authority with investigative, audit, and enforcement powers
  2. Would establish data processing principles (lawfulness, purpose limitation, data minimisation, accuracy, storage limitation) applicable to all public and private bodies in Namibia
  3. Data subjects would hold rights of access, correction, erasure, and data portability
  4. Data Protection Impact Assessments required for high-risk processing activities
  5. Proposed breach notification obligations for data controllers
  6. Restrictions on cross-border transfers to jurisdictions without adequate data protection
  7. Bill tabled in National Assembly September/October 2025; not enacted as of June 2026, entry to be updated upon enactment
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from DataGuidance (Namibia overview), NAMPA (Data Protection Bill enters final stage), The Brief Namibia, APC. NOTE: Brief stated law was recent (2024), confirmed by research to still be a draft bill as of June 2026.