Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022) (Eswatini)
sz-cyber-2022 · Act
The Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022) is Eswatini's dedicated cybercrime statute, enacted in 2022 alongside the Data Protection Act, 2022 as part of a package of digital-economy legislation. It criminalises a wide spectrum of conduct and equips law-enforcement agencies with extensive investigative powers, administered with reference to the national Computer Security Incident Response Team (NCSIRT). The Act creates two broad classes of offence. The first is a set of technical offences, illegal access, illegal interception, illegal data interference, illegal system interference, illegal devices, and computer-related forgery and fraud, most of which are actionable only where committed 'intentionally, without lawful excuse or justification', a formulation intended to narrow liability and avoid capturing good-faith conduct in the public interest. The second is a group of ten content-related offences spanning a broad range of subject matter, including an extensive set of provisions on child sexual abuse material ('child pornography'), cyberbullying and cyberterrorism. On procedure, the Act grants broad investigative powers subject to court approval: expedited preservation and collection of traffic data; production orders compelling service providers or individuals to hand over data; search and seizure of data or computer systems, including cross-border access where data is remotely available; and interception of content data. For enumerated serious crimes (such as murder, terrorism, corruption and drug trafficking) the Act permits installation of remote forensic tools, including spyware and keystroke loggers, under judicial authorisation, and provides for assistance and decryption orders compelling experts or service providers to help access or decrypt systems. The breadth of these surveillance powers, and the reach of the content offences, drew criticism from civil-society and digital-rights organisations, which warned of risks to privacy and free expression and of insufficient safeguards. For the ATLPF library the instrument is tagged Cybercrime with Digital Rights as a secondary topic, and is cross-referenced to Eswatini's Data Protection Act, 2022. The full text is published by the Eswatini Communications Commission (ESCCOM).
- Technical offences (actionable only if committed intentionally, without lawful excuse): illegal access, illegal interception, illegal data interference, illegal system interference, illegal devices, computer-related forgery and fraud
- Ten content-related offences, including an extensive set of child sexual abuse material ('child pornography') provisions, cyberbullying and cyberterrorism
- Procedural powers (subject to court approval): expedited preservation and collection of traffic data; production orders; search and seizure of computer systems including cross-border/remote access
- Interception of content data and installation of remote forensic tools (e.g. spyware, keystroke loggers) authorised only for enumerated serious crimes (murder, terrorism, corruption, drug trafficking)
- Assistance and decryption orders compelling service providers or experts to help access or decrypt systems
- Administered with reference to the national CSIRT (NCSIRT); full text published by ESCCOM
- Criticised by civil society for broad surveillance powers and limited safeguards