Data Protection Act, 2022
sz-dpa-2022 · Act
The Data Protection Act, 2022 (Act No. 41 of 2022) is Eswatini's primary data protection legislation, enacted and brought into force on 4 March 2022. The Act provides for the lawful collection, processing, disclosure, and protection of personal information in Eswatini, and aligns the country's data protection framework with regional and international standards. Note for ATLPF editors: the Brief identified Eswatini as a 'draft-stage country' with a bill under development. Current research confirms the Data Protection Act, 2022 has been enacted and in force since 4 March 2022. The Eswatini Data Protection Authority (EDPA) has been operationally active, issuing registration certificates and guidance documents. No further investigation of bill status is required. The Act applies to data controllers and processors that use automated means to process personal information in Eswatini. Both public and private bodies are within scope. The Eswatini Communications Commission (ESCCOM) is designated as the National Data Protection Authority, operating under the brand name Eswatini Data Protection Authority (EDPA), and is responsible for administering and fostering compliance with the Act. Data controllers must process personal information in accordance with the Act's processing principles, including lawfulness, purpose limitation, and data minimisation. The Act establishes heightened protections for sensitive categories of personal information. Data controllers are required to report personal data breaches to the EDPA within 72 hours of becoming aware of the breach. Data subjects hold rights of access to their personal information, the right to correction of inaccurate data, and the right to object to processing. Data controllers and processors are required to register with the EDPA. The Commission may impose a range of sanctions for non-compliance: warnings, compliance notices, suspension of processing authorisations, or administrative fines of up to E5 million or 2% of global annual turnover, whichever is lower. Serious and repeated violations may attract criminal liability under the Act.
- Applies to data controllers and processors using automated means to process personal information in Eswatini
- ESCCOM designated as National Data Protection Authority, operating as the Eswatini Data Protection Authority (EDPA)
- Mandatory registration of data controllers and processors with the EDPA
- Data controllers must report personal data breaches to the EDPA within 72 hours of becoming aware
- Data subjects hold rights of access, correction, and objection to processing
- Sensitive categories of personal information (health, biometric, racial origin, etc.) subject to additional safeguards and restricted processing
- Sanctions range from warnings and compliance notices to fines of up to E5 million or 2% of annual turnover
- Cross-border transfers of personal information subject to adequacy and safeguard requirements