Lesotho
Southern Africa
Lesotho has a comprehensive data protection law that is in force but effectively unenforced. The Data Protection Act, 2011 (Act No. 5 of 2012), gazetted on 22 February 2012, applies to every organisation that collects, stores, or processes personal information in Lesotho and is now recorded in ATLPF's Instruments database (AI-draft). The Act draws on the pre-GDPR / Convention 108 model and establishes data-protection principles, obligations on those handling personal information, and a supervisory Data Protection Commission. The decisive feature of the regime, however, is an enforcement vacuum: the Commission established by the Act has never been appointed. The law is therefore technically in force, and on some readings fully enforceable once a Commission exists, potentially even as to past conduct, but in practice there is no operational regulator and the statute goes largely unenforced. Because the Commission has never been constituted, no Regulator record is on file. With an instrument on file but no operational regulator, Lesotho scores in the one-instrument-without-an-operational-regulator band. The record is AI-drafted from a June 2026 verification search; detailed provisions await confirmation against the LesothoLII text.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 1 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 2 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 2 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Lesotho Communications Authority (Internet Broadcasting) Rules, 2020 (Proposed)
Enacted 1 Oct 2020
Computer Crime and Cyber Security Bill, 2024 (Lesotho)
Issuers of Electronic Payment Instruments Regulations, 2017
Enacted 1 Jan 2017
National Payment Systems Act, 2014 (Act No. 8 of 2014)
Enacted 1 Jan 2014
Artificial Intelligence Policy and Implementation Plan (Draft, Version 0.1)
Enacted 21 Jan 2025
Data Protection Act, 2011 (Act No. 5 of 2012) (Lesotho)
Enacted 22 Feb 2012
The Data Protection Commission has never been appointed, so the in-force law lacks an operational regulator and active enforcement, the defining compliance risk in the market. The Instrument record is AI-drafted and detailed provisions await confirmation against the primary text.