§ Dossier · SOUTHERN AFRICA · updated 22 July 2026
in force
DP law status
Data Protection Act 2024 (Act 18 of 2024; in force 14 January 2025, replacing the 2018 Act)
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Data Protection Act, 2024 (Act 18 of 2024) IN FORCE
commenced 2025-01-14 (replacing the Data Protection Act 2018) · Official full text ↗
- Scope
- Information relating to an identified or identifiable individual, processed wholly or partly by automated means or as part of a filing system; the sensitive-data definition is unusually broad, adding filiation, offence data and all personal data of minors.
- Key obligations
- Notification to the Commissioner before wholly or partly automated processing, with prescribed filing content (waived where a data protection representative is appointed or an exemption is granted); Immediate notification to the Commissioner of breaches of technical or organisational security safeguards, plus the 72-hour breach regime; Public register of data controllers maintained by the Commission; GDPR-family principles, incl. proposed-transfer disclosure in the notification
- DPO required
- No general obligation: a controller may appoint a qualified 'data protection representative' who keeps the processing list, escalates uncorrected contraventions to the Commissioner, and whose appointment/removal must be notified; appointment waives processing notification.
- Registration
- Yes: notification to the Commissioner before automated processing (public-register and representative-appointment exemptions apply); the Commission maintains a public register of controllers, though no registration method had been prescribed at last check.
- Cross-border transfers
- Part XIV (ss. 74-79), GDPR-family: general principle (s. 74) WITH A LOCAL-COPY PROVISO - a copy of the personal data being transferred must remain in Botswana for the period of processing; adequacy decisions by the Commission plus Ministerial designation by Gazette Order (s. 75, published list, 4-yearly review); appropriate safeguards without specific authorisation - binding public-authority instruments, BCRs (s. 77), Commission-adopted standard clauses, approved codes of conduct - while ad hoc contractual clauses and public-authority administrative arrangements need specific Commission authorisation (s. 76(3)); derogations (s. 78): explicit informed consent, contract performance/pre-contractual measures, contract in the data subject's interest, public interest, legal claims, vital interests, public-register transfers (partial only), and compelling legitimate interests (documented, unavailable to public authorities). Intended third-country transfers are disclosed in the s. 48 notification to the Commissioner. Verified against the archived Gazette text 2026-07-11.
- Breach notification
- Notify the Commission without delay and where feasible within 72 hours unless the breach is unlikely to risk data subjects' rights (late notification must be reasoned); processors notify controllers without undue delay; controllers must also immediately notify safeguard breaches.
- Penalties
- The two secondary accounts are BOTH in the Act - they describe different tracks. Administrative fines (ss. 82-83): up to BWP 10,000,000 or 2% of total worldwide annual turnover of the preceding financial year (whichever is higher) for contraventions of ss. 29 and 52; up to BWP 50,000,000 or 4% of worldwide turnover (whichever is higher) for contraventions of the processing principles (Parts IV-VI), data subject rights (Part VIII), third-country transfers (Part XIV) and Commission orders (s. 83(3)). Criminal offences (s. 84): failure to implement Part XI security safeguards, selling personal data, or any contravention without a specified penalty - fine of BWP 500,000 or up to 9 years' imprisonment, or both. Also: obstruction of an authorised officer - up to BWP 500,000 or 10 years (s. 15(4)); breach of confidentiality by Commission officials - up to BWP 50,000 or 3 years. All quanta verified against the archived Gazette text 2026-07-11.
- Authority
- Information and Data Protection Commission
Verified 2026-07-11
The regulator
- Authority
- Information and Data Protection Commission
- Established
- 2025
- Operational
- No
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Botswana
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.