Research hub / Botswana
§ Dossier · SOUTHERN AFRICA · updated 30 August 2026

Botswana

Regulator
Information and Data Protection Commission
Law
Data Protection Act 2024 (Act 18 of 2024; in force 14 January 2025, replacing the 2018 Act) ↗
Status
Law in force, enforcement not found
Authority
Information and Data Protection Commission, established 2025
in force
DP law status
Data Protection Act 2024 (Act 18 of 2024; in force 14 January 2025, replacing the 2018 Act)
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Data Protection Act, 2024 (Act 18 of 2024) IN FORCE

commenced 2025-01-14 per multiple secondary sources; NOT YET VERIFIED from the primary instrument. s.1 provides the Act 'shall come into operation on such date as the Minister may, by Order published in the Gazette, appoint' and the gazette copy records 'Date of Commencement: ON NOTICE'. The commencement Order is not held - obtain it before relying on the date. Repeals the Data Protection Act (Cap. 43:14) (s.100). · Official full text ↗

Scope
s.4: automated processing by a controller/processor established in Botswana, and non-automated processing of personal data in a file or filing system. Extraterritorial where an establishment's activities are in Botswana, or activities relate to offering goods or services to data subjects in Botswana or monitoring their behaviour in Botswana (s.4(2)). Excluded: purely personal or household activity, and State processing for national security, defence, public safety, criminal enforcement and economic grounds (s.4(3)). Sensitive personal data (s.30(1)) is the standard GDPR-family list - racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health, sex life and sexual orientation. Criminal-conviction data sits outside s.30 and is dealt with separately (e.g. the s.69 DPO trigger).
Key obligations
Designate a data protection officer where s.69(1) is triggered: processing by a public authority or body (except courts acting judicially), core activities requiring large-scale regular and systematic monitoring, or core activities involving large-scale sensitive data or criminal-conviction data; Maintain an internal record of processing activities with prescribed content (s.60) - the Act's substitute for filing anything with the Commission; Data protection by design and by default (s.52) and appropriate technical and organisational security measures (Part XI); Notify a personal data breach to the Commission without undue delay and where feasible within 72 hours, with reasons required if late (s.63); communicate high-risk breaches to data subjects (s.64); Carry out a data protection impact assessment and, where required, prior consultation (Part XII, ss.65-68); Parental consent for processing a child's personal data in the offer of information society services, with a child of 16 able to consent in the prescribed manner (s.29); Designate a written representative in Botswana where the controller or processor is not established in Botswana and s.4(2) applies (s.54); Keep a copy of any personal data transferred abroad in Botswana for the period of processing (s.74 proviso)
DPO required
Yes, in defined cases (s.69(1)): the data controller AND data processor shall designate a data protection officer where (a) processing is carried out by a public authority or body, except courts acting in their judicial capacity; (b) core activities consist of processing operations which by their nature, scope and purpose require regular and systematic monitoring of data subjects on a large scale; or (c) core activities consist of processing sensitive personal data on a large scale, or personal data relating to criminal convictions and offences. Position and duties at ss.70-72. NOTE: this is NOT the same thing as the s.54 'representative', which is the local representative a controller or processor not established in Botswana must designate.
Registration
No. The 2024 Act contains no registration duty and no notification-before-processing duty: the word 'registration' does not appear in the Act, and there is no public register of data controllers. 'Notification' in the Act refers only to rectification, erasure or restriction (s.46), personal data breach (s.63) and the Commission's own functions. The controller's filing obligation is internal - the record of processing activities under s.60. The REPEALED Data Protection Act (Cap. 43:14) did operate a notification-and-register scheme, whose compliance deadline was extended from 17 September 2023 to 17 September 2024 by Order; secondary commentary (including major international law-firm guides) still describes that repealed scheme as current.
Cross-border transfers
Part XIV (ss. 74-79), GDPR-family: general principle (s. 74) WITH A LOCAL-COPY PROVISO - a copy of the personal data being transferred must remain in Botswana for the period of processing; adequacy decisions by the Commission plus Ministerial designation by Gazette Order (s. 75, published list, 4-yearly review); appropriate safeguards without specific authorisation - binding public-authority instruments, BCRs (s. 77), Commission-adopted standard clauses, approved codes of conduct - while ad hoc contractual clauses and public-authority administrative arrangements need specific Commission authorisation (s. 76(3)); derogations (s. 78): explicit informed consent, contract performance/pre-contractual measures, contract in the data subject's interest, public interest, legal claims, vital interests, public-register transfers (partial only), and compelling legitimate interests (documented, unavailable to public authorities). (Corrected 2026-08-29: an earlier version of this field claimed intended transfers are disclosed in 'the s.48 notification to the Commissioner'. s.48 of the 2024 Act is the right to object; there is no such notification. Third-country destinations are instead recorded in the s.60 record of processing.) Verified against the archived Gazette text 2026-07-11.
Breach notification
Notify the Commission without delay and where feasible within 72 hours unless the breach is unlikely to risk data subjects' rights (late notification must be reasoned); processors notify controllers without undue delay; controllers must also immediately notify safeguard breaches.
Penalties
The two secondary accounts are BOTH in the Act - they describe different tracks. Administrative fines (ss. 82-83): up to BWP 10,000,000 or 2% of total worldwide annual turnover of the preceding financial year (whichever is higher) for contraventions of ss. 29 and 52 - i.e. the lower tier attaches specifically to children's consent for information society services and to data protection by design and by default; up to BWP 50,000,000 or 4% of worldwide turnover (whichever is higher) for contraventions of the processing principles (Parts IV-VI), data subject rights (Part VIII), third-country transfers (Part XIV) and Commission orders (s. 83(3)). Criminal offences (s. 84): failure to implement Part XI security safeguards, selling personal data, or any contravention without a specified penalty - fine of BWP 500,000 or up to 9 years' imprisonment, or both. Also: obstruction of an authorised officer - up to BWP 500,000 or 10 years (s. 15(4)); breach of confidentiality by Commission officials - up to BWP 50,000 or 3 years. All quanta verified against the archived Gazette text 2026-07-11.
Authority
Information and Data Protection Commission

Verified 2026-08-29

The regulator

Authority
Information and Data Protection Commission
Established
2025
Operational
No
Enforcing
No enforcement activity found
Publishes decisions
No

Enforcement record

No enforcement decisions could be found for this jurisdiction as of the last verification pass (30 August 2026). A country with no published enforcement is a data point, not a gap: see the methodology page for how coverage is measured.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Botswana

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.