Processing of personal data in Eswatini; GDPR-aligned framework.
Key obligations
Lawful processing conditions; Registration/notification to the Authority; Security safeguards and accountability
DPO required
Required in prescribed circumstances.
Registration
Yes: with the Data Protection Authority under ESCCOM.
Cross-border transfers
Adequacy/safeguards conditions for cross-border transfers.
Breach notification
Section 17 ('Notification of security compromises'), a POPIA-model provision: where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, the controller (or a processor under its authority) must notify the Commission and the data subject as soon as reasonably possible after discovery; notification to the subject is not required where identity cannot be established and may be delayed where the Police or Commission determine it would impede an investigation. No fixed hour/day clock.
Penalties
Administrative fines up to E5,000,000 or 2% of annual turnover; offences up to E100,000,000, 5% of turnover, or 10 years' imprisonment.
Authority
Eswatini Data Protection Authority (EDPA, under Eswatini Communications Commission)
Verified 2026-07-06
The regulator
Authority
Eswatini Data Protection Authority (under the Eswatini Communications Commission)