Research hub / Lesotho
§ Dossier · SOUTHERN AFRICA · updated 22 July 2026

Lesotho

Regulator
Data Protection Commission (provided for; never appointed)
Law
Data Protection Act 2011 (Act No. 5 of 2012) ↗
Status
Law in force, enforcement not found
Authority
Data Protection Commission (provided for; never appointed)
in force
DP law status
Data Protection Act 2011 (Act No. 5 of 2012)
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Data Protection Act 2011 (Act No. 5 of 2012) IN FORCE

commenced 2012 (one of Africa's oldest DP statutes; institutionally dormant) · Official full text ↗

Scope
Recorded information about an identifiable individual in any form, with an enumerated definition (identifiers, history, correspondence, third-party opinions) drawn from the Canadian/PIPEDA drafting tradition rather than the GDPR family.
Key obligations
Processing only upon notification to the Commission (s. 25(5)); Prohibition on processing sensitive personal information unless a s. 36 exemption applies (consent, legal claims, international public law, Commission authorisation under s. 37, parental consent for children, or data made public by the subject); Sensitive categories include gender and children's data: broader than GDPR; Breach notification to Commission and data subject; civil damages action for breach (s. 49)
DPO required
No: the head of a data controller MAY designate officers/employees as Data Protection Officers to exercise the head's functions (s. 58); enabling, not mandatory.
Registration
Notification to the Commission before processing (s. 25(5)): but the Commission has never been appointed, so the formality has no working machinery.
Cross-border transfers
POPIA-model accountability regime (s. 52): transfers abroad only where the recipient is subject to a law, code of conduct or contract upholding substantially similar processing principles including onward-transfer restrictions, or on consent, contract necessity/pre-contractual measures, a contract in the data subject's interest, or the data subject's benefit where consent is impracticable. No prior-authorisation step - and no Commission has ever been constituted. (Verified from the archived Gazette text 2026-07-11, S27.)
Breach notification
Notify the Commission and the data subject as soon as reasonably possible after discovering unauthorised access or acquisition (s. 23), with law-enforcement delay grounds and prescribed communication channels.
Penalties
The Act relies on offence provisions and civil damages (s. 49); even when appointed, the Commission would lack administrative fining powers: a key institutional-design lesson.
Authority
Data Protection Commission (provided for by the Act; never appointed in 14 years)

Verified 2026-07-10

The regulator

Authority
Data Protection Commission (provided for; never appointed)
Operational
No
Enforcing
No enforcement activity found
Publishes decisions
No

Enforcement record

No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Lesotho

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.