§ Dossier · SOUTHERN AFRICA · updated 22 July 2026
Lesotho
- Regulator
- Data Protection Commission (provided for; never appointed)
- Law
- Data Protection Act 2011 (Act No. 5 of 2012) ↗
- Status
- Law in force, enforcement not found
- Authority
- Data Protection Commission (provided for; never appointed)
in force
DP law status
Data Protection Act 2011 (Act No. 5 of 2012)
None found
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect
The law
Data Protection Act 2011 (Act No. 5 of 2012) IN FORCE
commenced 2012 (one of Africa's oldest DP statutes; institutionally dormant) · Official full text ↗
- Scope
- Recorded information about an identifiable individual in any form, with an enumerated definition (identifiers, history, correspondence, third-party opinions) drawn from the Canadian/PIPEDA drafting tradition rather than the GDPR family.
- Key obligations
- Processing only upon notification to the Commission (s. 25(5)); Prohibition on processing sensitive personal information unless a s. 36 exemption applies (consent, legal claims, international public law, Commission authorisation under s. 37, parental consent for children, or data made public by the subject); Sensitive categories include gender and children's data: broader than GDPR; Breach notification to Commission and data subject; civil damages action for breach (s. 49)
- DPO required
- No: the head of a data controller MAY designate officers/employees as Data Protection Officers to exercise the head's functions (s. 58); enabling, not mandatory.
- Registration
- Notification to the Commission before processing (s. 25(5)): but the Commission has never been appointed, so the formality has no working machinery.
- Cross-border transfers
- POPIA-model accountability regime (s. 52): transfers abroad only where the recipient is subject to a law, code of conduct or contract upholding substantially similar processing principles including onward-transfer restrictions, or on consent, contract necessity/pre-contractual measures, a contract in the data subject's interest, or the data subject's benefit where consent is impracticable. No prior-authorisation step - and no Commission has ever been constituted. (Verified from the archived Gazette text 2026-07-11, S27.)
- Breach notification
- Notify the Commission and the data subject as soon as reasonably possible after discovering unauthorised access or acquisition (s. 23), with law-enforcement delay grounds and prescribed communication channels.
- Penalties
- The Act relies on offence provisions and civil damages (s. 49); even when appointed, the Commission would lack administrative fining powers: a key institutional-design lesson.
- Authority
- Data Protection Commission (provided for by the Act; never appointed in 14 years)
Verified 2026-07-10
The regulator
- Authority
- Data Protection Commission (provided for; never appointed)
- Operational
- No
- Enforcing
- No enforcement activity found
- Publishes decisions
- No
Enforcement record
No enforcement decisions could be found for this jurisdiction as of the last verification pass (22 July 2026). A country with no published enforcement is a data point, not a gap: see the 54-state publication scorecard.
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Lesotho
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.