Data Protection Act, 2024 (Act No. 18 of 2024)
Data Protection Act, 2024 (Act No. 18 of 2024), ss. 1-5, 19-28, 51-62, 65-73
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 14 January 2025.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Obtain a lawful basis before processing personal data of a person in Botswana, or of a person elsewhere if the processing is by a controller or processor established in Botswana.
- Process personal data lawfully, fairly and transparently, only for a specified and legitimate purpose, and collect no more than is adequate and relevant to that purpose.
- Be able to demonstrate that a data subject has consented to processing based on consent, and let the data subject withdraw that consent at any time.
- Implement appropriate technical and organisational measures, including data protection by design and by default, to secure personal data at a level appropriate to the risk and to be able to demonstrate compliance with the Act.
- Carry out a data protection impact assessment before processing that is likely to result in a high risk to a natural person's rights and freedoms, and designate a data protection officer where your core activities require regular and systematic large-scale monitoring, or large-scale processing of sensitive personal data or of data relating to criminal convictions and offences.
What it reaches
Obligation class
Consent, Governance, DPIA, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Data Protection Act, 2024 (Act No. 18 of 2024) applies to automated and non-automated processing of personal data by a controller or processor established in Botswana, and reaches a foreign controller or processor that offers goods or services to people in Botswana or monitors their behaviour there; it binds the State and excludes only purely personal or household processing and specified state functions.
A controller or processor must process personal data lawfully, fairly and transparently, only for a specified and legitimate purpose, and must collect no more than is adequate and relevant to that purpose. Where processing is based on consent, the controller must be able to demonstrate that the data subject consented, and a data subject may withdraw consent at any time.
A controller and processor must implement appropriate technical and organisational measures, including data protection by design and by default, to secure personal data at a level appropriate to the risk and to be able to demonstrate compliance with the Act.
A controller must carry out a data protection impact assessment before processing that is likely to result in a high risk to a natural person's rights and freedoms, and a controller or processor must designate a data protection officer where its core activities require regular and systematic large-scale monitoring, or large-scale processing of sensitive personal data or of data relating to criminal convictions and offences.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachprocesses_voiceprocesses_biometrics
Read the law
Data Protection Act
2024, Government Gazette Extraordinary Vol. LXII, No. 144 of 29 October 2024, reproduced by dpo-india.com, with the commencement day from the Botswana Laws bulletin entry for the Act
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.