Data Protection Act, 2011 (Act No. 5 of 2012)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 22 February 2012.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Obtain a lawful basis, such as the data subject's explicit consent, contractual necessity, compliance with a legal obligation, or another listed ground, before processing personal information of an identifiable individual, whether by automated or non-automated means.
- Notify the Data Protection Commission of your processing of personal information before you process it, and again whenever the particulars you notified change.
- Collect personal information only for a specified, explicit and legitimate purpose, and do not further process it in a way incompatible with that purpose.
- Take appropriate, reasonable technical measures to secure the integrity of personal information in your possession or under your control against loss, damage, unauthorised destruction or unlawful access, and govern any agent who processes information on your behalf by a written contract that requires the same measures.
- Destroy, delete or de-identify a record of personal information as soon as reasonably practicable after you are no longer authorised to retain it, in a manner that prevents its reconstruction.
What it reaches
Obligation class
Consent, Governance, Retention, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Data Protection Act, 2011 (Act No. 5 of 2012) establishes the Data Protection Commission and applies to a data controller domiciled or having its principal place of business in Lesotho, and to a controller outside Lesotho that uses automated or non-automated means in Lesotho or uses such means only for forwarding personal information (s. 3), subject to exemptions for purely personal or household activity, de-identified information, specified State national security, defence or public safety functions, and journalistic, artistic or literary expression necessary to reconcile privacy with freedom of expression (s. 4).
Personal information may be processed only where the data subject gives explicit consent, the processing is necessary for a contract, a legal obligation, the data subject's legitimate interests, a public body's public law duty, or the legitimate interests of the controller or a third party, and personal information must be adequate, relevant and not excessive for the purpose for which it is processed (ss. 15-16).
A data controller must collect personal information directly from the data subject except in listed circumstances, and must collect it for a specified, explicit and legitimate purpose and not further process it in a way incompatible with that purpose (ss. 17-18).
Records of personal information may not be retained longer than a prescribed period absent a listed ground, and a data controller must destroy, delete or de-identify a record as soon as reasonably practicable once no longer authorised to retain it, in a manner that prevents its reconstruction (s. 19).
A data controller must take appropriate, reasonable technical measures to secure the integrity of personal information against loss, damage, unauthorised destruction and unlawful access, and govern any agent who processes information on its behalf by a written contract requiring the same confidentiality and security measures (ss. 20-22).
A data controller must take reasonably practicable steps to keep personal information complete, accurate, not misleading and up to date, and must ensure the Act's principles are complied with (ss. 24, 28). The further processing of personal information for historical, statistical or research purposes is exempt from every principle except security safeguards and information quality, provided the data controller establishes appropriate safeguards against other use (s. 38).
A data controller must notify the Commission of its processing of personal information before processing it and again whenever material particulars change, the Commission may issue, approve, amend or revoke codes of conduct, and the Minister may make regulations to give effect to the Act (ss. 53-54, 56).
A person already processing personal information when the Act commenced had two years, extendable to three by the Minister, to bring that processing into conformity with the Act and notify the Commission (s. 57).
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbot
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.