Data Protection Act, 2022 (Act No. 5 of 2022)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 4 March 2022.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Obtain a lawful basis, such as the data subject's explicit consent, contractual necessity, compliance with a legal obligation, or another listed ground, before processing personal information of an identifiable individual, whether by automated or non-automated means.
- Notify the Eswatini Communications Commission of your processing of personal information before you process it, and again whenever the particulars you notified change.
- Collect personal information only for a specified, explicit and legitimate purpose, and do not further process it in a way incompatible with that purpose.
- Take appropriate, reasonable technical and administrative measures to secure the integrity of personal information in your possession or under your control against loss, modification, damage, unauthorised destruction or unlawful access, and govern any data processor who processes information on your behalf by a written contract that requires the same measures.
- Destroy, delete or de-identify a record of personal information as soon as reasonably practicable after you are no longer authorised to retain it, in a manner that prevents its reconstruction.
What it reaches
Obligation class
Consent, Governance, Retention, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Data Protection Act, 2022 (Act No. 5 of 2022) applies to a data controller or data processor, whether or not domiciled in Eswatini, that uses automated or non-automated means in Eswatini to process personal information, and to processing performed wholly or partly by automated means (s. 3), subject to exemptions for purely personal or household activity, de-identified information, and specified State functions such as national security, defence and public safety (s. 4).
The Eswatini Communications Commission administers the Act, promotes compliance, investigates complaints, audits data controllers, and issues codes of conduct and guidelines, and its employees are immune from civil or criminal liability for anything done in good faith in the exercise of the Commission's powers, subject to a duty to treat information they learn as confidential (ss. 5, 7-8).
Personal information may be processed only where the data subject gives explicit consent, the processing is necessary for a contract, a legal obligation, the data subject's legitimate interests, a public body's public law duty, or the legitimate interests of the controller or a third party, and personal information must be adequate, relevant and not excessive for the purpose for which it is processed (s. 9).
A data controller must collect personal information directly from the data subject except in listed circumstances, give the data subject notice of the collection's purpose and particulars, and collect it for a specified, explicit and legitimate purpose that further processing may not depart from (ss. 10-12).
Records of personal information may not be retained longer than a prescribed period absent a listed ground, and a data controller must destroy, delete or de-identify a record as soon as reasonably practicable once no longer authorised to retain it, in a manner that prevents its reconstruction (s. 13).
A data controller must take appropriate, reasonable technical and administrative measures to secure the integrity of personal information against loss, modification, damage, unauthorised destruction and unlawful access, and govern any data processor who processes information on its behalf by a written contract requiring the same confidentiality and security measures (ss. 14-16).
A data controller must take reasonably practicable steps to keep personal information complete, accurate, not misleading and up to date, and must ensure the Act's principles are complied with and demonstrable to data subjects and the Commission (ss. 18, 21).
The processing of personal information for historical, statistical or research purposes is exempt from every principle except security safeguards, information quality and de-identification for research purposes, provided the data controller establishes appropriate safeguards against other use (s. 31).
A data controller must notify the Commission of its processing of personal information before processing it and again whenever material particulars change, the Commission may issue, approve, amend or revoke codes of conduct, the head of a data controller may designate a Data Protection Officer to discharge the controller's duties under the Act, and the Minister may make regulations to give effect to the Act (ss. 46-48, 54).
A person already processing personal information when the Act commenced had two years, extendable to three by the Minister, to bring that processing into conformity with the Act and notify the Commission (s. 55).
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbot
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.