Law / Botswana

Botswana

9 of 10 named instruments researched to a stage, across three of the six areas of law we track: 9 in force. As of 19 September 2026.

When they take effect9 of 9 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 1 instrument (1 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 6 instruments (6 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (413 words)

Botswana's comprehensive personal-data statute is the Data Protection Act, 2024 (Act No. 18 of 2024), passed by the National Assembly on 19 August 2024, assented to on 24 October 2024, published in Government Gazette Extraordinary Vol. LXII, No. 144 of 29 October 2024, and brought into force on 14 January 2025 by Statutory Instrument 4 of 2025, repealing the earlier Data Protection Act, 2018 (Cap. 43:14).

It applies to automated and non-automated processing of personal data by a controller or processor established in Botswana, and reaches a foreign controller or processor that offers goods or services to people in Botswana or monitors their behaviour there; it binds the State and excludes only purely personal or household processing and specified state functions such as national security, defence, and law enforcement, to the extent adequate safeguards exist elsewhere.

It prohibits processing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used to uniquely identify a person, health data, and sex-life or sexual-orientation data, subject to listed exceptions including the data subject's explicit consent and data the data subject has manifestly made public.

A controller must notify the Information and Data Protection Commission within 72 hours of becoming aware of a personal-data breach, where feasible, unless the breach is unlikely to risk a person's rights and freedoms, and must communicate the breach to the affected person without undue delay where the risk is high. Processing a child's personal data for an information-society service offered directly to them needs parental or guardian consent unless the child is at least sixteen.

A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, subject to narrow exceptions and safeguards including human intervention and a right to contest the decision.

A transfer of personal data to a third country or an international organisation needs an adequacy finding by the Commission, appropriate safeguards such as standard contractual clauses, approved binding corporate rules, or a listed derogation, and the Act additionally requires that a copy of any transferred personal data remain in Botswana for the period of processing.

Enforcement combines administrative fines the Commission can impose directly, a private right to compensation for a data subject who suffers material or non-material damage from a contravention, and criminal offences for failing to implement required security safeguards, selling personal data, or otherwise contravening the Act where no other penalty is specified.

Breach notification

Data Protection Act, 2024, personal data breach notification

Data Protection Act, 2024 (Act No. 18 of 2024), ss. 63-64Data Protection Act

In force since 14 January 2025. Binds public and private bodies.

What this law does

Section 63(1) requires a data controller to notify the Information and Data Protection Commission of a personal-data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the data subject, and section 63(2) requires reasons for any later notification.

Section 63(3) requires a data processor to notify the data controller of a personal-data breach without undue delay after becoming aware of it. Section 64(1) requires the data controller to communicate a personal-data breach to the affected data subject without undue delay where the breach is likely to result in a high risk to that person's rights and freedoms.

What it requires

Comprehensive regime

Data Protection Act, 2024 (Act No. 18 of 2024)

Data Protection Act, 2024 (Act No. 18 of 2024), ss. 1-5, 19-28, 51-62, 65-73Data Protection Act

In force since 14 January 2025. Binds public and private bodies.

What this law does

The Data Protection Act, 2024 (Act No. 18 of 2024) applies to automated and non-automated processing of personal data by a controller or processor established in Botswana, and reaches a foreign controller or processor that offers goods or services to people in Botswana or monitors their behaviour there; it binds the State and excludes only purely personal or household processing and specified state functions.

A controller or processor must process personal data lawfully, fairly and transparently, only for a specified and legitimate purpose, and must collect no more than is adequate and relevant to that purpose. Where processing is based on consent, the controller must be able to demonstrate that the data subject consented, and a data subject may withdraw consent at any time.

A controller and processor must implement appropriate technical and organisational measures, including data protection by design and by default, to secure personal data at a level appropriate to the risk and to be able to demonstrate compliance with the Act.

A controller must carry out a data protection impact assessment before processing that is likely to result in a high risk to a natural person's rights and freedoms, and a controller or processor must designate a data protection officer where its core activities require regular and systematic large-scale monitoring, or large-scale processing of sensitive personal data or of data relating to criminal convictions and offences.

What it requires

Cross border transfer

Data Protection Act, 2024, transfer of personal data to third countries or international organisations

Data Protection Act, 2024 (Act No. 18 of 2024), Part XIV (ss. 74-79)Data Protection Act

In force since 14 January 2025. Binds public and private bodies.

What this law does

Section 74 requires any transfer of personal data from a data controller or data processor in Botswana to a data controller, data processor or other recipient in a third country or an international organisation, including an onward transfer, to be carried out under Part XIV, and additionally requires a copy of the transferred personal data to remain in Botswana for the period of processing.

Sections 75 to 78 permit a transfer where the Commission has made an adequacy decision, appropriate safeguards such as standard contractual clauses are in place, approved binding corporate rules apply, or a listed derogation applies.

What it requires

Data subject rights

Data Protection Act, 2024, rights of data subjects

Data Protection Act, 2024 (Act No. 18 of 2024), Part VIII (ss. 37-49)Data Protection Act

In force since 14 January 2025. Binds public and private bodies.

What this law does

A data subject has the right to obtain confirmation of whether their personal data is being processed and, where it is, access to it together with information on the purpose of processing, the categories of data, the recipients, the retention period, and the existence of automated decision-making, including profiling.

A data controller must act on a data subject's request to rectify, erase, restrict the processing of, port, or object to the processing of their personal data, and must inform the data subject of the outcome without undue delay and, in any event, within one month of receipt of the request, extendable by up to two further months with the Commission's approval.

Section 49 gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or significantly affects them, subject to listed exceptions, and where an exception applies the controller must let the data subject obtain human intervention, express their point of view, and contest the decision.

What it requires

Enforcement supervision

Data Protection Act, 2024, compensation, administrative fines and offences

Data Protection Act, 2024 (Act No. 18 of 2024), Part XV (ss. 80-84)Data Protection Act

In force since 14 January 2025. Binds public and private bodies.

What this law does

A data subject may lodge a complaint with the Information and Data Protection Commission if they consider that processing of their personal data contravenes the Act, and the Commission must inform the complainant of the progress and outcome of the complaint. A person who suffers material or non-material damage from a contravention of the Act is entitled to compensation from the data controller or data processor.

The Commission may impose an administrative fine of up to P50,000,000, or four percent of an undertaking's total worldwide annual turnover of the preceding financial year, whichever is higher, for a contravention of the processing principles and consent conditions, data-subject rights, cross-border transfer rules, an obligation under a restricting law, or a Commission order, and a lower fine of up to P10,000,000, or two percent of worldwide annual turnover, whichever is higher, for a contravention of the children's-consent duty or the data-protection-by-design duty specifically.

A person who fails to implement required security safeguards, who sells personal data, or who otherwise contravenes the Act where no other penalty is specified, commits an offence carrying a fine of up to P500,000 or imprisonment of up to nine years, or both.

What it requires

Sensitive categories

Data Protection Act, 2024, sensitive personal data and children's data

Data Protection Act, 2024 (Act No. 18 of 2024), s. 29, Part VI (ss. 30-33)Data Protection Act

In force since 14 January 2025. Binds public and private bodies.

What this law does

Section 29 makes processing of a child's personal data for an information-society service offered directly to them lawful only where a parent or a person with parental duties over the child has given or authorised consent, except that a child who is sixteen years of age may consent themselves.

Section 30(1) prohibits processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, and prohibits processing genetic data, biometric data used to uniquely identify a person, health data, or data concerning a person's sex life or sexual orientation, subject to the exceptions listed in section 30(2), including the data subject's explicit consent and data the data subject has manifestly made public.

Section 32 confines processing of personal data relating to criminal convictions and offences to control by a public authority, or to processing authorised by a law that provides appropriate safeguards.

What it requires

Scraping law2 instruments, 2 in force

Research summary (465 words)

Open-web crawling of public pages carries no dedicated Botswana statute.

The applicable authority for unauthorized-access questions is the Cybercrime and Computer Related Crimes Act, 2018 (Act No. 18 of 2018), which criminalizes intentionally accessing or attempting to access all or part of a computer or computer system knowing the access is unauthorised, or causing a computer system to perform a function as a result of such unauthorised access (section 4), and separately criminalizes securing unauthorised access to a computer service or intercepting data (section 5); no Botswana court decision construes how authorisation is read for a public, unauthenticated page, and the Act's own definition of "unauthorised access" turns on entitlement or consent rather than on any technical measure, so it does not by its terms exempt a public page.

The Act was assented to on 29 June 2018 and came into force on 4 July 2018 by Statutory Instrument 83 of 2018; the current consolidated Laws of Botswana list its provisions under Chapter 08:06, which the Act itself confirms it repeals and re-enacts.

The Act carries no exemption for a search engine, indexer, or host from liability for unauthorised access or interference; its only host-facing duty is a bar on a service provider disclosing that a preservation, production, or surveillance order has been made against it (section 23).

No statute or case law addressing terms-of-service enforceability (browsewrap versus clickwrap), or whether login or acceptance of terms changes the legal picture, exists; ordinary contract-formation principles under Botswana's general law of contract would be the applicable general law for a contract-formation question, but this is unsettled rather than a specific regime.

Copyright protects a database only as a compilation, never through a separate sui generis right: the Copyright and Neighbouring Rights Act, 2000 (Cap. 68:02, as amended by Act 6 of 2006) defines "literary work" to include "a table of compilation", and separately withholds the Act's private-reproduction exception from "the whole or a substantial part of a data base", so a database that is an intellectual creation through the selection or arrangement of its contents is protected as a literary work, while the underlying facts and data are not protected as such.

Personal-data reach over scraped public personal data is governed by the Data Protection Act, 2024, researched in full under the privacy topic; its scope provisions carry no publicly-available-data exemption, so ordinary personal data scraped from a public source remains within the regime's reach, and processing that reveals a sensitive category, including a biometric identifier used to uniquely identify a person, is prohibited unless a listed exception applies, one of which is data the data subject has manifestly made public.

No specific unfair-competition or misappropriation doctrine addressed to scraping, and no case law or regulatory statement giving robots.txt legal weight or addressing AI-training-specific access rules, exists.

News aggregation law1 instrument, 1 in force

Research summary (373 words)

Botswana has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is the Copyright and Neighbouring Rights Act, 2000 (Cap. 68:02, as amended by Act 6 of 2006), whose neighbouring-rights Part protects only performers, producers of sound recordings, and broadcasting organisations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

The Act lets a newspaper or periodical, broadcaster, or other communicator to the public reproduce, without the author's authorisation but subject to naming the author and source, an article on current economic, political, or religious topics published in a newspaper or periodical, or a broadcast work of the same character, provided the right to authorise such reproduction has not been expressly reserved by the author or owner of copyright (section 18(a)); this express-reservation proviso functions as an author-side opt-out mechanism for that specific exception, the closest Botswana law comes to a machine-readable reservation, though it long predates the concept of one and is not framed as machine-readable.

The Act separately permits reproducing, broadcasting, or otherwise communicating short excerpts of a work seen or heard in the course of reporting current events, to the extent justified by the purpose (section 18(b)), and permits quotation of a short part of a published work compatible with fair practice and not exceeding the extent justified by the purpose, provided the source and author are named (section 14).

Neither exception is capped at a headline-length or short-extract threshold in the way some jurisdictions' quotation rights are, the section 18(a) exception is not confined to the press industry, and no reported Botswana decision applies either provision to a systematic news aggregator as opposed to a traditional newspaper or broadcaster.

The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists, and no statute or case law addressing whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.