Law / Lesotho

Lesotho

9 of 12 named instruments researched to a stage, across three of the six areas of law we track: 9 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (321 words)

Lesotho's comprehensive personal-data statute is the Data Protection Act, 2011 (Act No. 5 of 2012), published in the Government Gazette of 22 February 2012 and, under its own citation and commencement clause, in force from that same publication date; it is administered by the Data Protection Commission.

The Act binds a data controller domiciled or having its principal place of business in Lesotho, and a controller outside Lesotho that uses automated or non-automated means in Lesotho or only uses such means for forwarding personal information, reaching both public and private bodies subject only to narrow exemptions for purely personal or household activity, de-identified information, State processing for national security, defence or public safety, and journalistic, artistic or literary expression.

The Act lists spiritual, religious or philosophical beliefs, race or ethnic origin, trade union membership, political affiliation, health, sexual life and criminal behaviour as sensitive personal information carrying a heightened prohibition on processing; biometric identifiers are defined in the Act but are not named among this list, so they carry no heightened restriction beyond the Act's general lawfulness, purpose-limitation and security duties that apply to personal information generally.

A data controller must notify the Data Protection Commission and the affected data subject of a security compromise. Notification to the data subject may be delayed where the Lesotho Mounted Police Service, the National Security Service or the Commission determines that it would impede a criminal investigation, and a person may not be subjected to a legally or significantly consequential decision based solely on automated profiling except in narrow contract-related circumstances.

Cross-border transfer requires the foreign recipient to be subject to a law, code of conduct or contract that substantially upholds equivalent processing principles, or another listed condition. Enforcement combines a Commission-run complaints and investigation process with a data subject's own civil right of action for damages, and a criminal offence, on conviction, for hindering the Commission, breaching confidentiality, or violating the Act's provisions.

Breach notification

Data Protection Act, 2011, notification of security compromises

Data Protection Act, 2011, s. 23 (notification of security compromises)Data Protection Act, 2011 (Act No. 5 of 2012), official text reproduced by LesLII, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22

In force since 22 February 2012. Binds public and private bodies.

What this law does

Section 23(1) requires a data controller, on reasonable grounds to believe a data subject's personal information has been accessed or acquired by an unauthorised person, to notify the Commission and the data subject unless the data subject's identity cannot be established.

Section 23(2) requires that notification to be made as soon as reasonably possible after discovery of the compromise, taking into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise and restore the integrity of the controller's information system.

Section 23(3) requires the controller to delay notification to the data subject where the Lesotho Mounted Police Service, the National Security Service or the Commission determines that notification would impede a criminal investigation.

Section 23(4) requires the notification to the data subject to be in writing, delivered by post, email, a prominent website posting, publication in the news media, or another method the Commission directs, and section 23(5) requires it to contain enough information for the data subject to take protective measures, including the identity of the unauthorised person if known.

Section 23(6) lets the Commission direct a data controller to publicise a compromise where the Commission has reasonable grounds to believe publicity would protect an affected data subject.

What it requires

Comprehensive regime

Data Protection Act, 2011 (Act No. 5 of 2012)

Data Protection Act, 2011 (Act No. 5 of 2012), ss. 1-22, 24, 28, 38, 53-54, 56-57 (general processing principles)Data Protection Act, 2011 (Act No. 5 of 2012), official text reproduced by LesLII, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22

In force since 22 February 2012. Binds public and private bodies.

What this law does

The Data Protection Act, 2011 (Act No. 5 of 2012) establishes the Data Protection Commission and applies to a data controller domiciled or having its principal place of business in Lesotho, and to a controller outside Lesotho that uses automated or non-automated means in Lesotho or uses such means only for forwarding personal information (s. 3), subject to exemptions for purely personal or household activity, de-identified information, specified State national security, defence or public safety functions, and journalistic, artistic or literary expression necessary to reconcile privacy with freedom of expression (s. 4).

Personal information may be processed only where the data subject gives explicit consent, the processing is necessary for a contract, a legal obligation, the data subject's legitimate interests, a public body's public law duty, or the legitimate interests of the controller or a third party, and personal information must be adequate, relevant and not excessive for the purpose for which it is processed (ss. 15-16).

A data controller must collect personal information directly from the data subject except in listed circumstances, and must collect it for a specified, explicit and legitimate purpose and not further process it in a way incompatible with that purpose (ss. 17-18).

Records of personal information may not be retained longer than a prescribed period absent a listed ground, and a data controller must destroy, delete or de-identify a record as soon as reasonably practicable once no longer authorised to retain it, in a manner that prevents its reconstruction (s. 19).

A data controller must take appropriate, reasonable technical measures to secure the integrity of personal information against loss, damage, unauthorised destruction and unlawful access, and govern any agent who processes information on its behalf by a written contract requiring the same confidentiality and security measures (ss. 20-22).

A data controller must take reasonably practicable steps to keep personal information complete, accurate, not misleading and up to date, and must ensure the Act's principles are complied with (ss. 24, 28). The further processing of personal information for historical, statistical or research purposes is exempt from every principle except security safeguards and information quality, provided the data controller establishes appropriate safeguards against other use (s. 38).

A data controller must notify the Commission of its processing of personal information before processing it and again whenever material particulars change, the Commission may issue, approve, amend or revoke codes of conduct, and the Minister may make regulations to give effect to the Act (ss. 53-54, 56).

A person already processing personal information when the Act commenced had two years, extendable to three by the Minister, to bring that processing into conformity with the Act and notify the Commission (s. 57).

What it requires

Cross border transfer

Data Protection Act, 2011, transfer of personal information outside Lesotho

Data Protection Act, 2011, s. 52 (transfer outside Lesotho)Data Protection Act, 2011 (Act No. 5 of 2012), official text reproduced by LesLII, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22

In force since 22 February 2012. Binds public and private bodies.

What this law does

Section 52 bars a data controller in Lesotho from transferring personal information about a data subject to a third party in a foreign country unless the recipient is subject to a law, code of conduct or contract that effectively upholds processing principles substantially similar to the Act's, including onward-transfer protections.

The prohibition also does not apply where the data subject consents to the transfer, where the transfer is necessary for the performance of a contract between the data subject and the controller or for pre-contractual measures the data subject requested, or where the transfer is necessary for a contract concluded in the data subject's interest between the controller and a third party.

The prohibition additionally does not apply where the transfer is for the data subject's benefit and it is not reasonably practicable to obtain the data subject's consent, or where it would be reasonably practicable and the data subject would likely give it.

What it requires

Data subject rights

Data Protection Act, 2011, rights of data subjects

Data Protection Act, 2011, ss. 25-27, 50-51 (rights of data subjects)Data Protection Act, 2011 (Act No. 5 of 2012), official text reproduced by LesLII, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22

In force since 22 February 2012. Binds public and private bodies.

What this law does

Section 25 requires a data controller that collects personal information directly from a data subject to take reasonably practicable steps, before or as soon as practicable after collection, to make the data subject aware of the information being collected, the controller's name and address, the purpose of collection, whether the supply of the information is mandatory, the consequences of not providing it, and the existence of the rights of access and rectification.

Section 26 gives a data subject who proves their identity the right to request free confirmation of whether a controller holds personal information about them and to request that information, including the identity of third parties who have had access to it, and gives a right to written reasons and a right to challenge those reasons where a request is denied.

Section 27 gives a data subject a free right to have inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained personal information corrected or deleted, requires the controller to answer the request within 14 days, and requires the controller to tell every party the changed information had been disclosed to within 7 working days where a correction affects a decision about the data subject.

Section 50 entitles a data subject to require a controller by notice to cease, or not begin, processing their personal data for direct marketing, and lets the Commission order compliance where the controller fails to observe that notice.

Section 51 bars a decision that has a legal effect on a person, or that significantly affects them, from being based solely on automated processing of their personal information intended to profile their personality or habits, unless the decision is taken in connection with a contract at the data subject's request with appropriate safeguards, or is governed by a law or code that specifies appropriate protective measures.

What it requires

Enforcement supervision

Data Protection Act, 2011, enforcement and offences

Data Protection Act, 2011, ss. 39-49, 55 (enforcement and offences)Data Protection Act, 2011 (Act No. 5 of 2012), official text reproduced by LesLII, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22

In force since 22 February 2012. Binds public and private bodies.

What this law does

Section 39 lets a person submit a complaint to the Commission alleging a contravention of the Act or, where an approved code of conduct applies, a grievance about a determination under that code, and sections 40 to 45 give the Commission power to investigate, conciliate, decline to act on specified grounds, and inform the parties of the outcome.

Section 43 lets the Commission summon witnesses, administer oaths, receive evidence, and apply to the Magistrate Court for a warrant to enter and search premises where there are reasonable grounds to suspect a contravention or offence.

Section 46 lets the Commission serve a data controller found to have contravened the Act with an enforcement notice requiring it to take specified steps or stop processing personal information within a stated period, and sections 47 to 48 let the controller apply to cancel or vary the notice or appeal it to a court. Section 49 lets a data subject bring a civil action for damages against a data controller in a court having jurisdiction for breach of any provision of the Act.

Section 55 makes it an offence, on conviction, to hinder, obstruct or unlawfully influence the Commission, breach confidentiality rules made under the Act, obstruct execution of a warrant, or violate the Act's provisions without reasonable cause, punishable by a fine not exceeding M50,000 or imprisonment not exceeding five years, or both, with a juristic person's sentence served by its Chief Executive Officer.

What it requires

Sensitive categories

Data Protection Act, 2011, sensitive personal information

Data Protection Act, 2011, ss. 29-37 (sensitive personal information)Data Protection Act, 2011 (Act No. 5 of 2012), official text reproduced by LesLII, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/5/eng@2012-02-22

In force since 22 February 2012. Binds public and private bodies.

What this law does

Section 29 prohibits a data controller from processing personal information concerning a child who is subject to parental control, or a data subject's spiritual, religious or philosophical beliefs, race or ethnic origin, trade union membership, political affiliation, health, sexual life or criminal behaviour, unless the Act specifically permits it.

Biometric identifiers are separately defined in the Act as a technique of personal identification based on physical characteristics including fingerprinting, DNA analysis, retinal scanning and voice recognition, but they are not among the categories section 29 lists, so they carry no heightened restriction beyond the Act's general lawfulness, purpose limitation and security duties.

Sections 30 to 35 exempt specific processing of each listed category, including processing by a spiritual or religious organisation of its own members' beliefs, processing necessary to identify a data subject or comply with the law for race, processing by a trade union of its own members for the union's aims, processing by a political institution of its own members for the institution's aims, and processing by a medical professional, healthcare institution, insurer, school, or correctional or pension body for health or sexual life, each subject to a confidentiality obligation.

Personal information processed under the spiritual, religious, race, trade union or political exemptions may not be supplied to a third party without the data subject's consent.

Section 36 lifts the prohibition more generally where processing is carried out with prior parental consent for a child subject to parental control, where it is necessary to establish, exercise or defend a legal right, to comply with an obligation of international public law, where the Commission has authorised it in the public interest under section 37, where the data subject consents, or where the data subject has deliberately made the information public.

Section 37 lets the Commission authorise a data controller to process personal information where the public interest in the processing substantially outweighs the interference with the data subject's privacy, or where the processing carries a clear benefit to the data subject or a third party that substantially outweighs that interference, subject to any conditions the Commission imposes.

What it requires

Scraping law2 instruments, 2 in force

Research summary (349 words)

Lesotho has no scraping-specific statute, so general law governs each dimension separately. A dedicated Computer Crime and Cyber Security Bill (tabled in the National Assembly in 2022 and again, in revised form, in 2024) would establish unauthorized-access and computer-misuse offences, but neither version has been confirmed passed by both chambers or brought into force, so it binds nobody yet and is not recorded as an instrument here.

In its place, the Penal Code Act, 2010 (Act No. 6 of 2012) reaches computer misuse through its general property-offence chapter: section 62 makes it an offence for a person who either lawfully or unlawfully gains access to a computer or electronic storage device owned by another to extract information the owner would have no reason to consent to, or to interfere with the device or its data with intent to secure an advantage or cause damage; because the offence turns on whether the owner would consent to the extraction, its reach over a scraper reading a genuinely public, unauthenticated page is unsettled, and section 62 is not one of the offences listed in the Code's penalty Schedule, so no fixed fine or imprisonment term attaches and a court sets the sentence at its discretion.

No Lesotho court has ruled on the enforceability of a browsewrap or clickwrap terms of service against a scraper.

The Copyright Order, 1989 (Order No. 13 of 1989) protects original literary, artistic and scientific works from the moment of creation, but excludes "mere communications of facts and data" from protection altogether (s. 5(c)) and enacts no text-and-data-mining exception; its definition of protected subject matter does not extend to a table, compilation, or database as such, so Lesotho has no sui generis database right and no compilation-specific protection either.

Personal-data reach over scraped public personal data is governed by the Data Protection Act, 2011, researched in full under the privacy topic; its scope provisions carry no publicly-available-data exemption. No Lesotho statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and no source located assigns legal weight to a robots.txt directive or states an AI-training-specific rule.

Computer misuse

Penal Code Act, 2010, Misuse of Property of Another

Penal Code Act, 2010 (Act No. 6 of 2012), s. 62Penal Code Act, 2010 (Act No. 6 of 2012), official text reproduced by LesLII, read through an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://lesotholii.org/akn/ls/act/2012/6/eng@2012-03-09

In force since 9 March 2012. Binds public and private bodies.

What this law does

Section 62(2) makes it an offence for a person who either lawfully or unlawfully gains access to a computer or electronic storage device owned by another to (a) extract from it information which he or she has no reasonable cause to believe the owner would allow to be extracted, or (b) interfere with the device or the information it contains, without the owner's consent and with no reasonable ground to believe such consent would be given, intending to secure an advantage for themselves or cause damage to the electronic data or programmes.

The offence is framed around the owner's likely consent to the extraction rather than around defeating a technical access control, so its application to a person who reads or collects data from a genuinely public, unauthenticated web page, where the owner has made the content available to any visitor, is unsettled; no reported Lesotho case construes section 62 in that context.

Section 62 is not among the sections listed in the Code's penalty Schedule, so under section 109(3) a court convicting a person under section 62 imposes such penalty as another law provides or, absent one, such penalty as it thinks fit having regard to the offence's gravity and the Sentencing Guidelines issued by the Chief Justice, rather than a fixed statutory cap.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (339 words)

Lesotho has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Copyright Order, 1989 (Order No. 13 of 1989) is the only enacted law reaching an aggregator's reproduction of news content, and it predates the internet by decades.

Section 5(b)-(c) excludes "news of the day published, broadcast or publicly communicated by any other means" and "mere communications of facts and data" from copyright protection altogether, so factual news reporting as such is never protected subject matter.

Section 9(a)(ii) ("Free use") permits, without the author's consent, quotations from a protected work with mention of source, "including quotations from newspaper articles and periodicals in the form of press summaries," provided the quotation is compatible with fair practice and does not exceed the extent justified by the purpose.

Section 11(c) permits the reproduction in the press, or communication to the public, of an article published in a newspaper or periodical on a current economic, political or religious topic, or a work of the same character broadcast or distributed by cable, unless the article or work carried an express condition prohibiting such use and provided the source is clearly indicated; this express-reservation proviso is the closest the Order comes to an author-side opt-out, though it long predates the concept of a machine-readable reservation.

Section 11(d) separately permits, for the purpose of reporting a current event, reproduction or making the work available to the public to the extent justified by the informatory purpose. The Order's neighbouring-rights part (Part IV) protects only performers, producers of phonograms, and broadcasting organisations, not a print or online news publisher as such, so no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates exists.

No statute or reported case addresses whether a hyperlink is a communication to the public or whether framing or inline display changes the answer, and the Order predates the concept of a machine-readable text-and-data-mining opt-out; no reported Lesotho decision applies section 9 or 11 to a systematic news aggregator rather than a traditional newspaper or broadcaster.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.