What this law does
The Data Protection Act, 2022 (Act No. 5 of 2022) applies to a data controller or data processor, whether or not domiciled in Eswatini, that uses automated or non-automated means in Eswatini to process personal information, and to processing performed wholly or partly by automated means (s. 3), subject to exemptions for purely personal or household activity, de-identified information, and specified State functions such as national security, defence and public safety (s. 4).
The Eswatini Communications Commission administers the Act, promotes compliance, investigates complaints, audits data controllers, and issues codes of conduct and guidelines, and its employees are immune from civil or criminal liability for anything done in good faith in the exercise of the Commission's powers, subject to a duty to treat information they learn as confidential (ss. 5, 7-8).
Personal information may be processed only where the data subject gives explicit consent, the processing is necessary for a contract, a legal obligation, the data subject's legitimate interests, a public body's public law duty, or the legitimate interests of the controller or a third party, and personal information must be adequate, relevant and not excessive for the purpose for which it is processed (s. 9).
A data controller must collect personal information directly from the data subject except in listed circumstances, give the data subject notice of the collection's purpose and particulars, and collect it for a specified, explicit and legitimate purpose that further processing may not depart from (ss. 10-12).
Records of personal information may not be retained longer than a prescribed period absent a listed ground, and a data controller must destroy, delete or de-identify a record as soon as reasonably practicable once no longer authorised to retain it, in a manner that prevents its reconstruction (s. 13).
A data controller must take appropriate, reasonable technical and administrative measures to secure the integrity of personal information against loss, modification, damage, unauthorised destruction and unlawful access, and govern any data processor who processes information on its behalf by a written contract requiring the same confidentiality and security measures (ss. 14-16).
A data controller must take reasonably practicable steps to keep personal information complete, accurate, not misleading and up to date, and must ensure the Act's principles are complied with and demonstrable to data subjects and the Commission (ss. 18, 21).
The processing of personal information for historical, statistical or research purposes is exempt from every principle except security safeguards, information quality and de-identification for research purposes, provided the data controller establishes appropriate safeguards against other use (s. 31).
A data controller must notify the Commission of its processing of personal information before processing it and again whenever material particulars change, the Commission may issue, approve, amend or revoke codes of conduct, the head of a data controller may designate a Data Protection Officer to discharge the controller's duties under the Act, and the Minister may make regulations to give effect to the Act (ss. 46-48, 54).
A person already processing personal information when the Act commenced had two years, extendable to three by the Minister, to bring that processing into conformity with the Act and notify the Commission (s. 55).
What it requires