Law / Eswatini

Eswatini

All 9 named instruments researched to a stage, across four of the six areas of law we track: 9 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (283 words)

Eswatini's comprehensive personal-data statute is the Data Protection Act, 2022 (Act No. 5 of 2022), published in the Government Gazette Extraordinary of 4 March 2022 and, under its own citation and commencement clause, in force from that same publication date; it is administered and enforced by the Eswatini Communications Commission (ESCCOM).

The Act binds any data controller or data processor, whether or not domiciled in Eswatini, that processes personal data by automated or non-automated means in the country, and reaches both public and private bodies, carving out only purely personal or household processing, de-identified data, and processing by or on behalf of the State for national security, defence, or public safety.

It classifies biometric data (fingerprinting, DNA analysis, retinal scanning, and voice recognition) as sensitive personal information alongside genetic data, health data, and data revealing race, political opinion, religion, trade-union membership, or sex life, and prohibits processing any of it unless a listed exemption applies.

A data controller must notify the Commission and the affected data subject, as soon as reasonably possible after discovering unauthorised access to or acquisition of a data subject's personal information, and may not base a legally or significantly consequential decision solely on automated profiling except in narrow circumstances with a right to human intervention.

Cross-border transfer is conditioned on the recipient being in a SADC Member State that has transposed the SADC data-protection requirements or, for a non-SADC recipient, on an adequacy assessment or a listed derogation.

Enforcement combines the Commission's own administrative fines with a data subject's civil right of action for damages and a criminal offence, on conviction, for hindering the Commission, breaching confidentiality, unlawfully obtaining personal information, or violating the Act's obligations without reasonable cause.

Breach notification

Data Protection Act, 2022, notification of security compromises

Data Protection Act, 2022, s. 17 (notification of security compromises)Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)

In force since 4 March 2022. Binds public and private bodies.

What this law does

Section 17(1) requires a data controller, on reasonable grounds to believe a data subject's personal information has been accessed or acquired by an unauthorised person, to notify the Commission and the data subject unless the data subject's identity cannot be established.

Section 17(2) requires that notification to be made as soon as reasonably possible after discovery of the compromise, taking into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise and restore the integrity of the controller's information system.

Section 17(3) requires the controller to delay notification to the data subject where the Police or the Commission determines that notification would impede a criminal investigation.

Section 17(4) requires the notification to the data subject to be in writing, delivered by post, email, a prominent website posting, publication in the news media, or another method the Commission directs, and section 17(5) requires it to contain enough information for the data subject to take protective measures, including the identity of the unauthorised person if known.

Section 17(6) lets the Commission direct a data controller to publicise a compromise where the Commission has reasonable grounds to believe publicity would protect an affected data subject.

What it requires

Comprehensive regime

Data Protection Act, 2022 (Act No. 5 of 2022)

Data Protection Act, 2022 (Act No. 5 of 2022), ss. 1-5, 7-16, 18, 21, 31, 46-48, 54-55 (general processing principles)Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)

In force since 4 March 2022. Binds public and private bodies.

What this law does

The Data Protection Act, 2022 (Act No. 5 of 2022) applies to a data controller or data processor, whether or not domiciled in Eswatini, that uses automated or non-automated means in Eswatini to process personal information, and to processing performed wholly or partly by automated means (s. 3), subject to exemptions for purely personal or household activity, de-identified information, and specified State functions such as national security, defence and public safety (s. 4).

The Eswatini Communications Commission administers the Act, promotes compliance, investigates complaints, audits data controllers, and issues codes of conduct and guidelines, and its employees are immune from civil or criminal liability for anything done in good faith in the exercise of the Commission's powers, subject to a duty to treat information they learn as confidential (ss. 5, 7-8).

Personal information may be processed only where the data subject gives explicit consent, the processing is necessary for a contract, a legal obligation, the data subject's legitimate interests, a public body's public law duty, or the legitimate interests of the controller or a third party, and personal information must be adequate, relevant and not excessive for the purpose for which it is processed (s. 9).

A data controller must collect personal information directly from the data subject except in listed circumstances, give the data subject notice of the collection's purpose and particulars, and collect it for a specified, explicit and legitimate purpose that further processing may not depart from (ss. 10-12).

Records of personal information may not be retained longer than a prescribed period absent a listed ground, and a data controller must destroy, delete or de-identify a record as soon as reasonably practicable once no longer authorised to retain it, in a manner that prevents its reconstruction (s. 13).

A data controller must take appropriate, reasonable technical and administrative measures to secure the integrity of personal information against loss, modification, damage, unauthorised destruction and unlawful access, and govern any data processor who processes information on its behalf by a written contract requiring the same confidentiality and security measures (ss. 14-16).

A data controller must take reasonably practicable steps to keep personal information complete, accurate, not misleading and up to date, and must ensure the Act's principles are complied with and demonstrable to data subjects and the Commission (ss. 18, 21).

The processing of personal information for historical, statistical or research purposes is exempt from every principle except security safeguards, information quality and de-identification for research purposes, provided the data controller establishes appropriate safeguards against other use (s. 31).

A data controller must notify the Commission of its processing of personal information before processing it and again whenever material particulars change, the Commission may issue, approve, amend or revoke codes of conduct, the head of a data controller may designate a Data Protection Officer to discharge the controller's duties under the Act, and the Minister may make regulations to give effect to the Act (ss. 46-48, 54).

A person already processing personal information when the Act commenced had two years, extendable to three by the Minister, to bring that processing into conformity with the Act and notify the Commission (s. 55).

What it requires

Cross border transfer

Data Protection Act, 2022, transfer of personal information outside Eswatini

Data Protection Act, 2022, ss. 32-33 (transfer outside Eswatini)Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)

In force since 4 March 2022. Binds public and private bodies.

What this law does

Section 32 lets personal information be transferred to a recipient in a SADC Member State that has transposed the SADC data protection requirements only where the recipient establishes that the transfer is necessary for a task carried out in the public interest or the controller's lawful functions, or establishes the necessity of the transfer with no reason to assume the data subject's legitimate interests would be prejudiced, and requires the controller to make a provisional necessity evaluation and the recipient to be able to verify that necessity later.

Section 33(1) bars transferring personal information to a recipient outside a SADC Member State, or not subject to SADC derived national law, unless an adequate level of protection is ensured in the recipient's country and the data is transferred solely to permit processing the controller was otherwise authorised to undertake, with adequacy assessed against the nature of the data, the purpose and duration of the processing, and the recipient country's laws and security measures.

Section 33(4) lets a transfer to a country outside Eswatini or SADC that lacks adequate protection proceed anyway where the data subject has unambiguously consented, where the transfer is necessary for a contract with or in the interest of the data subject, where it is necessary or legally required on important public interest grounds or for legal claims, or where it is made from a public register open to consultation.

Section 33(5) lets the Commission authorise such a transfer even without the data subject's consent where the controller satisfies the Commission that adequate safeguards for privacy and fundamental rights will be ensured, including through contractual clauses.

What it requires

Data subject rights

Data Protection Act, 2022, rights of data subjects

Data Protection Act, 2022, ss. 19-20, 44-45, 51 (rights of data subjects)Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)

In force since 4 March 2022. Binds public and private bodies.

What this law does

Section 19 gives a data subject who proves their identity the right to request free confirmation of whether a controller holds personal information about them and to request that information, including the identity of third parties who have had access to it, and gives a right to written reasons and a right to challenge those reasons where a request is denied.

Section 20 gives a data subject a free right to have inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained personal information corrected or deleted, requires the controller to answer the request within fourteen days, and requires the controller to tell every party the changed information had been disclosed to within seven working days where a correction affects a decision about the data subject.

Section 44 entitles a data subject to require a controller by notice to cease, or not begin, processing their personal data for direct marketing, and lets the Commission order compliance where the controller fails to observe that notice.

Section 45 bars a decision that has a legal effect on a person, or that significantly affects them, from being based solely on automated processing of their personal information intended to profile their personality or habits, unless the decision is taken in connection with a contract at the data subject's request with appropriate safeguards, or is governed by a law, code or body of scientific proof that specifies appropriate protective measures.

Section 51 requires a data controller that operates a whistleblowing system to preserve fairness, proportionality and openness about the scope, purpose and consequences of reporting, and requires a person implicated in a report to be informed as soon as possible of the report's existence and the facts alleged, with a right of access, rectification and deletion that does not extend to a third party's personal data without that person's express written consent.

What it requires

Enforcement supervision

Data Protection Act, 2022, enforcement and offences

Data Protection Act, 2022, ss. 6, 34-43, 49-50, 52-53 (enforcement and offences)Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)

In force since 4 March 2022. Binds public and private bodies.

What this law does

Section 6 lets the Commission issue a warning or a formal compliance notice to a data controller. Section 34 lets a person complain to the Commission alleging a contravention of the Act, and sections 35 to 40 give the Commission power to investigate, conciliate, decline to act on specified grounds, and inform the parties of the outcome.

Section 38 lets the Commission summon witnesses, administer oaths, receive evidence, and enter and search premises it reasonably suspects are connected with activities it regulates. Section 41 lets the Commission serve a data controller found to have contravened the Act with an enforcement notice requiring it to take specified steps or stop processing personal information within a stated period, and sections 42 and 49 let the controller apply to cancel or vary the notice or appeal it to a court.

Section 43 lets a data subject bring a civil action for damages against a data controller in a Court having jurisdiction for breach of any provision of the Act. Section 50 requires the Commission to set up a class action system to assist data subjects in exercising their rights.

Section 52 lets the Commission impose a warning as a sanction and, in a case of serious and immediate violation of individual rights, rule in summary proceedings to limit or cease processing or restrict access to the data processed.

Section 53 makes it an offence, on conviction, to hinder, obstruct or unlawfully influence the Commission, breach confidentiality rules made under the Act, obstruct execution of a warrant, or violate the Act's obligations without reasonable cause, punishable by a fine of up to one hundred million Emalangeni or five percent of the data controller's annual turnover, or imprisonment of up to ten years, or both, with a juristic person's sentence served by the head of the data controller.

What it requires

Sensitive categories

Data Protection Act, 2022, sensitive personal information

Data Protection Act, 2022, ss. 22-30 (sensitive personal information)Data Protection Act, 2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)

In force since 4 March 2022. Binds public and private bodies.

What this law does

Section 22 bars a data controller from processing sensitive personal information unless the Act specifically permits it.

Section 2 defines sensitive personal information to include genetic data, data related to children, data related to offences, criminal sentences or security measures, biometric data, and, where processed for what it reveals, information about racial or ethnic origin, political opinions or affiliations, religious or philosophical beliefs, trade union membership, gender, and health or sex life.

Sections 23 to 28 exempt specific processing of each listed category, including processing by a spiritual or religious organisation of its own members' beliefs, processing necessary to identify a data subject or comply with the law for race, processing by a trade union of its own members for the union's aims, processing by a political institution of its own members for the institution's aims, and processing by a medical professional, healthcare institution, insurer, school, or correctional or pension body for health or sexual life.

Personal information processed under the race, trade union or political exemptions may not be supplied to a third party without the data subject's consent. A data controller permitted to process health or sexual life information who is not otherwise bound by a confidentiality duty must treat it as confidential.

Section 29 lifts the prohibition more generally where processing is carried out with prior parental consent for a child subject to parental control, where it is necessary to establish, exercise or defend a legal right, to comply with an obligation of international public law, where the Commission has authorised it in the public interest under section 30, where the data subject consents, or where the data subject has deliberately made the information public.

Section 30 lets the Commission authorise a data controller to process personal information where the public interest in the processing substantially outweighs the interference with the data subject's privacy, or where the processing carries a clear benefit to the data subject or a third party that substantially outweighs that interference, subject to any conditions the Commission imposes.

What it requires

Scraping law1 instrument, 1 in force

Research summary (335 words)

Eswatini has no scraping-specific statute, so general law governs each dimension separately.

The Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022) criminalizes illegal access to a computer system without lawful excuse or justification (s. 3), but "access" is defined, for that section only, as "logging into a computer system" (s. 2), so reading a public, unauthenticated page without logging in falls outside a plain reading of the offence; where a person does log in without lawful excuse, that is itself an offence even without defeating a security measure, and infringing a security measure to obtain data escalates the penalty; no reported Eswatini case construes either subsection's application to a web scraper.

Part V of the same Act grants a liability safe harbor to an access, hosting, caching, hyperlink, or search-engine provider, including a search engine that automatically indexes third-party content, where the provider does not initiate the transmission, select the receiver, or modify the content, or expeditiously acts once notified of illegal material (ss. 41-46); the Act assigns no legal weight to a robots.txt directive and states no AI-training-specific rule.

No Eswatini court has ruled on the enforceability of a browsewrap or clickwrap terms of service against a scraper. The Copyright and Neighbouring Rights Act, 2018 (Act No. 4 of 2018) permits fair dealing for research or private study and for criticism, review, or news reporting (ss.

16, 21), and a quotation exception (s. 23), but enacts no text-and-data-mining exception; its definition of "literary work" extends to "tables and compilations" (s. 2), so a database is protected only as a compilation-type literary work rather than through a separate sui generis database right.

Personal-data reach over scraped public personal data is governed by the Data Protection Act, 2022, researched in full under the privacy topic; its scope provisions carry no publicly-available-data exemption, and processing that reveals a sensitive category, biometric data included, is prohibited unless a listed exception applies. No Eswatini statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine.

Computer misuse

Computer Crime and Cybercrime Act, 2022, Illegal Access

Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022), s. 3 (Illegal Access)Computer Crime and Cybercrime Act

In force since 4 March 2022. Binds public and private bodies.

What this law does

Section 3(1) makes it an offence, without needing to defeat any security measure, for a person to intentionally access the whole or any part of a computer system "without lawful excuse or justification," carrying a fine of up to E300,000 or imprisonment of up to three years, or both; "access" is defined at s. 2, in relation to this section only, as "logging into a computer system," so a plain reading does not reach merely retrieving a public, unauthenticated page without logging in.

Section 3(2) raises the penalty to a fine of up to E500,000 or imprisonment of up to five years, or both, where the person accessing under subsection (1) also infringes a security measure with intent to obtain computer data.

What it requires

Age gating law1 instrument, 1 in force

Research summary (206 words)

Eswatini has no social-media minor-access statute, app-store age-verification requirement, or age-appropriate design code, but the Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022) carries an adult-content labeling and distribution duty at section 15: a person who publishes or exhibits pornographic material without printing prescribed identification particulars or indicating its age restriction or consumer advice, who distributes, publishes, advertises, or exposes pornographic material to a child or to a non-consenting adult, or who broadcasts a pornographic film to children or non-consenting adults, commits an offence.

The same Act's section 14 separately criminalizes producing, distributing, procuring, possessing, or knowingly accessing child pornography through a computer system, and making pornography available to a child or facilitating a child's access to it; these are content and offender-focused criminal offences rather than a duty on a service to verify a user's age before granting access.

The Sexual Offences and Domestic Violence Act, 2018 similarly criminalizes making, and other conduct involving, pornographic material involving a child, again as an offender-focused offence rather than an age-verification duty on a publisher or platform; its own citation and commencement clause leaves its Act number and commencement date to be filled in, and no numbered Act citation or commencement notice has been located.

Adult content age verification (AV)

Computer Crime and Cybercrime Act, 2022, Pornography Distribution and Labeling

Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022), s. 15 (Prohibition of Distribution or Publication of Pornography)Computer Crime and Cybercrime Act

In force since 4 March 2022. Binds public and private bodies.

What this law does

Section 15(1) makes it an offence for a person to distribute, publish, advertise, or expose pornographic material to a child or to an adult without that adult's consent; to publish or exhibit pornographic material without printing the publisher's name and prescribed address particulars, or without indicating the material's age restriction or consumer advice; or to broadcast a pornographic film, publicly or privately, to children or non-consenting adults.

Each of these is punishable, on conviction, by a fine of up to E100,000 or imprisonment of up to one year, or both; section 15(2) applies the same penalty where the offender has parental power or control over the child concerned. "Child" is defined, for the whole Act, as a person under the age of eighteen years (s. 2).

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (295 words)

Eswatini has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Copyright and Neighbouring Rights Act, 2018 (Act No. 4 of 2018) is the only enacted law reaching an aggregator's reproduction of news content.

Section 22(2) lets a newspaper or periodical, or a broadcast or cable programme, reproduce an article on a current economic, political, or religious topic published in a newspaper, periodical, or broadcast, without the author's authorisation, if the right of reproduction has not been expressly reserved and sufficient acknowledgement is given; this express-reservation proviso is the closest the Act comes to an author-side opt-out, though it predates the concept of a machine-readable reservation and is not framed as one.

Section 21 separately excuses fair dealing for the purposes of criticism, review, or reporting current events, subject to sufficient acknowledgement, except by means of an audio-visual work, sound recording, broadcast, or programme-carrying signal, and except a photograph used to report current events; section 23 excuses a quotation from a literary or musical work, including a quotation from a journal article that summarizes the work, where the quotation is compatible with fair practice, does not exceed the extent justified by the purpose, and is sufficiently acknowledged.

The Act's neighbouring-rights part reaches only performers, producers of sound recordings, and broadcasting organisations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or reported case addresses whether a hyperlink is a communication to the public or whether framing or inline display changes the answer, and the Act predates the concept of a machine-readable text-and-data-mining opt-out; no reported Eswatini decision applies section 21 or 23 to a systematic news aggregator rather than a traditional newspaper or broadcaster.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.