Botswana Rewrote Its Privacy Law Before the First Version Settled In
Botswana’s Data Protection Act No. 18 of 2024 did not merely adjust the country’s earlier privacy framework. It replaced it with a more operational regime that came into force on 14 January 2025.
The new Act binds the state in the circumstances it defines, expands the reach of the law to some services and monitoring connected to people in Botswana, clarifies controller and processor duties and strengthens the Information and Data Protection Commission.
The lesson is unusually useful. Passing a law is not the same as having a workable compliance system. Botswana used the 2024 rewrite to address structural and implementation gaps before the earlier regime had fully settled.
The scope now follows the service
The Act covers automated processing and structured manual records. It can also apply to controllers or processors outside Botswana where processing relates to offering goods or services to people in Botswana or monitoring their behaviour there.
International providers should therefore test scope by looking at users and processing, not only corporate presence. Local payments, location analytics, customer support and fraud monitoring may create a stronger connection than the address on the supplier contract suggests.
Processors have their own duties
The 2024 framework gives more detail to controller, processor and subprocessor relationships. A processor that decides purposes and means outside its instructions may be treated as a controller for that processing.
That makes role mapping more than contract drafting. Managed services, analytics platforms and security vendors should check whether product telemetry or reuse of customer data changes the role they actually perform.
High-risk processing needs design review
The Act provides for data protection impact assessments and data protection officers in defined circumstances. It also adds clearer protections for children’s data and expands accountability, integrity and confidentiality requirements.
Impact assessment should occur before deployment while architecture can still change. It should cover data sources, automated decisions, access, retention, vendors, failure modes and the people who could be affected.
A breach starts a 72-hour clock
A controller must notify the Commission without undue delay and, where feasible, within 72 hours after becoming aware of a personal-data breach, unless the breach is unlikely to risk people’s rights and freedoms. Processors must notify controllers without undue delay.
Where the breach is likely to create a high risk, communication to affected people is also required. The practical dependency is fast processor escalation and an incident record capable of explaining risk, scope, consequences and mitigation.
Transfers and local copies need architecture evidence
The Act regulates transfers to third countries and international organisations. Botswana’s legislative process also preserved a requirement that a copy of transferred personal data remain in Botswana for the processing period in the relevant circumstances.
Organisations should verify this at the data-flow level. A policy statement cannot prove where replicas, backups or extracted data actually reside.
What organisations should do now
- Reassess scope for services offered to people in Botswana.
- Map controller, processor, joint-controller and subprocessor roles.
- Trigger impact assessment before high-risk processing is deployed.
- Build a 72-hour breach decision and reporting workflow.
- Review children’s data, consent and age-assurance controls.
- Validate international transfer and local-copy arrangements technically.
The rewrite rewards evidence over assumption
Botswana’s 2024 Act is a reminder that privacy programmes must survive legislative iteration. Reusable controls help, but the evidence must still reflect local scope, regulator powers, transfer conditions and breach rules.
Official sources
- Government of Botswana: access to national legislation
- Botswana e-Laws: Data Protection Act 2024
- Botswana National Assembly: adopted amendments to the 2024 Bill
This article provides general information and is not legal advice.
Continue the series: Africa Cyber & Digital Law Series index


