Data Protection in Botswana

Registration in Botswana

The Commission is responsible for creating and maintaining a public register of all data controllers. There is, however, currently no prescribed method of registration. 

A data controller is a person who alone or jointly with others determines the purposes and means of which personal data is to be processed, regardless of whether or not such data is processed by such person or agent on that person's behalf. Additionally, a data controller may engage a data processor, being a person who processes data on behalf of the data controller.  

In terms of the DPA, data controllers are required to notify the Commissioner of the Commission (“the Commissioner”) before carrying out any wholly or partially automated processing operation or set of such operations which are intended to serve a single purpose or serve several related purposes.

The notification should include the following details: 

  • The name and address of the data controller or data processor;
  • The purpose of the processing;
  • A description of the category or categories of a data subject and of the personal data or categories of personal data relating to the data subject;
  • The recipients to whom personal data can be disclosed to;
  • Proposed transfers of personal data to a third country; and
  • A general description to allow the Commission to preliminarily assess the appropriateness of the security measures.

The requirement for notification does not apply to operations which have the sole purpose of keeping a register that is intended to provide information to the public by virtue of any law, and for which the register is open for public inspection. In addition, the notification will not be required where a data controller has appointed a data protection representative.

Data controllers are further required to immediately notify the Commissioner of any breach to the technical or organizational security safeguards for processing of personal data.

The Commissioner has the authority to grant an exemption for notification when satisfied that:

  1. The personal data being processed has no apparent risk of infringement to the rights of the data subject;
  2. The purposes of the processing, the category of processing, the category of a data subject, the category of a recipient, and the data retention period are specified; and
  3. The data controller has appointed a data protection representative, and the Commissioner has been notified of such appointment.

Continue reading

  • no results

Previous topic
Back to top