Skip to content

Evidence request lists

Botswana Data Protection Act (2024)

Evidence request list. 32 controls, 32 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Botswana DPA Part I: Preliminary

BW-DPA-s2
Interpretation

Interpretation. Section 2 defines the terms used in the Act (personal data, processing, data controller, data subject, sensitive personal data, the Commission and others).

Artefacts an auditor will ask for
  • Mapping of statutory definitions to internal terminology
  • Classification of data as personal/sensitive per s2
Where this commonly fails
  • Definitions not applied
  • Sensitive data not identified
BW-DPA-s3
Application

Application. Section 3 sets out to whom and to what processing the Act applies, including territorial scope and any excluded processing.

Artefacts an auditor will ask for
  • Determination of controller status and processing in scope
  • Records of processing subject to the Act
Where this commonly fails
  • Processing wrongly scoped out
  • Territorial application misjudged

Botswana DPA Part II: Information and Data Protection Commission

BW-DPA-s4
Establishment of the Information and Data Protection Commission

Establishment of the Commission. Section 4 continues/establishes the Information and Data Protection Commission as the supervisory authority for the Act.

Artefacts an auditor will ask for
  • Recognition of the Commission as supervisory authority
  • Engagement records with the Commission
Where this commonly fails
  • Commission role not recognised
  • No engagement with the Commission
BW-DPA-s5
Functions and powers of Commission

Functions and powers of the Commission. Section 5 sets out the Commission's functions and powers, including supervision, guidance, registration and enforcement of the Act.

Artefacts an auditor will ask for
  • Responses to Commission guidance and requirements
  • Cooperation with Commission supervision
Where this commonly fails
  • Commission requirements not met
  • No cooperation
BW-DPA-s7
Powers of the Commissioner

Powers of the Commissioner. Section 7 sets out the powers of the Commissioner in administering the Act.

Artefacts an auditor will ask for
  • Responses to Commissioner exercise of powers
  • Records of Commissioner directions and compliance
Where this commonly fails
  • Commissioner directions not complied with
  • Correspondence not tracked

Botswana DPA Part III: Commission's Specific Powers

BW-DPA-s10
Right of access to information by Commissioner

Right of access by the Commissioner. Section 10 empowers the Commissioner to access information held by a data controller for the purposes of the Act.

Artefacts an auditor will ask for
  • Procedures for providing the Commissioner access
  • Records of information provided to the Commissioner
Where this commonly fails
  • Access to the Commissioner refused or delayed
  • No procedure for Commissioner requests
BW-DPA-s11
Commission to seek rectification

Commission to seek rectification. Section 11 empowers the Commission to require a data controller to rectify personal data.

Artefacts an auditor will ask for
  • Procedures to action Commission rectification requirements
  • Records of rectifications made on Commission direction
Where this commonly fails
  • Rectification requirements not actioned
  • No procedure
BW-DPA-s12
Order to delete personal data

Order to delete personal data. Section 12 empowers the Commission to order the deletion of personal data in defined circumstances.

Artefacts an auditor will ask for
  • Procedures to action deletion orders
  • Records of deletions made on Commission order
Where this commonly fails
  • Deletion orders not actioned
  • No procedure

Botswana DPA Part IV: Requirements and Criteria for Processing Data

BW-DPA-s14
Requirements for processing

Requirements for processing. Section 14 sets out the general requirements that must be met for the lawful processing of personal data.

Artefacts an auditor will ask for
  • Documentation that processing meets the s14 requirements
  • Mapping of processing activities to lawful requirements
Where this commonly fails
  • Processing not assessed against s14
  • Requirements not documented
BW-DPA-s15
Limitation to processing

Limitation to processing. Section 15 limits processing to what is necessary and compatible with the purposes, embodying minimisation and purpose constraints.

Artefacts an auditor will ask for
  • Assessment that processing is limited to what is necessary
  • Data minimisation controls
Where this commonly fails
  • Excessive processing
  • No limitation assessment
BW-DPA-s16
Criteria for processing

Criteria for processing. Section 16 sets out the lawful criteria (including consent and other permitted grounds) under which personal data may be processed.

Artefacts an auditor will ask for
  • Record of the lawful criterion relied on for each processing
  • Consent records where consent is the basis
Where this commonly fails
  • Processing without a valid s16 criterion
  • Consent not demonstrable
BW-DPA-s17
Processing for other purposes

Processing for other purposes. Section 17 governs the further processing of personal data for purposes other than those for which it was collected.

Artefacts an auditor will ask for
  • Compatibility assessment for any new purpose
  • Records of secondary uses and their basis
Where this commonly fails
  • Secondary use without a compatible purpose
  • No compatibility assessment
BW-DPA-s18
Processing for direct marketing

Processing for direct marketing. Section 18 sets the conditions and data-subject objection rights for processing personal data for direct marketing.

Artefacts an auditor will ask for
  • Consent/opt-out records for direct marketing
  • Mechanism to honour objections to marketing
Where this commonly fails
  • Marketing without a valid basis
  • No opt-out mechanism
BW-DPA-s19
Revocation of consent

Revocation of consent. Section 19 provides the data subject the right to revoke consent and requires controllers to act on revocation.

Artefacts an auditor will ask for
  • Mechanism for data subjects to revoke consent
  • Records of consent revocations actioned
Where this commonly fails
  • No revocation mechanism
  • Revocations not actioned

Botswana DPA Part V: Processing of Sensitive Personal Data

BW-DPA-s20
Prohibition for processing of sensitive personal data

Prohibition on sensitive data. Section 20 prohibits the processing of sensitive personal data except where a permitted exception applies.

Artefacts an auditor will ask for
  • Identification of sensitive personal data
  • Permitted exception relied on for any sensitive-data processing
Where this commonly fails
  • Sensitive data processed without an exception
  • Sensitive categories not identified
BW-DPA-s21
Safeguards for processing sensitive personal data

Safeguards for sensitive data. Section 21 requires specific safeguards where sensitive personal data are processed under a permitted exception.

Artefacts an auditor will ask for
  • Documented safeguards for sensitive-data processing
  • Access restriction and confidentiality for sensitive data
Where this commonly fails
  • No enhanced safeguards
  • Access not restricted
BW-DPA-s25
Processing of genetic and biometric data

Genetic and biometric data. Section 25 imposes specific conditions on the processing of genetic and biometric personal data.

Artefacts an auditor will ask for
  • Lawful condition for genetic/biometric processing
  • Enhanced safeguards for genetic/biometric data
Where this commonly fails
  • Genetic/biometric data processed without conditions
  • No safeguards

Botswana DPA Part VI: Data Collection, Right to Access and Duties of Data Controllers

BW-DPA-s28
Information for data subject

Information for the data subject. Section 28 requires the controller to provide prescribed information to the data subject (transparency at collection).

Artefacts an auditor will ask for
  • Collection notices covering the s28 information
  • Process to provide notice at or before collection
Where this commonly fails
  • No collection notice
  • Notice missing required information
BW-DPA-s30
Rights of data subject

Rights of the data subject. Section 30 sets out the data subject's rights, including access, rectification, erasure, objection and related rights.

Artefacts an auditor will ask for
  • Procedure for handling data-subject rights requests
  • Records of requests and responses
  • Identity verification for requesters
Where this commonly fails
  • Rights requests not handled
  • No procedure
  • Statutory timeframes missed
BW-DPA-s32
Safeguards for processing of personal data

Safeguards for processing. Section 32 requires controllers to implement appropriate technical and organisational safeguards to secure personal data.

Artefacts an auditor will ask for
  • Technical and organisational security measures
  • Access controls and protection against loss/unauthorised access
  • Measures proportionate to risk
Where this commonly fails
  • Inadequate safeguards
  • No access controls
  • Security not documented
BW-DPA-s33
Notification of breach to safeguards

Notification of breach to safeguards. Section 33 requires controllers to address and notify breaches affecting the safeguards protecting personal data.

Artefacts an auditor will ask for
  • Breach response procedure and records
  • Breach register
Where this commonly fails
  • Breaches not addressed
  • No breach process
BW-DPA-s34
Obligation to notify Commissioner

Obligation to notify the Commissioner. Section 34 requires controllers to notify the Commissioner of breaches as prescribed.

Artefacts an auditor will ask for
  • Records of breach notifications to the Commissioner within required timeframes
  • Criteria for notifiable breaches
Where this commonly fails
  • Notifiable breaches not reported
  • No notification criteria
BW-DPA-s36
Data protection representative

Data protection representative. Section 36 requires the appointment of a data protection representative (officer) with defined responsibilities for compliance.

Artefacts an auditor will ask for
  • Appointment record for the data protection representative
  • Defined responsibilities and independence
  • Contact details made available
Where this commonly fails
  • No representative appointed
  • Responsibilities undefined
  • No contact point
BW-DPA-s38
Mandatory notification and registration

Mandatory notification. Section 38 requires data controllers to notify/register their processing with the Commissioner as prescribed (with the Commissioner's register under s39).

Artefacts an auditor will ask for
  • Evidence of notification/registration with the Commissioner
  • Updates to registration on change
  • Internal record of registered processing
Where this commonly fails
  • Processing not notified/registered
  • Registration not updated

Botswana DPA Part VII: Investigations and Enforcement

BW-DPA-s41
Investigation by Commissioner

Investigation by the Commissioner. Section 41 empowers the Commissioner to investigate compliance with the Act, with which controllers must cooperate.

Artefacts an auditor will ask for
  • Procedures for supporting Commissioner investigations
  • Records of investigations and responses
Where this commonly fails
  • Investigations not supported
  • Findings not remediated
BW-DPA-s42
Complaints

Complaints. Section 42 gives data subjects the right to complain to the Commissioner and sets out how complaints are handled.

Artefacts an auditor will ask for
  • Internal complaint-handling procedure
  • Cooperation with Commissioner complaints
  • Records of complaints and outcomes
Where this commonly fails
  • Complaints not handled or escalated
  • No procedure
BW-DPA-s43
Enforcement notice

Enforcement notice. Section 43 empowers the Commissioner to issue enforcement notices requiring a controller to take or refrain from specified action.

Artefacts an auditor will ask for
  • Records of any enforcement notices and compliance
  • Remediation of matters subject to notices
Where this commonly fails
  • Enforcement notices not complied with
  • Remediation not tracked
BW-DPA-s45
Appeals Tribunal

Appeals Tribunal. Section 45 establishes the Appeals Tribunal and the right to appeal decisions of the Commissioner.

Artefacts an auditor will ask for
  • Awareness of appeal rights and the Tribunal process
  • Records of any appeals
Where this commonly fails
  • Appeal rights not understood
  • Appeals not tracked

Botswana DPA Part VIII: Miscellaneous Provisions

BW-DPA-s48
Transborder flow of personal data

Transborder flow. Section 48 governs the transborder flow of personal data, requiring conditions to be met before data leaves Botswana.

Artefacts an auditor will ask for
  • Inventory of transborder data flows
  • Conditions/safeguards met for each transfer
Where this commonly fails
  • Transfers without meeting s48 conditions
  • Transfers not inventoried
BW-DPA-s49
Transfer of personal data to a third country

Transfer to a third country. Section 49 sets the conditions for transferring personal data to a third country, including adequacy and safeguards.

Artefacts an auditor will ask for
  • Adequacy assessment or safeguards for third-country transfers
  • Records of transfer mechanisms used
Where this commonly fails
  • Third-country transfers without adequacy/safeguards
  • No assessment of the recipient country
BW-DPA-s51
Offences and penalties

Offences and penalties. Section 51 sets out the offences under the Act and the corresponding penalties (fines and, in defined cases, imprisonment).

Artefacts an auditor will ask for
  • Awareness of offence and penalty exposure
  • Controls preventing penalised conduct
  • Records of any penalties and remediation
Where this commonly fails
  • Offence exposure not assessed
  • No controls against penalised conduct
BW-DPA-s52
Compensation for damages

Compensation for damages. Section 52 provides a right to compensation for damage suffered as a result of a contravention of the Act.

Artefacts an auditor will ask for
  • Awareness of compensation exposure
  • Claim-handling records
  • Legal review of contraventions
Where this commonly fails
  • Compensation exposure not assessed
  • Claims not handled
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Botswana Data Protection Act (2024) framework page.