Botswana Data Protection Act (2024)
Evidence request list. 32 controls, 32 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Botswana DPA Part I: Preliminary
Interpretation. Section 2 defines the terms used in the Act (personal data, processing, data controller, data subject, sensitive personal data, the Commission and others).
- Mapping of statutory definitions to internal terminology
- Classification of data as personal/sensitive per s2
- Definitions not applied
- Sensitive data not identified
Application. Section 3 sets out to whom and to what processing the Act applies, including territorial scope and any excluded processing.
- Determination of controller status and processing in scope
- Records of processing subject to the Act
- Processing wrongly scoped out
- Territorial application misjudged
Botswana DPA Part II: Information and Data Protection Commission
Establishment of the Commission. Section 4 continues/establishes the Information and Data Protection Commission as the supervisory authority for the Act.
- Recognition of the Commission as supervisory authority
- Engagement records with the Commission
- Commission role not recognised
- No engagement with the Commission
Functions and powers of the Commission. Section 5 sets out the Commission's functions and powers, including supervision, guidance, registration and enforcement of the Act.
- Responses to Commission guidance and requirements
- Cooperation with Commission supervision
- Commission requirements not met
- No cooperation
Powers of the Commissioner. Section 7 sets out the powers of the Commissioner in administering the Act.
- Responses to Commissioner exercise of powers
- Records of Commissioner directions and compliance
- Commissioner directions not complied with
- Correspondence not tracked
Botswana DPA Part III: Commission's Specific Powers
Right of access by the Commissioner. Section 10 empowers the Commissioner to access information held by a data controller for the purposes of the Act.
- Procedures for providing the Commissioner access
- Records of information provided to the Commissioner
- Access to the Commissioner refused or delayed
- No procedure for Commissioner requests
Commission to seek rectification. Section 11 empowers the Commission to require a data controller to rectify personal data.
- Procedures to action Commission rectification requirements
- Records of rectifications made on Commission direction
- Rectification requirements not actioned
- No procedure
Order to delete personal data. Section 12 empowers the Commission to order the deletion of personal data in defined circumstances.
- Procedures to action deletion orders
- Records of deletions made on Commission order
- Deletion orders not actioned
- No procedure
Botswana DPA Part IV: Requirements and Criteria for Processing Data
Requirements for processing. Section 14 sets out the general requirements that must be met for the lawful processing of personal data.
- Documentation that processing meets the s14 requirements
- Mapping of processing activities to lawful requirements
- Processing not assessed against s14
- Requirements not documented
Limitation to processing. Section 15 limits processing to what is necessary and compatible with the purposes, embodying minimisation and purpose constraints.
- Assessment that processing is limited to what is necessary
- Data minimisation controls
- Excessive processing
- No limitation assessment
Criteria for processing. Section 16 sets out the lawful criteria (including consent and other permitted grounds) under which personal data may be processed.
- Record of the lawful criterion relied on for each processing
- Consent records where consent is the basis
- Processing without a valid s16 criterion
- Consent not demonstrable
Processing for other purposes. Section 17 governs the further processing of personal data for purposes other than those for which it was collected.
- Compatibility assessment for any new purpose
- Records of secondary uses and their basis
- Secondary use without a compatible purpose
- No compatibility assessment
Processing for direct marketing. Section 18 sets the conditions and data-subject objection rights for processing personal data for direct marketing.
- Consent/opt-out records for direct marketing
- Mechanism to honour objections to marketing
- Marketing without a valid basis
- No opt-out mechanism
Revocation of consent. Section 19 provides the data subject the right to revoke consent and requires controllers to act on revocation.
- Mechanism for data subjects to revoke consent
- Records of consent revocations actioned
- No revocation mechanism
- Revocations not actioned
Botswana DPA Part V: Processing of Sensitive Personal Data
Prohibition on sensitive data. Section 20 prohibits the processing of sensitive personal data except where a permitted exception applies.
- Identification of sensitive personal data
- Permitted exception relied on for any sensitive-data processing
- Sensitive data processed without an exception
- Sensitive categories not identified
Safeguards for sensitive data. Section 21 requires specific safeguards where sensitive personal data are processed under a permitted exception.
- Documented safeguards for sensitive-data processing
- Access restriction and confidentiality for sensitive data
- No enhanced safeguards
- Access not restricted
Genetic and biometric data. Section 25 imposes specific conditions on the processing of genetic and biometric personal data.
- Lawful condition for genetic/biometric processing
- Enhanced safeguards for genetic/biometric data
- Genetic/biometric data processed without conditions
- No safeguards
Botswana DPA Part VI: Data Collection, Right to Access and Duties of Data Controllers
Information for the data subject. Section 28 requires the controller to provide prescribed information to the data subject (transparency at collection).
- Collection notices covering the s28 information
- Process to provide notice at or before collection
- No collection notice
- Notice missing required information
Rights of the data subject. Section 30 sets out the data subject's rights, including access, rectification, erasure, objection and related rights.
- Procedure for handling data-subject rights requests
- Records of requests and responses
- Identity verification for requesters
- Rights requests not handled
- No procedure
- Statutory timeframes missed
Safeguards for processing. Section 32 requires controllers to implement appropriate technical and organisational safeguards to secure personal data.
- Technical and organisational security measures
- Access controls and protection against loss/unauthorised access
- Measures proportionate to risk
- Inadequate safeguards
- No access controls
- Security not documented
Notification of breach to safeguards. Section 33 requires controllers to address and notify breaches affecting the safeguards protecting personal data.
- Breach response procedure and records
- Breach register
- Breaches not addressed
- No breach process
Obligation to notify the Commissioner. Section 34 requires controllers to notify the Commissioner of breaches as prescribed.
- Records of breach notifications to the Commissioner within required timeframes
- Criteria for notifiable breaches
- Notifiable breaches not reported
- No notification criteria
Data protection representative. Section 36 requires the appointment of a data protection representative (officer) with defined responsibilities for compliance.
- Appointment record for the data protection representative
- Defined responsibilities and independence
- Contact details made available
- No representative appointed
- Responsibilities undefined
- No contact point
Mandatory notification. Section 38 requires data controllers to notify/register their processing with the Commissioner as prescribed (with the Commissioner's register under s39).
- Evidence of notification/registration with the Commissioner
- Updates to registration on change
- Internal record of registered processing
- Processing not notified/registered
- Registration not updated
Botswana DPA Part VII: Investigations and Enforcement
Investigation by the Commissioner. Section 41 empowers the Commissioner to investigate compliance with the Act, with which controllers must cooperate.
- Procedures for supporting Commissioner investigations
- Records of investigations and responses
- Investigations not supported
- Findings not remediated
Complaints. Section 42 gives data subjects the right to complain to the Commissioner and sets out how complaints are handled.
- Internal complaint-handling procedure
- Cooperation with Commissioner complaints
- Records of complaints and outcomes
- Complaints not handled or escalated
- No procedure
Enforcement notice. Section 43 empowers the Commissioner to issue enforcement notices requiring a controller to take or refrain from specified action.
- Records of any enforcement notices and compliance
- Remediation of matters subject to notices
- Enforcement notices not complied with
- Remediation not tracked
Appeals Tribunal. Section 45 establishes the Appeals Tribunal and the right to appeal decisions of the Commissioner.
- Awareness of appeal rights and the Tribunal process
- Records of any appeals
- Appeal rights not understood
- Appeals not tracked
Botswana DPA Part VIII: Miscellaneous Provisions
Transborder flow. Section 48 governs the transborder flow of personal data, requiring conditions to be met before data leaves Botswana.
- Inventory of transborder data flows
- Conditions/safeguards met for each transfer
- Transfers without meeting s48 conditions
- Transfers not inventoried
Transfer to a third country. Section 49 sets the conditions for transferring personal data to a third country, including adequacy and safeguards.
- Adequacy assessment or safeguards for third-country transfers
- Records of transfer mechanisms used
- Third-country transfers without adequacy/safeguards
- No assessment of the recipient country
Offences and penalties. Section 51 sets out the offences under the Act and the corresponding penalties (fines and, in defined cases, imprisonment).
- Awareness of offence and penalty exposure
- Controls preventing penalised conduct
- Records of any penalties and remediation
- Offence exposure not assessed
- No controls against penalised conduct
Compensation for damages. Section 52 provides a right to compensation for damage suffered as a result of a contravention of the Act.
- Awareness of compensation exposure
- Claim-handling records
- Legal review of contraventions
- Compensation exposure not assessed
- Claims not handled
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Botswana Data Protection Act (2024) framework page.