Compliance Requirements for Personal Data Protection Legislation in Botswana and South Africa in the Digital Economy
DOI:
https://doi.org/10.25159/2663-659X/22333Keywords:
Botswana, data protection, personal data, privacy, South AfricaAbstract
Across the globe, the protection of personal data is a growing concern, particularly with personal data being increasingly collected by deployed digital technologies in the conduct of business processes. Addressing the increasing concerns for personal privacy has become an obsession in the Fourth Industrial Revolution with its disruptive technologies. Through content analysis and a review of literature, this article explores compliance requirements for personal data protection in Botswana and South Africa, with a special focus on obtaining consent from data subjects, the rights of data subjects, data security and breach notification, and offences and penalties for breaching security safeguards under the two countries’ data protection legislation. The findings reveal that both Botswana and South Africa have enacted personal data legislation, the Data Protection Act (DPA) and the Protection of Personal Information Act (POPIA), respectively to safeguard data privacy. Furthermore, the two countries have made significant gains in establishing comprehensive frameworks for the protection of personal data. Although there are similarities in goals and principles in their data protection laws, there are differences in the approaches related to areas of consent, data subject rights, breach notification, and penalties for offences under the legislation.
References
BackOffice Associates. 2018. “GDPR Is Here and I’m Not Ready! What Do I Do?” Bright Talk, May 25. Accessed May 5, 2026. https://www.brighttalk.com/webcast/16317/320823.
Bengtsson, M. 2016. “How to Plan and Perform a Qualitative Study Using Content Analysis.” NursingPlus Open 2: 8–14. https://doi.org/10.1016/j.npls.2016.01.001. DOI: https://doi.org/10.1016/j.npls.2016.01.001
Botha, G. J. 2018. “The Effects of the Protection of Personal Information Act Adoption on Personal Identifiable Information Leakages in South Africa.” MIT diss., University of South Africa.
Botha, J., M. Eloff, and M. Globler. 2016. “Ethical and Legal Issues Involved in the Proactive Collection of Personal Information to Reduce Online Disclosure.” Paper presented at the 12th IFIP International Conference on Human Choice and Computers (HCC), Salford, United Kingdom. Accessed May 5, 2026. https://inria.hal.science/hal-01449451v1/document.
Botha, J., M. M. Eloff, and I. Swart. 2016. “Pro-active Data Breach Detection: Examining Accuracy and Applicability on Personal Information Detected.” Paper presented at the International Conference on Cyber Warfare and Security (ICCWS 2016), Boston, United States. Accessed July 17, 2025. https://www.researchgate.net/publication/301295098_Pro-active_Data_Breach_Detection_Examining_Accuracy_and_Applicability_on_Personal_Information_Detected
Bukht, R., and R. Heeks. 2017. “Defining, Conceptualising and Measuring the Digital Economy.” Development Informatics Working Paper No. 68. SSRN, August 3, 2017. https://doi.org/10.2139/ssrn.3431732. DOI: https://doi.org/10.2139/ssrn.3431732
Bulgurcu, B., H. Cavusoglu, and I. Benbasat. 2010. “Information Security Policy Compliance: An Empirical Study of Rationality-Based Beliefs and Information Security Awareness.” MIS Quarterly 34 (3): 523–548. https://doi.org/10.2307/25750690. DOI: https://doi.org/10.2307/25750690
Bwalya, K. 2021. “Automating Public Business Processes—Towards AI-Augmented Government.” Accessed July 26, 2025. https://www.uj.ac.za/newandevents/Documents/Inaugural%20Address%20Kelvin.pdf.
Chimboza, T., and E. Smith. 2024. “How Does Compliance with the Protection of Personal Information Act (POPI Act) Affect Organisations in South Africa?” Paper presented at the Africa Conference on Information Systems and Technology, the 10th Annual ACIST Proceedings, Kennesaw State University. https://digitalcommons.kennesaw.edu/acist/2024/presentations/19.
Creswell, J. W. 2014. Research Design: Qualitative, Quantitative, and Mixed Methods Approaches. Thousand Oaks: Sage Publications.
European Commission. 2021. “Ethics and Data Protection.” Accessed August 4, 2025. https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/horizon/guidance/ethics-and-data-protection_he_en.pdf.
Fitzgerald, A. 2025. “Non-Compliance Fines and Sanctions: Real Cases with $ Impact + Enforcement Trends to Watch in 2026.” Secureframe, October 30. Accessed July 16, 2025. https://secureframe.com/blog/sanctions-non-compliance-fine.
Frank, I., and E. Odunayo. 2013. “Approach to Cyber Security Issues in Nigeria: Challenges and Solutions.” IJCRSEE: International Journal of Cognitive Research in Science, Engineering and Education 1 (1): 1–11.
GDPR.EU. 2025. “What Are the GDPR Consent Requirements?” Accessed July 16, 2025. https://gdpr.eu/gdpr-consent-requirements/.
Government of Botswana. 2018. Data Protection Act. Gaborone: Government Printer.
Government of Botswana. 2024. Data Protection Act: Gaborone: Government Printer.
Hoofnagle, J. C., B. van der Sloot, and F. Zuiderveen Borgesius. 2019. “The European Union General Data Protection Regulation: What It Is and What It Means.” Information and Communications Technology Law 28 (1): 65–98. https://doi.org/10.1080/13600834.2019.1573501. DOI: https://doi.org/10.1080/13600834.2019.1573501
IMF (International Monetary Fund). 2023. “Towards a Definition of the Digital Economy.” In Handbook on Measuring Digital Trade, 140–143. Washington, DC: IMF. Accessed August 8, 2025. https://www.imf.org/-/media/files/publications/books/2023/english/hmdtea.pdf. DOI: https://doi.org/10.30875/9789287073594c010
Jafta, Y., L. Leenen, and P. Chan. 2020. “An Ontology for the South African Protection of Personal Information Act.” Paper presented at the 19th European Conference on Cyber Warfare and Security. Accessed May 8, 2026. https://www.cair.org.za/sites/default/files/2020-10/Jafta_Paper_FinalPaper.pdf.
Jersey Office of the Information Commissioner. 2018. Data Protection (Jersey Law) 2018. Accessed June 30, 2025. https://www.jerseylaw.je/laws/current/PDFs/L_3_2018_20230505.pdf.
Karyda, M., and L. Mitrou. 2016. “Data Breach Notification: Issues and Challenges for Security Management.” Paper presented at the AIS Electronic Library (AISeL) Association for Information Systems, 10th Mediterranean Conference on Information Systems (MCIS), Cypris. Accessed June 27, 2026. https://www.researchgate.net/publication/309414062_DATA_BREACH_NOTIFICATION_ISSUES_AND_CHALLENGES_FOR_SECURITY_MANAGEMENT.
Kidanemariam, M. B. 2015. “Consent as a Basis for the Processing of Personal Data under the European Data Protection Directive: Case Study on Facebook.” LLM diss., University of Oslo. Accessed August 5, 2025. https://www.researchgate.net/publication/336851843_Consent_as_a_Basis_for_the_Processing_of_Personal_Data_under_the_European_Data_Protection_Directive_Case_Study_on_Facebook.
Kwatsha, N. 2020. “Small Enterprise Finance Agency (SEFA) Preparedness to Implement the Protection of Personal Information (POPI) Act, No. 4 of 2013.” MA diss., University of South Africa. Accessed May 8, 2026. https://www.proquest.com/openview/ad1b791c760add8b68fd442de7ab01a3/1?pq-origsite=gscholar&cbl=2026366&diss=y.
MA Business. 2019. “Verizon 2019: Data Breach Research Investigations Report Verizon.” Computer Fraud and Security 6: 4. Accessed March 11, 2019. https://www.verizon.com/business/resources/reports/2023-data-breach- investigations- report-dbir.pdf. https://doi.org/10.1016/S1361-3723(19)30060-0. DOI: https://doi.org/10.1016/S1361-3723(19)30060-0
MA Business. 2021. “IBM: Cost of a Data Breach Report.” Computer Fraud and Security 8: 4. https://doi.org/10.1016/S1361-3723(21)00082-8. DOI: https://doi.org/10.1016/S1361-3723(21)00082-8
Manyeke, M. 2026. “Examining the Impediments to Compliance with the Botswana Protection Act at the Botswana Unified Revenue Services (BURS).” Records Management Journal 36 (1): 53–68. https://doi.org/10.1108/RMJ-12-2024-0061. DOI: https://doi.org/10.1108/RMJ-12-2024-0061
Marutha, N., and O. Mosweu. 2021. “Confidentiality and Security of Information in the Public Health-Care Facilities to Curb HIV/AIDS Trauma among Patients in Africa.” Global Knowledge, Memory and Communication 70 (8–9): 684–696. https://doi.org/10.1108/GKMC-06-2020-0089. DOI: https://doi.org/10.1108/GKMC-06-2020-0089
Mather, N., and T. Laubscher. 2023. “South Africa: Information Regulator Shows Its Teeth and Conducts an Increasing Number of Assessments.” Bowmans, May 31. Accessed May 8, 2026. https://bowmanslaw.com/wp-admin/admin-ajax.php?action=generate_acf_pdf_insight&post_id=51065&nonce=640715f0b6.
Millard, D., and G. E. Bascerano. 2016. “Employers’ Statutory Vicarious Liability in Terms of the Protection of Personal Information Act.” Potchefstroom Electronic Law Journal 19. Accessed May 8, 2026. https://www.saflii.org/za/journals/PER/2016/12.html. DOI: https://doi.org/10.17159/1727-3781/2016/v19i0a555
Modiba, M., M. Ngoepe, and P. Ngulube. 2019. “Application of Disruptive Technologies to the Management and Preservation of Records.” Mousaion 37 (1): 1–14. https://doi.org/10.25159/2663-659X/6159. DOI: https://doi.org/10.25159/2663-659X/6159
Mulindwa, C. 2025. “Understanding Botswana’s 2018 and 2024 Data Protection Acts.” Accessed August 6, 2025. https://cipit.strathmore.edu/understanding-botswanas-2018-and-2024-data-protection-acts/.
Ntsaluba, N. 2017. “Cybersecurity Policy and Legislation in South Africa.” LLM diss., University of Pretoria. Accessed May 8, 2026. https://repository.up.ac.za/server/api/core/bitstreams/aa43e8ee-870d-4ce1-bd0e-68ba82a1ef30/content.
Nyagadza, B., R. Pashapa, A. Chare, G. Mazuruse, and P. K. Hove. 2022. “Digital Technologies, Fourth Industrial Revolution (4IR) & Global Value Chains (GVCs) Nexus with Emerging Economies’ Future Industrial Innovation Dynamics.” Cogent Economics and Finance 10 (1): 2014654. https://doi.org/10.1080/23322039.2021.2014654. DOI: https://doi.org/10.1080/23322039.2021.2014654
Nyoni, P., M. Velempini, and N. Mavetera. 2024. “Privacy Perceptions on Personal Data and Data Breaches in South Africa.” The African Journal of Information Systems 16 (3): 1. Accessed July 25, 2025. https://digitalcommons.kennesaw.edu/ajis/vol16/iss/1.
OECD. 2015. Digital Security Risk Enforcement for Economic and Social Prosperity: OECD Recommendation and Companion Document. Paris: OECD. https://www.oecd.org/content/dam/oecd/en/publications/reports/2015/10/digital-security-risk-management-for-economic-and-social-prosperity_g1g5c3dc/9789264245471-en.pdf.
Paganini, P. 2015. “Cybercrime Exploits Anthem Data Breach in Phishing Campaigns.” Cyber Defence Magazine, February 9. Accessed July 12, 2025. https://www.cyberdefensemagazine.com/cybercrime-exploits-anthem-data-breach-in-phishing-campaigns/.
Papadopoulou, E., A. Stobart, N. Taylor, and M. H. Williams. 2015. “Enabling Data Subjects to Remain Data Owners.” In Smart Innovation, Systems and Technologies: Agent and Multi-Agent Systems: Technologies and Applications: 9th KES International Conference, KES-AMSTA 2015 Sorrento, Italy, June 2015, Proceedings, Vol. 38, Smart Innovation, Systems and Technologies, edited by G. Jezic, R. Howlett, and L. Jain, 239–248. Cham: Springer. https://doi.org/10.1007/978-3-319-19728-9_20. DOI: https://doi.org/10.1007/978-3-319-19728-9_20
Picinali, F. 2017. “The Denial of Procedural Safeguards in Trials for Regulatory Offences. A Justification.” Criminal Law and Philosophy 11 (4): 681–703. https://doi.org/10.1007/s11572-016-9400-y. DOI: https://doi.org/10.1007/s11572-016-9400-y
Privacy International. 2018. “A Guide for Policy Engagement on Data Protection: PART 4: The Rights of Data Subjects.” Accessed July 15, 2025. https://privacyinternational.org/sites/default/files/2018-09/Part%204%20-%20Rights%20of%20Data%20Subjects.pdf.
Reeves, G. 2020. “A Study to Identify If There Is a Clear Understanding and Awareness of Required Records Management Policies and Procedures in Irish Organisations, Specifically, in Relation to Compliance with the General Data Protection Regulations (GDPR) Which Came into Force on 28th May 2018.” MSM diss., National College of Ireland. https://norma.ncirl.ie/id/eprint/4682.
Rhoen, M. 2015. “Big Data and Consumer Participation in Privacy Contracts: Deciding Who Decides on Privacy.” Utrecht Journal of International and European Law 31 (80): 51–71. https://doi.org/10.5334/ujiel.cu. DOI: https://doi.org/10.5334/ujiel.cu
Rhoen, M. 2016. “Beyond Consent: Improving Data Protection through Consumer Protection Law.” Internet Policy Review 5 (1). https://doi.org/10.14763/2016.1.404. DOI: https://doi.org/10.14763/2016.1.404
RSA (Republic of South Africa). 2013. Protection of Personal Information Act. Government Gazette, Vol. 581, No. 37067. Cape Town: Government Printers. Accessed July 16, 2025. https://www.gov.za/documents/protection-personal-information-act#:~:text=385.2%20KB-,4%20of%202013,provide%20for%20matters%20connected%20therewith.
Safa, S. N., C. Maple, T. Watson, and R. Von Solms. 2018. “Motivation and Opportunity-Based Model to Reduce Information Security Insider Threats in Organisations.” Journal of Information Security and Applications 40: 247–257. https://doi.org/10.1016/j.jisa.2017.11.001. DOI: https://doi.org/10.1016/j.jisa.2017.11.001
Singh, D. 2024. “Botswana Tackles Data Privacy Turmoil with New Bill.” African Law Business, August 22. Accessed August 1, 2025. https://www.africanlawbusiness.com/news/21334-botswana-tackles-data-privacy-turmoil-with-new-bill/.
Theys, M. W., E. Ruhode, and P. Harpur. 2021. “Challenges of Implementation of Data Protection Legislation in a South African Context.” In Proceedings of the 11th International Conference on Research in Science and Technology, 39–50. Paris: Diamond Scientific Publishing. https://research-portal.uws.ac.uk/en/publications/challenges-of-implementation-of-data-protection-legislation-in-a-/.
Veale, M., R. Binns, and J. Ausloos. 2018. “When Data Protection by Design and Data Subject Rights Clash.” International Data Privacy Law 8 (2): 105–123. https://doi.org/10.1093/idpl/ipy002. DOI: https://doi.org/10.1093/idpl/ipy002
Wolofsky, S. 2021. “What’s Your Privacy Worth on the Global Tech Market? Weighing the Cost of Protecting Consumer Data against the Risk That New Legislation May Stifle Competition and Innovation During this Global, Technological Revolution.” Fordham International Law Journal 44 (4): 1149–1206. Accessed May 8, 2026. https://ir.lawnet.fordham.edu/ilj/vol44/iss4/6.
Wong, A. T. T. 2020. “E- Tourism: How Will Customers’ Intention to Use Be Affected?” Academy of Marketing Studies Journal 24 (4): 1–19.
World Economic Forum. 2015. Expanding Participation and Boosting Growth: The Infrastructure Needs of the Digital Economy. Prepared in collaboration with the Boston Consulting Group. Accessed August 8, 2025. https://www3.weforum.org/docs/WEFUSA_DigitalInfrastructure_Report2015.pdf.
Yanamala, Y. K. A., and S. Suryadevara. 2023. “Advances in Data Protection and Artificial Intelligence: Trends and Challenges.” International Journal of Advanced Engineering Technologies and Innovations 1 (1): 294–319.
Zluky, N., and B. M. Purcell. 2020. “GDPR: The Importance of Consent and Data Protection.” Journal of Technology Research 9: 1–11.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Unisa PressAccepted 2026-06-19
Published 2026-07-01