No. 3 Data Protection 1
(Published 2nd February, 2024)
Act
No. 3 of 2024
I assent
DR. LAZARUS McCARTHY CHAKWERA PRESIDENT 31st January, 2024
ARRANGEMENT OF SECTIONS
SECTION
PART I—PRELIMINARY 1. Short title and commencement 2. Interpretation 3. Application
PART II—ADMINISTRATION 4. Designation of Data Protection Authority 5. Functions of the Authority 6. Powers of the Authority 7. Advisory committees
PART III—PRINCIPLES RELATING TO THE PROCESSING OF PERSONAL DATA 8. Personal data to be processed lawfully, fairly, etc. 9. Purpose limitation 10. Data minimization 11. Data accuracy 12. Storage limitation 13. Data integrity and data confidentiality 14. Principles for determining the validity of consent 15. Provision of information to a data subject 16. Processing of sensitive personal data 17. Processing personal data of children and other legally incapacitated persons
Data Protection No. 3
# SECTION
- Processing of personal data relating to criminal offences, convictions, etc.
PART IV—RIGHTS OF A DATA SUBJECT
- Right to access personal data
- Right to data portability
- Right to rectification of personal data
- Right to erasure of personal data
- Right to restriction of processing personal data
- Right to object
- Automated decision-making
- Derogations
PART V—DUTIES OF A DATA CONTROLLER AND DATA PROCESSOR
- Adherence to data protection principles
- Technical and organizational measures
- Record of personal data processing activities
- Data protection impact assessment
- Joint data controllers
- Regulation of the relationship between data controllers and data processors
- Designation of a data protection officer
- Duties of a data protection officer
PART VI—DATA SECURITY
- Security of personal data
- Notification of personal data breach
- Communication of personal data breach to data subjects
PART VII—CROSS-BORDER TRANSFERS OF PERSONAL DATA
- Cross-border transfer of personal data
- Adequacy of protection of personal data
- Binding corporate rules, certification mechanisms, etc.
PART VIII—REGISTRATION OF DATA CONTROLLERS OF MAJOR IMPORTANCE AND DATA PROCESSORS OF MAJOR IMPORTANCE
- Registration of data controllers of significant importance and data processors of significant importance
- Suspension or cancellation of registration
- Exemptions
No. 3 Data Protection 3
# SECTION
PART IX—COMPLAINTS
- Complaints
- Compliance orders
PART X—MISCELLANEOUS
- Appeal against decisions of the Authority
- Civil remedies
- Obstruction, interference with the Authority
- Breach of confidentiality
- Offences committed by legal persons, firms, etc.
- Vicarious liability
- Regulations
- Transitional provision
An Act to provide for the protection of personal data of natural persons; the regulation of the processing and movement of personal data of natural persons; the rights of natural persons with respect to the processing of personal data; the obligations of data controllers and data processors; the designation of a Data Protection Authority; and matters incidental thereto
ENACTED by the Parliament of Malawi as follows—
PART I—PRELIMINARY
- This Act may be cited as the Data Protection Act, 2024, and shall come into operation on such date as the Minister may appoint by notice published in the Gazette.