World Watch/eSwatini/Cybersecurity

Cybersecurity · eSwatini

Cybersecurity regulation in eSwatini (2026)

Comprehensive lawComputer Crime and Cybercrime Act, 2022; Data Protection Act, 2022; Electronic Communications and Transactions Act, 2022 — administered by the Eswatini Communications Commission (ESCCOM)Country index 65 · C+

eSwatini shaded by its cybersecurity status

eSwatini enacted a coordinated package of cybersecurity and data-protection legislation gazetted on 4 March 2022, anchored by the Computer Crime and Cybercrime Act, 2022, which criminalises a broad range of cyber offences and establishes a National Cybersecurity Incident Response Team (NCSIRT) and National Cybersecurity Advisory Council. The Data Protection Act, 2022 imposes a 72-hour breach-notification duty on data controllers to report to ESCCOM and affected individuals. A five-year National Cybersecurity Strategy (2022–2027) sets strategic goals covering critical-infrastructure resilience and sectoral CIRT development.

Key points

Computer Crime & Cybercrime Act 2022

In force from 4 March 2022, the Act criminalises unauthorised access, data interference, cyberbullying, child exploitation, and cyberterrorism; grants law enforcement search, seizure, preservation, and interception powers; and establishes the NCSIRT and National Cybersecurity Advisory Council (up to 15 members drawn from ICT, law, finance, defence, and civil society).

Data Protection Act 2022 & Breach Notification

Data controllers must notify ESCCOM (acting as data-protection authority) and affected individuals of a personal-data breach within 72 hours. Non-compliance carries fines up to E5 million (approx. USD 268,000) or 2% of annual turnover, and imprisonment in severe cases.

NCSIRT — Operational Incident Response

The National Cybersecurity Incident Response Team, housed within ESCCOM, is the operational body for cyber-incident coordination; it is a listed active member of FIRST (Forum of Incident Response and Security Teams) and maintains a public portal at ncsirt.org.sz.

National Cybersecurity Strategy 2022–2027

The five-year strategy sets six strategic pillars; the first is enhancing the security and resilience of national critical information infrastructure. It mandates creation of sectoral CIRTs in finance, utilities, energy, communications, and transport sectors.

Regulatory Authority — ESCCOM

The Eswatini Communications Commission is the designated national cybersecurity authority, overseeing enforcement of the Computer Crime Act, Data Protection Act, and Electronic Communications and Transactions Act, with powers to impose administrative fines and sanctions on non-compliant organisations.

Electronic Communications & Transactions Act 2022

Enacted alongside the cybercrime and data-protection laws, this Act governs lawful electronic transactions and communications; together the three 2022 Acts form eSwatini's integrated digital-regulation package.

eSwatini - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →