World Watch/Lesotho/Cybersecurity

Cybersecurity · Lesotho

Cybersecurity regulation in Lesotho (2026)

ProposedComputer Crime and Cyber Security Bill, 2024 (pending enactment); Data Protection Act, 2013; Lesotho Communications Authority Act, 2000Country index 65 · C+

Lesotho shaded by its cybersecurity status

Lesotho has no comprehensive cybersecurity law in force as of May 2026. A succession of bills (2021, 2022, 2023, 2024) have been introduced but none has received royal assent and been gazetted as law. The most recent iteration, the Computer Crime and Cyber Security Bill, 2024, was tabled in the National Assembly in May 2024 and was still progressing through committee and stakeholder review as of late 2024. Existing cyber-adjacent regulation is limited to the Data Protection Act, 2013 and sector-level oversight by the Lesotho Communications Authority.

Key points

Repeated Bill Failures

Bills introduced in 2021, 2022, and 2023 each stalled or were sent back due to constitutional concerns, particularly around surveillance provisions and criminal defamation clauses. The 2022 bill passed the National Assembly but did not complete the Senate and royal-assent stages to become law.

2024 Bill Scope

The Computer Crime and Cyber Security Bill, 2024 — tabled in the National Assembly on 23 May 2024 — would criminalise unauthorised access, data interference, cyber terrorism, and cyberbullying, and would establish a National Cyber Security Advisory Council and a Computer Incident Response Team with formal legal mandates.

No Breach-Notification Duty in Force

Because no cybersecurity statute has been enacted, there is currently no statutory incident-reporting or breach-notification obligation in Lesotho. The 2024 Bill would introduce such duties for operators of critical information infrastructure, but they remain prospective.

Data Protection Act, 2013

The Data Protection Act, 2013 is the principal in-force instrument that touches on data security, establishing obligations around personal data handling. It does not constitute a cybersecurity framework but provides some protection against unlawful data processing.

Lesotho Communications Authority (LCA) Oversight

The LCA, established under the Lesotho Telecommunications Authority Act, 2000, exercises sector-level oversight of electronic communications and has undertaken cybersecurity awareness initiatives and a partnership with digital-risk firm CTM360, but has no published binding cybersecurity regulations beyond subscriber-registration rules.

Capacity Maturity Assessment

The 2022–2023 Cybersecurity Capacity Maturity Model (CMM) review conducted by C3SA/GCSCC found Lesotho at an early/formative stage across all five cybersecurity dimensions, citing the absence of enacted legislation and limited technical and institutional capacity as the primary gaps.

Lesotho - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →