MALAWI
Since January 2024, entry into force in June 2024
Pillar Domestic data policies |
Indicator Framework for data protection
Data Protection Act, 2024
The Data Protection Act establishes a comprehensive regime for data protection in Malawi. It repeals the data protection provisions contained in the Electronic Transactions and Cyber Security Act, 2016, and designates the Malawi Communications Regulatory Authority (MACRA) as the national data protection authority. The Act applies to the processing of personal data within Malawi, including by entities outside the country that offer goods or services to, or monitor the behaviour of, individuals in Malawi. It excludes processing undertaken solely for personal or household purposes, as well as the mere transmission of data through Malawi. The Act imposes obligations on data controllers and processors, including mandatory registration for those of significant importance. These entities are required to comply with the Act within six months of its commencement, while others are granted a 24-month grace period. MACRA is empowered to investigate potential or actual violations of the Act.
Coverage Horizontal
MALAWI
Since February 2017, entry into force in September 2020
Since November 2016, entry into force in June 2017
Since November 2016, entry into force in June 2017
Pillar Domestic data policies |
Indicator Minimum period for data retention
Access to Information Act, 2016
Electronic Transactions and Cybersecurity Act of 2016
Electronic Transactions and Cybersecurity Act of 2016
Section 13 of the Access to Information Act mandates information holders to maintain information for a period of seven years from the date on which the information is generated by the institution or on which the information comes under its custody or control. If that information is exempted from disclosure, it may be kept for a longer period. Section 2 establishes that information holder means a public body and a relevant private body, and according to Section 3, this Act shall apply to information in custody or under the control of any information holder listed in the Schedule. Among the information holders to which the Act applies are the institutions and organisations, whether established by or under an Act of Parliament or otherwise, in which the Government hold shares or exercises financial or administrative control and persons in the service of those institutions and organisations, and organisations contracted by Government to do work for the Government and persons in the service of those organisations.
Furthermore, Section 17 of the Electronic Transactions and Cybersecurity Act establishes that where any written law requires that a document, record or information shall be retained, that requirement shall be satisfied if the document, record or information is held in electronic form. Such document, record or information shall be kept in electronic form for at least seven years.
Furthermore, Section 17 of the Electronic Transactions and Cybersecurity Act establishes that where any written law requires that a document, record or information shall be retained, that requirement shall be satisfied if the document, record or information is held in electronic form. Such document, record or information shall be kept in electronic form for at least seven years.
Coverage Horizontal
Sources
- https://web.archive.org/web/20211202154613/http://www.mhrcmw.org/mhrc/resource-center/legal-instruments/national-legal-instruments
- https://web.archive.org/web/20231210114811/https://www.voanews.com/a/africa_malawi-sweeps-access-information-law-effect/6195799.html
- https://web.archive.org/web/20211128050101/https://www.macra.org.mw/?wpdmpro=e-transactions-act-2016
- Show more...
MALAWI
Since January 2024, entry into force in June 2024
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Data Protection Act, 2024
Section 30 of the Data Protection Act stipulates that data controllers are obliged to undertake a data protection impact assessment (DPIA) where the envisaged processing is likely to give rise to significant risks to the rights of data subjects. The Act delineates categories of high-risk processing, including the use of automated processing systems, profiling, the large-scale processing of sensitive data or data relating to criminal convictions, and the large-scale monitoring of publicly accessible areas. The resulting DPIA report must be submitted to the Malawi Communications Regulatory Authority (MACRA) prior to the commencement of processing. Also, data controllers are required to review and, where necessary, update the DPIA when the nature or level of risk has changed.
In addition, Section 33 provides that, where a data controller or processor constitutes a public authority other than a court, or its core activities involve either large-scale monitoring or the large-scale processing of sensitive data, the Act requires the appointment of a data protection officer to discharge the responsibilities prescribed therein.
In addition, Section 33 provides that, where a data controller or processor constitutes a public authority other than a court, or its core activities involve either large-scale monitoring or the large-scale processing of sensitive data, the Act requires the appointment of a data protection officer to discharge the responsibilities prescribed therein.
Coverage Horizontal
MALAWI
Since November 2016, entry into force in June 2017
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Electronic Transactions and Cybersecurity Act of 2016
The Electronic Transactions and Cybersecurity Act of 2016 establishes a safe harbour regime for intermediaries for copyright infringements. Sections 25 to 30 of the Act protect an Intermediary service provider from liability to civil or criminal proceedings for any electronic information under its service provided that it neither initiated transmission of the message nor modified it and that it was not aware of the unlawful character of the stored information. Additionally, protection is provided if the intermediary service provider expeditiously removed or disabled access to the information when served with a takedown notice issued under the Act.
Coverage Internet intermediaries
MALAWI
Since November 2016, entry into force in June 2017
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Electronic Transactions and Cybersecurity Act of 2016
The Electronic Transactions and Cybersecurity Act of 2016 establishes a safe harbour regime for intermediaries beyond copyright infringements. Sections 25 to 30 of the Act protect an Intermediary service provider from liability to civil or criminal proceedings for any electronic information under its service provided that it neither initiated transmission of the message nor modified it and that it was not aware of the unlawful character of the stored information. Additionally, protection is provided if the intermediary service provider expeditiously removed or disabled access to the information when served with a takedown notice issued under the Act.
Coverage Internet intermediaries
MALAWI
Since October 2016
Pillar Intermediary liability |
Indicator User identity requirement
Communications Act of 2016
According to Sections 92-94 of the Communications Act of 2016, All SIM cards in Malawi need to be registered on a central database, and a customer’s national identity number needs to be verified when purchasing, replacing, or swapping a SIM card.
Coverage Telecommunications sector
Sources
- https://web.archive.org/web/20230322070646/https://www.gsma.com/mobilefordevelopment/wp-content/uploads/2019/02/Digital-Identity-Country-Report.pdf
- https://web.archive.org/web/20220701110136/https://macra.mw/wp-content/uploads/2021/04/COMMUNICATIONS-ACT-2016.pdf
- https://freedomhouse.org/country/malawi/freedom-net/2021
- Show more...
MALAWI
Since November 2016, entry into force in June 2017
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Electronic Transactions and Cybersecurity Act of 2016
According to Section 52-53 of the Electronic Transactions and CyberSecurity Act of 2016, cryptography services or products are required to be registered by the Communications Authority. Additionally, the use, importation, and exportation of encryption programs and encryption products are subject to authorisation by the government.
Coverage Encryption services
MALAWI
Since June 2020
Pillar Public procurement of ICT goods and online services |
Indicator Other limitations on foreign participation in public procurement
Public Procurement and Disposal of Public Assets (Participation by Micro, Small, and Medium Enterprises) Order, 2020
Section 10 of the Public Procurement and Disposal of Public Assets (Participation by Micro, Small, and Medium Enterprises) Order seeks to promote MSMEs and the marginalised by way of preferences and reservations. The Order sets a minimum threshold of 15% for the procurement of goods and services and 10% for the procurement of works to be granted under a preference scheme to marginalised groups. To ensure compliance with this provision, the law requires procuring and disposing entities to submit annual procurement plans indicating the value and percentage of procurement contracts intended for award to MSMEs and quarterly progress reports.
Coverage Horizontal
MALAWI
N/A
Pillar Public procurement of ICT goods and online services |
Indicator Signatory of the WTO Agreement on Government Procurement (GPA) with coverage of the most relevant services sectors (CPC 752, 754, 84)
Lack of participation in the WTO Agreement on Government Procurement (GPA)
Malawi is not a party to the World Trade Organization (WTO) Agreement on Government Procurement (GPA), nor does it have observer status.
Coverage Horizontal
MALAWI
Since October 2016
Pillar Foreign Direct Investment (FDI) in sectors relevant to digital trade |
Indicator Maximum foreign equity share
Communications Act of 2016
Section 35 of the Communications Act mandates an electronic communications licensee (Network and Application Services) to maintain a shareholding by nationals of at least 20%.
Coverage Telecommunications sector
MALAWI
Since April 1984, last amended in July 2013
Pillar Foreign Direct Investment (FDI) in sectors relevant to digital trade |
Indicator Nationality/residency requirement for directors or managers
Malawi Companies Act of 2013 (replacing Companies Act 1984)
Section 162.3 of the Malawi Companies Act requires a company to have at least one director ordinarily resident in Malawi.
Coverage Horizontal
MALAWI
Since January 1978
Pillar Intellectual Property Rights (IPRs) |
Indicator Participation in the Patent Cooperation Treaty (PCT)
Patent Cooperation Treaty (PCT)
Malawi is a party to the Patent Cooperation Treaty (PCT).
Coverage Horizontal
MALAWI
Since April 1989, as amended in September 2016
Pillar Intellectual Property Rights (IPRs) |
Indicator Copyright law with clear exceptions
Copyright Act of 2016 (A repeal of the 1989 Act)
Malawi has a copyright regime under the Copyright Act of 2016. However, the exceptions do not follow the fair use or fair dealing model, therefore limiting the lawful use of copyrighted work by others. Arts. 36-53 list the exceptions, which include personal and teaching purposes; reproduction, translation, adaptation, arrangement or other transformation of a work exclusively for the user’s own personal or private use of a work which has already been lawfully made available to the public; among others.
Coverage Horizontal
MALAWI
N/A
Pillar Intellectual Property Rights (IPRs) |
Indicator Adoption of the WIPO Copyright Treaty
Lack of signature of the WIPO Copyright Treaty
Malawi has not signed the World Intellectual Property Organization (WIPO) Copyright Treaty.
Coverage Horizontal
MALAWI
N/A
Pillar Intellectual Property Rights (IPRs) |
Indicator Adoption of the WIPO Performances and Phonograms Treaty
Lack of signature of the WIPO Performances and Phonograms Treaty
Malawi has not signed the World Intellectual Property Organization (WIPO) Performances and Phonograms Treaty.
Coverage Horizontal
