Pillar Online sales and transactions |
Sub-pillar Adoption of United Nations Commission on International Trade Law (UNCITRAL) Model Law on Electronic Signatures
Lack of adoption of UNCITRAL Model Law on Electronic Signatures
Malawi has not adopted national legislation based on or influenced by the United Nations Commission on International Trade Law (UNCITRAL) Model Law on Electronic Signatures.
Coverage Horizontal
Since November 2016, entry into force in June 2017
Pillar Intermediary liability |
Sub-pillar Safe harbour for intermediaries for any activity other than copyright infringement
Electronic Transactions and Cybersecurity Act of 2016
The Electronic Transactions and Cybersecurity Act of 2016 establishes a safe harbour regime for intermediaries beyond copyright infringements. Sections 25 to 30 of the Act protect an Intermediary service provider from liability to civil or criminal proceedings for any electronic information under its service provided that it neither initiated transmission of the message nor modified it and that it was not aware of the unlawful character of the stored information. Additionally, protection is provided if the intermediary service provider expeditiously removed or disabled access to the information when served with a takedown notice issued under the Act.
Coverage Internet intermediaries
Since October 2016
Pillar Intermediary liability |
Sub-pillar User identity requirement
Communications Act of 2016
According to Sections 92-94 of the Communications Act of 2016, All SIM cards in Malawi need to be registered on a central database, and a customer’s national identity number needs to be verified when purchasing, replacing, or swapping a SIM card.
Coverage Telecommunications sector
- Show more...
Since November 2016, entry into force in June 2017
Pillar Quantitative trade restrictions for ICT goods and online services |
Sub-pillar Other import restrictions, including non-transparent/discriminatory import procedures
Electronic Transactions and Cybersecurity Act of 2016
According to Section 52-53 of the Electronic Transactions and CyberSecurity Act of 2016, cryptography services or products are required to be registered by the Communications Authority. Additionally, the use, importation, and exportation of encryption programs and encryption products are subject to authorisation by the government.
Coverage Encryption services
Since November 2016, entry into force in June 2017
Pillar Quantitative trade restrictions for ICT goods and online services |
Sub-pillar Export restrictions on ICT goods or online services
Electronic Transactions and Cybersecurity Act of 2016
According to Section 52-53 of the Electronic Transactions and CyberSecurity Act of 2016, cryptography services or products are required to be registered by the Communications Authority. Additionally, the use, importation, and exportation of encryption programs and encryption products are subject to authorisation by the government.
Coverage Encryption services
Pillar Cross-border data policies |
Sub-pillar Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Malawi has not joined any free trade agreement committing to open transfers of cross-border data flows.
Coverage Horizontal
Pillar Domestic data policies |
Sub-pillar Framework for data protection
Lack of comprehensive data protection framework
Malawi lacks a dedicated data protection law, with only data protection provisions found in the Electronics and Cybersecurity Act of 2016. This Act outlines principles for processing personal data, legal bases for processing activities, data subjects' rights, and the security measures required for data controllers. In March 2018, the Minister of Information and Communication Technology announced plans to enact a standalone data protection law, but it remains in Bill form.
Coverage Horizontal
Since February 2017, entry into force in September 2020
Since November 2016, entry into force in June 2017
Since November 2016, entry into force in June 2017
Pillar Domestic data policies |
Sub-pillar Minimum period for data retention
Access to Information Act, 2016
Electronic Transactions and Cybersecurity Act of 2016
Electronic Transactions and Cybersecurity Act of 2016
Section 13 of the Access to Information Act mandates information holders to maintain information for a period of seven years from the date on which the information is generated by the institution or on which the information comes under its custody or control. If that information is exempted from disclosure, it may be kept for a longer period. Section 2 establishes that information holder means a public body and a relevant private body, and according to Section 3, this Act shall apply to information in custody or under the control of any information holder listed in the Schedule. Among the information holders to which the Act applies are the institutions and organisations, whether established by or under an Act of Parliament or otherwise, in which the Government hold shares or exercises financial or administrative control and persons in the service of those institutions and organisations, and organisations contracted by Government to do work for the Government and persons in the service of those organisations.
Furthermore, Section 17 of the Electronic Transactions and Cybersecurity Act establishes that where any written law requires that a document, record or information shall be retained, that requirement shall be satisfied if the document, record or information is held in electronic form. Such document, record or information shall be kept in electronic form for at least seven years.
Furthermore, Section 17 of the Electronic Transactions and Cybersecurity Act establishes that where any written law requires that a document, record or information shall be retained, that requirement shall be satisfied if the document, record or information is held in electronic form. Such document, record or information shall be kept in electronic form for at least seven years.
Coverage Horizontal
- Show more...
Since November 2016, entry into force in June 2017
Pillar Intermediary liability |
Sub-pillar Safe harbour for intermediaries for copyright infringement
Electronic Transactions and Cybersecurity Act of 2016
The Electronic Transactions and Cybersecurity Act of 2016 establishes a safe harbour regime for intermediaries for copyright infringements. Sections 25 to 30 of the Act protect an Intermediary service provider from liability to civil or criminal proceedings for any electronic information under its service provided that it neither initiated transmission of the message nor modified it and that it was not aware of the unlawful character of the stored information. Additionally, protection is provided if the intermediary service provider expeditiously removed or disabled access to the information when served with a takedown notice issued under the Act.
Coverage Internet intermediaries
Since April 1989, as amended in September 2016
Pillar Intellectual Property Rights (IPRs) |
Sub-pillar Copyright law with clear exceptions
Copyright Act of 2016 (A repeal of the 1989 Act)
Malawi has a copyright regime under the Copyright Act of 2016. However, the exceptions do not follow the fair use or fair dealing model, therefore limiting the lawful use of copyrighted work by others. Arts. 36-53 list the exceptions, which include personal and teaching purposes; reproduction, translation, adaptation, arrangement or other transformation of a work exclusively for the user’s own personal or private use of a work which has already been lawfully made available to the public; among others.
Coverage Horizontal
Pillar Intellectual Property Rights (IPRs) |
Sub-pillar Adoption of the World Intellectual Property Organization (WIPO) Copyright Treaty
Lack of signature of the WIPO Copyright Treaty
Malawi has not signed the World Intellectual Property Organization (WIPO) Copyright Treaty.
Coverage Horizontal
Pillar Intellectual Property Rights (IPRs) |
Sub-pillar Adoption of the World Intellectual Property Organization (WIPO) Performances and Phonogram Treaty
Lack of signature of the WIPO Performances and Phonograms Treaty
Malawi has not signed the World Intellectual Property Organization (WIPO) Performances and Phonograms Treaty.
Coverage Horizontal
Since November 2016, entry into force in June 2017
Pillar Intellectual Property Rights (IPRs) |
Sub-pillar Mandatory disclosure of business trade secrets such as algorithms or source code
Electronic Transactions and Cybersecurity Act of 2016
The Law in Malawi, according to Sections 52 and 53 of the Electronic Transactions and CyberSecurity Act of 2016, requires cryptography services or products to be registered by the Communications Authority. Additionally, the use, importation, and exportation of encryption programs and encryption products is subject to authorisation by the government. In addition, Section 67 of the Act mandates encryption services providers to declare to the Authority the technical characteristics of the encryption means as well as the source code of the software used. Violation of these regulations is a criminal offence punishable by up by imprisonment and a fine.
Coverage Encryption services
Pillar Intellectual Property Rights (IPRs) |
Sub-pillar Effective protection covering trade secrets
Lack of regulatory framework covering trade secrets
Malawi has no rules applicable to the protection of trade secrets.
Coverage Horizontal
Pillar Telecom infrastructure & competition |
Sub-pillar Passive infrastructure sharing obligation
Requirement of passive infrastructure sharing
It is reported that there is an obligation for passive infrastructure sharing in Malawi to deliver telecom services to end users. It is practised in both the mobile and fixed sectors based on commercial agreements.
Coverage Telecommunications sector