Rebaone Ditlale
Lead Skills Consultant
The implementation of Botswana’s Data Protection Act No. 18 of 2025 (DPA) necessitates compliance with data protection principles. Private, government and parastatal institutions are expected to demonstrate that they process personal data lawfully, securely and transparently. A data protection audit is a formal review of how an organisation manages personal data to ensure it complies with the DPA, protects individuals’ privacy, and implements effective security measures. The Act gives the Information and Data Protection Commission (IDPC) powers to conduct audits and investigations to assess compliance. This article has one question “Are you prepared for a data protection audit?” If not, read on as we unpack how to be.
Assess your compliance
Understanding how personal data is handled within your company is the first step towards being audit-ready. In order to maintain compliance, organisations should specify what personal data they collect, why they collect it, how it is processed, where they store it, who can access it, and for how long they keep it. Additionally, organisations should also maintain accurate records of processing activities and regularly review privacy notices, consent mechanisms, and contracts with third-party service providers.
Strengthen security measures
A successful data protection audit examines whether appropriate technical and organisational measures are in place to safeguard personal data. Organisations should put in place strong cybersecurity measures, including access controls, password management, encryption where appropriate, secure backups, antivirus protection, and regular software updates. Also, for employees to understand their duties when handling personal data, employee awareness should be taken into consideration as a security measure. Additionally, entities that are obliged to designate a Data Protection Officer (DPO) should make sure the officer has sufficient authority, resources, and independence to monitor compliance. Lastly on security measures, organisations should craft data protection policies, effectively communicated throughout the organisation and regularly review them to ensure ongoing compliance.
Prepare for the auditor
Being audit-ready means having your personal data processing records in order. Organisations should conduct periodic internal audits and address identified gaps without delay. The commission has the power to search, seize and detain an organisation’s gadgets and equipment when conducting an audit and may request, amongst others, policies, staff training records, breach registers, consent records, contracts with processors, and documentation showing how data subject rights are handled. Management should also continuously monitor compliance rather than waiting for regulatory inspections to prevent being caught off guard.
Our services
The Data Protection Act (DP Act) mandates every organization to put strict safeguards regarding personal data and in that regard, we can assist with crafting Data Protection Policies in line with the said Act. Some organizations, such as schools, hospitals, regulatory bodies, etc, because of the volumes of personal data they handle, are required to have full-time Data Protection Officers (DPO). If you cannot afford a full-time DPO, we can act as your organization’s DPO on a contract basis. If you need training for your staff on the provisions of the Data Protection Act and other business courses such as Leadership & Supervisory Skills, Customer Care, Team Building, as well as secondments of Tax, HR and DPOs, contact us at: +267 76 213 233 or +267 393 9435 or skills@aupracontax.co.bw. This article is general, and written advice or training is recommended if decisions are to be made. If you would like to join our free WhatsApp groups or to know more about our services, please send us a text/WhatsApp on the numbers above.