About Us

Protect the Personal Data and Privacy of Individuals

The Malawi Data Protection Authority is an independent statutory body established under the Data Protection Act, 2024 to protect the personal data and privacy of individuals by regulating the processing of personal information. The Act empowers data subjects to have greater autonomy and control over their personal data by ensuring that  public and private institutions handle their users’ data with care. The Malawi Regulatory Authority (MACRA) is the designated Data Protection Authority that is key to ensuring appropriate handling of personal data in Malawi as enshrined in the Data Protection Act (DPA) of 2024.

Vision

Lawful, fair and transparent processing of personal data.

Mission

To protect personal data in Malawi by regulation of the processing of personal data as prescribed under the Data Protection Act and overseeing the implementation and enforcement of the Act.

Objectives

a. To develop and publish guidelines on data protection to promote data protection and compliance with the Act;
b. To promote public awareness of the Data Protection Act and International Personal Data Protection legal frameworks;
c. To encourage the development and introduction of personal data protection technologies and administrative measures, in line with international standards and applicable international laws;
d. To engage with national, regional and international authorities responsible for data protection to develop consistent and efficient approaches to the regulation of cross-border transfer of personal data;
e. To advise the Minister on policy issues relating to personal data protection;
f. To collect and publish information with respect to personal data protection, including personal data breaches;
g. To keep and maintain a register of data controllers of significant importance and data processors of significant importance; and
h. To do all such acts and things as are necessary or incidental to the implementation of this act.

The Malawi Data Protection Authority is an independent statutory body established under the Data Protection Act, 2024 to protect the personal data and privacy of individuals by regulating the processing of personal information.

Data Protection Authority
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.