EZULWINI – The Eswatini Communications Commission (ESCCOM), acting as the Eswatini Data Protection Authority (EDPA), has started validating draft advisory guidelines on the lawful processing of personal health data as part of efforts to strengthen privacy standards across the country’s healthcare sector.
The validation workshops, which began yesterday (Monday, July 28, 2026) at SibaneSami Hotel in Ezulwini, bring together representatives from the Ministry of Health, public and private healthcare providers, insurers, pharmacies, medical aid schemes and other stakeholders. The sessions continue until Friday.
The guidelines are being reviewed before they are published as a regulatory instrument under the Data Protection Act, 2022. The initiative is supported by Smart Africa, which assisted in developing the document and is sponsoring the workshops, while GIZ also provided technical and financial support.
Speaking on behalf of Acting ESCCOM Chief Executive Officer Fikile Gama, Sicelo Simelane said the validation process was intended to ensure the final guidelines reflected the realities faced by the health sector while remaining compliant with the law.
He said the Commission appreciated the contributions made by stakeholders throughout the drafting process, adding that the collaborative approach would help produce guidance that was practical, balanced and responsive to healthcare delivery. “The participation of stakeholders demonstrates the commitment that exists towards strengthening the protection of personal health information in the Kingdom of Eswatini,” Simelane said.
He also acknowledged Advocate Dirontso Mohale, who drafted the guidelines, saying the document struck a balance between protecting patients’ privacy and recognising the operational realities faced by healthcare institutions and professionals.

As the country’s Data Protection Authority established under the Data Protection Act, 2022, ESCCOM has the responsibility of promoting compliance with data protection laws while supporting innovation and efficient service delivery.
Simelane said the draft guidelines were designed to provide practical direction to organisations and professionals who collect, process or store personal health information.
He noted that health records contained some of the most sensitive personal information, with healthcare providers, laboratories, insurers, employers and researchers handling data that revealed deeply private aspects of people’s lives.
According to Simelane, the rapid adoption of electronic medical records, eHealth platforms and cloud-based systems had improved healthcare delivery but also introduced new privacy and cybersecurity risks.
He said the guidelines explained how personal health information should be collected, used, retained, shared, secured and eventually disposed of in line with the Data Protection Act. They also outline lawful grounds for processing health information while reinforcing principles such as lawfulness, fairness, transparency, data minimisation, integrity, confidentiality and accountability.
In addition, the document provides guidance on privacy programmes within healthcare institutions, data sharing, data protection impact assessments, breach notification, cloud services, patient rights and governance responsibilities.
Simelane said the guidelines were intended to improve compliance across the health sector while strengthening public confidence that personal health information would be handled responsibly.
Patients, he said, should be able to seek medical care knowing their information would remain confidential, while healthcare providers should have clear guidance to help them comply with the law without disrupting service delivery.
The Commission also revealed that it had already investigated and concluded a complaint involving the unlawful access to and disclosure of a patient’s personal information by a healthcare practitioner.
Although details of the case were not disclosed, Simelane said the incident illustrated that data protection risks within the health sector were real and capable of causing significant harm to individuals. He said the case reinforced the need to strengthen confidentiality, ethical conduct and compliance among healthcare professionals and institutions.
Rather than viewing the guidelines as another regulatory requirement, Simelane said they should be regarded as a practical tool to help healthcare providers prevent similar incidents, improve internal governance and protect patient trust.
He urged participants to use the validation workshop to provide constructive feedback so that the final document would be practical, implementable and responsive to the operational needs of the health sector while remaining consistent with the requirements of the Data Protection Act, 2022.
The validation workshops are being conducted across different sectors before the guidelines are finalised and published.