Data Protection & Technology Law Training
Why This Programme Exists
Botswana’s Data Protection Act No. 18 of 2024 came into force on 29 October 2024. If your organization holds personal data about customers, employees or patients — and every organization does — your obligations have changed.
There is a second problem, and it is worth naming plainly. A great deal of the data protection training sold into Gaborone is European GDPR material with a Botswana city name in the page title. GDPR is a useful reference point and the concepts overlap, but it is not the law that binds you. A course that teaches your team the GDPR’s supervisory authority structure and lawful bases will leave them confidently applying the wrong framework.
The same gap exists on the intellectual property side. Most organizations can name the software they license but not the IP they own, and fewer still know who holds the rights to work produced by a contractor. This course covers both: the data you must protect, and the assets you may not realise you have.
What You Will Be Able To Do Afterwards
- Explain the structure of the Data Protection Act No. 18 of 2024 and who it applies to
- Tell the difference between a data controller and a data processor, and know which your organization is in each relationship
- Identify a lawful basis for each processing activity you carry out
- Understand the notification obligation to the Commissioner, and how appointing a data protection representative affects it
- Build a data inventory and a retention schedule that people will actually maintain
- Draft a privacy notice that meets the Act’s requirements and can still be understood
- Handle a data subject request properly and within time
- Assess a cross-border data transfer before it happens rather than after
- Respond to a data breach with the legal obligations in mind, not only the technical ones
- Identify the intellectual property your organization creates in software, data, content and branding, and know what protects each type
- Understand who owns IP created by an employee, a contractor or a technology partner
- Review a technology or licensing agreement for the IP and data processing terms that matter
- Apply the law to online transactions, digital contracting and electronic signatures
- Recognise the governance questions raised by AI and automated decision-making
Who Should Attend
What The Programme Covers
Day One
- Why data protection law arrived, and what it is trying to prevent
- The Data Protection Act No. 18 of 2024: scope, structure and commencement
- Key definitions — personal data, processing, special categories, data subject
- Controllers and processors: who carries which obligation
- The data protection principles and what each one demands operationally
- Lawful bases for processing, including where consent is and is not the right basis
- Notification to the Commissioner, available exemptions, and the data protection representative route
- Data subject rights and building a request-handling procedure
- Data inventories, records of processing and retention schedules
- Privacy notices — drafting for compliance and for comprehension
- Cross-border transfers of personal data
- How the Act compares to GDPR, and where assuming they are the same will hurt you
Day Two
- Security obligations under the Act: what “appropriate measures” means in practice
- Data breach response — legal, notification and evidential considerations alongside the technical ones
- Building an incident response plan that includes the legal workflow
- Cybercrime and computer misuse: the legal landscape
- Employee monitoring, BYOD and workplace privacy
- Intellectual property in the digital economy:
- Copyright in software, databases, content and documentation
- Trademarks and brand protection online
- Trade secrets and confidential business information
- Ownership of IP created by employees, contractors and technology partners
- Licensing, assignment and technology transfer
- Technology contracts — SaaS, cloud, hosting and data processing agreements, and the IP terms to check before signing
- Supplier due diligence where the supplier holds your data
- E-commerce: online terms, formation of electronic contracts, electronic signatures
- Consumer protection in online transactions
- Digital marketing, cookies, tracking and direct marketing consent
- Artificial intelligence and automated decision-making — governance, transparency and legal risk
- Practical exercises: a data subject request, a breach scenario, a contract review
FAQ