Data Privacy & Information Protection

Data Privacy & Information
Protection Statement

The Eswatini Environment Authority is committed to handling your personal and environmental data responsibly, transparently and securely — in accordance with the Data Protection Act, 2022.

Eswatini Environment Authority
Effective: 2026
Data Protection Act, 2022
1 Introduction

The Eswatini Environment Authority (EEA) is the national environmental regulator established under the Environment Management Act, 2002 with mandates including environmental protection, pollution control, climate change management, biodiversity conservation, compliance monitoring, environmental impact assessment (EIA) administration, and coordination of multilateral environmental agreements.

In fulfilling these mandates, EEA collects and processes information from regulated entities, communities, consultants, stakeholders, and the general public. The EEA is committed to ensuring that personal and environmental data is handled responsibly, transparently, and securely, in accordance with the Data Protection Act, 2022.

2 Purpose of This Policy

This policy outlines how the EEA manages all personal and environmental information required to fulfil its regulatory, monitoring, enforcement, advisory, and coordination functions as defined in national law. Protecting the privacy, confidentiality and security of your personal information is very important to us — it is critical for us to maintain your trust and act in the right way to meet your needs.

3 Scope

This policy applies to:

  • All EEA functions, directorates and units.
  • All information collected during EIAs, compliance audits, inspections, stakeholder engagements, climate and pollution monitoring, biodiversity programmes, licensing processes, and environmental fund administration.
  • All staff, contractors, consultants, and service providers working with the EEA.
4 Categories of Data Collected
4.1 Personal Information

EEA collects personal information only where necessary for regulatory, operational or administrative purposes. This may include:

  • Identification information (names, PINs, IDs).
  • Contact details.
  • Professional credentials (EIA practitioners, consultants).
  • Stakeholder submissions during public participation processes.
  • Financial information.
  • Compliance records of individuals involved in regulated operations.
4.2 Environmental & Regulatory Information

Collected as part of EEA's statutory functions under the EMA and other environmental legislation:

  • Environmental Impact Assessment data and reports.
  • Pollution monitoring data (water, air, land).
  • Climate change data, emissions reports and resilience information.
  • Biodiversity and biosafety assessments, including GMO handling data.
  • Hazardous waste and chemicals management records.
  • Spatial, GIS and environmental mapping information.
  • Information from inspections and law enforcement actions.
  • Laboratory test results (air, water, soil, pollution, chemicals).
  • Data generated from digital monitoring tools, WMIS, EDMS, e-licensing systems and project management systems.
4.3 Community & Stakeholder Inputs
  • Public comments during EIAs.
  • Feedback from Tinkhundla consultations and municipal engagements.
  • Information submitted during environmental education and awareness programmes.
  • Public consultation meetings and workshops.
5 How Data Is Collected

Data is obtained through:

  • Direct submissions (applications, permits, complaints, EIA reports).
  • Field inspections and monitoring visits.
  • Laboratory analysis and environmental sampling.
  • Digital platforms (EDMS, GIS systems, web applications, WMIS, "Government in Your Hand" systems).
  • Stakeholder consultations and public meetings.
  • Third-party sources such as municipalities, ministries, research institutions and law enforcement.
6 Legal Basis for Data Processing

Data processing is carried out under:

  • Environment Management Act, 2002.
  • EIA Regulations 2022, Waste Regulations, Air & Water Pollution Regulations.
  • Biosafety Act & Nagoya Protocol obligations.
  • Data Protection Act, 2022.
  • EEA's statutory functions in environmental monitoring, compliance enforcement, public awareness, environmental standards, biodiversity management and waste management.
7 Why EEA Processes Information
7.1 Regulatory Functions
  • Administering EIAs, permits and environmental authorizations.
  • Conducting inspections, compliance audits and enforcement.
  • Identifying pollution sources and issuing corrective actions.
  • Waste management authorizations.
  • Environmental monitoring (air, water, land, climate, biodiversity).
7.2 Policy, Planning & International Reporting
  • Supporting national obligations under MEAs such as UNFCCC, CBD, Stockholm, Basel, Rotterdam.
  • Compiling State of Environment Reports.
  • Climate change adaptation, emissions tracking and resilience planning.
7.3 Environmental Fund Administration
  • Assessing funding proposals.
  • Monitoring performance of funded projects.
  • Ensuring transparent and accountable fund management.
7.4 Public Engagement & Awareness
  • Conducting environmental education, advocacy and community outreach.
  • Facilitating meaningful public participation in EIA processes.
7.5 Institutional Operations
  • Digital transformation and automation of processes.
  • Risk management and performance monitoring.
  • Staff and stakeholder administration.
  • Financial administration.
8 Sharing of Information

EEA may share information with:

  • Government ministries, municipalities and regulators involved in environmental management.
  • Royal Eswatini Police Service and DPP for environmental crime enforcement.
  • International environmental bodies for MEA reporting.
  • Parties involved in transboundary movement of waste, genetically modified organisms, and HCFCs.
  • Laboratories, auditors and consultants performing work for the EEA.
  • Communities and the public where required by law (e.g. EIA disclosures).
  • Environment Fund Board of Trustees and donors.

Information is shared only where lawful, necessary, and aligned with the Data Protection Act. Providing personal information is voluntary; however it may be mandatory under certain circumstances.

9 Data Security

EEA implements administrative, physical and technological safeguards including:

Restricted access to sensitive data
Secure digital platforms (EDMS, WMIS, GIS)
Encryption and secure document transfer
Secure laboratory data records
Staff training on confidentiality
Incident reporting & breach response
10 Data Retention

Retention follows legal, regulatory and operational requirements, including:

  • Minimum retention aligned with environmental legislation, national guidelines and EEA policies.
  • Longer retention for compliance, climate data, biodiversity records, and long-term monitoring datasets essential for national reporting (e.g. SOER, SDG indicators, NDCs).
11 Rights of Data Subjects

In accordance with the Data Protection Act, individuals have the right to:

Access

Access your personal information held by the EEA.

Correction

Request correction of inaccurate or outdated data.

Objection

Object to processing, except where required by law.

Deletion

Request deletion of your data where appropriate.

Explanation

Request explanations on how your data is used.

12 Use of Environmental & Scientific Data

Certain environmental data such as pollution readings, emissions reports, SOER data, and EIA summaries may be published to advance public transparency, scientific research, and national policy development, in line with EEA's mandate.

No personal information will be published unless legally mandated.

13 Cookies & Digital Tools

Where EEA uses websites, environmental data portals, mobile reporting applications, or environmental mapping dashboards, cookies or analytics tools may be used to improve user experience. This includes:

  • Websites and web-based portals.
  • Environmental data and mapping dashboards.
  • Mobile reporting applications.

Any personal data collected digitally complies with the Data Protection Act, 2022.

14 Third-Party Service Providers

Service providers must comply with EEA's data protection standards and may be required to sign confidentiality or data processing agreements, especially when handling:

  • Laboratory samples.
  • Digital systems and platforms.
  • Environmental monitoring equipment.
  • EIA reviews.
  • Training and research partnerships.
15 Social Media

When you engage with us through our social media accounts, your personal information may be processed by the social media platform owner. This process is outside our control and the processing activities may be in a country outside of your home country that may have different data protection laws. For more information about the privacy practices of a social media platform, please refer to the terms and conditions of that platform before sharing any personal information.

Our social media accounts are not appropriate forums to discuss personal information and data. We will never ask you to share personal, account or security information on social media platforms.

16 Amendments to This Policy

EEA may update this policy in line with:

  • New environmental laws or regulations.
  • Updates to the Data Protection Act.
  • Institutional reforms.
  • Technological advancements in monitoring and compliance.
  • MEA updates.
17 Contact Information

For questions, complaints, or requests regarding personal or environmental information, contact:

Eswatini Environment Authority (EEA)
2404 6960 / 7893