This paper aims to examine impediments to compliance with the Botswana Data Protection Act (DPA) emanating from records management at the Botswana Unified Revenue Service (BURS). The goal is to provide recommendations in line with the UK Data Protection Code of Ethics (2007) to improve compliance with the DPA.
This paper applied a mixed research methodology and used questionnaires from 147 participants and interviews with 9 participants from a total population of 806 participants. Data from the questionnaires was analysed using Statistical Package for Social Sciences software Version 28 for descriptive statistics, whereas interviews were analysed using thematic analysis to identify themes and patterns.
The findings show that records management at BURS is not sound, thus undermining compliance with the DPA. The absence of an up-to-date records management policy, a procedure manual based on the records management function and a classification scheme illustrates this. Besides records management-related challenges, the findings also revealed a lack of awareness and understanding of the Act among BURS personnel and deficiencies in technical proficiency, regulatory guidance, management support and policies aligned with the Act.
The findings of this study can be used by policymakers (the government of Botswana, the judiciary and legislators) and other stakeholders to gain insight into compliance challenges and assist organisations in developing relevant policies, manuals and guidelines for data protection implementation in Botswana.
Research into the challenges of compliance with data protection legislation in Botswana is still in its infancy; hence, there is a need to provide insights and establish recommendations to improve compliance. To the best of the authors’ knowledge, this paper is one of the first research contributions to examine the impediments of compliance with the data protection law legislation in Botswana.
Introduction
Globally, data protection has become a critical concern for governments, ensuring that citizens’ personal information is protected from harm and misuse (Phillips, 2020; Wachter et al., 2017). This concern is especially relevant in Africa, where the growing interest in data protection regimes has spurred legislative efforts across the continent. However, previous studies indicate that despite efforts by African governments to enact data protection and privacy legislation, many remain non-operational due to several obstacles, which include poor implementation, lack of regulatory enforcement, inadequate institutional policies and financial constraints (Babalola, 2022; Reeves, 2021; Bryant, 2020; Ilori, 2020; Ademuyiwa and Adeniran, 2020; Makulilo, 2018). Several scholars have also suggested that poor records management within organisations is a critical factor hindering the implementation of data protection laws (Beckles, 2014; Kashaija and Ndumbaro, 2020; Keakopa and Mosweu, 2020). Scholars have argued that most countries lag in implementing data protection laws because colonial records management systems have become unfunctional. Consequently, the non-functional record-keeping systems contribute to poor records classification systems, over-retention of records and disposition, which affect compliance (McClure, 2018a, 2018b). The importance of records management in compliance with records and archival laws has been widely acknowledged in the literature.
Contextual background
Amid the growing interest in data protection regimes, Botswana enacted the Botswana Data Protection Act (DPA) of 2018. Before the DPA ratification, Botswana had provisions for protecting personal data under common law, the Constitution of Botswana and other passive legislation (Sebina, 2005). These provisions are embodied in Articles 3 and 9 of the Constitution, which guarantee the rights and freedoms of individuals, including the rights to property, opinion, race and others. Balule (2021) argued that these constitutional provisions do not address all privacy issues but instead focus on protecting property, and their interpretation is vague. Unlike the constitutional provisions, the DPA ensures the security of personal data obtained from identifiable individuals by ensuring that data managers adhere to security measures and provisions when processing data (DataGuidance, 2023). Specifically, it establishes a legal framework for the protection of personal information and individuals’ rights to process their data. Under this Act, individuals have access to their data, request the correction of inaccurate data and object to data processing (Government of Botswana, 2018). In 2021, organisations were provided with a 12-month transition period to comply with the DPA, which was extended to 2022 for another year due to a delay in the appointment of the Information Commissioner. In 2023, the grace period was extended again for another year to give organisations the time to develop procedures and guidelines for implementation.
This study was conducted at the Botswana Unified Revenue Service (BURS), a parastatal entity under the Ministry of Finance. BURS was established through the BURS Act of 2003 and has been operational since 2004, with the main headquarters in Gaborone and regional offices in Francistown, Lobatse, Selibe-Phikwe and Maun and satellite offices in Jwaneng, Mahalapye, Palapye and Serowe (BURS, 2021). The function of BURS entails assessing and collecting various taxes, including income tax, value added tax and capital transfer tax and managing statutory controls at border posts (BURS, 2024; Botlhale, 2016). The selection of BURS as a case study was motivated by their extensive handling of recorded data subject to the DPA requirements and the challenges they face in managing records. Some of these challenges include the absence of defined policies and procedures for electronic records, inadequate storage facilities, lack of management support, low prioritisation of records management functions, lack of trained records managers and deficiencies in classification schemes (Keakopa, 2013; Thabakgolo, 2023). These challenges are compounded by the requirements of the DPA, which necessitate robust records management practices for compliance. Against this background, this study sought to examine the impediments to compliance with the DPA emanating from records management at BURS.
Study objectives
This study was guided by two objectives, which sought to:
assess the impediments to compliance with the DPA at BURS emanating from records management; and
recommend practical solutions to address the impediments to enhance compliance.
Literature review
The nexus between records management and data protection
To uncover and unravel the relationship between records management and data protection, it is imperative to understand the meaning of each. ISO 15489 (International Organisation for Standardisation, 2016, p. 4) defines records management as an efficient and systematic control of the creation, receipt, maintenance, use and disposition of records, including processes for capturing and maintaining evidence and information about business activities and transactions. According to Privacy International (2018), data protection refers to safeguarding individuals’ data. Beckles (2014) mapped the relationship between these two concepts. He argued that records management and data protection are two sides of the same coin. For instance, the records management function ensures that recorded information is secure and has integrity, whereas data protects recorded information from harm by putting in place appropriate measures to safeguard the integrity of the data contained in records. Rylander (2018) expanded Beckles’ study by exploring the relationship between records management and data protection. He illustrated the connections between the association of records managers and administrators (ARMA) General Record Keeping Principles and key data protection laws such as the general data protection regulation (GDPR). For example, ARMA’s principle of accountability aligns with all GDPR principles, while the principle of availability corresponds with purpose limitation. The principle of compliance relates to data minimisation, lawfulness and transparency in the GDPR.
Records management as a catalyst for compliance
Globally, scholars such as Kahn (2004), Beckles (2014), McClure (2018a) and Canteli (2018) acknowledged that good record-keeping practices are required to comply with relevant legislative requirements. This is widely accepted in literature, which proves that records management and compliance are inseparable (Nkwe and Ngoepe, 2021; Keakopa and Mosweu, 2020). As such, records management is a prerequisite for compliance and vice versa. The understanding is that for sound records management to be attained, records management procedures and practices should be in line with data protection law requirements. Compliance with data protection laws affects all stages of the records management lifecycle, including the creation, storage, use and retrieval of records. McClure (2018a) highlighted that records management practices, such as classification, appraisal, retention and disposition, facilitate the protection of records.
Challenges of records management’s compliance with data protection laws
Despite the passing of data protection legislation globally, it has been observed that there are still gaps relating to compliance, resulting in the objectives of the law not being met. Theys et al. (2021) found that records management contributes to poor compliance with data protection legislation. The authors argued that the failure to comply with legislation results from ineffective record-keeping systems, such as poor classification systems, over-retention and record disposition (Theys et al., 2021). In the UK, data breaches have increased by 133% between 28th May 2018 and the end of October 2018, leaving over a million records vulnerable to unauthorised access (Reeves, 2020, p. 18). The conclusions drawn by Reeves (2020) reveal that most records management systems are non-existent and chaotic, making it difficult to comply with data protection legislation. Furthermore, legislation such as the GDPR requires records to be maintained for specific purposes. These laws emphasise the importance of not retaining data longer than necessary. However, organisations often fail to adhere to these provisions and keep records for extended periods, a practice known as “over-retention” (Costigan, 2020) Costigan (2020) further argued that the over-retention of records poses risks and opportunities for unauthorised access. Canteli (2018) concurred, stating that holding onto data for an excessive duration is likely to breach data protection laws and regulations. For instance, the UK’s excessive retention of personal data contravenes the storage limitation principle of the GDPR (McClure, 2018a). While the GDPR does not specify a specific retention period for data, organisations are responsible for determining appropriate retention periods [Information Commissioner’s Office (ICO), 2022]. The same applies to the Botswana DPA, as organisations have the responsibility for developing retention and disposition schedules in line with the requirements of the law. Similarly, the South African Protection of Personal Information Act (POPIA) also requires organisations to develop retention schedules (Government of South Africa, 2013).
Beckles (2014) asserted that compliance with data protection is experiencing challenges, such as limited resources, short compliance periods, lack of awareness, lack of guidelines, lack of management support and lack of policies and procedures for implementation. Some of these challenges were explicitly explained by Baloyi and Kotzé (2017), who revealed that information managers lack awareness of personal data laws, which makes it difficult to classify records in line with data protection requirements. Similarly, Kwatsha (2020) reported that SEFA organisations in South Africa lacked policies and guidelines specifically designed to facilitate compliance with the POPIA. In Botswana, the Work Bank report (2022) reported that the challenge affecting compliance spans from the failure of the regulatory authority to establish structures and guidelines required for implementation of the law. Kashaija and Ndumbaro (2020) highlighted the lack of policies as a significant barrier to compliance with privacy laws. They argued that the absence of organisational policies and guidelines hinders the effective adoption and application of legislation. Baloyi and Kotzé (2017) expressed a similar view, asserting that in the absence of records management policies, legislation, such as data protection laws, cannot effectively function as they need to align with institutional policies. Likewise, Makwae (2021) stated that the absence of policies signifies a lack of accountability and awareness regarding records management standards. This absence puts personal records at risk since there are no clear guidelines on how they should be handled and classified.
Hofman and Katuu (2022) argued that, without legal expertise, archives and records managers are bound to have problems interpreting laws. This problem has been linked to insufficient training of records managers. The lack of training programmes on data protection has been identified by Philips (2020) and Kwatsha (2020). The authors emphasised that limited knowledge of data protection legislation hampers their ability to meet compliance expectations. The lack of training is also acknowledged as a problem in Botswana, particularly in public services (Mosweu, 2019). The Botswana DPA is relatively new, and these challenges are compounded by the pressure to meet compliance requirements. This review did not come across any study that has examined the impediments to compliance with the Botswana DPA, thus prompting a study on this subject area.
Conceptual lens
This study adopted the UK Code of Practice for Archivists and Records Managers under the Data Protection Act of 1998. The Code of Practice was formulated in 2007 through collaboration involving the Society of Archivists, the Records Management Society and The National Archives. It provides comprehensive guidelines for managing personal data under the UK Data Protection Act, emphasising the establishment of meticulous records management policies, secure storage infrastructure and strict adherence to retention and disposition schedules (The National Archives, 2007). This framework is integral to this study as it offers a structured approach to ensuring compliance with data protection regulations. By promoting sound records management practices encompassing clear policies, procedural standards, ongoing training initiatives and adequate resource allocation, organisations such as BURS can effectively uphold data protection standards and operational integrity.
Methodology
This study adopted a mixed methods approach, integrating both quantitative and qualitative techniques to provide an understanding of the impediments to compliance with the DPA from records management. According to Cresswell and Cresswell (2018), the mixed methods approach enhances data validity through multiple data collection methods. Saunders et al. (2012) added that using mixed methods allows for both breadth and depth in data collection and analysis. For quantitative data, the sample size was computed to ensure that the study objectives were achieved. A preliminary sample size was estimated assuming a 95% confidence level, 5% margin of error and maximum variability (p = 0.5) for proportion estimates. This was then adjusted using finite population correction (FPC) to account for the known population size of n = 806, resulting in n = 261. To accommodate stratification, the sample was multiplied by an assumed design effect of 1.2. Hence, a final sample size of 314 (rounded up) was required. Proportional allocation was used to ensure fair distribution for each division. This was done to ensure that each division had an equal chance of being represented in the sample and that the results obtained can be generalised to the entire population (see Table 1).
Study participants and sample size
| Division | In post for HQ | Sample size |
|---|---|---|
| Board Secretary and Legal Services | 12 | 5 |
| Internal Audit and Ethics | 21 | 8 |
| Domestic Taxes | 22 | 9 |
| Customs Services | 36 | 13 |
| Commissioner General’s Office | 37 | 14 |
| Human Resources | 41 | 16 |
| Information Technology | 48 | 19 |
| Finance and Administration | 135 | 53 |
| Operations | 454 | 177 |
| Total | 806 | 314 |
| Division | In post for | Sample size |
|---|---|---|
| Board Secretary and Legal Services | 12 | 5 |
| Internal Audit and Ethics | 21 | 8 |
| Domestic Taxes | 22 | 9 |
| Customs Services | 36 | 13 |
| Commissioner General’s Office | 37 | 14 |
| Human Resources | 41 | 16 |
| Information Technology | 48 | 19 |
| Finance and Administration | 135 | 53 |
| Operations | 454 | 177 |
| Total | 806 | 314 |
Questionnaires and interviews were used for data collection. The study first distributed 314 questionnaires to a randomly selected sample from a population of 806 employees at BURS. The respondents included directors, managers, accounts officers, human resources, legal personnel, information technology personnel and other action officers across divisions. The questionnaire was designed to address all research objectives. The respondents returned 147 out of the 314 questionnaires distributed, resulting in a response rate of 47%. Baruch and Holtom (2008) suggested that a response rate of 60% (±20) is acceptable. Even though the response rate was below this suggested threshold, it was substantial enough to make generalisable conclusions about compliance at BURS. Therefore, the response rate was deemed acceptable because it provided sufficient data to conduct the analysis and draw reliable conclusions.
Following the questionnaire survey, semi-structured interviews were conducted through purposive sampling with nine respondents from six divisions: finance and administration, operations, human resources, legal and board secretary, information technology and domestic tax. The selection criteria included expertise in records management and direct involvement in data protection and the compliance process. The interviews were intended to corroborate the questionnaire data until theoretical saturation was reached. For quantitative data analysis, a descriptive frequency analysis was performed using IBM Statistical Package for Social Sciences version 28 for descriptive statistics. The interviews were analysed using thematic analysis to identify themes and patterns. For anonymity, alpha-numeric codes were used for respondents who took part in interviews, for example, respondent BURS-4/BURS-7. The study required the participation of employees at BURS; hence, their individual consents were sought. Moreover, the study was submitted to the Office of Research and Development for ethical review.
Findings and discussion
This section presents the findings of this study, including a brief discussion. These findings are presented in line with the research questions.
Impediments of compliance with the DPA emanating from records management
The first objective examined the impediments to compliance with the DPA emanating from records management. The study first focused on the records management function by interviewing three respondents. Respondents were questioned on the following: records management policy and procedures, retention and disposal schedule, records classification scheme and management support for records programmes:
Obsolete records management policies and procedures.
Sound records management policies and procedures are essential for enhancing compliance with data protection regulations (The National Archives, 2007). While BURS has a policy and procedures for paper records aligned with ISO 15489, the interviews highlighted a gap. These policies have not been updated to reflect relevant clauses emanating from the DPA. This misalignment suggests a reactive rather than proactive approach to compliance. Also, insisting on the lack of a detailed records management policy, BURS-4 stated, “We do have a records management policy which is general in its clauses and does not have any specific inclusion of personal data, or how it is supposed to be handled”. The obsolete records policy and procedures are problematic because without clear, updated guidelines, BURS may struggle with fundamental compliance areas such as access control, data handling procedures and data retention schedules. Makwae (2021) underscored that the absence of an updated policy signals a lack of accountability and awareness in data protection, which increases the risk of mishandling sensitive data. Furthermore, without explicit directives on personal data processing, employees may apply inconsistent data handling practices, leading to potential data breaches:
Lack of records classification schemes.
Records classification is a fundamental element of effective data governance, ensuring that records are systematically identified, protected and retrieved. However, findings from the study revealed that BURS lacks a specific security classification scheme for personal data. Instead, records are categorised under broad classifications, which include confidential, open and secret, which may not adequately address the security requirements for the DPA. Although the aforementioned categorisations restrict unauthorised access to personal data and align with the DPA principles, the absence of a security classification scheme still makes it difficult for the records management function to protect records. These findings are consistent with those of McClure (2018a) and Netshakhuma (2020), who observed similar challenges in other organisations lacking classification schemes in the UK and South Africa, respectively. Moreover, previous studies in Botswana (Tshotlo and Mnjama, 2010; Ngoepe and Keakopa, 2011; Mampe and Kalusopa, 2012) have widely documented that the absence of classification schemes undermines security standards. As the Code of Practice highlights, failing to implement security classifications not only increases the risk of unauthorised access, but also impacts on an organisation’s ability to meet compliance requirements (The National Archives, 2007):
Obsolescence of retention and disposition schedules.
The UK Code of Practice emphasises that effective retention and disposition schedules are critical for ensuring compliance with data protection laws by preventing unnecessary storage of personal data, which can increase risks related to security breaches. The presence of a records retention and disposition schedule at BURS demonstrates an effort towards sound records management. These schedules, incorporated into the records policy, stipulate a five-year retention period for records and guide the destruction process. However, despite the existence of these schedules, this study found that they are outdated and misaligned with the data protection requirements. One significant issue is that the organisation’s records policy, under which these schedules fall, has not been reviewed to align with the DPA. This means that the schedules may not adequately meet compliance expectations, leaving BURS at the risk of retaining records for longer durations than necessary or disposing them prematurely. A further challenge arises from the vague provisions of the DPA in Section 14, Article (h) (Government of Botswana, 2018). This ambiguity is not unique to Botswana; similar gaps exist within the GDPR, leaving retention periods at the discretion of institutions (ICO, 2022). While this flexibility allows for sector-specific policies, it also places a significant compliance burden on institutions, requiring them to determine and justify retention and disposition schedules independently:
Insufficient storage for records.
As identified by Beckles (2014), the adequacy of resources from the records management function plays a pivotal role in supporting sound records management practices that align with data protection prescriptions. In relation to this, participants were asked about the availability of sufficient storage. Only one interviewee, BURS-4, indicated that adequate resources were available, while two of the interviewees, BURS-1 and 3, said that resources were lacking. Respondent BURS-4 was further questioned on available resources. They mentioned that resources such as locked safes and in-built strong rooms are present to secure personal data and thereby enhance compliance. Despite these positives, interviewee BURS-1 stated that:
BURS still lacks forensic teams and facilities to protect data from criminal exhibits or evidence.” This is because such data cannot be mixed with day-to-day data processes.
They further explained that BURS is forced to send such data and property to the Receiver’s office, which operates under the Ministry of Defence, for appropriate handling. This is important as it ensures that criminal exhibits or evidence are treated with care and security to prevent tampering or loss of such data. However, this practice increases the risk of unauthorised access to records during transfer. The issue of inadequate storage space is not new at BURS, as was confirmed in an earlier study by Keakopa (2013). This paper argues that this issue affects records management procedures such as retention and disposition, which are key for compliance.
Broader challenges to DPA compliance across BURS
Beyond the records management function, the study also identified other systemic and organisational factors that impede compliance with the DPA:
Lack of management support.
This study posits that management support for records management plays a vital role in enhancing compliance. The study findings revealed that BURS management did not support DPA implementation. Most respondents, 128 (67.9%), indicated that they did not receive any support relating to DPA compliance. These findings were further corroborated by interviewees who expressed frustration over the management’s lack of commitment to both records management and compliance activities. In their own words, interviewee BURS-7 and 1 mentioned that:
I do not think the top management has done enough to publicise the DPA and send notices as they should. We are still waiting to hear from their side (BURS-7).
I have noticed that no support is there for the records function regarding any law not just the DPA, because records are undervalued, and people forget that they are the core of the organization (BURS-1).
In addition, respondent BURS-5 highlighted that senior management has been silent on matters of compliance and has yet to engage with the records management function regarding the DPA. This lack of engagement suggests that the records management function is not integrated into the BURS compliance strategy, making the implementation unrealistic. These findings are consistent with those of Keakopa (2013) and Thabakgolo (2023), who identified a longstanding lack of commitment to records management activities within BURS. Similar trends have been observed in the ESARBICA region, where governments have historically overlooked records management, leading to poor legislative compliance (Ngoepe and Keakopa, 2011). Karlos and Nengomasha (2018) further argued that without proactive leadership, records management programmes struggle to function effectively, thus increasing institutional risks:
Lack of awareness and understanding of data protection provisions.
Most data protection legislations are complex and lack uniformity across jurisdictions (Mulligan et al., 2019, p. 1; Brinnen and Westman, 2019). Given this complexity, regular awareness campaigns are essential to ensure that records management staff and action officers understand their compliance responsibilities. However, the findings of this study indicate a low awareness of DPA at BURS. A total of 107 (72.8%) respondents indicated that they were unaware of DPA requirements (see Table 2). This lack of awareness presents a critical compliance risk, as employees who handle personal data may unknowingly engage in practices that violate DPA requirements. Moatlhodi and Kalusopa (2016) stressed that the lack of awareness of archival legislation contributes to lower compliance levels in the public sector, thus exposing them to legal, reputational and operational risks. These findings are consistent with studies in other contexts. For instance, Baloyi and Kotzé (2017) found that individuals handling personal data in South Africa struggled with compliance due to unfamiliarity with the Protection of Personal Information Act (PoPI). Similarly, Netshakhuma (2020) reported that most South African universities lacked awareness of the PoPI Act, which delayed compliance. This suggests that low regulatory awareness is a widespread issue, not unique to BURS or Botswana, further reinforcing the need for structured educational programmes.
Responses on the impediments of compliance with the DPA
| Statement | Yes | No | NR | Total | |||
|---|---|---|---|---|---|---|---|
| Impediments of compliance | f | (%) | f | (%) | (%) | ||
| Awareness of the DPA | 107 | 72.8 | 40 | 27.2 | 147 | ||
| Comprehension of the DPA | 119 | 81.0 | 26 | 17.6 | 2 | 1.4 | 147 |
| Technical skills and knowledge on the use of the DPA | 133 | 90.5 | 12 | 8.5 | 2 | 1.4 | 147 |
| Procedural guidance for DPA use | 132 | 89.9 | 13 | 8.8 | 2 | 1.4 | 147 |
| Management support for DPA implementation | 128 | 67.9 | 19 | 12.9 | 147 | ||
| Training on DPA application | 137 | 93.2 | 9 | 6.1 | 1 | 0.7 | 147 |
| Statement | Yes | No | Total | ||||
|---|---|---|---|---|---|---|---|
| Impediments of compliance | f | (%) | f | (%) | (%) | ||
| Awareness of the | 107 | 72.8 | 40 | 27.2 | 147 | ||
| Comprehension of the | 119 | 81.0 | 26 | 17.6 | 2 | 1.4 | 147 |
| Technical skills and knowledge on the use of the | 133 | 90.5 | 12 | 8.5 | 2 | 1.4 | 147 |
| Procedural guidance for | 132 | 89.9 | 13 | 8.8 | 2 | 1.4 | 147 |
| Management support for | 128 | 67.9 | 19 | 12.9 | 147 | ||
| Training on | 137 | 93.2 | 9 | 6.1 | 1 | 0.7 | 147 |
NR = no response
This paper also argues that general awareness of the DPA does not translate to its comprehension, which is critical to compliance. This implies that records managers might be aware of the DPA, yet they still struggle to interpret and apply its requirements. The UK Code of Practice supports this as it requires record managers to understand data protection to ensure compliance with data protection laws (The National Archives, 2007). The study findings have revealed that there is a lack of understanding of the requirements of the DPA at BURS. A total of 119 respondents (81.0%) indicated that they did not understand the provisions of the said law. This was confirmed in an interview with respondent BURS-6, who stated the following:
Despite being at the forefront of the compliance team, I still lack an in-depth understanding of the requirements stipulated in the DPA. Most of the time, our office applies professional ethics to protect personal data.
The above statement suggests that instead of relying on the DPA, employees at BURS continue to depend on traditional data privacy protocols, such as the Oath of Secrecy and other tax laws, to manage personal data. This reliance on outdated mechanisms, rather than DPA requirements, poses compliance risks and highlights the need for improved regulatory literacy. Furthermore, a review of the DPA shows that the terminology used to describe principles is new to records management practice. For instance, participants do not understand that they are “data controllers”, making it difficult to understand their role in data protection. Similarly, Kandeh et al. (2018) found that, although there was general awareness of POPI among data controllers, they still faced challenges in relation to enforcement because of the complexity of the law. Furthermore, DPA is not prescriptive in nature, as it does not define what measures must be taken explicitly in practice, for example, in Sections 14 and 15, which relate to collecting and processing personal data. Thus, this becomes a problem when developing and aligning policies to the DPA. This problem, as explained by Botha et al. (2015), poses a significant risk, as it increases the likelihood of mishandling or improper processing of personal data, potentially leading to violations of the law:
Lack of technical proficiency.
According to the UK Code of Practice, technical proficiency of data controllers is a critical factor in ensuring compliance with data protection legislation (The National Archives, 2007). This implies that BURS records and action officers should possess the technical skills required for the application of the DPA in handling and processing data. The study findings revealed that 133 respondents (90.5%) were not technically proficient to use the law. This deficiency was further highlighted in interviews, where respondents expressed uncertainty about how to operationalise the law. Interviewees stated that:
I find the law to be generic and vague in its application. Also, I think the DPA is good in theory, but when it comes to implementation mechanisms, it is unclear what organisations are required to do. (BURS-1).
I do not know how to use the DPA because there is no manual or procedure on how the law is to be applied in business practice. I think BURS should engage with us in on training and workshops to educate us on how to use the law (BURS- 9).
These findings highlight the skills and knowledge gap within BURS regarding protection. As discussed earlier, Sections 14 and 15, which govern the collection and processing of personal data, are non-prescriptive, leaving BURS with insufficient guidance on how to develop internal compliance frameworks. Without technical expertise, BURS personnel may struggle to tailor their data handling policies in line with the DPA requirements. The lack of technical proficiency related to privacy laws has also been identified by other researchers (Phillips, 2020; Ducato, 2020). Keakopa (2013) notes that the deficiency in technical proficiency often stems from inadequate training among records managers in the public service. Consequently, this prevents data managers from discerning record management requirements from legislative requirements (Mosweu, 2019, p. 121):
Lack of training on data protection.
Several scholars have identified the absence of training as one of the factors that hinder compliance with archival laws (Kashaija and Ndumbaro, 2020; Makwae, 2021; Baloyi and Kotzé, 2017). This is consistent with the findings of this study, which show that BURS lacks training initiatives on the DPA. This was revealed by 137 respondents (93.2%) who reported that they had not received formal training concerning DPA, whereas 9 (6.1%) reported that they had been trained (see Table 2). Despite the absence of formal training programmes, the interview findings showed that BURS has made limited efforts to educate employees through workshops on how to handle personal data. For instance, a workshop was conducted to educate the information technology division on the requirements of the DPA. However, this was not consistently implemented throughout BURS, which is a concern, particularly for other departments, such as the records management function, given their role in compliance. The lack of training on data protection at BURS presents compliance risks, as employees are expected to enforce the DPA requirements that they have not been adequately trained to understand or implement. This is supported by Keakopa and Mosweu (2020), who argued that if information managers do not have appropriate record management training, there is a high probability of poor record-keeping practices and compliance requirements are unlikely to be met. The lack of training in record management is a widespread problem in Botswana, as acknowledged by Mosweu (2019). This problem continues to prevail in the ESARBICA region, as highlighted by Nengomasha (2013) and Makwae (2021):
Lack of procedural guidance.
The availability of procedures is one of the key success factors in compliance with data protection laws within a records management programme. The UK Code of Practice states that organisations need to develop procedures that guide the implementation of data protection laws (The National Archives, 2007). However, this study established that BURS lacks structured procedures and guidelines to guide compliance. A total of 132 respondents (89.9%) indicated that there were no compliance procedures. The interviews also confirmed that there was no manual or interpretation of how the law should be applied to business activities. Revealing this, interviewees BURS-3 and BURS-4 stated that:
As an officer, I have gone through the Act, and there is no manual on how the DPA must be integrated into corporate information and security policies yet. BURS needs to develop manuals to guide us; otherwise, the law will result in staff unable to carry out their work or not complying at all because they do not know what to do (BURS-3).
The act is still new and there is no interpretation yet on how it should be applied. I think there should be detailed procedures on how it should be applied, otherwise enforcement of the law is going to be extremely difficult (BURS-4).
The absence of guidelines presents obstacles to compliance at BURS, particularly when the DPA requires practical translation into institutional policies and workflows. The lack of procedural guidance has been widely documented in the literature. For example, Phillips (2020) reported a lack of guidance on how to apply and practice with the UK GDPR in the UK’s further education sector. Phillips (2020) pointed out that a lack of guidance leads to a gap in data protection practices. This finding is consistent with that of Maraga et al. (2022, p. 133), who argued that the DPA is not yet fully operational due to the absence of a robust institutional framework. The lack of procedures to guide data protection implementation appears to be a global problem as revealed by Netshakhuma (2020) and Kwatsha (2020). In addition, this study contends that the lack of procedures spans from the failure of the Botswana Communications Regulatory Authority and the Botswana National Archives and Records Services (BNARS) to develop structures and procedures for DPA implementation. Moreover, the delayed appointment of an information commissioner may have contributed to the delay in developing procedures for DPA compliance. Ngoepe et al. (2010) revealed that there is lack of document code of ethics that embrace policies and regulatory frameworks in the ESARBICA region. This study contends that the lack of procedures will continue to create problems for compliance, because requirements regulating data protection are dependent on RM procedures for implementation.
Recommendations with the guidance of the UK code of practice to improve compliance
Given the impediments to compliance with the DPA at BURS, the second objective of the study provides recommendations with the guidance of the UK Code of Practice to curb the identified impediments to compliance:
Strengthen the records management programme.
The study highlighted that BURS still grapples with outdated records management policies and procedures, thus undermining records management as a tool for compliance. To address this, this study recommends BURS to redevelop the records management programme in line with the requirements emanating from the DPA. For instance, the programme should establish how records should be created, captured, classified, stored and destroyed. This is in line with the UK Code of Practice, which emphasises the need for current policies that align with legal requirements and safeguards for personal data. The policies should address the classifications systems, retention and disposition schedules:
Raise awareness on data protection requirements.
This study documented that most respondents at BURS were unaware of the DPA requirements and their implications. Therefore, this study recommends that BURS urgently educate employees through awareness campaigns, workshops and timely notices. This will help employees understand compliance risks and their data protection responsibilities. This area needs to be addressed urgently, considering the national grace period for complying with the DPA. This is in line with the UK Code of Practice, which underscores that it is the responsibility of records managers to ensure they are familiar with the data protection requirements (The National Archives, 2007):
Develop data protection procedures and guidelines.
Data controllers and record managers at BURS need proper guidelines to understand and apply DPA prescriptions. The UK Code of Practice offers some good insight into the importance of having clear ethical guidelines and procedures to ensure responsible data handling. This study recommends BURS to develop a code of practice and manuals involving stakeholders, such as senior management, legal counsel and the records management function. These guidelines must cover data protection requirements, roles, training, security, access, transfer, retention and destruction of personal records. In addition, BURS should collaborate with BNARS for best practices and BORCA for DPA implementation structures (see Figure 1):
The diagram presents a hierarchical organisational chart. At the topmost level is the Information Commissioner. Below this role, two parallel entities are listed: B O C R A and B N A R S, connected by vertical lines indicating a reporting relationship. These in turn lead down to a central block labeled Senior Management, signifying a shared supervisory level beneath the two entities. From Senior Management, three distinct roles are connected horizontally: Legal Counsel, Records Manager, and IT Manager. Each of these roles appears on the same tier and is aligned directly below Senior Management. Dashed lines are used throughout the chart to represent reporting pathways and organisational relationships. The structure is vertically aligned, with a clear top-down flow showing how authority and roles are distributed within the organisation.Proposed framework for stakeholders responsible for developing data protection policies and manuals
Source: Author’s own work
The diagram presents a hierarchical organisational chart. At the topmost level is the Information Commissioner. Below this role, two parallel entities are listed: B O C R A and B N A R S, connected by vertical lines indicating a reporting relationship. These in turn lead down to a central block labeled Senior Management, signifying a shared supervisory level beneath the two entities. From Senior Management, three distinct roles are connected horizontally: Legal Counsel, Records Manager, and IT Manager. Each of these roles appears on the same tier and is aligned directly below Senior Management. Dashed lines are used throughout the chart to represent reporting pathways and organisational relationships. The structure is vertically aligned, with a clear top-down flow showing how authority and roles are distributed within the organisation.Proposed framework for stakeholders responsible for developing data protection policies and manuals
Source: Author’s own work
Training and staff orientation.
This study recommends that BURS develop training programs for all divisions to address the gap in skills required to apply DPA requirements. Collaboration with the HR department, training should be included in the induction programme and conducted through divisional seminars and workshops. This will improve data controllers’ comprehension of the law and integrate data protection into the organisational strategy.
Conclusion
This study underscored the importance of having effective records management programmes to support data protection activities that enhance compliance. A detailed look at BURS records management illustrated gaps in their programme, highlighting the shortcomings of complying with the DPA. This has shown that the records management function is not prepared to implement and comply with the DPA. The existing records management procedures are yet to reflect the desired and expected privacy benefits. These include unlawful creation, storage and sharing of records; incomplete records; inconsistent classification schemes; and poor records retention and disposition. To this end, this study concludes that the only way to comply with the DPA at BURS is through sound records management. Other common issues that affect compliance with the data protection legislation include the low level of awareness of legal frameworks, the lack of guidance and support, the lack of resources, poor implementation and the lack of records management policies and procedures that guide the data protection law practice.

