(ii) in the case of a body corporate, a partnership or a firm, be liable to a fine of K25,000,000; and (b) is deemed to be a terrorist act, the person who committed the offence shall, upon conviction, be liable to imprisonment for twenty five years. (5) In addition to the penalty provided under subsection (4) (a) (ii), every director or officer of the body corporate, or member of the partnership, or any other person concerned with the management of the firm, shall be deemed to have committed the same offence and shall, upon summary conviction, be liable to a fine of K10,000,000. (6) A person shall not be convicted of an offence by virtue of subsection (5) if it is proved that – (a) due diligence was exercised on the part of the person to prevent the commission of the offence; or (b) the offence was committed without the knowledge, consent or connivance of the person. Localization of critical data 23. - (1) An owner of critical data shall store all critical data on a server or data center that is located within Malawi. (2) Notwithstanding subsection (1), the Minister may authorize an owner of critical data to externalize the critical data outside Malawi. (3) In the event that the purpose for which the critical data was collected expires, or the data controller ceases to exist, the critical data shall be surrendered to the Authority. PART VI - CYBERSECURITY INCIDENT REPORTING Duty to report cybersecurity incident 24. - (1) Where a particular sector has experienced a cybersecurity incident, the relevant sectoral CERT shall report to the Malawi CERT on the occurrence of the incident. 21

Select target paragraph3