(ii) in the case of a body corporate, a partnership or a firm, be liable to a
fine of K25,000,000; and
(b) is deemed to be a terrorist act, the person who committed the offence shall,
upon conviction, be liable to imprisonment for twenty five years.
(5) In addition to the penalty provided under subsection (4) (a) (ii), every director or officer
of the body corporate, or member of the partnership, or any other person concerned with
the management of the firm, shall be deemed to have committed the same offence and
shall, upon summary conviction, be liable to a fine of K10,000,000.
(6) A person shall not be convicted of an offence by virtue of subsection (5) if it is proved
that –
(a) due diligence was exercised on the part of the person to prevent the
commission of the offence; or
(b) the offence was committed without the knowledge, consent or connivance of
the person.
Localization
of
critical
data
23. - (1) An owner of critical data shall store all critical data on a server or data center
that is located within Malawi.
(2) Notwithstanding subsection (1), the Minister may authorize an owner of critical
data to externalize the critical data outside Malawi.
(3) In the event that the purpose for which the critical data was collected expires, or the
data controller ceases to exist, the critical data shall be surrendered to the Authority.
PART VI - CYBERSECURITY INCIDENT REPORTING
Duty
to
report
cybersecurity
incident
24. - (1) Where a particular sector has experienced a cybersecurity incident, the relevant
sectoral CERT shall report to the Malawi CERT on the occurrence of the incident.
21