Big news from Malawi: MACRA is reviewing the Communications Act (Cap 68:01) and wants input by September 5, 2025. This could significantly impact email marketing, ISP obligations, and data protection enforcement across the region.
The public call for recommendations is to update the Communications Act [Cap 68:01]. The review sits alongside Malawi’s anti‑spam rules in the Electronic Transactions and Cyber Security Act (2016) and the Data Protection Act (2024), where MACRA serves as the designated Data Protection Authority.
Stakeholders have 21 days from the notice to file inputs. MACRA requests each submission include the contributor’s name or organisation, contact details, interest in the sector, and specific recommendations with justification. Submissions may be sent by email, post, or delivered at MACRA offices; deadline 5 September 2025 as reported by TechAfrica News
Current rules that already affect email
- Unsolicited email is prohibited without prior consent. Senders must provide an unsubscribe option and, on request, identify the data source. Breaches carry penalties up to K2,000,000 and five years’ imprisonment for sending without consent, and K1,000,000 and twelve months for continuing after an unsubscribe.
- The Communications Act (2016) gives MACRA broad consumer‑protection and rule‑making powers, plus an electronic monitoring system for compliance. The law bars monitoring of actual content and limits use to regulatory purposes.
- Under the Data Protection Act (2024), MACRA is the designated Data Protection Authority; the Act covers breach notification and tightly regulates cross‑border transfers (sections 38–40) via adequacy, BCRs, contractual clauses, codes, or certification.
Why this review matters to email professionals
Updating Cap 68:01 is MACRA’s chance to align communications enforcement with privacy obligations and modernise ISP/ESP responsibilities. It may shape how consent standards, complaint handling, monitoring interfaces, and takedown actions are operationalised for bulk senders and platforms as reported by malawilii.org
Practical talking points for submissions
Focus on clarity, interoperability, and enforceability:
- Consent standard: Reaffirm opt‑in for direct marketing. Define soft opt‑in narrowly for existing customer relationships. Map the interplay with Data Protection Act lawful bases.
- Transactional vs promotional: Codify definitions and permissible service notifications.
- Unsubscribe and identification: Preserve one‑click unsubscribe and sender identification obligations across channels; ensure penalties align across Acts.
- ESP vs sender duties: Clarify due‑diligence, complaint handling, and abuse desk expectations for ESPs, while keeping primary liability on senders. Reference the Communications Act’s consumer‑protection and rule‑making framework.
- Monitoring safeguards: If MACRA uses data feeds from providers under the Act’s electronic monitoring parts, preserve the statutory ban on content monitoring and require transparency on what telemetry is collected.
- Breach and cross‑border: Align breach notice triggers and timelines, and reference sections 38–40 for international transfers to avoid contradictory obligations.
Logistics
- Deadline: 5 September 2025
- Where to send: dg@macra.mw (email), or deliver to MACRA offices; include identity, contact, interest, and justified recommendations.
Primary documents
- Communications Act (2016) – MACRA mandate, rule‑making, and electronic monitoring provisions. malawilii.org
- Electronic Transactions and Cyber Security Act (2016) – unsolicited communications and unsubscribe requirements with penalties. malawilii.org
- Data Protection Act (2024) – MACRA designated as DPA; breach and cross‑border transfer framework. Data Protection Authoritymwcert.mw
Editor’s note: MACRA states the review aims to keep the framework responsive to technology and market change and has stood up a Digital Laws Taskforce to intake feedback. Treat this as a live chance to harmonise email and privacy compliance in Malawi.








