BPS LogoBPS eServices

Privacy Policy

This Privacy Policy explains how the Botswana Government ("Government"), through the Botswana Police Service ("BPS"), uses and protects any information that you provide when using the BPS e-Services Portal ("Portal").

Government is committed to ensuring that your privacy is protected. If we ask you to provide information by which you can be identified when using this Portal, you can be assured that it will only be used in accordance with this Privacy Policy and applicable laws of the Republic of Botswana.

1. Information We Collect

Government may collect the following categories of information:

  • Company names, officials' details and addresses;
  • Individual names, national ID or passport details, date of birth, gender and other identity information;
  • Contact information including email address, telephone numbers and mobile number;
  • Demographic information such as residential address, postal address, locality and related location details;
  • Information relating to specific services requested or provided, including application forms, supporting documents and correspondence;
  • Sensitive personal data: Photographs and fingerprints collected for police clearance, firearms licensing or identity verification; records of offences and related proceedings revealed by a clearance check or a traffic-fine search; disability information you choose to give us; and the personal data of a child where a parent or guardian applies on their behalf. Section 8 explains how each is handled;
  • Technical information such as IP address, browser type, device information and usage logs collected for security and audit purposes.

2. Why We Collect This Information

We collect and process this information to provide you with a better service, and in particular for the following reasons:

  • Processing applications, requests and other services offered through the Portal;
  • Service offering and delivery improvement;
  • Communication about the services you have requested — application status, appointments, payments and verification codes;
  • Registry upkeep and maintenance of accurate public records as may be applicable;
  • Security monitoring, fraud prevention, auditing and compliance with legal or regulatory obligations.

We do not use your personal data for direct marketing. If that ever changes, you will be told first and given a free and simple way to object, as section 48 of the Data Protection Act, 2024 requires.

Fields marked with an asterisk on our forms are required: without them we cannot verify your identity or process the application concerned. All other fields are voluntary, and leaving them empty does not affect your application.

3. Legal Basis for Processing

We process your personal data under the following legal bases, under section 26 of the Data Protection Act, 2024: your consent (s.26(a)), compliance with a legal obligation (s.26(c)), and the performance of a task carried out in the public interest or in the exercise of BPS's official authority (s.26(e)). We do not rely on the legitimate-interests basis (s.26(f)), because that basis is not available to BPS as a public authority acting in the performance of its functions. Where a service does not need your consent to proceed, we never make giving it a condition of using that service (s.27(4)). The table below maps each processing activity to its primary lawful basis:

Processing ActivityData InvolvedLawful Basis
Account registration & loginName, ID/passport, email, phoneConsent & contractual necessity
Identity verification (Omang)National ID number, biographic detailsLegal obligation & public interest
Application processing (permits, clearances)Application forms, supporting documentsContractual necessity & public interest
Biometric collection (photos, fingerprints)Photographs, fingerprint dataExplicit consent & legal obligation
Firearms registrationFirearm details, ownership recordsLegal obligation
Online payment processingPayment reference, amount, payer identityContractual necessity (at your initiative)
Session management & authenticationSession tokens, JWT, IP addressContractual necessity
Security monitoring & audit logsIP address, browser info, access logsPublic interest task & legal obligation (s.26(c)/(e))
Cookie consent preferencesConsent choices, timestampConsent

4. Sharing and Disclosure

Information you provide may be shared within Government ministries, departments and agencies strictly on a need-to-know basis for the purposes mentioned above. Government will not sell your personal information to third parties.

No trade secrets, intellectual property or confidential information should be shared via this Portal unless expressly requested. Where necessary for further contracting, appropriate written agreements, including Non-Disclosure Agreements, shall be signed.

5. Third-Party Data Processors

The Portal uses the following third-party systems to deliver its services. Data shared with these systems is limited to what is necessary for their function:

  • Keycloak (Identity Provider): Manages authentication and user account security. Receives your login credentials and identity details.
  • 1Gov (Government Platform): Confirms your identity details against the national register during registration, and receives application data for processing by the relevant government departments.
  • Omang Verification Service: Used to verify national ID details during registration and identity validation.
  • MinIO (Document Storage): Stores uploaded documents such as photos, identity documents and supporting files securely.
  • Resend (United States): Sends transactional email on our behalf, including one-time codes used to verify your account and reset your password. Resend receives your email address and the content of the message.
  • PayGate (Payment Gateway, South Africa):Processes online card payments. When you pay, you are redirected to PayGate's secure page, where PayGate receives your payment and connection details; your card details are entered directly with PayGate and never pass through the Portal.
  • Traffic-fine payment gateway: Where a service lets you search and pay traffic fines, your ID number, name, address and the fine details are shared with the gateway operating that fine system to identify your fines and issue the invoice.
  • Push notifications:the Portal can register your browser to receive push notifications, but the Service does not send them at present — outbound delivery to the browser vendors' relays (Google, Mozilla or Apple) is blocked by the platform's egress policy, so no notification of yours is sent to them. If push delivery is switched on, this notice will be updated before it is.

6. International Data Transfers

Your personal data is stored and processed within Botswana on Government-managed infrastructure. Two kinds of transfer are known to take personal data outside Botswana, and both are described below; they are the only ones we have identified. One further recipient is unresolved: the hosting country of the traffic-fine payment gateway is being established, and this notice will be updated when it is. Browser push notifications are not a transfer either: the Service does not deliver any today because no relay is on the platform's egress allowlist, and this notice will be updated before that changes.

  • Resend (United States): sends transactional email on our behalf, including the one-time codes used to verify your account and reset your password. Resend receives your email address and the content of the message.
  • PayGate / DPO Group (South Africa): processes card payments when you choose to pay online. PayGate receives your payment reference, amount and payer identity; your card details are entered directly with PayGate and never pass through the Portal.

No adequacy decision has been published under section 75 of the Data Protection Act, 2024 for either the United States or South Africa. BPS is applying to the Information and Data Protection Commission for authorisation of the contractual clauses that will govern these transfers under section 76(3)(a). Once that authorisation is in place, you may obtain a copy of the clauses by emailing the Data Protection Officer at dpo@police.gov.bw. We have identified no other transfer: push notifications are not delivered (see section 5), and identity verification is hosted by BPS in Botswana. The one open question is the traffic-fine payment gateway — its hosting country is being established, and this notice will be updated when it is.

7. Automated Decision-Making and Profiling

The Portal uses automated processing in three places:

  • Identity check: software compares a live photo of you with your identity document. If the comparison is refused three times, you are referred to a police station to complete the check in person. After any refusal, you may ask a police officer to review the result; we aim to complete the review within 5 working days and escalate it to the Data Protection Officer if it is late.
  • Firearms acquisition-permit draw: where permits are limited, successful applicants are selected by a computer random draw within the quotas published for that draw. The result is confirmed by a supervisor before letters are issued.
  • Emergency reports: your answers to the incident questionnaire are used to generate a priority risk score that helps route the report; a BPS officer decides how to respond, and the score does not itself determine the outcome.

No fully automated decision with legal or significant effects is made about you without the possibility of human review. Under sections 49 and 40(1)(g) of the Data Protection Act, 2024 you may request human intervention, express your point of view, and contest any decision informed by automated processing, including through the Data Protection Officer or by complaint to the Information and Data Protection Commission (s.49(3), s.80).

8. Sensitive Personal Data

The Data Protection Act, 2024 treats some kinds of personal data as sensitive and allows them to be processed only with your written consent, where another law authorises it, or in the other narrow cases the Act lists. The portal touches the following:

  • Biometric data (photographs and fingerprints): Photographs are collected during police clearance applications, firearms licensing and identity verification. Fingerprints are taken at the police station you select as part of clearance certificate processing. Both are collected only with your written consent, which you give when you accept the terms of that service, and you may withdraw it by cancelling the application before the certificate or licence is issued.
  • Records of offences and proceedings: A police clearance check reveals whether any offence is recorded against you; a traffic-fine search returns the fines recorded against your ID number. These records are processed under the written law that governs each service and are used only to produce the result you applied for.
  • Personal financial information: Fine amounts and payment references, processed only to identify and settle the fine you selected.
  • Disability and health-related information: Voluntary. You may leave the disability field on your profile empty; if you complete it, it is used only to arrange reasonable accommodation at appointments.
  • Personal data of children:Applicants aged 16 or 17 hold their own account and submit their own applications; a parent or guardian confirms consent when the account is created (section 29). Under 16, a parent or guardian applies on the child's behalf at a police station. In either case, the child's details are sensitive personal data and only the details the service needs are collected.

Sensitive personal data receives enhanced protection:

  • Stored separately from general personal data with additional access controls;
  • Access restricted to authorised officers on a strict need-to-know basis;
  • Retained only for as long as required by the relevant statutory retention period, after which it is securely deleted.

9. Protection and Security of Information

Government is committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.

These measures include encrypted data transmission (TLS/HTTPS), secure token-based authentication, role-based access controls, and regular security monitoring of all Portal systems.

However, you also play an important role in protecting your information by keeping your login details confidential and notifying BPS promptly of any suspected misuse of your account.

10. Data Breach Notification

In the event of a breach of the security safeguards protecting your personal data, BPS will:

  • Notify the Information and Data Protection Commission within 72 hours of becoming aware of the breach, as section 63 of the Data Protection Act, 2024 requires, and require any processor holding data on our behalf to notify us without delay in turn;
  • Notify you directly, without undue delay, where the breach is likely to result in a high risk to your rights and freedoms, as section 64 requires, using the contact details held on file (email and/or SMS);
  • Document all breaches, including the facts, effects, and remedial actions taken, regardless of whether notification is required.

11. Data Retention

Information will be retained only for as long as is necessary to fulfil the purposes for which it was collected. The table shows the period for each category and how it is enforced. "Automated" means a scheduled job on the portal identifies and removes the data when the period ends; "BPS records schedule" means the data lives in police record systems and is disposed of under the Service's records management procedures rather than by the portal. The time limits below reflect the platform's configured retention policy, but the automated rows are enforced by the platform only once the Data Protection Commissioner's order bringing them into force has been made; until then the scheduled job runs in report-only mode.

Data CategoryRetention PeriodAfter ExpiryEnforcement
Sign-in session8 hours, or 30 minutes without activity, whichever comes firstSession cookie expires; you are signed outAutomated
Passport scan uploaded during a registration that was never completed7 daysSecurely deleted from storageAutomated
User account and profile dataUntil an approved erasure requestErased: every identifying detail is removed from the account and your sign-in identity is deleted. Application records the law requires BPS to keep are retained under their own row below, no longer linked to your identity.Automated
Applications you start but never submit (drafts)12 monthsSecurely deletedAutomated
One-time codes and password-reset tokensCleared within one day of expiryPermanently deletedAutomated
Audit & security logs3 yearsPermanently deletedAutomated
Permit & clearance applications5 years from decision dateArchived or deletedBPS records schedule
Documents uploaded with an application (photos, IDs, supporting files)Duration of application processing + 2 yearsSecurely deleted from storageBPS records schedule
Biometric data (fingerprints, photographs)As required by the statute governing the serviceSecurely deletedBPS records schedule
Firearms registration recordsDuration of licence + 10 yearsArchived per statutory requirementsBPS records schedule
Consent recordsKept for as long as the processing they authorised can be questionedConsent records: kept as evidence of lawful basis; health-related consent records are deleted with the dataBPS records schedule
Cookie preference and other browser-side settingsUntil you change them or clear your browser dataRemoved from your browser; never held on our serversYou control it

12. Children's Data

You may hold a Portal account from age 16, with a parent's or guardian's consent recorded at registration, until the Information and Data Protection Commission prescribes the manner in which that attestation is to be given (s.29). If you are 16 or 17, your parent or guardian must give this attestation when you register. If you are under 16, an account cannot be created online: a parent or legal guardian must apply on your behalf at a police station.

The Data Protection Act, 2024 classes the personal data of a minor as sensitive personal data. When a guardian applies for a child, we collect only the child's details that the service requires, the guardian gives written consent on the child's behalf when accepting that service's terms, and the child's data is handled as described in section 8.

If we become aware that a child's personal data has been collected without a guardian's consent, we will delete it promptly. If you believe a child's data has been submitted without proper authorisation, please contact the Data Protection Officer.

13. Cookies and Usage Data

The Portal uses essential cookies for authentication and CSRF protection. We do not currently use analytics or marketing cookies. You can manage your cookie preferences at any time via the "Cookie Settings" link in the portal footer. For full details, see our Cookie Policy.

14. Your Data Rights

Under section 42 of the Data Protection Act, 2024 you have the right to confirmation of whether we hold personal data about you, to receive a copy of it within a reasonable time, to be given reasons if a request is refused, and to challenge that refusal or the data itself by complaint to the Information and Data Protection Commission, with the data corrected, completed or deleted if your challenge succeeds. Your right to data portability (s.47) is served by the data export described below. We charge nothing for any of these requests.

Where processing rests on your consent, you may withdraw it at any time under Profile → Security → Privacy & Data (s.28): each consent you gave — the Privacy Notice, biometric identity verification, accessibility information, and any parental or guardian attestation — is listed there with its own withdrawal control, and the Privacy Notice consent is withdrawn by requesting account deletion. Withdrawal does not affect processing already carried out.

To exercise any of these rights, please email the Data Protection Officer at dpo@police.gov.bw. We will respond within one month; where the request is complex or numerous, we may extend this by up to two further months with the Commission's approval, and will tell you if we do (s.38(3) – (4)). For full details on each right and how to exercise them, see our Data Subject Rights page.

15. Data Protection Officer

For any questions, concerns or requests regarding your personal data, please contact the BPS Data Protection Officer:

  • Data Protection Officer (designation in progress under section 69 of the Data Protection Act, 2024)
  • Email: dpo@police.gov.bw
  • Post: Data Protection Officer, Botswana Police Service, Police Headquarters, Gaborone, Botswana
  • Phone: 3605423

16. Record of Processing and Complaints

As a public body, BPS is required by section 60 of the Data Protection Act, 2024 to maintain a record of the Portal's processing operations, available to the Information and Data Protection Commission on request. The record contains the name and address of the data controller; the purposes of processing; the categories of data subject and of personal data; the recipients or categories of recipient; proposed transfers to other countries; and a general description of the security measures.

Any person, not only a data subject, may request a copy of that record. To do so, email the Data Protection Officer at dpo@police.gov.bw with the subject "Record of processing operations".

If you are not satisfied with how BPS has handled your personal data or a rights request, you may lodge a complaint with the Information and Data Protection Commission, and appeal a decision of the Commissioner to the Information and Data Protection Appeals Tribunal, under section 80 of the Act. We encourage you to contact the Data Protection Officer first so we can try to resolve your concern directly.

17. Changes to this Privacy Policy

Government may change this Privacy Policy from time to time as may be necessary. Any changes will be posted on this page with a revised effective date. Where changes are significant, we will make reasonable efforts to notify registered users by email. Your continued use of the Portal after such changes have been posted will constitute your acceptance of the updated Privacy Policy.

18. Effective Date

This Privacy Policy is effective from 13 September 2026 (it replaces the version of 12 September 2026). Consent you give on this Portal is recorded against version 2026-09-13of this Policy. Continued use of the Portal following updates indicates that you have carefully read, understood and agreed to the terms and conditions of this Privacy Policy and Disclaimer notice.

This Policy shall be binding upon you and, where applicable, your heirs, successors, representatives and assigns.