Across the globe, the protection of personal data is a growing concern, particularly with personal data being increasingly collected by deployed digital technologies in the conduct of business processes. Addressing the increasing concerns for personal privacy has become an obsession in the Fourth Industrial Revolution with its disruptive technologies. Through content analysis and a review of literature, this article explores compliance requirements for personal data protection in Botswana and South Africa, with a special focus on obtaining consent from data subjects, the rights of data subjects, data security and breach notification, and offences and penalties for breaching security safeguards under the two countries’ data protection legislation. The findings reveal that both Botswana and South Africa have enacted personal data legislation, the Data Protection Act (DPA) and the Protection of Personal Information Act (POPIA), respectively to safeguard data privacy. Furthermore, the two countries have made significant gains in establishing comprehensive frameworks for the protection of personal data. Although there are similarities in goals and principles in their data protection laws, there are differences in the approaches related to areas of consent, data subject rights, breach notification, and penalties for offences under the legislation.