Zambia

ICT Management in Zambia

How Zambian organisations can run IT governance, cybersecurity and compliance against the laws and regulators that actually apply to them.

Last reviewed · Sources

What does ICT management involve for organisations in Zambia?

ICT management in Zambia means running an organisation's technology — assets, infrastructure, networks, security, continuity and suppliers — in a way that also meets Zambian law. The core statutes are the Data Protection Act No. 3 of 2021 and the Cyber Security Act No. 3 of 2025, with sector rules such as the Bank of Zambia's 2023 cyber risk guidelines for regulated financial entities.

Every organisation manages the same technical disciplines: knowing which IT assets it owns, keeping infrastructure and networks available, protecting systems from attack and recovering from disruption. In Zambia several of these now carry legal duties — registering with the Office of the Data Protection Commissioner, keeping personal data in the country unless an exception applies, and reporting breaches and cyber incidents within set timeframes.

Which duties apply depends on the organisation. Every data controller and data processor is covered by the Data Protection Act. The Cyber Security Act 2025 adds heavier duties for controllers of information or infrastructure that the Zambia Cyber Security Agency designates as critical. Regulated financial entities also follow the Bank of Zambia's guidelines, and public bodies work within the Electronic Government Act 2021.

This page summarises that landscape from primary sources and shows where an ICT management platform such as Ontech ICTM can keep the records and evidence these obligations call for. It is general information, not legal advice: confirm how each law applies to you with a qualified adviser or the relevant regulator.

The regulatory landscape

Zambia's ICT obligations come from a small number of statutes and sector instruments. This list is not exhaustive, but it covers the rules ICT teams meet most often.

  • Data Protection Act No. 3 of 2021 — governs the processing of personal data and establishes the Office of the Data Protection Commissioner (s.4). In force since 1 April 2021 under SI No. 22 of 2021.
  • Cyber Security Act No. 3 of 2025 — establishes the Zambia Cyber Security Agency in the Office of the President (s.3), regulates critical information infrastructure and licenses cyber security services. It repealed the Cyber Security and Cyber Crimes Act, 2021 (s.73).
  • Cyber Crimes Act No. 4 of 2025 — creates computer-related offences such as unauthorised access, interference with systems and data, and cyber extortion.
  • Electronic Communications and Transactions Act No. 4 of 2021 — covers electronic transactions, electronic signatures and the national public key infrastructure.
  • Information and Communication Technologies Act No. 15 of 2009 — continues the Zambia Information and Communications Technology Authority (ZICTA) as the sector regulator.
  • Electronic Government Act No. 41 of 2021 — makes the Electronic Government Division (operating as the Smart Zambia Institute) responsible for coordinating ICT in public bodies, including security and quality standards.
  • Bank of Zambia Cyber and Information Risk Management Guidelines, 2023 — minimum cyber-risk requirements for regulated financial entities (Gazette Notice No. 668 of 2023).
  • Policy framework — the National Cybersecurity Policy (approved by Cabinet in January 2021) and the National ICT Policy 2023.

IT governance in Zambia

IT governance is how leadership sets direction for technology, approves policies and checks that risk stays within agreed limits. Zambian law rarely prescribes a governance model outright, but it assumes one: the Data Protection Act requires controllers and processors to have internal mechanisms for demonstrating compliance to data subjects and the Commissioner (s.50), and the Bank of Zambia expects the boards of regulated entities to approve cyber-risk policies and risk appetite and management to appoint a chief information security officer independent of day-to-day IT operations.

For public bodies, the Electronic Government Act 2021 makes the Electronic Government Division responsible for coordinating ICT and for developing, disseminating and enforcing security and quality standards (s.5(2), s.6(1)(i)), and allows it to audit public bodies for compliance (s.28). In every sector, written and versioned policies, recorded approvals and an audit trail are the practical foundations.

Cybersecurity management in Zambia

Cybersecurity management is the continuing work of identifying assets and threats, applying protective controls, detecting attacks and responding to incidents. The Cyber Security Act 2025 turns much of this into law for controllers of critical information and critical information infrastructure: they must meet prescribed baseline security requirements (s.9(2)), register designated infrastructure within thirty days (s.11), host it in Zambia unless the Agency authorises otherwise (s.12), commission an annual cyber audit (s.14) and report incidents promptly (s.17).

The Act lists critical sectors — defence and security, the public sector, banking and finance, health, transport, pensions and insurance, information and communications technology, energy, education and mining (s.8). Being in one of these sectors does not by itself make a system critical: designation is made by the Agency by notice in the Gazette (s.9). Organisations in those sectors should still expect closer scrutiny.

IT compliance in Zambia

IT compliance means showing, with evidence, that systems and processes meet the rules that apply. For most organisations the starting point is the Data Protection Act: register with the Commissioner, appoint a data protection officer, keep records of processing, assess high-risk processing, secure personal data and be ready to report breaches. Sector rules and international standards such as ISO/IEC 27001 or PCI DSS then add their own control requirements.

Compliance is easier to sustain when evidence is produced as a by-product of normal work — an up-to-date asset register, recorded approvals, logged incidents, tested recovery plans — rather than assembled in a rush before each audit.

Data localisation and hosting decisions

The Data Protection Act requires a data controller to process and store personal data on a server or data centre located in Zambia (s.70(1)). The Minister may prescribe categories of personal data that may be stored abroad (s.70(2)), but sensitive personal data must be processed and stored in Zambia (s.70(3)), subject to the narrow exceptions in s.71(4). Other transfers are allowed only in defined circumstances — for example, with the data subject's consent plus contract terms approved by the Commissioner or a ministerial prescription, or with the Commissioner's approval where a transfer is necessary (s.71). Critical information infrastructure has its own hosting rule under the Cyber Security Act (s.12).

In practice this affects cloud and SaaS choices, backup locations and where AI tools process data. Keep a register of where each system stores personal data and record the legal basis for anything held outside the country.

Three different incident-reporting clocks

One incident can trigger several reporting duties, each with its own deadline and recipient. Agree in advance who decides whether each duty applies, and record the times of detection, decisions and notifications.

  • Data Protection Act s.49 — a data controller must notify the Data Protection Commissioner within twenty-four hours of any security breach affecting personal data, and tell affected data subjects as soon as practicable.
  • Cyber Security Act s.17 — a controller must immediately notify the Zambia Cyber Security Agency of a perceived or actual incident affecting critical information or critical information infrastructure (or systems connected to it), submit a preliminary report within twelve hours of that notification, and file a detailed report once the incident is resolved.
  • Bank of Zambia Guidelines para 11.1(5)–(6) — a regulated entity must inform the Bank immediately a medium or highly classified incident is discovered and before any media interaction, then submit a formal report with root-cause analysis and corrective actions.

Practical priorities

  • Build and maintain an inventory of IT assets and of the systems that hold personal data.
  • Confirm your registration with the Office of the Data Protection Commissioner and diarise renewals — certificates are issued for twelve months.
  • Appoint and record a data protection officer and keep records of processing activities.
  • Document where data is hosted and the legal basis for any storage outside Zambia.
  • Write an incident response procedure that covers every reporting clock that applies to you.
  • Run vulnerability assessments, test backups and exercise recovery plans on a schedule.
  • Before engaging an outside firm for penetration testing or other cyber security services, check that it holds a licence under the Cyber Security Act 2025.

Key obligations and how ICTM helps

A summary of provisions that affect how organisations manage ICT. It is not exhaustive — read the legislation for the full requirements.

ObligationSourceWhat it requiresHow ICTM helps
Register as a data controller or data processor Data Protection Act No. 3 of 2021, s.19; ODPC Guidelines for Registration (January 2025) A person may not control or process personal data without registering with the Data Protection Commissioner. The Commissioner's registration guidelines state that certificates are valid for twelve months and renewable. Tracks each registration's certificate number, status and renewal date, with in-app reminders to administrators before expiry.
Appoint a data protection officer Data Protection Act No. 3 of 2021, s.48 Data controllers and data processors must appoint a data protection officer in accordance with guidelines issued by the Commissioner. Keeps a register of appointed data protection officers alongside registration records.
Keep records of processing activities Data Protection Act No. 3 of 2021, s.45 A data controller must keep written records of its processing activities and make them available to the Commissioner on demand. Records-of-processing register with CSV export; entries can be imported from ICTM's network-monitoring module.
Report personal data breaches Data Protection Act No. 3 of 2021, s.49 Notify the Data Protection Commissioner within twenty-four hours of a security breach affecting personal data, and affected data subjects as soon as practicable. Breach register records each breach, when it was detected and when the Commissioner and data subjects were notified, and alerts administrators in-app and by email.
Keep personal data in Zambia unless an exception applies Data Protection Act No. 3 of 2021, s.70–71 Personal data must be processed and stored on servers or data centres in Zambia; transfers abroad are permitted only in the circumstances set out in s.71. Cross-border transfer register records each transfer and summarises what is stored in Zambia and what is held abroad.
Register designated critical information infrastructure Cyber Security Act No. 3 of 2025, s.9 and s.11 Where the Agency designates information or infrastructure as critical, the controller must meet prescribed baseline security requirements and register it with the Agency within thirty days of designation. The asset register and dependency mapping help identify and document the systems in scope, their owners and what depends on them.
Notify the Zambia Cyber Security Agency of incidents Cyber Security Act No. 3 of 2025, s.17 Immediately notify the Agency of a perceived or actual incident affecting critical information or infrastructure, followed by a preliminary report within twelve hours and a detailed report once resolved. Incident records with severity, status and PDF/CSV export, plus security events from log collection and network detection that can be escalated to incidents.
Commission an annual cyber audit Cyber Security Act No. 3 of 2025, s.14 A controller must annually appoint an information technology auditor to perform a cyber audit on its critical information or infrastructure. Audit-readiness scores, vulnerability and penetration-test findings, control mappings and exportable reports give the auditor organised evidence. ICTM does not replace the independent auditor.
Report significant incidents to the Bank of Zambia Bank of Zambia Cyber and Information Risk Management Guidelines, 2023, para 11.1(5)–(6) Regulated entities must inform the Bank immediately a medium or highly classified incident is discovered and before any media interaction, then file a formal report that includes root-cause analysis. Incident register and root-cause analysis records (5-whys and fishbone) support the investigation and the formal report.

Frequently asked questions

Which laws govern ICT and data in Zambia?

The main statutes are the Data Protection Act No. 3 of 2021 for personal data, the Cyber Security Act No. 3 of 2025 for critical information infrastructure and cyber security services, the Cyber Crimes Act No. 4 of 2025 for computer offences, the Electronic Communications and Transactions Act 2021, the ICT Act 2009 (which continues ZICTA) and, for public bodies, the Electronic Government Act 2021. Regulated financial entities also follow the Bank of Zambia's 2023 cyber risk guidelines.

Has the Cyber Security and Cyber Crimes Act 2021 been repealed?

Yes. It was repealed by section 73 of the Cyber Security Act No. 3 of 2025, which came into operation on 12 May 2025 under SI No. 22 of 2025. Computer-related offences such as unauthorised access and cyber extortion are now in the separate Cyber Crimes Act No. 4 of 2025, brought into force by SI No. 23 of 2025. Documents that still cite the 2021 Act should be updated.

Do organisations have to store data in Zambia?

For personal data, the default is yes: section 70(1) of the Data Protection Act requires a data controller to process and store personal data on a server or data centre in Zambia, and s.70(3) requires sensitive personal data to be processed and stored in Zambia, subject to narrow exceptions in s.71(4) such as emergencies or the data subject's explicit consent. Section 71 allows other transfers abroad in defined circumstances, such as consent plus approved contract terms, or the Commissioner's approval. Separately, controllers of designated critical information infrastructure must host it in Zambia unless the Cyber Security Agency authorises otherwise (Cyber Security Act s.12).

Who regulates data protection in Zambia?

The Office of the Data Protection Commissioner, established under section 4 of the Data Protection Act 2021 within the ministry responsible for communications. Its website uses the name Data Protection Commission. It registers data controllers and processors through an online portal, issues guidelines and receives breach notifications.

How quickly must a data breach be reported in Zambia?

Under section 49 of the Data Protection Act, a data controller must notify the Data Protection Commissioner within twenty-four hours of any security breach affecting personal data, and tell affected individuals as soon as practicable. If the incident also affects critical information infrastructure, the Cyber Security Act requires immediate notice to the Cyber Security Agency and a preliminary report within twelve hours; banks and other regulated entities must also inform the Bank of Zambia immediately.

How can an ICT management platform help with Zambian regulation?

It keeps the records regulators and auditors ask for in one place. Ontech ICTM holds registers for data protection registration, data protection officers, records of processing, DPIAs, consent, breaches and cross-border transfers, alongside an asset register, incident records, risk register, vulnerability findings and recovery plans. Software cannot decide how a law applies to you, so pair it with legal advice and clear ownership of each obligation.

Organise your ICT obligations in one place

Ontech ICTM keeps your registers, assessments, incidents and evidence together. Book a walkthrough with the Ontech team in Lusaka.