What does Zambia's Data Protection Act require of organisations?
Zambia's Data Protection Act No. 3 of 2021 requires data controllers and data processors to register with the Data Protection Commissioner, appoint a data protection officer and secure personal data. Controllers must also keep records of processing, assess high-risk processing, report breaches to the Commissioner within 24 hours, keep personal data in Zambia unless an exception applies, and respect data subjects' rights.
The Act has applied since 1 April 2021, when the Data Protection Act (Commencement) Order, SI No. 22 of 2021, brought it into force. It is administered by the Office of the Data Protection Commissioner, established under section 4. Registration is made in the prescribed manner and form (s.20), using the forms and guidelines published by the Commissioner.
Most obligations fall on the data controller — the organisation that decides why and how personal data is processed — but data processors must also register, appoint a data protection officer and tell the controller about breaches. Accountability is explicit: section 50 requires internal mechanisms for demonstrating compliance to data subjects and to the Commissioner, so records and evidence matter as much as the controls themselves.
Registration with the Data Protection Commissioner
Section 19 prohibits controlling or processing personal data without registering as a data controller or data processor, and section 20 sets out how to apply. The Commissioner's Guidelines for Registration of Data Controllers and Data Processors (January 2025) state that a certificate of registration is valid for twelve months and renewable on reapplication; renewal is dealt with in section 22. Applications are made through the online portal at registration.dataprotection.gov.zm.
Under section 27 the Commissioner may, by declaration, exempt a person from the requirement to register; do not assume an exemption without one.
Records of processing, DPIAs and the data protection officer
Section 45 requires a data controller to keep written records of its processing activities, in the prescribed manner and form, and to make them available to the Commissioner on demand.
Section 46 requires a data protection impact assessment before processing that uses new technologies and is likely to result in a high risk to individuals — in particular automated decision-making or profiling with legal or similarly significant effects, large-scale processing of sensitive personal data or data about criminal convictions, and systematic monitoring of a publicly accessible area on a large scale.
Section 48 requires data controllers and data processors to appoint a data protection officer, in line with guidelines issued by the Commissioner.
Security of processing and breach notification
Section 47 requires appropriate technical and organisational safeguards, having regard to the nature, scope and risks of the processing. The Act names pseudonymisation and encryption among the methods, alongside measures to prevent misuse, unauthorised access, disclosure or destruction.
Under section 49, a data controller must notify the Commissioner within twenty-four hours of any security breach affecting personal data. A data processor must tell the controller as soon as practicable, and affected data subjects must be told as soon as practicable.
Data localisation and cross-border transfers
Section 70(1) requires a data controller to process and store personal data on a server or data centre located in Zambia. The Minister may prescribe categories of personal data that may be stored outside Zambia (s.70(2)), and sensitive personal data must be processed and stored in Zambia (s.70(3)). Section 71 allows transfers outside Zambia where the data subject has consented and the transfer uses standard contracts or intragroup schemes approved by the Commissioner or is permitted by ministerial prescription, or where the Commissioner approves a transfer as necessary; s.71(4) adds limited further cases, including emergencies involving health or emergency services and a data subject's explicit consent to the transfer of sensitive personal data.
Map where each system stores personal data — including cloud services, backups and support tools — and record the basis for anything held abroad.
Data-subject rights
Part IX gives individuals enforceable rights. Controllers need a way to receive, track and complete requests, and must pass rectifications, erasures or restrictions on to recipients of the data where practicable (s.66).
- Right of access and notification (s.58)
- Right to rectification (s.59)
- Right to erasure (s.60)
- Right of objection (s.61)
- Rights concerning decisions based on automatic processing (s.62)
- Right to restriction of processing (s.63)
- Right to data portability (s.65)
Retention and records of disclosure
Section 51 requires personal information to be kept for as long as it is used and relevant for the purpose it was collected for, and for at least one year after that or another prescribed period. Controllers and processors must also record the purpose of collection and the third parties to whom, and when, personal information was disclosed.
Key obligations and how ICTM helps
A summary of provisions that affect how organisations manage ICT. It is not exhaustive — read the legislation for the full requirements.
| Obligation | Source | What it requires | How ICTM helps |
|---|---|---|---|
| Register and renew | Data Protection Act No. 3 of 2021, s.19, s.20 and s.22; ODPC Guidelines for Registration (January 2025) | Register as a data controller or data processor before processing personal data, and renew the certificate, which the Commissioner's guidelines state is valid for twelve months. | Tracks certificate numbers, status and renewal dates, with daily in-app reminders to administrators before a registration expires. |
| Appoint a data protection officer | Data Protection Act No. 3 of 2021, s.48 | Controllers and processors must appoint a data protection officer in line with the Commissioner's guidelines. | Keeps a register of appointed data protection officers. |
| Keep records of processing activities | Data Protection Act No. 3 of 2021, s.45 | Keep written records of processing activities and make them available to the Commissioner on demand. | Records-of-processing register with CSV export, including entries imported from ICTM's network-monitoring module. |
| Assess high-risk processing | Data Protection Act No. 3 of 2021, s.46 | Carry out a data protection impact assessment before high-risk processing, including profiling, large-scale sensitive data and large-scale systematic monitoring of public areas. | Keeps a register of DPIAs so each assessment and its outcome is recorded. |
| Secure personal data | Data Protection Act No. 3 of 2021, s.47 | Implement appropriate technical and organisational safeguards, such as pseudonymisation and encryption, proportionate to the risk. | A self-assessment questionnaire mapped to sections of the Act scores your position section by section with remediation guidance; device compliance checks, vulnerability scans and access reviews add technical evidence; IP addresses in network-flow data are pseudonymised with keyed hashing. |
| Notify breaches | Data Protection Act No. 3 of 2021, s.49 | Notify the Commissioner within twenty-four hours of a security breach affecting personal data; processors notify the controller, and data subjects are told, as soon as practicable. | Breach register records each breach, when it was detected and when the Commissioner and data subjects were notified, and alerts administrators in-app and by email. |
| Keep personal data in Zambia unless an exception applies | Data Protection Act No. 3 of 2021, s.70–71 | Process and store personal data in Zambia; transfer it abroad only in the circumstances section 71 allows. | Cross-border transfer register records each transfer and totals what is stored in Zambia versus abroad. |
| Handle data-subject requests | Data Protection Act No. 3 of 2021, s.58–65 | Respond to requests for access, rectification, erasure, objection, restriction and portability. | Deletion requests can be approved or rejected; completing one anonymises the person's account details and deactivates the account. Users can export their own data, and access or erasure requests can purge a person's records from network-monitoring data. |
| Retain data appropriately and record disclosures | Data Protection Act No. 3 of 2021, s.51 | Keep personal information only as long as the Act allows and record the purpose of collection and third-party disclosures. | Network-monitoring data is deleted on category-based retention schedules, with the legal basis recorded for each category. |
Frequently asked questions
Who must register under Zambia's Data Protection Act?
Section 19 says a person may not control or process personal data without registering as a data controller or data processor, so in practice most organisations that handle personal data — employee, customer or supplier records — need to register. Under section 27 the Commissioner may exempt a person by declaration. Applications are made to the Office of the Data Protection Commissioner through its online portal.
How long is a data protection registration certificate valid?
The Commissioner's Guidelines for Registration of Data Controllers and Data Processors (January 2025) state that a certificate of registration is valid for twelve months and renewable on reapplication. Section 22 of the Act deals with renewal. Track the renewal date well in advance so that processing does not continue on an expired registration.
How soon must a personal data breach be reported in Zambia?
A data controller must notify the Data Protection Commissioner within twenty-four hours of any security breach affecting personal data (s.49(1)). Processors must inform the controller, and affected data subjects must be told, as soon as practicable. Other duties may run in parallel, such as incident reporting under the Cyber Security Act 2025 or to the Bank of Zambia for regulated financial entities.
Can personal data be stored outside Zambia?
Only in limited circumstances. Section 70(1) requires controllers to process and store personal data on a server or data centre in Zambia, and s.70(3) requires sensitive personal data to be processed and stored in Zambia. Section 71 permits transfers where the data subject has consented and Commissioner-approved standard contracts or intragroup schemes apply, where a ministerial prescription permits it, or where the Commissioner approves a transfer as necessary; s.71(4) adds narrow exceptions such as emergencies and explicit consent to transferring sensitive data. Check cloud and backup arrangements against these rules.
When is a data protection impact assessment required?
Section 46 requires a DPIA before processing that uses new technologies and is likely to result in a high risk to individuals. The Act lists three cases: automated processing or profiling with legal or similarly significant effects, large-scale processing of sensitive personal data or criminal-conviction data, and systematic monitoring of a publicly accessible area on a large scale, such as extensive CCTV coverage of public spaces.
Does using ICTM make an organisation compliant with the Act?
No software can do that on its own: compliance depends on your processing, policies and decisions. ICTM helps by keeping the registers the Act points to — registration, data protection officers, records of processing, DPIAs, consent, breaches, transfers and deletion requests — and by scoring a self-assessment questionnaire mapped to sections of the Act, so gaps are visible and evidence is ready when the Commissioner asks.
Sources
- Data Protection Act No. 3 of 2021 (National Assembly of Zambia)
- Data Protection Act (Commencement) Order, 2021 — SI No. 22 of 2021 (ZambiaLII)
- Office of the Data Protection Commissioner — Regulations
- Office of the Data Protection Commissioner — Registration guidance
- ODPC online registration portal
This page is general information about Zambian law as reviewed on 13 September 2026. It is not legal advice. Laws and regulator guidance change — check the current legislation or consult a qualified legal adviser before relying on it. Ontech ICTM helps you organise records and evidence; it does not by itself make an organisation compliant.