Zambia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Zambia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
By default, personal data must be kept and used on a server or in a data centre inside Zambia. That makes Zambia one of the strictest countries in Africa on paper. You can send a copy abroad only with the person's consent and a contract the regulator has approved. The regulator has approved none so far. Every organisation that handles personal data must register. You must report a breach within 24 hours.
Data governance in Zambia
The eight things that decide how you handle data about people in Zambia. Same eight on every country page, so you can compare.
Who has to follow these rules
Almost certainly yes, but the law does not say so clearly. The Data Protection Act, 2021 covers personal data handled by computer and personal data kept on paper. The regulator says every person and every organisation in every industry must register. Your turnover and staff numbers make no difference. The registration form has a part for anyone representing a foreign business. So the regulator clearly expects overseas companies to be covered too.
- What you have to do here:
- Register or notify · Appoint a representative
The Data Protection Act, 2021 sets its reach by how data is handled, not by where your company sits. Kenya, Nigeria and Ghana each have a clause that catches a foreign company aiming at their residents. Zambia has no such clause. So no Zambian court has ever settled whether the Act covers a company based only abroad. What is clear is what the regulator expects. The Ministry of Technology and Science published a registration guideline in January 2025. It says all persons and entities in all sectors that handle personal data must register. Their annual turnover, revenue and number of employees make no difference. The only people left out are individuals using data for their own personal use. The registration form, Form I, Part 5, is headed 'Representative in Zambia'. Businesses and individuals representing a foreign entity fill it in. You give the name, address, phone number and email of your representative in Zambia. Registering is not optional. Handling personal data without registering is a crime and can mean up to five years in prison.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021 (Act No. 3 of 2021), sections 3 and 19
parliament.gov.zm
“This Act applies to the processing of personal data performed wholly or partly by automated means and to any processing otherwise than by electronic means.”
Link checked 18 August 2026
- Official sourceData Protection Commission / Ministry of Technology and ScienceGuidelines for Registration of Data Controllers and Data Processors, January 2025 — mandatory registration and Zambian representative for foreign entities
dataprotection.gov.zm
“Save for individuals processing personal data for personal use, ALL PERSONS AND ENTITIES processing Personal Data IN ALL SECTORS regardless of their annual Turnover/ Revenue or number of employees are required to register”
Link checked 18 August 2026
Where the data is allowed to live
Only if a copy stays in Zambia. You must keep and use personal data on a server or in a data centre inside Zambia. The most sensitive kinds of data must always be kept and used in Zambia, with no exception at all. That list covers health, race, religion, politics, sex life, fingerprints, genetics, trade union membership and child abuse records. Sending anything abroad needs its own permission from the regulator. That includes a cloud region in another country and an off-site backup.
- What you have to do here:
- Keep the data in the country
The Data Protection Act, 2021 says you must keep and use personal data on a server or in a data centre in Zambia. That is a flat rule. The Minister can name kinds of personal data that are allowed to be stored outside Zambia. That power has never been used, so nothing is released from the rule today. Sensitive personal data is shut out of that power altogether, so it can never be released this way. The regulator reads 'storing data outside Zambia' very widely. It covers an off-site data recovery site abroad. It covers a cloud service that stores data abroad. It covers anything else that ends with your data sitting outside Zambia. If you answer yes to that question on the registration form, you have to apply for a separate permission to store personal data outside Zambia. A second rule sits on top. The Cyber Security Act, 2025 says critical information, and the systems that run it, must be hosted inside Zambia. The Zambia Cyber Security Agency can allow hosting abroad, case by case. It names eleven critical industries. They are defence and security, the public sector, banking and finance, health, transport, pensions and insurance, information and communications technology, energy, education and mining. That duty only starts for you once the Agency names your information as critical in the government gazette. We found no such notice on any government source as at 18 August 2026. So this rule exists but is not yet switched on for anyone. Two industries add more. In payments, we found no rule about where data must sit. But the Bank of Zambia now makes electronic money firms give it live read-only access to their platforms. In telecoms, the subscriber and device registers must sit on the operator's own network, with an unbroken link to the regulator's central register in Zambia. In health research, sending human biological samples abroad needs approval first from the National Health Research Authority. That comes with a material transfer agreement, which also controls who can reach the data produced from the samples.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 70 and 71 (Part X — Transfer of personal data outside the Republic)
parliament.gov.zm
“A data controller shall process and store personal data on a server or data centre located in the Republic. ... Despite subsection (2), sensitive personal data shall be processed and stored in a server or data centre located in the Republic.”
Link checked 18 August 2026
- Official sourceData Protection Commission / Ministry of Technology and ScienceGuidelines for Registration of Data Controllers and Data Processors, January 2025 — Section 4, Data Storage outside Zambia
dataprotection.gov.zm
“Storing data outside Zambia includes: a) An off-site data recovery site outside Zambia, b) A cloud-based system which stores data outside Zambia, and c) Any other as long as the data is stored outside Zambia. ... If the response is YES, then you will need to apply for a separate authorization to store personal data outside of Zambia”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaCyber Security Act, 2025 (Act No. 3 of 2025), sections 8, 9 and 12
parliament.gov.zm
“A controller shall host critical information or critical information infrastructure within the Republic, in a prescribed manner and form.”
Link checked 18 August 2026
What to do: Plan for a database inside Zambia: this data is not allowed to leave.
Sending data out of the country
Each transfer needs its own permission. There are three routes, and none of them is a form you can simply sign. Route one needs the person's consent, plus a standard contract or group-wide scheme that the regulator has approved. The regulator has published no approved contracts, so route one does not work today. Route two needs the Minister to declare that sending data to your destination country is allowed. That has not happened. Route three is a one-off approval from the regulator for one particular transfer.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Standard contract clauses · Government sign-off needed · Explicit consent · To save someone’s life
The Data Protection Act, 2021 sets out the routes for any personal data the Minister has not released from the storage rule. Route one: the person the data is about agrees, and one of two extra things is true. Either the transfer runs under standard contracts or group-wide schemes approved by the Data Protection Commissioner. Or the Minister has ruled that transfers out of Zambia are allowed. Route two: the Commissioner approves your particular transfer, or a set of transfers, because there is a real necessity. The Act adds a few narrow exceptions. They cover emergencies involving health or emergency services. They cover explicit consent for sensitive personal data. And they cover sending data to an international organisation, or to a country the Commissioner is satisfied about. If you rely on an approved standard contract, the work does not stop there. You must confirm to the Commissioner that the contract is being honoured, and report on that from time to time. You also carry the liability if the company receiving the data causes harm by breaking the rules. The catch is that the approved lists are empty. As at 18 August 2026 the Commission's resources page held eleven documents. They are the Act, the 2021 registration regulations, registration forms and guides, a code of conduct, a breach management guide and a records guide. There is no approved set of standard contracts. There is no list of approved countries. There is no guidance at all on sending data abroad. Two more points. The regulator treats storing data abroad as needing its own permission, on top of any transfer approval. And if you are allowed to use a foreign server, you pay the cost of auditing it.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, section 71 and section 81(2)
parliament.gov.zm
“the transfer is made subject to standard contracts or intragroup schemes that have been approved by the Data Protection Commissioner”
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Resources library (eleven published documents; no approved standard contracts and no transfer guideline), checked 18 August 2026
dataprotection.gov.zm
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Data Protection Commission enforces the rules. It sits inside the Ministry of Technology and Science. It is real and working. There is a named Commissioner, a live online registration portal, published fees and guidelines issued in early 2025. But it looks short of staff and money, and it does not appear to be punishing anyone. Its website has published exactly two news items, both on 3 February 2025. Two of its guidance pages still contain placeholder filler text. We found no published fine or decision against any named organisation.
- What it costs if you get it wrong:
- Criminal liability · Claims by individuals
The Data Protection Act, 2021 set up the Office of the Data Protection Commissioner inside the ministry that covers communications. That is the Ministry of Technology and Science. The Commission's own team page names Likando Luywa as Data Commissioner. Registration really works. There is an online portal and a manual route by email. The fees are published. An individual or a very small organisation pays about 67 kwacha to apply and 667 kwacha for the certificate. A large organisation, or a company that handles data for others, pays up to 400 kwacha to apply and 4,000 kwacha for the certificate. The Bank of Zambia rate on 18 August 2026 was about 18.74 kwacha to the United States dollar. So the largest of those fees is roughly 215 dollars. Certificates last twelve months and you must renew them. The signs of a young regulator are easy to spot. The Audit Guidelines page and the Other Guidelines page both still show Latin placeholder text. The team page still lists a made-up second member. The only press release on the site opens to a blank page. The published documents have download counts in the low hundreds. The Commission is not the only body that can act. Most of the punishments in the Act are crimes, so they go through the courts. People can also sue you for compensation. Three other regulators work nearby. The Zambia Information and Communications Technology Authority covers telecoms. The Zambia Cyber Security Agency, created in 2025, covers cyber security. The Bank of Zambia covers payments, and in July 2025 it issued a data access order with a firm deadline.
Sources
- Official sourceData Protection Commission of ZambiaData Protection Commission — Our Team (names Likando Luywa as Data Commissioner; second entry is a placeholder), checked 18 August 2026
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — News (two posts only, both dated 3 February 2025), checked 18 August 2026
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Registration, fee table and online portal, checked 18 August 2026
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 4 to 6 (Office of the Data Protection Commissioner) and section 72 (compensation)
parliament.gov.zm
Link checked 18 August 2026
How long you must keep it — and when to delete it
Zambia sets both a minimum and a maximum, and they pull against each other. The minimum is unusual. You must keep personal data for at least one year after you finish using it for the purpose you collected it for. The maximum is the normal rule. You must not keep data in a form that identifies people for longer than you need it. People can also ask you to delete their data. Telecoms operators have their own minimum of three years after a device was last used.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Let people delete their data · Keep records of how you use data
The Data Protection Act, 2021 sets a minimum. You must keep personal data while you are using it for the purpose you collected it for. You must keep it while it is still relevant to that purpose. Then you must keep it for at least one year more. A shorter period could be set by rules, and none has been. So one year is a hard minimum, not a maximum. The Act pulls the other way too. It says data must be stored in a form that identifies people for no longer than you need. It also gives people a right to have their data deleted without undue delay. That right applies once the data is no longer needed, once consent is withdrawn, or once your use of the data is found unlawful. There is a separate duty to keep records of why you collected data, who you shared it with, and when. Zambia gives no rule for which of these wins. The sensible reading is that the specific one-year minimum beats the general principle. So if someone asks you to delete data inside that year, lock it away and stop using it rather than destroying it. No Zambian court has tested that reading. In telecoms, the 2011 device registration regulations were amended in January 2026. An operator must keep the information in its equipment identification register for three years after the device was last used. Zambian tax and company law set longer minimums too. We did not check those for this record.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 12(1)(e), 51 and 60
parliament.gov.zm
“a data controller and data processor shall keep personal information for as long as that personal information is used for the specific purpose for which the personal information was collected and for as long as the personal information is relevant for that purpose and for a period of at least one year thereafter”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaInformation and Communication Technologies Act, 2009 (Act No. 15 of 2009), section 64(9) to (11) — power to make device and SIM registration regulations
parliament.gov.zm
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchInformation and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026 (Statutory Instrument No. 10 of 2026), regulation 15
zambialii.org
“keep the information in the equipment identification register for a period of three years after the last use of the electronic communications apparatus”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
You have 24 hours to tell the regulator about a breach. The clock starts when the breach happens, not when you finish deciding what to call it. You must also tell the people affected as soon as you can. If you handle data for another company, you tell that company as soon as you can, and it carries the deadline. A shorter clock applies if you hold information the government has labelled critical. Then you must tell the cyber security agency straight away and send a written first report within twelve hours.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The Data Protection Act, 2021 gives you 24 hours to tell the Data Protection Commissioner about any security breach affecting personal data you hold. There is no harm test and no risk filter. As written, every security breach involving personal data must be reported. If you handle data for another company, you must tell that company as soon as you can. The person whose data was exposed must also be told as soon as you can. The Commission publishes a guide on handling data security breaches and hosts an online breach report form. The second clock comes from the Cyber Security Act, 2025. If you hold information the government has named critical, you must tell the Zambia Cyber Security Agency straight away about any incident, suspected or real. You then send a written first report within twelve hours, and a full report once the incident is over. The Agency can also set intervals for progress reports. Missing this can cost up to five hundred thousand penalty units or five years in prison. The twelve-hour duty only applies once your information has been named critical in the government gazette. We found no such notice as at 18 August 2026. The overlap is the real danger. One incident at a bank or a hospital could set off a twelve-hour cyber report and a 24-hour privacy report. That means two different regulators and two different forms.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, section 49 (notification of security breach)
parliament.gov.zm
“A data controller shall notify the Data Protection Commissioner within twenty-four hours of any security breach affecting personal data processed.”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaCyber Security Act, 2025, section 17 (duty to report cyber security incidents)
parliament.gov.zm
“a controller shall submit a preliminary cyber incident report to the Agency within twelve hours of notifying the Agency of the perceived or actual occurrence of the incident”
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Guide on Management of Data Security Breach
dataprotection.gov.zm
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that are not in any summary. One: you must keep data for a year after you stop needing it, which clashes with the right to have data deleted. Two: every organisation must appoint a data protection officer, whatever its size. Three: every organisation must be audited every year. If you were allowed to store data abroad, you also pay for auditing the foreign server. Four: the punishments are criminal, and directors, managers, shareholders and partners can be convicted in person. Five: a child in Zambia is anyone under eighteen, so you must build age checks and parental consent into your product.
- What you have to do here:
- Appoint a data protection officer · Independent audit · Get a parent's consent for children · Keep data for a minimum period
- What it costs if you get it wrong:
- Criminal liability · Percentage of global turnover
Trap one is the clash between the one-year minimum and the right to have data deleted. It is described in the retention answer. Trap two is the data protection officer. The Data Protection Act, 2021 says every company that decides how data is used, and every company that handles data for others, must appoint one. Guidelines will say how. Europe only requires this above a certain scale or sensitivity, or for public bodies. Zambia sets no trigger at all. Trap three is the yearly audit. The Commissioner, or an independent licensed data auditor, audits your policies and your handling of data every year. If you were allowed to use a foreign server, you pay the cost of auditing it. Data auditors must themselves be licensed. Trap four is the punishment. A company that breaks the rules on handling personal data faces a fine. The cap is one hundred million penalty units, or two percent of last year's turnover, whichever is higher. At forty ngwee per penalty unit, that fixed cap is forty million kwacha, roughly 2.1 million United States dollars. An individual faces up to one million penalty units or five years in prison. Handling personal data without registering carries up to five hundred thousand penalty units or five years. Unlawfully disclosing sensitive personal data carries up to two hundred thousand penalty units or two years. A director, manager, shareholder or partner is personally liable if the offence happened with their knowledge, consent or help. A court can also seize whatever the data was stored on, and ban a convicted person from running any data work at all. Trap five is children. Zambia's Constitution says a child is anyone under eighteen. You need a parent's or guardian's consent, and you must build age checks and parental consent into your product. There is a sixth, quieter trap. Mobile lines now need biometric data. The January 2026 change to the device registration regulations makes operators send subscriber biometric data to the telecoms regulator. It also makes a parent or guardian the registered subscriber for any line a child uses, until that child turns eighteen.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 17, 18, 48, 51, 73, 75, 76, 77 and 81
parliament.gov.zm
“a fine not exceeding one hundred million penalty units; or two percent of annual turnover of the preceding financial year, whichever is higher”
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchFees and Fines (Fee and Penalty Unit Value) (Amendment) Regulations, 2024 (Statutory Instrument No. 25 of 2024) — penalty unit raised from thirty ngwee to forty ngwee
zambialii.org
“deletion of the words “thirty ngwee” and the substitution therefor of the words “forty ngwee””
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchInformation and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026, regulations 12 and 26
zambialii.org
Link checked 18 August 2026
What's changing next
No big new law is due to start in the next twelve months. The risk here is a different kind. The government already holds three powers it has never used. Any one of them could change the rules with a single notice and no public consultation. Two would make your life much easier. One would make it much harder.
Switch one would loosen things. The Minister can name kinds of personal data that are allowed to be stored outside Zambia. The power has existed since the Act started on 1 April 2021 and has never been used. One short set of rules could free most ordinary business data from the storage duty overnight. Switch two would also loosen things. The Data Protection Commissioner can approve standard contracts and group-wide schemes. None have been approved or published. That is why the main legal route for sending data abroad is closed today. If an approved set were published, Zambia would move from case-by-case approval to something closer to paperwork. Switch three would tighten things. The Zambia Cyber Security Agency can publish a notice in the government gazette naming information or infrastructure in eleven critical industries as critical. From the date of that notice, you would have thirty days to register with the Agency. You would have to host that information inside Zambia unless you got separate permission. You would have to appoint an information technology auditor every year. And you would fall under the twelve-hour incident report. We found no such notice on any government source as at 18 August 2026. Two other things are worth watching. The Ministry of Technology and Science has asked the public for comments on a review of the older cyber security law. And the Cyber Security Act, 2025 and the Cyber Crimes Act, 2025 both still need detailed rules, which had not appeared by August 2026. A single notice can change the storage rules in either direction, so we check this record every sixty days.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 70(2) and 71(1) and (5) — unused ministerial and Commissioner powers
parliament.gov.zm
“Despite subsection (1), the Minister may prescribe categories of personal data that may be stored outside the Republic.”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaCyber Security Act, 2025, sections 9, 11, 12 and 14 — designation of critical information by Gazette notice
parliament.gov.zm
“The Agency shall, by notice in the Gazette, designate information or information infrastructure relevant to a critical sector as critical information or critical information infrastructure.”
Link checked 18 August 2026
- Official sourceMinistry of Technology and Science, ZambiaMinistry of Technology and Science — news and consultations, including the call for comments on the review of the cyber security legislation, checked 18 August 2026
mots.gov.zm
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cyber security rules
Official name: The Cyber Security Act, 2025 · Act No. 3 of 2025 · Act of parliament
A second rule that forces hosting inside Zambia. It aims at eleven named critical industries. They are defence and security, the public sector, banking and finance, health, transport, pensions and insurance, information and communications technology, energy, education and mining. The law is in force. But it only starts to apply to you once the Zambia Cyber Security Agency names your information as critical in the government gazette. We found no such notice as at 18 August 2026, so it binds nobody yet.
Enforced by Zambia Cyber Security Agency — not yet operational
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryYou must host inside Zambia from the day the Agency names your information as critical in the government gazette. The Agency can allow hosting abroad. It weighs national security and the country's ability to withstand cyber attacks. It also weighs whether the destination country has cyber security laws, and which kinds of personal data must stay in Zambia under the privacy law.
- Register or notifyRegistration with the Agency within thirty days of designation.
- Report cyber incidents — within 12 hoursTell the Agency straight away. Send a written first report within twelve hours. Send a full report once the incident is over. Send progress reports in between.
- Independent auditYou must appoint an information technology auditor every year to run a cyber audit.
- Secure the dataYou must meet the basic security rules and use detection tools that match the standards the Agency publishes in the government gazette.
What it costs if you get it wrong
- Criminal liability: 500,000 penalty units (about ZMW 200,000) or 5 years imprisonment — about $11 thousandFailing to register designated critical information, failing to report an incident, or failing to notify a change of ownership
Sources
- Official sourceNational Assembly of ZambiaThe Cyber Security Act, 2025 (Act No. 3 of 2025), Part III — protection of critical information and critical information infrastructure
parliament.gov.zm
“A controller shall host critical information or critical information infrastructure within the Republic, in a prescribed manner and form.”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaThe Cyber Security and Cyber Crimes Act, 2021 (Act No. 2 of 2021), section 18 — the predecessor localisation clause, repealed and replaced in 2025
parliament.gov.zm
“A controller of critical information shall store all critical information on a server or data center located within the Republic.”
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchCyber Security Act (Commencement) Order, 2025 (Statutory Instrument No. 22 of 2025) — appoints 12 May 2025
zambialii.org
Link checked 18 August 2026
Payment data rules
Official name: PSB Circular No. 08/2025 — Requirement to Provide Real Time Read-Only Access · BOZ/EXEC/DG/psd/bp, 11 July 2025 · Regulator directive
We found no rule saying payments data must stay in Zambia. Instead the central bank demands live access. Since 15 August 2025 every electronic money firm must give the Bank of Zambia real-time read-only access to its platform and its analytics tools. Banks must give the same access to the accounts that back electronic money. That shapes how you build your systems, even though it says nothing about where the data sits.
Enforced by Bank of Zambia
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataElectronic money institutions must give the central bank real-time read-only access to the platforms used to create and manage electronic money. That access also covers their business analytics tools. Banks and deposit-taking non-bank institutions must give the same access to all holding and pool accounts held for electronic money issuance.
- Keep records of how you use dataThis builds on the electronic money rules, which require live monitoring of holding and pool accounts and of electronic money platforms.
What it costs if you get it wrong
- Order to stopPenalties and other supervisory sanctions under the National Payment Systems Act for failure to provide the access
Sources
- Official sourceBank of Zambia, Office of the Deputy Governor - OperationsPSB Circular No. 08/2025 — Requirement to Provide Real Time Read-Only Access, 11 July 2025
boz.zm
“Electronic money institutions shall provide the Bank with real-time read only access to its platform(s) used to create, manage electronic money and its business analytics tools ... The access requested above shall be provided no later than August 15, 2025.”
Link checked 18 August 2026
- Official sourceBank of ZambiaNational Payment Systems Directives on Electronic Money Issuance, 2023 — outsourcing and systems controls (no data location requirement found)
boz.zm
Link checked 18 August 2026
Telecoms data needs a copy kept in the country
Official name: The Information and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026 · Statutory Instrument No. 10 of 2026, made under section 64 of the Information and Communication Technologies Act (Cap. 169) · Directly binding regulation
Zambia's telecoms rules were rewritten on 30 January 2026. Mobile operators must collect subscriber biometric data and hand it to the telecoms regulator. They must keep a device register inside their own network, with an unbroken live link to the regulator's central register. They must hold that information for three years after a device was last used. A parent or guardian must be the registered subscriber for any line used by someone under eighteen.
Enforced by Zambia Information and Communications Technology Authority
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThe equipment identification register must be kept and made available in the operator's own network. It must have uninterrupted communication with the regulator's Central Equipment Identification Register in Zambia.
- Register or notifyOperators must submit subscriber biometric data and device identifiers to the regulator, and send the register of sellers daily.
- Keep data for a minimum period — 3 yearsInformation in the equipment identification register must be kept for three years after the last use of the device.
- Get a parent's consent for children — applies at: under 18A parent or guardian is the registered subscriber for a child's mobile line until the child turns eighteen. Then they have ninety days to transfer, keep or deactivate it.
What it costs if you get it wrong
- Criminal liability: 2,500 penalty units (about ZMW 1,000) per SIM, or up to 2 years imprisonment — about $55Selling pre-registered SIM cards, registering without an identity document, or failing to maintain the subscriber or seller register
Sources
- Official sourceNational Assembly of ZambiaInformation and Communication Technologies Act, 2009 (Act No. 15 of 2009), section 64 — the power under which these Regulations are made
parliament.gov.zm
“The Minister may, in consultation with the Authority, by statutory instrument, make regulations for the registration of electronic equipment including mobile devices and subscriber identification modules”
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchInformation and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026 (Statutory Instrument No. 10 of 2026)
zambialii.org
“An electronic communications service provider shall keep, maintain and make available, in that electronic communications service provider's network, an equipment identification register”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Personal data needs a copy kept in the country
Official name: The Data Protection Act, 2021 · Act No. 3 of 2021 · Act of parliament
Zambia's general privacy law. By default, personal data must be kept and used inside Zambia. Copies can go abroad only with approval, given one transfer at a time. Everyone who handles personal data must register, appoint a data protection officer and be audited every year. You must report a breach to the regulator within 24 hours. The punishments are criminal. Fines for companies can be set against turnover, and directors can be held personally liable.
Enforced by Data Protection Commission (Office of the Data Protection Commissioner)
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Government sign-off needed, Explicit consent, To save someone’s life
What you have to do
- Keep the data in the countryBy default you must keep and use personal data on a server or in a data centre in Zambia. The Minister can release some kinds of data from this, but never has.
- Register or notifyNo turnover or headcount threshold. Certificate lasts twelve months and must be renewed.
- Appoint a representativeIf your company is not registered in Zambia, you must name a representative in Zambia on the registration form.
- Appoint a data protection officerEvery company that decides how data is used, and every company that handles data for others, must appoint one. The Act sets no size threshold.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Written vendor contractA company that handles data for you cannot pass it to another company without your written permission first.
- Report breaches to the regulator — within 24 hours
- Tell affected peopleTell them as soon as you reasonably can. There is no harm test.
- Keep data for a minimum period — 1 yearAt least one year after the personal data stops being relevant to the purpose it was collected for.
- Delete data after a periodYou must not keep data longer than you need it, and people can force you to delete it. This pulls against the one-year minimum.
- Independent auditThe Commissioner, or a licensed independent data auditor, audits you every year. If you were allowed to use a foreign server, you pay for auditing it.
- Get a parent's consent for children — applies at: under 18This also covers a vulnerable person aged 18 or over whose decision-making is impaired. You must have a way to check ages.
- Put a transfer safeguard in placeIf you rely on an approved standard contract, you must confirm to the Commissioner that it is being honoured. You must report on that from time to time. You are liable if the company receiving the data fails.
What it costs if you get it wrong
- Fixed maximum fine: 100,000,000 penalty units (about ZMW 40,000,000 at 40 ngwee per unit) — about $2 millionBody corporate breaching the principles and rules on processing personal data
- Percentage of global turnover: 2% of annual turnover of the preceding financial yearBody corporate breaching the principles and rules on processing personal data, where higher than the fixed cap
- Criminal liability: 1,000,000 penalty units (about ZMW 400,000) or 5 years imprisonment — about $21 thousandNatural person breaching the principles and rules on processing personal data
- Criminal liability: 500,000 penalty units (about ZMW 200,000) or 5 years imprisonment — about $11 thousandControlling or processing personal data without registering
- Criminal liability: 200,000 penalty units (about ZMW 80,000) or 2 years imprisonment — about $4 thousandUnlawfully disclosing sensitive personal data, or breaching a code of conduct or binding guideline
- Criminal liability: 300,000 penalty units (about ZMW 120,000) or 3 years imprisonment — about $6 thousandAny offence under the Act for which no specific penalty is provided
- Claims by individualsA data subject who suffers damage from an infringement may claim compensation in court
Sources
- Official sourceNational Assembly of ZambiaThe Data Protection Act, 2021 (Act No. 3 of 2021) — full text
parliament.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaThe Data Protection Act, 2021 — copy published by the Data Protection Commission
dataprotection.gov.zm
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchData Protection Act (Commencement) Order, 2021 (Statutory Instrument No. 22 of 2021) — appoints 1 April 2021
zambialii.org
Link checked 18 August 2026
Personal data needs a copy kept in the country (2021)
Official name: The Data Protection Act, 2021, section 70(3) · Act No. 3 of 2021, s 70(3) · Act of parliament
The strictest rule in Zambian data law. Sensitive personal data must be kept and used on a server or in a data centre in Zambia. That covers health, race, religion, political opinion, ethnic or social origin, genetics, biometrics, sex or sexual orientation, trade union membership and child abuse records. The Minister cannot release any of it from that duty. A copy can go abroad only with the person's explicit consent, or in a health or emergency situation.
Enforced by Data Protection Commission (Office of the Data Protection Commissioner)
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Explicit consent, To save someone’s life, Government sign-off needed
What you have to do
- Keep the data in the countryNo exceptions. The Minister cannot release sensitive personal data from the duty to keep it in Zambia.
- Get consentExplicit consent is the main route for sending a copy of sensitive personal data abroad.
What it costs if you get it wrong
- Criminal liability: 200,000 penalty units (about ZMW 80,000) or 2 years imprisonment — about $4 thousandUnlawful disclosure of sensitive personal data
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 2 (sensitive personal data), 70(3) and 71(4)
parliament.gov.zm
“Despite subsection (2), sensitive personal data shall be processed and stored in a server or data centre located in the Republic.”
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Frequently Asked Questions, definition of sensitive data
dataprotection.gov.zm
Link checked 18 August 2026
General data protection law
Official name: The Data Protection (Registration and Licensing) Regulations, 2021 · Statutory Instrument No. 58 of 2021 · Directly binding regulation
The detailed rules behind the duty to register. They set the fees by organisation size and they license data auditors. They also drive the application form. That form asks whether you store personal data outside Zambia, and it asks foreign businesses to name a representative in Zambia. Certificates last twelve months and must be renewed.
Enforced by Data Protection Commission (Office of the Data Protection Commissioner)
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Register or notify — 1 yearAn individual or very small organisation pays about 67 kwacha to apply and 667 kwacha for the certificate. A large organisation, or a company that handles data for others, pays about 400 kwacha to apply and 4,000 kwacha for the certificate. Size is set by staff numbers: up to ten is micro, eleven to fifty is medium, more than fifty is large.
- Appoint a representativeForm I, Part 5 asks for a representative in Zambia if your company is not registered there.
- Independent auditData auditors must themselves be licensed by the Commissioner.
- Put a transfer safeguard in placeThe registration form asks whether you store personal data outside Zambia, or plan to. If you answer yes, you must apply for a separate permission.
What it costs if you get it wrong
- Criminal liability: 500,000 penalty units (about ZMW 200,000) or 5 years imprisonment — about $11 thousandControlling or processing personal data without registering
- Order to stopSuspension or cancellation of registration, including where information given at registration was false or misleading
Sources
- Official sourceData Protection Commission of ZambiaThe Data Protection (Registration and Licensing) Regulations, 2021 (Statutory Instrument No. 58 of 2021)
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Registration page, fee table, online portal and forms
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission / Ministry of Technology and ScienceTerms and Conditions for Registration as a Data Controller or Data Processor, February 2025
dataprotection.gov.zm
“This certificate is valid for a period of twelve months and is renewable upon reapplication.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the Data Protection Act reaches a company with no presence in Zambia at all
The Act sets its reach by how data is handled. It says nothing about where your company is based. Kenya, Nigeria and Ghana each have a clause that catches foreign companies. Zambia has none. We found no Zambian court ruling on the question. The regulator's own form assumes foreign businesses register through a representative in Zambia. So the likely answer is yes, but no court has tested it.
Whether any standard contractual clauses or intra-group schemes have been approved by the Data Protection Commissioner
We checked the Commission's resources library and every page of its website on 18 August 2026 and found none. Approvals may exist without being published. If they do, the main legal route for sending data abroad would be open instead of closed. Ask the Commission before you assume either way.
Whether the Minister has ever prescribed categories of personal data that may be stored outside Zambia
We found no such rules in any legislation index or on any government site. The only substantial rules we found under the Act are the 2021 Registration and Licensing Regulations. If a release order does exist, the storage duty would be far narrower than described here. Check with the Ministry of Technology and Science before you rely on this.
Whether the Zambia Cyber Security Agency has designated any critical information or critical information infrastructure by gazette notice
Zambia does not publish its gazette notices online in one place, and we found no website for the Agency. The hosting duty in the 2025 cyber security law depends entirely on such a notice, so the difference matters. If you work in one of the critical industries, ask the Agency directly.
Whether the Data Protection Commission has issued any fine, order or enforcement decision
Nothing is published on its website, and it has had no new post since February 2025. Zambia has no public register of enforcement. Fines may have been issued without being published.
The text of the January 2026 telecoms registration regulations and the 2021 and 2025 commencement orders
We read these rules in full, but only on ZambiaLII, an independent legal information website. We could not find them on a Zambian government site. Zambia does not publish these rules anywhere official that we could reach. The parent Acts do come from the National Assembly's own site.
Minimum retention periods under Zambian tax, company and anti-money-laundering law
We did not check these. Longer minimums almost certainly exist, and they would beat the one-year privacy minimum for the records they cover. Ask your accountant which records you must keep and for how long.
Sector rules for insurance, securities, gambling and mapping or geospatial data
We could not reach the Pensions and Insurance Authority or the Securities and Exchange Commission websites on 18 August 2026. We searched the Zambian statute book and found no other law about where servers or data centres must sit. Any such rules would most likely sit in licence conditions rather than in law. If you work in one of these industries, check your licence.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.