Skip to the content
Global Data RulesData governance rules, country by country

Zambia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Zambia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

A copy must stayWork: Very highEnforcement: Waking up

By default, personal data must be kept and used on a server or in a data centre inside Zambia. That makes Zambia one of the strictest countries in Africa on paper. You can send a copy abroad only with the person's consent and a contract the regulator has approved. The regulator has approved none so far. Every organisation that handles personal data must register. You must report a breach within 24 hours.

Data governance in Zambia

The eight things that decide how you handle data about people in Zambia. Same eight on every country page, so you can compare.

Who has to follow these rules

Almost certainly yes, but the law does not say so clearly. The Data Protection Act, 2021 covers personal data handled by computer and personal data kept on paper. The regulator says every person and every organisation in every industry must register. Your turnover and staff numbers make no difference. The registration form has a part for anyone representing a foreign business. So the regulator clearly expects overseas companies to be covered too.

What you have to do here:
Register or notify · Appoint a representative
Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Only if a copy stays in Zambia. You must keep and use personal data on a server or in a data centre inside Zambia. The most sensitive kinds of data must always be kept and used in Zambia, with no exception at all. That list covers health, race, religion, politics, sex life, fingerprints, genetics, trade union membership and child abuse records. Sending anything abroad needs its own permission from the regulator. That includes a cloud region in another country and an off-site backup.

What you have to do here:
Keep the data in the country

What to do: Plan for a database inside Zambia: this data is not allowed to leave.

Sending data out of the country

Each transfer needs its own permission. There are three routes, and none of them is a form you can simply sign. Route one needs the person's consent, plus a standard contract or group-wide scheme that the regulator has approved. The regulator has published no approved contracts, so route one does not work today. Route two needs the Minister to declare that sending data to your destination country is allowed. That has not happened. Route three is a one-off approval from the regulator for one particular transfer.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Standard contract clauses · Government sign-off needed · Explicit consent · To save someone’s life

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Data Protection Commission enforces the rules. It sits inside the Ministry of Technology and Science. It is real and working. There is a named Commissioner, a live online registration portal, published fees and guidelines issued in early 2025. But it looks short of staff and money, and it does not appear to be punishing anyone. Its website has published exactly two news items, both on 3 February 2025. Two of its guidance pages still contain placeholder filler text. We found no published fine or decision against any named organisation.

What it costs if you get it wrong:
Criminal liability · Claims by individuals

How long you must keep it — and when to delete it

Zambia sets both a minimum and a maximum, and they pull against each other. The minimum is unusual. You must keep personal data for at least one year after you finish using it for the purpose you collected it for. The maximum is the normal rule. You must not keep data in a form that identifies people for longer than you need it. People can also ask you to delete their data. Telecoms operators have their own minimum of three years after a device was last used.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Let people delete their data · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

You have 24 hours to tell the regulator about a breach. The clock starts when the breach happens, not when you finish deciding what to call it. You must also tell the people affected as soon as you can. If you handle data for another company, you tell that company as soon as you can, and it carries the deadline. A shorter clock applies if you hold information the government has labelled critical. Then you must tell the cyber security agency straight away and send a written first report within twelve hours.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that are not in any summary. One: you must keep data for a year after you stop needing it, which clashes with the right to have data deleted. Two: every organisation must appoint a data protection officer, whatever its size. Three: every organisation must be audited every year. If you were allowed to store data abroad, you also pay for auditing the foreign server. Four: the punishments are criminal, and directors, managers, shareholders and partners can be convicted in person. Five: a child in Zambia is anyone under eighteen, so you must build age checks and parental consent into your product.

What you have to do here:
Appoint a data protection officer · Independent audit · Get a parent's consent for children · Keep data for a minimum period
What it costs if you get it wrong:
Criminal liability · Percentage of global turnover

What's changing next

No big new law is due to start in the next twelve months. The risk here is a different kind. The government already holds three powers it has never used. Any one of them could change the rules with a single notice and no public consultation. Two would make your life much easier. One would make it much harder.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Cyber security rules

Official name: The Cyber Security Act, 2025 · Act No. 3 of 2025 · Act of parliament

In forceA copy must stay

A second rule that forces hosting inside Zambia. It aims at eleven named critical industries. They are defence and security, the public sector, banking and finance, health, transport, pensions and insurance, information and communications technology, energy, education and mining. The law is in force. But it only starts to apply to you once the Zambia Cyber Security Agency names your information as critical in the government gazette. We found no such notice as at 18 August 2026, so it binds nobody yet.

In force since 12 May 2025

Enforced by Zambia Cyber Security Agency — not yet operational

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Payments

Payment data rules

Official name: PSB Circular No. 08/2025 — Requirement to Provide Real Time Read-Only Access · BOZ/EXEC/DG/psd/bp, 11 July 2025 · Regulator directive

In forceYes — store it anywhere

We found no rule saying payments data must stay in Zambia. Instead the central bank demands live access. Since 15 August 2025 every electronic money firm must give the Bank of Zambia real-time read-only access to its platform and its analytics tools. Banks must give the same access to the accounts that back electronic money. That shapes how you build your systems, even though it says nothing about where the data sits.

In force since 11 July 2025Enforced from 15 August 2025

Enforced by Bank of Zambia

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Telecoms

Telecoms data needs a copy kept in the country

Official name: The Information and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026 · Statutory Instrument No. 10 of 2026, made under section 64 of the Information and Communication Technologies Act (Cap. 169) · Directly binding regulation

In forceA copy must stay

Zambia's telecoms rules were rewritten on 30 January 2026. Mobile operators must collect subscriber biometric data and hand it to the telecoms regulator. They must keep a device register inside their own network, with an unbroken live link to the regulator's central register. They must hold that information for three years after a device was last used. A parent or guardian must be the registered subscriber for any line used by someone under eighteen.

In force since 30 January 2026

Enforced by Zambia Information and Communications Technology Authority

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Personal data needs a copy kept in the country

Official name: The Data Protection Act, 2021 · Act No. 3 of 2021 · Act of parliament

In forceA copy must stay

Zambia's general privacy law. By default, personal data must be kept and used inside Zambia. Copies can go abroad only with approval, given one transfer at a time. Everyone who handles personal data must register, appoint a data protection officer and be audited every year. You must report a breach to the regulator within 24 hours. The punishments are criminal. Fines for companies can be set against turnover, and directors can be held personally liable.

In force since 1 April 2021

Enforced by Data Protection Commission (Office of the Data Protection Commissioner)

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Government sign-off needed, Explicit consent, To save someone’s life

Personal data needs a copy kept in the country (2021)

Official name: The Data Protection Act, 2021, section 70(3) · Act No. 3 of 2021, s 70(3) · Act of parliament

In forceA copy must stay

The strictest rule in Zambian data law. Sensitive personal data must be kept and used on a server or in a data centre in Zambia. That covers health, race, religion, political opinion, ethnic or social origin, genetics, biometrics, sex or sexual orientation, trade union membership and child abuse records. The Minister cannot release any of it from that duty. A copy can go abroad only with the person's explicit consent, or in a health or emergency situation.

In force since 1 April 2021

Enforced by Data Protection Commission (Office of the Data Protection Commissioner)

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Explicit consent, To save someone’s life, Government sign-off needed

General data protection law

Official name: The Data Protection (Registration and Licensing) Regulations, 2021 · Statutory Instrument No. 58 of 2021 · Directly binding regulation

In forceA copy must stay

The detailed rules behind the duty to register. They set the fees by organisation size and they license data auditors. They also drive the application form. That form asks whether you store personal data outside Zambia, and it asks foreign businesses to name a representative in Zambia. Certificates last twelve months and must be renewed.

In force since 14 May 2021

Enforced by Data Protection Commission (Office of the Data Protection Commissioner)

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Who you would hear from

  • Data Protection Commission

    General privacy law: registration of controllers and processors, licensing of data auditors, breach reports, complaints, approval of standard contracts for transfers abroad

    It was set up inside the Ministry of Technology and Science. A Commissioner, Likando Luywa, is named on the Commission's own team page. The registration and self-assessment portals both work, the fees are published, and guidelines came out in January and February 2025. But the Commission has published only two news items ever, both dated 3 February 2025. Its Audit Guidelines and Other Guidelines pages still show Latin placeholder text. Its team page still lists a made-up member. Its only press release opens to a blank page. And we found no enforcement decision against any named organisation. Treat it as working for registration and inactive on enforcement.

  • Ministry of Technology and Science

    Rule-making under the data protection and cyber security laws, including the unused power to prescribe categories of personal data that may be stored outside Zambia

    Active and publishing news through August 2026. Hosts the Data Protection Commission.

  • Zambia Cyber Security Agency

    Designation, registration, in-country hosting and incident reporting for critical information and critical information infrastructure; licensing of cyber security service providers

    The Cyber Security Act, 2025 created this agency, and the Act started on 12 May 2025. As at 18 August 2026 we found no website of its own, no gazette notice naming any information as critical, and no detailed rules. Until it names something as critical, its hosting duty binds nobody. We list the parent ministry's site here because the agency has no site of its own.

  • ZICTA

    Telecoms and postal regulation, SIM and device registration, the Central Equipment Identification Register

    A long-established licensing regulator. When we checked on 18 August 2026, its latest news was from 2022. So we could not check its published material in depth.

  • Bank of Zambia

    Banking, payment systems and electronic money supervision

    Fully active. It issues dated circulars with firm deadlines. The most recent is the July 2025 order requiring real-time read-only access to electronic money platforms by 15 August 2025.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the Data Protection Act reaches a company with no presence in Zambia at all

    The Act sets its reach by how data is handled. It says nothing about where your company is based. Kenya, Nigeria and Ghana each have a clause that catches foreign companies. Zambia has none. We found no Zambian court ruling on the question. The regulator's own form assumes foreign businesses register through a representative in Zambia. So the likely answer is yes, but no court has tested it.

  • Whether any standard contractual clauses or intra-group schemes have been approved by the Data Protection Commissioner

    We checked the Commission's resources library and every page of its website on 18 August 2026 and found none. Approvals may exist without being published. If they do, the main legal route for sending data abroad would be open instead of closed. Ask the Commission before you assume either way.

  • Whether the Minister has ever prescribed categories of personal data that may be stored outside Zambia

    We found no such rules in any legislation index or on any government site. The only substantial rules we found under the Act are the 2021 Registration and Licensing Regulations. If a release order does exist, the storage duty would be far narrower than described here. Check with the Ministry of Technology and Science before you rely on this.

  • Whether the Zambia Cyber Security Agency has designated any critical information or critical information infrastructure by gazette notice

    Zambia does not publish its gazette notices online in one place, and we found no website for the Agency. The hosting duty in the 2025 cyber security law depends entirely on such a notice, so the difference matters. If you work in one of the critical industries, ask the Agency directly.

  • Whether the Data Protection Commission has issued any fine, order or enforcement decision

    Nothing is published on its website, and it has had no new post since February 2025. Zambia has no public register of enforcement. Fines may have been issued without being published.

  • The text of the January 2026 telecoms registration regulations and the 2021 and 2025 commencement orders

    We read these rules in full, but only on ZambiaLII, an independent legal information website. We could not find them on a Zambian government site. Zambia does not publish these rules anywhere official that we could reach. The parent Acts do come from the National Assembly's own site.

  • Minimum retention periods under Zambian tax, company and anti-money-laundering law

    We did not check these. Longer minimums almost certainly exist, and they would beat the one-year privacy minimum for the records they cover. Ask your accountant which records you must keep and for how long.

  • Sector rules for insurance, securities, gambling and mapping or geospatial data

    We could not reach the Pensions and Insurance Authority or the Securities and Exchange Commission websites on 18 August 2026. We searched the Zambian statute book and found no other law about where servers or data centres must sit. Any such rules would most likely sit in licence conditions rather than in law. If you work in one of these industries, check your licence.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.