Zambia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Zambia is one of the strictest countries in Africa on paper. The default rule is that personal data must be processed and stored on a server or in a data centre inside Zambia. A copy may go abroad only with the person's consent plus a contract the regulator has approved — and the regulator has approved none. Every organisation handling personal data must register, and breaches must be reported within 24 hours.
Data governance in Zambia
The eight things that decide how you handle data about people in Zambia. Same eight on every country page, so you can compare.
Who has to follow these rules
Almost certainly yes in practice, but the law does not say so clearly. The Act applies to processing of personal data by automated means and to processing done on paper. The regulator's own registration guideline says all persons and entities in all sectors must register, whatever their turnover or staff numbers. The registration form has a section to be completed by anyone representing a foreign entity, so the regulator plainly expects overseas businesses to be inside the net.
Section 3 of the Data Protection Act, 2021 sets the scope by reference to the method of processing, not to the location of the organisation. Unlike Kenya, Nigeria or Ghana, Zambia has no express clause reaching a controller established outside the country who targets residents. That silence means the reach of the Act over a purely foreign business has never been settled by a Zambian court. What is clear is the practical position: the Ministry of Technology and Science guideline for registration (January 2025) states that, apart from individuals processing data for personal use, 'ALL PERSONS AND ENTITIES processing Personal Data IN ALL SECTORS regardless of their annual Turnover/ Revenue or number of employees are required to register'. Form I, Part 5, is headed 'Representative in Zambia' and is to be completed 'by entities and or individuals that represent a foreign entity or individual', with the name, address, phone and email of the Zambian representative. Registration itself is a criminal matter: processing without it is an offence carrying up to five years in prison.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021 (Act No. 3 of 2021), sections 3 and 19
parliament.gov.zm
“This Act applies to the processing of personal data performed wholly or partly by automated means and to any processing otherwise than by electronic means.”
Link checked 18 August 2026
- Official sourceData Protection Commission / Ministry of Technology and ScienceGuidelines for Registration of Data Controllers and Data Processors, January 2025 — mandatory registration and Zambian representative for foreign entities
dataprotection.gov.zm
“Save for individuals processing personal data for personal use, ALL PERSONS AND ENTITIES processing Personal Data IN ALL SECTORS regardless of their annual Turnover/ Revenue or number of employees are required to register”
Link checked 18 August 2026
Where the data is allowed to live
Only if a copy stays behind. Zambian law starts from the position that a company must process and store personal data on a server or in a data centre located in Zambia. The most sensitive categories — health, race, religion, politics, sex life, fingerprints, genetics, trade union membership, child abuse records — must be processed and stored in Zambia with no exception at all. Sending anything abroad, including to a cloud region or an off-site backup, needs its own permission from the regulator.
Section 70(1) of the Data Protection Act, 2021 is a flat storage mandate. Section 70(2) gives the Minister a power to name categories of personal data that may be stored outside Zambia — that power has never been used, so no category is currently released. Section 70(3) then removes even that possibility for sensitive personal data. The regulator's registration guideline is explicit about how wide 'storing data outside Zambia' is: it covers 'an off-site data recovery site outside Zambia', 'a cloud-based system which stores data outside Zambia', and 'any other as long as the data is stored outside Zambia'. The same guideline tells applicants that if they answer yes, 'you will need to apply for a separate authorization to store personal data outside of Zambia'. There is a second, overlapping layer. The Cyber Security Act, 2025 requires a controller to host 'critical information or critical information infrastructure within the Republic', and lets the Zambia Cyber Security Agency permit hosting abroad case by case. The critical sectors it names are defence and security, the public sector, banking and finance, health, transport, pensions and insurance, information and communications technology, energy, education and mining. That duty only attaches once the Agency designates specific information as critical by notice in the Gazette. No such designation was found on any government source as at 18 August 2026, which means this layer is armed but not yet fired. Two sectors add further texture. In payments, no data location rule was found, but the Bank of Zambia now requires electronic money institutions to give it real-time read-only access to their platforms. In telecoms, the subscriber and device registers must be kept on the operator's own network with an uninterrupted link to the regulator's central register in Zambia. In health research, exporting human biological samples needs prior approval from the National Health Research Authority under a material transfer agreement that also governs access to the data generated.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 70 and 71 (Part X — Transfer of personal data outside the Republic)
parliament.gov.zm
“A data controller shall process and store personal data on a server or data centre located in the Republic. ... Despite subsection (2), sensitive personal data shall be processed and stored in a server or data centre located in the Republic.”
Link checked 18 August 2026
- Official sourceData Protection Commission / Ministry of Technology and ScienceGuidelines for Registration of Data Controllers and Data Processors, January 2025 — Section 4, Data Storage outside Zambia
dataprotection.gov.zm
“Storing data outside Zambia includes: a) An off-site data recovery site outside Zambia, b) A cloud-based system which stores data outside Zambia, and c) Any other as long as the data is stored outside Zambia. ... If the response is YES, then you will need to apply for a separate authorization to store personal data outside of Zambia”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaCyber Security Act, 2025 (Act No. 3 of 2025), sections 8, 9 and 12
parliament.gov.zm
“A controller shall host critical information or critical information infrastructure within the Republic, in a prescribed manner and form.”
Link checked 18 August 2026
Sending data out of the country
Each transfer needs its own permission. There are three routes and none of them is a form you can simply sign. The first needs the person's consent plus a standard contract or group-wide scheme approved by the regulator — the regulator has published no approved contracts, so this route is not usable today. The second needs the Minister to declare a destination country acceptable, which has not happened. The third is a one-off approval from the regulator for a particular transfer.
Section 71 of the Data Protection Act, 2021 sets out the routes for personal data other than the categories released by the Minister under section 70(2). Route one: the data subject consents and either the transfer is made under standard contracts or intra-group schemes approved by the Data Protection Commissioner, or the Minister has prescribed that transfers outside Zambia are permissible. Route two: the Commissioner approves a particular transfer or set of transfers as permissible due to a situation of necessity. Section 71(4) adds narrow escape hatches — emergencies involving health or emergency services, explicit consent for sensitive personal data, and transfers to an international organisation or country the Commissioner is satisfied about. Section 71(6) then adds an ongoing duty: a controller relying on a standard contract must certify and periodically report to the Commissioner that the contract is being honoured, and must carry liability for harm caused by the recipient's non-compliance. The critical operational fact is that the lists are empty. As at 18 August 2026 the Commission's own resources page lists eleven documents — the Act, the 2021 registration regulations, registration forms and guides, a code of conduct, a breach management guide and a records guide. There is no approved set of standard contractual clauses, no adequacy list, and no cross-border transfer guideline. Separately, storing data abroad is treated by the regulator as needing its own authorisation over and above any transfer approval, and section 81(2) of the Act makes the controller pay the cost of auditing any foreign server it has been allowed to use.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, section 71 and section 81(2)
parliament.gov.zm
“the transfer is made subject to standard contracts or intragroup schemes that have been approved by the Data Protection Commissioner”
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Resources library (eleven published documents; no approved standard contracts and no transfer guideline), checked 18 August 2026
dataprotection.gov.zm
Link checked 18 August 2026
The regulator, and whether it actually acts
The Data Protection Commission, which sits inside the Ministry of Technology and Science. It is real: it has a named Commissioner, a live online registration portal, published fees and a set of guidelines issued in early 2025. But it looks thinly resourced and it is not visibly punishing anyone. Its website has published exactly two news items, both on 3 February 2025, and two of its guidance pages still contain placeholder filler text. We found no published fine or decision against any named organisation.
The Office of the Data Protection Commissioner is established by section 4 of the Data Protection Act, 2021 inside the ministry responsible for communications, which is the Ministry of Technology and Science. The Commission's own team page names Likando Luywa as Data Commissioner. Registration is genuinely operating: there is an online portal, a manual route by email, and a published fee table running from about 67 kwacha to apply and 667 kwacha for a certificate for an individual or micro organisation, up to 400 kwacha to apply and 4,000 kwacha for a certificate for a large organisation or a data processor. At the Bank of Zambia mid rate of about 18.74 kwacha to the United States dollar on 18 August 2026, the largest of those is roughly 215 dollars. Certificates last twelve months and must be renewed. Against that, the signs of an immature regulator are hard to miss: the Audit Guidelines page and the Other Guidelines page both still display Latin placeholder text, the Team page still lists a dummy second member, the only press release on the site opens to an empty body, and the resources have download counts in the low hundreds. Enforcement is also not the Commission's alone. Most of the Act's teeth are criminal offences prosecuted through the courts, individuals can sue for compensation, and three other regulators are active in adjacent space: the Zambia Information and Communications Technology Authority for telecoms, the Zambia Cyber Security Agency created in 2025 for cyber security, and the Bank of Zambia for payments, which issued a dated and deadlined data access order in July 2025.
Sources
- Official sourceData Protection Commission of ZambiaData Protection Commission — Our Team (names Likando Luywa as Data Commissioner; second entry is a placeholder), checked 18 August 2026
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — News (two posts only, both dated 3 February 2025), checked 18 August 2026
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Registration, fee table and online portal, checked 18 August 2026
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 4 to 6 (Office of the Data Protection Commissioner) and section 72 (compensation)
parliament.gov.zm
Link checked 18 August 2026
How long you must keep it — and when to delete it
Zambia has a floor and a ceiling, and they point in opposite directions. The floor is unusual: you must keep personal data for at least one year after you have finished using it for the purpose you collected it for. The ceiling is the ordinary rule that you must not keep data in an identifiable form for longer than you need it, and people can ask you to erase it. Telecoms operators have their own floor of three years after a device was last used.
Section 51(1) of the Data Protection Act, 2021 says a controller and processor 'shall keep personal information for as long as that personal information is used for the specific purpose for which the personal information was collected and for as long as the personal information is relevant for that purpose and for a period of at least one year thereafter or other period that may be prescribed'. That is a mandatory minimum, not a maximum, and no shorter period has been prescribed. Pulling the other way, section 12(1)(e) requires data to be 'stored in a form which permits identification of data subjects for no longer than is necessary', and section 60 gives an enforceable right to erasure without undue delay once the data is no longer needed, once consent is withdrawn, or once processing is found unlawful. Section 51(2) adds a separate record-keeping duty covering the purpose of collection and the third parties data was disclosed to and when. Zambia gives no statutory tie-breaker between the one-year floor and the erasure right. The practical reading is that the specific one-year rule in section 51 beats the general principle, so an erasure request received inside that year should be met by restricting and quarantining the data rather than destroying it — and that reading has not been tested by a Zambian court. In telecoms, regulation 15 of the 2011 device registration regulations as amended in January 2026 requires an operator to keep the information in its equipment identification register for three years after the last use of the device. Longer floors also exist in Zambian tax and company law, which we did not verify for this record.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 12(1)(e), 51 and 60
parliament.gov.zm
“a data controller and data processor shall keep personal information for as long as that personal information is used for the specific purpose for which the personal information was collected and for as long as the personal information is relevant for that purpose and for a period of at least one year thereafter”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaInformation and Communication Technologies Act, 2009 (Act No. 15 of 2009), section 64(9) to (11) — power to make device and SIM registration regulations
parliament.gov.zm
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchInformation and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026 (Statutory Instrument No. 10 of 2026), regulation 15
zambialii.org
“keep the information in the equipment identification register for a period of three years after the last use of the electronic communications apparatus”
Link checked 18 August 2026
If something goes wrong
Twenty-four hours to tell the regulator, and that clock starts when the breach happens, not when your lawyers finish arguing about it. You must also tell the affected people as soon as practicable. If you are a processor working for someone else, you tell your client as soon as practicable and they carry the deadline. A second and shorter clock applies if you hold information the government has labelled critical: you must notify the cyber security agency immediately and file a written preliminary report within twelve hours.
Section 49(1) of the Data Protection Act, 2021 requires a data controller to notify the Data Protection Commissioner 'within twenty-four hours of any security breach affecting personal data processed'. There is no harm threshold and no risk filter — on the face of the text every security breach affecting personal data is reportable. Section 49(2) puts a processor on an 'as soon as practicable' duty to its controller, and section 49(3) requires notice to the affected individual as soon as practicable. The Commission publishes a guide on management of data security breaches and hosts an online breach report form. The second clock comes from section 17 of the Cyber Security Act, 2025: a controller of critical information must immediately notify the Zambia Cyber Security Agency of a perceived or actual incident, then submit a preliminary written incident report within twelve hours, then a detailed report once the incident is resolved, plus status reports at intervals the Agency sets. Failure carries a fine of up to five hundred thousand penalty units or five years in prison. The twelve-hour duty only bites on organisations whose information has been designated critical by Gazette notice, and no such designation was found as at 18 August 2026. The overlap is the operational danger: an incident at a bank or hospital could in principle trigger a twelve-hour cyber report and a twenty-four hour privacy report to two different regulators with two different forms.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, section 49 (notification of security breach)
parliament.gov.zm
“A data controller shall notify the Data Protection Commissioner within twenty-four hours of any security breach affecting personal data processed.”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaCyber Security Act, 2025, section 17 (duty to report cyber security incidents)
parliament.gov.zm
“a controller shall submit a preliminary cyber incident report to the Agency within twelve hours of notifying the Agency of the perceived or actual occurrence of the incident”
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Guide on Management of Data Security Breach
dataprotection.gov.zm
Link checked 18 August 2026
What catches people out
Five things that are not in any summary. One: you must keep data for a year after you stop needing it, which collides head-on with the right to be erased. Two: every organisation must appoint a data protection officer — there is no size cut-off. Three: every organisation must be audited every year, and if you were allowed to store data abroad you pay for auditing the foreign server too. Four: the fines are criminal, and directors, managers, shareholders and partners can be convicted personally. Five: a child in Zambia is anyone under eighteen, and you must build age checks and parental consent into your product.
Trap one is section 51 against sections 12(1)(e) and 60, described in the retention answer. Trap two is section 48: 'a data controller and data processor shall appoint a data protection officer', with the manner of appointment left to guidelines. Unlike Europe there is no trigger based on scale, sensitivity or public authority status. Trap three is section 81: the Commissioner or an independent licensed data auditor audits the policies and processing of a data controller annually, and section 81(2) puts the cost of auditing an authorised foreign server on the controller. Data auditors must themselves be licensed under Part VI. Trap four is the penalty structure. A body corporate that breaches the processing principles faces a fine of up to one hundred million penalty units or two percent of the previous year's annual turnover, whichever is higher; at forty ngwee per penalty unit that fixed cap is forty million kwacha, roughly 2.1 million United States dollars. A natural person faces up to one million penalty units or five years in prison. Processing without registration carries up to five hundred thousand penalty units or five years. Unlawfully disclosing sensitive personal data carries up to two hundred thousand penalty units or two years. Section 76 makes a director, manager, shareholder or partner personally liable where the offence was committed with their knowledge, consent or connivance, and section 75 lets a court forfeit the medium holding the data and ban a convicted person from managing any processing at all. Trap five is section 17 read with the Constitution's definition of a child, which is a person below eighteen: parental or guardian consent is required, and the controller must 'incorporate appropriate mechanisms for age verification and parental consent'. A sixth, quieter trap: mobile lines now require biometric data. The January 2026 amendment to the device registration regulations requires operators to submit subscriber biometric data to the telecoms regulator, and makes a parent or guardian the registered subscriber for any line used by a child until that child turns eighteen.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 17, 18, 48, 51, 73, 75, 76, 77 and 81
parliament.gov.zm
“a fine not exceeding one hundred million penalty units; or two percent of annual turnover of the preceding financial year, whichever is higher”
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchFees and Fines (Fee and Penalty Unit Value) (Amendment) Regulations, 2024 (Statutory Instrument No. 25 of 2024) — penalty unit raised from thirty ngwee to forty ngwee
zambialii.org
“deletion of the words “thirty ngwee” and the substitution therefor of the words “forty ngwee””
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchInformation and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026, regulations 12 and 26
zambialii.org
Link checked 18 August 2026
What's changing next
Nothing large is scheduled to start in the next twelve months. The risk here is the opposite kind: three switches the government already holds and has not yet flipped. Any one of them could change the picture with a single notice and no consultation. Two would make life much easier; one would make it much harder.
Switch one, the liberalising one: the Minister may prescribe categories of personal data that may be stored outside Zambia. This power has existed since the Act commenced on 1 April 2021 and has never been used. A single statutory instrument could release most ordinary business data from the storage mandate overnight. Switch two, also liberalising: the Data Protection Commissioner may approve standard contracts and intra-group schemes. None have been approved or published, which is why the main legal route out of the country is currently closed. Publication of an approved set would move Zambia from case-by-case approval to something closer to a paperwork regime. Switch three, the tightening one: the Zambia Cyber Security Agency may, by notice in the Gazette, designate information or infrastructure in eleven critical sectors as critical. From the date of designation, the controller has thirty days to register with the Agency, must host that information inside Zambia unless separately authorised, must appoint an information technology auditor annually, and falls under the twelve-hour incident report. No designation notice was found on any government source as at 18 August 2026. Also worth watching: the Ministry of Technology and Science has run a public call for comments on the review of the earlier cyber security legislation, and the new Cyber Security Act, 2025 and Cyber Crimes Act, 2025 both need implementing regulations that had not appeared by August 2026. Because a single notice can change the storage picture in either direction, this record is set to refresh every sixty days.
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 70(2) and 71(1) and (5) — unused ministerial and Commissioner powers
parliament.gov.zm
“Despite subsection (1), the Minister may prescribe categories of personal data that may be stored outside the Republic.”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaCyber Security Act, 2025, sections 9, 11, 12 and 14 — designation of critical information by Gazette notice
parliament.gov.zm
“The Agency shall, by notice in the Gazette, designate information or information infrastructure relevant to a critical sector as critical information or critical information infrastructure.”
Link checked 18 August 2026
- Official sourceMinistry of Technology and Science, ZambiaMinistry of Technology and Science — news and consultations, including the call for comments on the review of the cyber security legislation, checked 18 August 2026
mots.gov.zm
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
The Cyber Security Act, 2025
Act of parliament · Act No. 3 of 2025
A second in-country hosting mandate aimed at eleven named critical sectors: defence and security, the public sector, banking and finance, health, transport, pensions and insurance, information and communications technology, energy, education and mining. The law is in force, but the duty attaches to a particular organisation only once the Zambia Cyber Security Agency names its information as critical by notice in the government gazette. No such notice was found as at 18 August 2026, so this is an armed but unfired switch.
Enforced by Zambia Cyber Security Agency — not yet operational
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryHosting inside Zambia is required from the date the Agency designates the information as critical by Gazette notice. The Agency may authorise hosting abroad after weighing national security, national cyber resilience, whether the destination has a cyber security legal framework, and which categories of personal data must stay in Zambia under the privacy law.
- Register or notifyRegistration with the Agency within thirty days of designation.
- Report cyber incidents — within 12 hoursImmediate notification, then a written preliminary report within twelve hours, then a detailed report on resolution, plus periodic status reports.
- Independent auditAn information technology auditor must be appointed annually to perform a cyber audit.
- Secure the dataBaseline security requirements as prescribed, plus detection mechanisms aligned to standards the Agency publishes in the Gazette.
What it costs if you get it wrong
- Criminal liability: 500,000 penalty units (about ZMW 200,000) or 5 years imprisonment — about $11 thousandFailing to register designated critical information, failing to report an incident, or failing to notify a change of ownership
Sources
- Official sourceNational Assembly of ZambiaThe Cyber Security Act, 2025 (Act No. 3 of 2025), Part III — protection of critical information and critical information infrastructure
parliament.gov.zm
“A controller shall host critical information or critical information infrastructure within the Republic, in a prescribed manner and form.”
Link checked 18 August 2026
- Official sourceNational Assembly of ZambiaThe Cyber Security and Cyber Crimes Act, 2021 (Act No. 2 of 2021), section 18 — the predecessor localisation clause, repealed and replaced in 2025
parliament.gov.zm
“A controller of critical information shall store all critical information on a server or data center located within the Republic.”
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchCyber Security Act (Commencement) Order, 2025 (Statutory Instrument No. 22 of 2025) — appoints 12 May 2025
zambialii.org
Link checked 18 August 2026
PSB Circular No. 08/2025 — Requirement to Provide Real Time Read-Only Access
Regulator directive · BOZ/EXEC/DG/psd/bp, 11 July 2025
No payments localisation rule was found in Zambia, but the central bank now requires live supervisory access instead. Since 15 August 2025 every electronic money institution must give the Bank of Zambia real-time read-only access to its platform and analytics tools, and banks must give the same access to the accounts backing electronic money. That is a real architectural constraint even though it does not say where the data must sit.
Enforced by Bank of Zambia
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataElectronic money institutions must give the central bank real-time read-only access to the platforms used to create and manage electronic money and to their business analytics tools. Banks and deposit-taking non-bank institutions must give the same access to all holding and pool accounts held for electronic money issuance.
- Keep records of processingUnderpinned by the requirement in the electronic money issuance directives to enable real-time monitoring of holding and pool accounts and electronic money platforms.
What it costs if you get it wrong
- Order to stopPenalties and other supervisory sanctions under the National Payment Systems Act for failure to provide the access
Sources
- Official sourceBank of Zambia, Office of the Deputy Governor - OperationsPSB Circular No. 08/2025 — Requirement to Provide Real Time Read-Only Access, 11 July 2025
boz.zm
“Electronic money institutions shall provide the Bank with real-time read only access to its platform(s) used to create, manage electronic money and its business analytics tools ... The access requested above shall be provided no later than August 15, 2025.”
Link checked 18 August 2026
- Official sourceBank of ZambiaNational Payment Systems Directives on Electronic Money Issuance, 2023 — outsourcing and systems controls (no data location requirement found)
boz.zm
Link checked 18 August 2026
The Information and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026
Directly binding regulation · Statutory Instrument No. 10 of 2026, made under section 64 of the Information and Communication Technologies Act (Cap. 169)
Zambia's telecoms rules were rewritten on 30 January 2026. Mobile operators must collect and hand over subscriber biometric data to the telecoms regulator, keep a device register inside their own network with an unbroken live link to the regulator's central register, and hold that information for three years after a device was last used. A parent or guardian must be the registered subscriber for any line used by someone under eighteen.
Enforced by Zambia Information and Communications Technology Authority
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryThe equipment identification register must be kept and made available in the operator's own network, with uninterrupted communication to the regulator's Central Equipment Identification Register in Zambia.
- Register or notifyOperators must submit subscriber biometric data and device identifiers to the regulator, and send the register of sellers daily.
- Keep data for a minimum period — 3 yearsInformation in the equipment identification register must be kept for three years after the last use of the device.
- Get a parent's consent for children — applies at: under 18A parent or guardian is the registered subscriber for a child's mobile line until the child turns eighteen, then has ninety days to transfer, keep or deactivate it.
What it costs if you get it wrong
- Criminal liability: 2,500 penalty units (about ZMW 1,000) per SIM, or up to 2 years imprisonment — about $55Selling pre-registered SIM cards, registering without an identity document, or failing to maintain the subscriber or seller register
Sources
- Official sourceNational Assembly of ZambiaInformation and Communication Technologies Act, 2009 (Act No. 15 of 2009), section 64 — the power under which these Regulations are made
parliament.gov.zm
“The Minister may, in consultation with the Authority, by statutory instrument, make regulations for the registration of electronic equipment including mobile devices and subscriber identification modules”
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchInformation and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026 (Statutory Instrument No. 10 of 2026)
zambialii.org
“An electronic communications service provider shall keep, maintain and make available, in that electronic communications service provider's network, an equipment identification register”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
The Data Protection Act, 2021
Act of parliament · Act No. 3 of 2021
Zambia's general privacy law. Its defining feature is that personal data must be processed and stored inside Zambia by default, with copies allowed abroad only through case-by-case approval. Everyone who handles personal data must register, appoint a data protection officer and be audited annually. Breaches go to the regulator within 24 hours. Penalties are criminal and include a turnover-based cap for companies and personal liability for directors.
Enforced by Data Protection Commission (Office of the Data Protection Commissioner)
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Standard contract clauses, Government sign-off needed, Explicit consent, Someone's life is at risk
What it makes you do
- Keep the data in the countryDefault duty to process and store personal data on a server or in a data centre located in Zambia. The ministerial power to release categories has never been used.
- Register or notifyNo turnover or headcount threshold. Certificate lasts twelve months and must be renewed.
- Appoint a local representativeAn entity not registered in Zambia must give the details of a representative in Zambia on the registration form.
- Appoint a data protection officerRequired of every controller and every processor. No size threshold in the Act.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of processing
- Assess high-risk projects
- Written vendor contractA processor may not engage a sub-processor without the controller's prior written authorisation.
- Report breaches to the regulator — within 24 hours
- Tell affected peopleAs soon as practicable. No harm threshold.
- Keep data for a minimum period — 1 yearAt least one year after the personal data stops being relevant to the purpose it was collected for.
- Delete data after a periodStorage limitation principle plus an enforceable right to erasure. Sits in tension with the one-year minimum.
- Independent auditAnnual audit of every controller by the Commissioner or a licensed independent data auditor. The controller pays for auditing any authorised foreign server.
- Get a parent's consent for children — applies at: under 18Also applies to a 'vulnerable person' aged 18 or over whose decision-making is impaired. Age verification mechanisms are mandatory.
- Put a transfer safeguard in placeA controller relying on an approved standard contract must certify and periodically report compliance to the Commissioner and carries liability for the recipient's failures.
What it costs if you get it wrong
- Fixed maximum fine: 100,000,000 penalty units (about ZMW 40,000,000 at 40 ngwee per unit) — about $2 millionBody corporate breaching the principles and rules on processing personal data
- Percentage of global turnover: 2% of annual turnover of the preceding financial yearBody corporate breaching the principles and rules on processing personal data, where higher than the fixed cap
- Criminal liability: 1,000,000 penalty units (about ZMW 400,000) or 5 years imprisonment — about $21 thousandNatural person breaching the principles and rules on processing personal data
- Criminal liability: 500,000 penalty units (about ZMW 200,000) or 5 years imprisonment — about $11 thousandControlling or processing personal data without registering
- Criminal liability: 200,000 penalty units (about ZMW 80,000) or 2 years imprisonment — about $4 thousandUnlawfully disclosing sensitive personal data, or breaching a code of conduct or binding guideline
- Criminal liability: 300,000 penalty units (about ZMW 120,000) or 3 years imprisonment — about $6 thousandAny offence under the Act for which no specific penalty is provided
- Claims by individualsA data subject who suffers damage from an infringement may claim compensation in court
Sources
- Official sourceNational Assembly of ZambiaThe Data Protection Act, 2021 (Act No. 3 of 2021) — full text
parliament.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaThe Data Protection Act, 2021 — copy published by the Data Protection Commission
dataprotection.gov.zm
Link checked 18 August 2026
- Secondary sourceZambiaLII / Southern African Institute for Policy and ResearchData Protection Act (Commencement) Order, 2021 (Statutory Instrument No. 22 of 2021) — appoints 1 April 2021
zambialii.org
Link checked 18 August 2026
The Data Protection Act, 2021, section 70(3)
Act of parliament · Act No. 3 of 2021, s 70(3)
The strictest rule in Zambian data law. Sensitive personal data — health, race, religion, political opinion, ethnic or social origin, genetics, biometrics, sex or sexual orientation, trade union membership and child abuse records — must be processed and stored on a server or in a data centre in Zambia, with no ministerial exemption available. A copy may go abroad only with the person's explicit consent or in a health or emergency situation.
Enforced by Data Protection Commission (Office of the Data Protection Commissioner)
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Explicit consent, Someone's life is at risk, Government sign-off needed
What it makes you do
- Keep the data in the countryAbsolute. The Minister's power to release categories from the storage mandate does not reach sensitive personal data.
- Get consentExplicit consent is the main route for sending a copy of sensitive personal data abroad.
What it costs if you get it wrong
- Criminal liability: 200,000 penalty units (about ZMW 80,000) or 2 years imprisonment — about $4 thousandUnlawful disclosure of sensitive personal data
Sources
- Official sourceNational Assembly of ZambiaData Protection Act, 2021, sections 2 (sensitive personal data), 70(3) and 71(4)
parliament.gov.zm
“Despite subsection (2), sensitive personal data shall be processed and stored in a server or data centre located in the Republic.”
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Frequently Asked Questions, definition of sensitive data
dataprotection.gov.zm
Link checked 18 August 2026
The Data Protection (Registration and Licensing) Regulations, 2021
Directly binding regulation · Statutory Instrument No. 58 of 2021
The machinery behind the registration duty. It sets the fee bands by organisation size, licenses data auditors, and drives the application form that asks whether you store personal data outside Zambia and requires a Zambian representative from foreign entities. Certificates last twelve months and must be renewed.
Enforced by Data Protection Commission (Office of the Data Protection Commissioner)
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Register or notify — 1 yearApplication and certificate fees run from about ZMW 67 and ZMW 667 for an individual or micro organisation to about ZMW 400 and ZMW 4,000 for a large organisation or a data processor. Size bands are set by employee count: micro is up to ten, medium is eleven to fifty, large is more than fifty.
- Appoint a local representativeForm I, Part 5 requires the details of a Zambian representative where the applicant is an entity not registered in Zambia.
- Independent auditData auditors must themselves be licensed by the Commissioner under these Regulations.
- Put a transfer safeguard in placeThe registration form asks whether the applicant stores or intends to store personal data outside Zambia; a yes answer requires a separate authorisation application.
What it costs if you get it wrong
- Criminal liability: 500,000 penalty units (about ZMW 200,000) or 5 years imprisonment — about $11 thousandControlling or processing personal data without registering
- Order to stopSuspension or cancellation of registration, including where information given at registration was false or misleading
Sources
- Official sourceData Protection Commission of ZambiaThe Data Protection (Registration and Licensing) Regulations, 2021 (Statutory Instrument No. 58 of 2021)
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission of ZambiaData Protection Commission — Registration page, fee table, online portal and forms
dataprotection.gov.zm
Link checked 18 August 2026
- Official sourceData Protection Commission / Ministry of Technology and ScienceTerms and Conditions for Registration as a Data Controller or Data Processor, February 2025
dataprotection.gov.zm
“This certificate is valid for a period of twelve months and is renewable upon reapplication.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the Data Protection Act reaches a company with no presence in Zambia at all
Section 3 defines scope by the method of processing and says nothing about where the controller is established. There is no express extraterritorial clause of the kind found in Kenyan, Nigerian or Ghanaian law, and no Zambian court decision on the point was found. The regulator's own form assumes foreign entities register through a Zambian representative, so the practical answer is yes, but the legal answer is untested.
Whether any standard contractual clauses or intra-group schemes have been approved by the Data Protection Commissioner
We checked the Commission's resources library and every page of its website on 18 August 2026 and found none. We cannot prove a negative: approvals may exist and simply not be published. If they do exist, the main legal route for sending data abroad would be open rather than closed.
Whether the Minister has ever prescribed categories of personal data that may be stored outside Zambia
No such statutory instrument was found in any legislation index or on any government site. Only one substantive instrument under the Act was found, the 2021 Registration and Licensing Regulations. If a release order exists, the storage mandate would be far narrower than described here.
Whether the Zambia Cyber Security Agency has designated any critical information or critical information infrastructure by gazette notice
Gazette notices are not systematically published online in Zambia and the Agency has no website we could find. The in-country hosting duty in the 2025 cyber security law turns entirely on this, so the difference matters.
Whether the Data Protection Commission has issued any fine, order or enforcement decision
Nothing is published on its website, which has had no new post since February 2025. Zambia has no public enforcement register. Absence of publication is not proof of absence of enforcement.
The text of the January 2026 telecoms registration regulations and the 2021 and 2025 commencement orders
These statutory instruments were read in full, but only from ZambiaLII, an independent legal information institute, not from a Zambian government domain. Zambia does not publish its statutory instruments on an official website that we could reach. The parent Acts are cited from the National Assembly's own site.
Minimum retention periods under Zambian tax, company and anti-money-laundering law
Out of scope for this pass. Longer floors almost certainly exist and would override the one-year privacy-law minimum for the records they cover.
Sector rules for insurance, securities, gambling and mapping or geospatial data
The Pensions and Insurance Authority and the Securities and Exchange Commission websites were unreachable from this environment on 18 August 2026. A search of the Zambian statute book found no other law using server or data centre location language, so any such rules would most likely sit in licence conditions rather than legislation.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Zambia versus
Compare