Skip to the content
Global Data RulesData governance rules, country by country

Zambia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

A copy must stayWork: Very highEnforcement: Waking up

Zambia is one of the strictest countries in Africa on paper. The default rule is that personal data must be processed and stored on a server or in a data centre inside Zambia. A copy may go abroad only with the person's consent plus a contract the regulator has approved — and the regulator has approved none. Every organisation handling personal data must register, and breaches must be reported within 24 hours.

Data governance in Zambia

The eight things that decide how you handle data about people in Zambia. Same eight on every country page, so you can compare.

Who has to follow these rules

Almost certainly yes in practice, but the law does not say so clearly. The Act applies to processing of personal data by automated means and to processing done on paper. The regulator's own registration guideline says all persons and entities in all sectors must register, whatever their turnover or staff numbers. The registration form has a section to be completed by anyone representing a foreign entity, so the regulator plainly expects overseas businesses to be inside the net.

Medium confidenceNational rulesRegister or notifyAppoint a local representative

Where the data is allowed to live

Only if a copy stays behind. Zambian law starts from the position that a company must process and store personal data on a server or in a data centre located in Zambia. The most sensitive categories — health, race, religion, politics, sex life, fingerprints, genetics, trade union membership, child abuse records — must be processed and stored in Zambia with no exception at all. Sending anything abroad, including to a cloud region or an off-site backup, needs its own permission from the regulator.

High confidenceA copy must stayApproval each timeKeep the data in the country

Sending data out of the country

Each transfer needs its own permission. There are three routes and none of them is a form you can simply sign. The first needs the person's consent plus a standard contract or group-wide scheme approved by the regulator — the regulator has published no approved contracts, so this route is not usable today. The second needs the Minister to declare a destination country acceptable, which has not happened. The third is a one-off approval from the regulator for a particular transfer.

High confidenceApproval each timeStandard contract clausesGovernment sign-off neededExplicit consentSomeone's life is at riskPut a transfer safeguard in place

The regulator, and whether it actually acts

The Data Protection Commission, which sits inside the Ministry of Technology and Science. It is real: it has a named Commissioner, a live online registration portal, published fees and a set of guidelines issued in early 2025. But it looks thinly resourced and it is not visibly punishing anyone. Its website has published exactly two news items, both on 3 February 2025, and two of its guidance pages still contain placeholder filler text. We found no published fine or decision against any named organisation.

High confidenceWaking upCriminal liabilityClaims by individuals

How long you must keep it — and when to delete it

Zambia has a floor and a ceiling, and they point in opposite directions. The floor is unusual: you must keep personal data for at least one year after you have finished using it for the purpose you collected it for. The ceiling is the ordinary rule that you must not keep data in an identifiable form for longer than you need it, and people can ask you to erase it. Telecoms operators have their own floor of three years after a device was last used.

High confidenceKeep data for a minimum periodDelete data after a periodLet people delete their dataKeep records of processing

If something goes wrong

Twenty-four hours to tell the regulator, and that clock starts when the breach happens, not when your lawyers finish arguing about it. You must also tell the affected people as soon as practicable. If you are a processor working for someone else, you tell your client as soon as practicable and they carry the deadline. A second and shorter clock applies if you hold information the government has labelled critical: you must notify the cyber security agency immediately and file a written preliminary report within twelve hours.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that are not in any summary. One: you must keep data for a year after you stop needing it, which collides head-on with the right to be erased. Two: every organisation must appoint a data protection officer — there is no size cut-off. Three: every organisation must be audited every year, and if you were allowed to store data abroad you pay for auditing the foreign server too. Four: the fines are criminal, and directors, managers, shareholders and partners can be convicted personally. Five: a child in Zambia is anyone under eighteen, and you must build age checks and parental consent into your product.

High confidenceAppoint a data protection officerIndependent auditGet a parent's consent for childrenKeep data for a minimum periodCriminal liabilityPercentage of global turnover

What's changing next

Nothing large is scheduled to start in the next twelve months. The risk here is the opposite kind: three switches the government already holds and has not yet flipped. Any one of them could change the picture with a single notice and no consultation. Two would make life much easier; one would make it much harder.

Medium confidenceIn forceApproval each timeKeep the data in the country

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

The Cyber Security Act, 2025

Act of parliament · Act No. 3 of 2025

In forceA copy must stay

A second in-country hosting mandate aimed at eleven named critical sectors: defence and security, the public sector, banking and finance, health, transport, pensions and insurance, information and communications technology, energy, education and mining. The law is in force, but the duty attaches to a particular organisation only once the Zambia Cyber Security Agency names its information as critical by notice in the government gazette. No such notice was found as at 18 August 2026, so this is an armed but unfired switch.

In force since 12 May 2025

Enforced by Zambia Cyber Security Agency — not yet operational

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed

Medium confidence
Payments

PSB Circular No. 08/2025 — Requirement to Provide Real Time Read-Only Access

Regulator directive · BOZ/EXEC/DG/psd/bp, 11 July 2025

In forceYes — store it anywhere

No payments localisation rule was found in Zambia, but the central bank now requires live supervisory access instead. Since 15 August 2025 every electronic money institution must give the Bank of Zambia real-time read-only access to its platform and analytics tools, and banks must give the same access to the accounts backing electronic money. That is a real architectural constraint even though it does not say where the data must sit.

In force since 11 July 2025But only enforceable from 15 August 2025

Enforced by Bank of Zambia

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Telecoms

The Information and Communication Technologies (Registration of Electronic Communication Apparatus) (Amendment) Regulations, 2026

Directly binding regulation · Statutory Instrument No. 10 of 2026, made under section 64 of the Information and Communication Technologies Act (Cap. 169)

In forceA copy must stay

Zambia's telecoms rules were rewritten on 30 January 2026. Mobile operators must collect and hand over subscriber biometric data to the telecoms regulator, keep a device register inside their own network with an unbroken live link to the regulator's central register, and hold that information for three years after a device was last used. A parent or guardian must be the registered subscriber for any line used by someone under eighteen.

In force since 30 January 2026

Enforced by Zambia Information and Communications Technology Authority

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed

Medium confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

The Data Protection Act, 2021

Act of parliament · Act No. 3 of 2021

In forceA copy must stay

Zambia's general privacy law. Its defining feature is that personal data must be processed and stored inside Zambia by default, with copies allowed abroad only through case-by-case approval. Everyone who handles personal data must register, appoint a data protection officer and be audited annually. Breaches go to the regulator within 24 hours. Penalties are criminal and include a turnover-based cap for companies and personal liability for directors.

In force since 1 April 2021

Enforced by Data Protection Commission (Office of the Data Protection Commissioner)

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Standard contract clauses, Government sign-off needed, Explicit consent, Someone's life is at risk

High confidence

The Data Protection Act, 2021, section 70(3)

Act of parliament · Act No. 3 of 2021, s 70(3)

In forceA copy must stay

The strictest rule in Zambian data law. Sensitive personal data — health, race, religion, political opinion, ethnic or social origin, genetics, biometrics, sex or sexual orientation, trade union membership and child abuse records — must be processed and stored on a server or in a data centre in Zambia, with no ministerial exemption available. A copy may go abroad only with the person's explicit consent or in a health or emergency situation.

In force since 1 April 2021

Enforced by Data Protection Commission (Office of the Data Protection Commissioner)

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Explicit consent, Someone's life is at risk, Government sign-off needed

High confidence

The Data Protection (Registration and Licensing) Regulations, 2021

Directly binding regulation · Statutory Instrument No. 58 of 2021

In forceA copy must stay

The machinery behind the registration duty. It sets the fee bands by organisation size, licenses data auditors, and drives the application form that asks whether you store personal data outside Zambia and requires a Zambian representative from foreign entities. Certificates last twelve months and must be renewed.

In force since 14 May 2021

Enforced by Data Protection Commission (Office of the Data Protection Commissioner)

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

  • Data Protection Commission

    General privacy law: registration of controllers and processors, licensing of data auditors, breach reports, complaints, approval of standard contracts for transfers abroad

    Established inside the Ministry of Technology and Science. A Commissioner, Likando Luywa, is named on the Commission's own team page. Registration and self-assessment portals both respond, fees are published, and guidelines were issued in January and February 2025. But the Commission has published only two news items ever, both dated 3 February 2025; its Audit Guidelines and Other Guidelines pages still show Latin placeholder text; its team page still lists a dummy member; its only press release opens to an empty page; and no enforcement decision against any named organisation could be found. Treat it as functioning for registration and dormant for enforcement.

  • Ministry of Technology and Science

    Rule-making under the data protection and cyber security laws, including the unused power to prescribe categories of personal data that may be stored outside Zambia

    Active and publishing news through August 2026. Hosts the Data Protection Commission.

  • Zambia Cyber Security Agency

    Designation, registration, in-country hosting and incident reporting for critical information and critical information infrastructure; licensing of cyber security service providers

    Created by the Cyber Security Act, 2025, which commenced on 12 May 2025. We could not find a website of its own, any gazette notice designating critical information, or any implementing regulations as at 18 August 2026. Until it designates something, its in-country hosting duty binds nobody. Listed here with the parent ministry's site because no dedicated official site was found.

  • ZICTA

    Telecoms and postal regulation, SIM and device registration, the Central Equipment Identification Register

    Long-established licensing regulator. Its public website is a single-page application that returns very little to automated retrieval and displayed news no more recent than 2022 when checked on 18 August 2026, so its published material could not be verified in depth.

  • Bank of Zambia

    Banking, payment systems and electronic money supervision

    Fully active. Issues dated circulars with hard compliance deadlines, most recently the July 2025 order requiring real-time read-only access to electronic money platforms by 15 August 2025.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the Data Protection Act reaches a company with no presence in Zambia at all

    Section 3 defines scope by the method of processing and says nothing about where the controller is established. There is no express extraterritorial clause of the kind found in Kenyan, Nigerian or Ghanaian law, and no Zambian court decision on the point was found. The regulator's own form assumes foreign entities register through a Zambian representative, so the practical answer is yes, but the legal answer is untested.

  • Whether any standard contractual clauses or intra-group schemes have been approved by the Data Protection Commissioner

    We checked the Commission's resources library and every page of its website on 18 August 2026 and found none. We cannot prove a negative: approvals may exist and simply not be published. If they do exist, the main legal route for sending data abroad would be open rather than closed.

  • Whether the Minister has ever prescribed categories of personal data that may be stored outside Zambia

    No such statutory instrument was found in any legislation index or on any government site. Only one substantive instrument under the Act was found, the 2021 Registration and Licensing Regulations. If a release order exists, the storage mandate would be far narrower than described here.

  • Whether the Zambia Cyber Security Agency has designated any critical information or critical information infrastructure by gazette notice

    Gazette notices are not systematically published online in Zambia and the Agency has no website we could find. The in-country hosting duty in the 2025 cyber security law turns entirely on this, so the difference matters.

  • Whether the Data Protection Commission has issued any fine, order or enforcement decision

    Nothing is published on its website, which has had no new post since February 2025. Zambia has no public enforcement register. Absence of publication is not proof of absence of enforcement.

  • The text of the January 2026 telecoms registration regulations and the 2021 and 2025 commencement orders

    These statutory instruments were read in full, but only from ZambiaLII, an independent legal information institute, not from a Zambian government domain. Zambia does not publish its statutory instruments on an official website that we could reach. The parent Acts are cited from the National Assembly's own site.

  • Minimum retention periods under Zambian tax, company and anti-money-laundering law

    Out of scope for this pass. Longer floors almost certainly exist and would override the one-year privacy-law minimum for the records they cover.

  • Sector rules for insurance, securities, gambling and mapping or geospatial data

    The Pensions and Insurance Authority and the Securities and Exchange Commission websites were unreachable from this environment on 18 August 2026. A search of the Zambian statute book found no other law using server or data centre location language, so any such rules would most likely sit in licence conditions rather than legislation.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Zambia versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.