Law / Zambia

Data Protection Act, 2021, personal data processing framework

Data Protection Act, 2021 (Act No. 3 of 2021), general duties (ss. 1-13, 15-16, 19-48 and 50-57)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 April 2021.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Before processing personal data, establish a lawful basis such as consent, a contract, a legal obligation, or a legitimate interest, and process it fairly, transparently, and only for the purpose collected.
  • Register with the Data Protection Commissioner as a data controller or data processor before controlling or processing personal data.
  • Tell a data subject of the right to withdraw consent before they give it, present the request separately from other matters in clear and plain language, be able to prove the consent was given, and destroy immediately every piece of personal data collected after a withdrawal.
  • Collect personal data directly from the data subject unless one of the exceptions in section 16(2) applies.
  • Keep a written record of your processing activities and of all categories of processing you carry out, and make it available to the Data Protection Commissioner on demand.
  • Carry out a data protection impact assessment before processing that uses new technologies and is likely to result in a high risk, and in particular before automated processing including profiling that produces legal effects, large-scale processing of sensitive personal data, or systematic monitoring of a publicly accessible area on a large scale.
  • Implement security safeguards proportionate to the risk, including pseudonymisation and encryption, measures against misuse, unauthorised access, modification, disclosure or destruction, and data protection policies, and review them periodically against the Commissioner's guidelines.
  • Appoint a data protection officer in accordance with the Commissioner's guidelines.
  • Do not disclose personal data without the data subject's consent, and before any disclosure tell them when and to whom it will be disclosed, why, what policies will protect it, and how to complain.
  • Tell the Data Protection Commissioner of any third-party agreement that lets a third party trade on a data subject's profile.

What it reaches

Obligation class

Consent, Security, Retention, Governance, DPIA, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 3 applies the Act to processing personal data wholly or partly by automated means and to processing otherwise than by electronic means, and exempts only an individual's processing for personal use.

Section 12 sets the principles: personal data is to be processed lawfully, fairly and transparently, collected for explicit, specified and legitimate purposes and not further processed incompatibly with them, adequate, relevant and limited to what those purposes need, accurate and kept up to date with inaccurate data erased or rectified without delay, stored in identifiable form no longer than necessary, processed in accordance with the data subject's rights, and secured by appropriate technical or organisational measures against unauthorised or unlawful processing and against loss, destruction or damage.

Section 13 lists the grounds on which a data controller may process, and section 15 requires consent, with the data subject told of the right to withdraw it beforehand, the request presented separately from other matters in clear and plain language, the burden of proving consent on the controller, and everything collected after a withdrawal destroyed immediately. Section 16 requires collection directly from the data subject unless one of its listed exceptions applies.

Section 19 bars controlling or processing personal data without registration, and sections 20 to 28 govern that registration while sections 29 to 38 license data auditors.

Section 45 requires a written record of processing activities, available to the Commissioner on demand; section 46 requires a data protection impact assessment before high-risk processing using new technologies; section 47 requires security safeguards including pseudonymisation and encryption and a periodic review of them; section 48 requires a data protection officer; section 51 sets data retention; section 52 governs the engagement of a data processor; section 53 bars disclosure without the data subject's consent outside the grounds it lists; section 54 makes joint controllers jointly and severally liable; and section 57 requires notice to the Commissioner of any third-party agreement allowing a third party to trade on a data subject's profile.

Section 1 leaves commencement to a statutory instrument appointed by the Minister. The Data Protection Act (Commencement) Order, 2021 brought the Act into operation on 1 April 2021, which is the day these provisions began to bind.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Official Act text as published by the National Assembly of Zambia (Parliament of Zambia)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app