Law / Zambia

Zambia

9 of 11 named instruments researched to a stage, across three of the six areas of law we track: 8 in force and 1 repealed, withdrawn or blocked. As of 19 September 2026.

When they take effect9 of 9 carry a date. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 7 instruments (6 in force, 1 repealed, withdrawn or blocked) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 1 instrument (1 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (131 words)

Zambia's comprehensive personal-data regime is the Data Protection Act, 2021, enforced by the Office of the Data Protection Commissioner, which became fully operational in 2025 with an April 2025 controller and processor registration deadline.

The Act covers personal data processed wholly or partly by automated means, gives biometric and genetic data heightened status as sensitive personal data, requires breach notification to the Commissioner within twenty-four hours, gives a data subject a right against a purely automated decision that produces legal or similarly significant effects, and, by default, requires personal data to be processed and stored on a server or data centre located in Zambia, with an absolute in-country storage rule for sensitive personal data that sits alongside a separate provision permitting a sensitive-data transfer abroad on the data subject's explicit consent.

Breach notification

Data Protection Act, 2021, notification of a security breach

Data Protection Act, 2021, s. 49 (notification of a security breach)Official Act text as published by the National Assembly of Zambia (Parliament of Zambia)

In force since 1 April 2021. Binds public and private bodies.

What this law does

Section 49(1) requires a data controller to notify the Data Protection Commissioner within twenty-four hours of any security breach affecting personal data processed, a period the Act runs from the breach itself rather than from the moment the controller becomes aware of it. Section 49(2) requires a data processor to notify the data controller, as soon as practicable, of any security breach affecting personal data processed on the controller's behalf.

Section 49(3) requires a data controller or data processor to notify the data subject, as soon as practicable, of any security breach affecting personal data processed. None of the three duties is qualified by a risk threshold: the Act attaches them to any security breach affecting personal data, not only to one likely to cause harm. Section 82(2)(b) lets the Minister make regulations on the notification of security breaches, so the detail may be prescribed later.

Section 1 leaves commencement to a statutory instrument appointed by the Minister. The Data Protection Act (Commencement) Order, 2021 brought the Act into operation on 1 April 2021, which is the day these provisions began to bind.

What it requires

Comprehensive regime

Data Protection Act, 2021, personal data processing framework

Data Protection Act, 2021 (Act No. 3 of 2021), general duties (ss. 1-13, 15-16, 19-48 and 50-57)Official Act text as published by the National Assembly of Zambia (Parliament of Zambia)

In force since 1 April 2021. Binds public and private bodies.

What this law does

Section 3 applies the Act to processing personal data wholly or partly by automated means and to processing otherwise than by electronic means, and exempts only an individual's processing for personal use.

Section 12 sets the principles: personal data is to be processed lawfully, fairly and transparently, collected for explicit, specified and legitimate purposes and not further processed incompatibly with them, adequate, relevant and limited to what those purposes need, accurate and kept up to date with inaccurate data erased or rectified without delay, stored in identifiable form no longer than necessary, processed in accordance with the data subject's rights, and secured by appropriate technical or organisational measures against unauthorised or unlawful processing and against loss, destruction or damage.

Section 13 lists the grounds on which a data controller may process, and section 15 requires consent, with the data subject told of the right to withdraw it beforehand, the request presented separately from other matters in clear and plain language, the burden of proving consent on the controller, and everything collected after a withdrawal destroyed immediately. Section 16 requires collection directly from the data subject unless one of its listed exceptions applies.

Section 19 bars controlling or processing personal data without registration, and sections 20 to 28 govern that registration while sections 29 to 38 license data auditors.

Section 45 requires a written record of processing activities, available to the Commissioner on demand; section 46 requires a data protection impact assessment before high-risk processing using new technologies; section 47 requires security safeguards including pseudonymisation and encryption and a periodic review of them; section 48 requires a data protection officer; section 51 sets data retention; section 52 governs the engagement of a data processor; section 53 bars disclosure without the data subject's consent outside the grounds it lists; section 54 makes joint controllers jointly and severally liable; and section 57 requires notice to the Commissioner of any third-party agreement allowing a third party to trade on a data subject's profile.

Section 1 leaves commencement to a statutory instrument appointed by the Minister. The Data Protection Act (Commencement) Order, 2021 brought the Act into operation on 1 April 2021, which is the day these provisions began to bind.

What it requires

Cross border transfer

Data Protection Act, 2021, transfer of personal data outside the Republic

Data Protection Act, 2021, ss. 70-71 (transfer of personal data outside the Republic)Official Act text as published by the National Assembly of Zambia (Parliament of Zambia)

In force since 1 April 2021. Binds public and private bodies.

What this law does

Section 70(1) requires a data controller to process and store personal data on a server or data centre located in the Republic. Section 70(2) lets the Minister prescribe categories of personal data that may be stored outside it. Section 70(3) keeps sensitive personal data on a server or data centre in the Republic despite that power.

Section 71(1) lets personal data outside those prescribed categories be transferred abroad where the data subject has consented and either the transfer is made under standard contracts or intra-group schemes the Commissioner has approved or the Minister has prescribed that transfers out are permissible, or where the Commissioner approves a particular transfer or set of transfers as permissible out of necessity.

Section 71(2) lets the Minister prescribe the criteria for those transfers only where the personal data will be subject to an adequate level of protection and enforcement by authorities with appropriate jurisdiction is effective, and section 71(3) has the Commissioner monitor the circumstances of data so transferred.

Section 71(4) permits transfer in an emergency to a person providing health or emergency services, where the data subject has explicitly consented to the transfer of sensitive personal data, and to an international organisation or country the Commissioner is satisfied about.

Section 71(6) requires a controller transferring under a standard contract or intra-group scheme to certify and periodically report to the Commissioner that it does so, and to bear liability for harm caused by the transferee's non-compliance. Section 1 leaves commencement to a statutory instrument appointed by the Minister. The Data Protection Act (Commencement) Order, 2021 brought the Act into operation on 1 April 2021, which is the day these provisions began to bind.

What it requires

Data subject rights

Data Protection Act, 2021, rights of the data subject

Data Protection Act, 2021, ss. 58-67 (rights of the data subject)Official Act text as published by the National Assembly of Zambia (Parliament of Zambia)

In force since 1 April 2021. Binds public and private bodies.

What this law does

Section 58 gives a data subject confirmation of whether their personal data is being processed and access, in terms they understand, to the purpose, the categories of data and of recipients, the envisaged storage period or the criteria that set it, the data and its source, and the basic logic involved in any automated decision-making, along with notification of every third party the data was disclosed to and the safeguards put in place; the first copy is free and further copies carry a reasonable administrative fee, and an electronic request is answered in a commonly used electronic format.

Section 59 gives a right to rectification of inaccurate personal data as soon as practicable and to completion of incomplete data.

Section 60 gives a right to erasure as soon as practicable, with the controller obliged to erase without undue delay where the data is no longer necessary, where consent is withdrawn and no other ground exists, where the data subject objects and no overriding legitimate ground exists, where the processing was unlawful, or where a legal obligation requires it, and requires reasonable steps to tell processors and third parties processing data the controller made public.

Section 61 gives a right of objection, including an objection to direct marketing that ends processing for that purpose, and requires the rights to be brought to the data subject's attention clearly and separately at the first communication.

Section 62 bars a decision based solely on automated processing, including profiling, that produces legal effects or similarly affects the data subject, except on contract, written law or explicit consent, and then only with suitable safeguards including human intervention so the data subject can put their point of view and contest the decision; automated processing of sensitive personal data is barred outright unless the data subject has expressly consented, it is in the public interest, or a written law permits it with safeguards in place.

Section 63 gives a right to restriction of processing, section 64 fixes the information to be given when personal data is collected directly from the data subject, section 65 gives a right to data portability, and section 66 requires any rectification, erasure or restriction to be communicated to every recipient the data was disclosed to where practicable. Section 1 leaves commencement to a statutory instrument appointed by the Minister.

The Data Protection Act (Commencement) Order, 2021 brought the Act into operation on 1 April 2021, which is the day these provisions began to bind.

What it requires

Enforcement supervision

Data Protection Act, 2021, offences, penalties, complaints and redress

Data Protection Act, 2021, ss. 18, 55 and 68-77 (offences, penalties, complaints and redress)Official Act text as published by the National Assembly of Zambia (Parliament of Zambia)

In force since 1 April 2021. Binds public and private bodies.

What this law does

Section 18(1) makes a body corporate that contravenes the Part IV processing principles liable on conviction to a fine of up to one hundred million penalty units, valued at ZMW 0.40 each since 19 April 2024, or two percent of annual turnover of the preceding financial year, whichever is higher; section 18(2) makes a natural person liable instead to a fine of up to one million penalty units or imprisonment of up to five years, or both.

Section 55 sets the same two-percent-or-two-million-penalty-unit structure for the Part VIII duties of a data controller, with ten years' imprisonment for a natural person. Section 68 lets a data subject lodge a complaint with the Data Protection Commissioner, and section 69 lets a person aggrieved by the Commissioner's decision appeal to the High Court within thirty days of it.

Section 72 entitles a data subject who has suffered damage from an infringement to compensation from the data controller or data processor as a court determines.

Section 73 makes unlawfully disclosing sensitive personal data an offence carrying up to two hundred thousand penalty units or two years' imprisonment, section 74 lets the Commissioner compound an offence for up to half the maximum fine, section 75 lets a court order forfeiture of the medium holding the data and bar the convicted person from managing any processing for a period, section 76 reaches a director, manager, shareholder or partner who knew of, consented to or connived in the offence, and section 77 sets a residual penalty of up to three hundred thousand penalty units or three years' imprisonment where no specific penalty is provided.

Section 81 has the Commissioner or a licensed independent data auditor audit a data controller's policies and processing annually. Section 1 leaves commencement to a statutory instrument appointed by the Minister. The Data Protection Act (Commencement) Order, 2021 brought the Act into operation on 1 April 2021, which is the day these provisions began to bind.

What it requires

Sensitive categories

Data Protection Act, 2021, sensitive personal data, children and vulnerable persons

Data Protection Act, 2021, ss. 14 and 17 (sensitive personal data, children and vulnerable persons)Official Act text as published by the National Assembly of Zambia (Parliament of Zambia)

In force since 1 April 2021. Binds public and private bodies.

What this law does

Section 2 defines sensitive personal data to include genetic data and biometric data, child abuse data, a data subject's political opinions, religious or similar beliefs, trade union membership, and physical or mental health or condition.

Section 14 bars anyone from processing sensitive personal data unless the processing is necessary for the establishment, exercise or defence of a legal claim or for a court exercising a judicial function, necessary for preventive or occupational medicine, assessing an employee's working capacity, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services, or necessary for reasons of public interest; the medical ground runs only where the processing is by or under the responsibility of a professional subject to secrecy, and the public-interest ground only where adequate measures to safeguard the data subject's rights and freedoms are in place.

Section 17 lets a child's or a vulnerable person's rights be exercised by a parent, legal guardian or person with parental responsibility, bars a data controller from processing their personal data without that person's consent, requires every reasonable effort to verify that the consent was given or authorised taking available technology into account, and requires appropriate mechanisms for age verification and parental consent in processing a child's personal data.

A vulnerable person is someone aged 18 or above whose ability to make informed decisions about their rights and well-being is temporarily or permanently impaired. Section 1 leaves commencement to a statutory instrument appointed by the Minister. The Data Protection Act (Commencement) Order, 2021 brought the Act into operation on 1 April 2021, which is the day these provisions began to bind.

What it requires

Scraping law2 instruments, 1 in force, 1 repealed, withdrawn or blocked

Research summary (248 words)

Zambia has no scraping-specific statute, so general law governs each dimension separately.

The Cyber Crimes Act, 2025 (in force since 12 May 2025) prohibits intentionally and without lawful authority infringing a security measure to access or monitor a computer system, so a person who reads a public, unauthenticated page without defeating an access control falls outside a plain reading of that offence; the repealed Cyber Security and Cyber Crimes Act, 2021 that it replaced read more broadly, with no express security-measure requirement.

No Zambian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper. The Copyright and Performance Rights Act, 1994 permits fair dealing for private research and for reporting current events, but Zambia has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the general research fair-dealing ground if it can be characterised as private, non-profit research.

Zambia's copyright statute confers no sui generis database right; a compilation is protected only where it is a product of creativity by reason of the selection or arrangement of its contents. The Data Protection Act, 2021 applies to personal data without a general carve-out for information that is publicly accessible, and by default requires personal data to be processed and stored on a server or data centre located in Zambia.

No Zambian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Cyber Crimes Act, 2025, unauthorised access to computer system and data

Cyber Crimes Act, 2025 (Act No. 4 of 2025), s. 3Official Act text, ZambiaLII (Zambia Legal Information Institute)

In force since 12 May 2025. Binds public and private bodies.

What this law does

Section 3(1) prohibits intentionally and without lawful authority or in excess of authority, infringing a security measure to access or monitor a computer system, or any part of a computer system, of another person. Contravention carries a fine of up to five hundred thousand penalty units, valued at ZMW 0.40 each since 19 April 2024 (ZMW 200,000), or imprisonment of up to five years, or both.

Because the offence's trigger is infringing a security measure, a person who reads a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision. This section narrows the unauthorised-access offence it replaced: section 49 of the repealed Cyber Security and Cyber Crimes Act, 2021 penalised accessing or intercepting data without authority or exceeding authorised access, with no express requirement to infringe a security measure.

What it requires

Cyber Security and Cyber Crimes Act, 2021, unauthorised access to computer system and data (repealed)

Cyber Security and Cyber Crimes Act, 2021 (Act No. 2 of 2021), s. 49Official Act text, ZambiaLII (Zambia Legal Information Institute)

Repealed: no longer in force, effective 1 April 2021. Binds public and private bodies.

What this law does

Section 49(1) prohibited intentionally accessing or intercepting data without authority or permission, or exceeding authorised access, with no express requirement that the person infringe a security measure to do so, so its unauthorised-access offence read more broadly than the offence that replaced it. Contravention carried a fine of up to five hundred thousand penalty units, valued at ZMW 0.40 each since 19 April 2024 (ZMW 200,000), or imprisonment of up to five years, or both.

The Cyber Security Act, 2025 repealed this Act outright. The repeal took legal effect on 12 May 2025 when that Act itself came into operation. The equivalent unauthorised-access offence, narrowed to require infringing a security measure, now sits at section 3 of the companion Cyber Crimes Act, 2025.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (154 words)

Zambia has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognised hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically.

Unlike a civil-law statute that excludes the news of the day from copyright outright, the Copyright and Performance Rights Act, 1994 does not exclude bare facts or news items from copyright by definition; instead, section 21(1)(c) exempts fair dealing with a work for the purpose of reporting current events, in a newspaper, magazine, or similar periodical with a sufficient acknowledgement, or by broadcasting, cable-program inclusion, or use in an audiovisual work.

Whether that exception reaches a systematic aggregator's reproduction of headlines and snippets, as distinct from a newspaper's own current-events report, has not been tested in a reported Zambian decision. The Act predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists either.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.