Research hub / Zambia
§ Dossier · SOUTHERN AFRICA · updated 22 July 2026

Zambia

Regulator
Office of the Data Protection Commissioner / Data Protection Commission ↗
Law
Data Protection Act No. 3 of 2021 ↗
Status
Enforces without publishing
Authority
Office of the Data Protection Commissioner / Data Protection Commission, established 2024
in force
DP law status
Data Protection Act No. 3 of 2021
Yes
enforcement activity
as of the last landscape verification
No
decisions published
no public record to collect

The law

Data Protection Act, No. 3 of 2021 IN FORCE

commenced 2021-03-24 (assent); enforcement operational from 2025 · Official full text ↗

Scope
Processing of personal data performed wholly or partly in Zambia; controllers/processors domiciled in Zambia.
Key obligations
Mandatory registration/licensing of controllers and processors (deadline 30 Apr 2025); Processing principles, consent, children's data protections; Data localisation: sensitive personal data to be stored on a server/data centre in Zambia
DPO required
Controllers must appoint a data protection officer.
Registration
Yes: criminal offence to default (fine ~ZMW 200,000 and/or up to 5 years).
Cross-border transfers
S27 primary-text correction (2026-07-11): s. 70(1) requires ALL personal data to be processed and stored on a server or data centre located in Zambia; the Minister may prescribe categories storable abroad (s. 70(2)); sensitive personal data must ALWAYS be processed and stored in Zambia with no carve-out (s. 70(3)). Non-exempt data may be transferred out only on consent PLUS Commissioner-approved standard contracts/intragroup schemes (with liability certification, s. 71(5)-(6)) or a ministerial prescription applying adequacy criteria (s. 71(2)), or on Commissioner-approved necessity; emergency transfers to health/emergency services and explicit-consent sensitive-data transfers are the s. 71(4) derogations. Earlier 'sensitive data only' localization descriptions understate the statute.
Breach notification
Section 49 ('Notification of security breach'): the controller must notify the Data Protection Commissioner within 24 hours of any security breach affecting personal data processed; a processor notifies the controller as soon as practicable (s.49(2)); the controller or processor must notify the data subject as soon as practicable (s.49(3)). An absolute 24-hour clock with no risk threshold.
Penalties
Fines (penalty units), imprisonment, and turnover-linked penalties for corporate offenders.
Authority
Office of the Data Protection Commissioner / Data Protection Commission (dataprotection.gov.zm)

Verified 2026-07-06

Access to information

Access to Information Act No. 24 of 2023 IN FORCE

The regulator

Authority
Office of the Data Protection Commissioner / Data Protection Commission
Website
https://www.dataprotection.gov.zm ↗
Established
2024
Operational
Yes
Enforcing
Yes
Publishes decisions
No

Enforcement record

Enforcement activity is documented for this jurisdiction, but the authority does not publish its decisions. The tracker records only what can be verified against a public document, so no decision pages exist here; the publication gap itself is measured in Enforcement in the Dark.

Related reading

Analysis is at lawlab.africa/analysis; method, inclusion rules and the correction policy are on the methodology page.


Track Zambia

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.