ZAMBIA Trends and Developments Contributed by: Mweshi Banda-Mutuna, Musenge Leah Nkonde and Lumbanya Judah Mulenga, Mweshi Banda & Associates Legal Practitioners
data governance into the centre of organisational activity. Operational requirements and internal governance The Act requires businesses to adopt internal meas- ures that demonstrate active protection of personal data. These include: • comprehensive data inventories documenting what data is collected, how it is used, where it is stored and who has access; • lawful basis assessments for each processing activity; • retention schedules aligned with statutory and business requirements; • privacy policies and data protection manuals that reflect actual practice rather than aspirational intentions; and • appointment of Data Protection Officers (DPOs) in cases where organisations process large volumes of personal data or special categories of data. Failure to implement these measures is no longer sim- ply a procedural lapse; it may result in significantly high administrative penalties (100 million penalty units, which is currently equal to ZMW40 million, or in some instances 2% of the businesses annual turnover), civil liability or criminal sanctions against the business and or its data processor/controller. Cross-border data transfer controls One of the most impactful aspects of the Act is its regulation of cross-border data flows. In an era where businesses rely heavily on cloud computing, multina- tional software platforms, remote work arrangements and e-commerce, data frequently leaves Zambia’s borders. The Act places the burden on businesses to: • obtain the consent of the data subject; • assess whether destination countries provide adequate data protection standards; • implement binding contractual safeguards, such as data transfer agreements; • verify the security standards of cloud service pro- viders; and
• maintain audit trails for data shared with external entities. This means businesses must ensure that their IT pro- curement teams collaborate with compliance officers to evaluate vendors and businesses with whom they share data. This evaluation is not based solely on technical capabilities, but on their regulatory posture because of the legal implications flowing from a failure Data protection and cybersecurity are now intercon- nected. A failure in cybersecurity may trigger a data breach under the Act, requiring notification to the Data Protection Commissioner and affected individuals. As a result, the Act pushes businesses to adopt robust incident-response frameworks, including: • breach detection and reporting systems; • forensic investigation procedures; • evidence preservation practices; and • communication plans for regulators and data sub- jects. to adhere to the Act and regulations. Data security and incident response In short, Zambia’s data protection regime requires companies to not merely claim but also prove that personal information is being processed responsibly. Cybersecurity Zambia’s approach to cybersecurity has undergone a notable recalibration with the enactment of the Cyber Security Act, No 3 of 2025 and the Cyber Crimes Act, No 4 of 2025. These statutes replace the earlier unified regulatory framework and introduce a clear distinction between cybersecurity governance and cyber-related crime. Distinguishing cybersecurity governance from cybercrime enforcement A notable development is the separation of cyberse- curity management from criminal enforcement: • the Cyber Security Act focuses on organisational responsibilities, security standards, information- sharing and national cybersecurity co-ordination; and
617 CHAMBERS.COM
Powered by FlippingBook