ZAMBIA Trends and Developments Contributed by: Mweshi Banda-Mutuna, Musenge Leah Nkonde and Lumbanya Judah Mulenga, Mweshi Banda & Associates Legal Practitioners
• the Cyber Crimes Act establishes offences such as unauthorised access, identity theft, cyber fraud, and dissemination of illegal content. This distinction underscores a dual focus of the rel- evant regulators of the cyber laws, preventing cyber- threats while enhancing accountability for cyber-relat- ed misconduct. Organisational cybersecurity obligations The Cyber Security Act introduces expectations that organisations must adopt: • preventative controls, such as firewalls, encryption, access controls and vulnerability management; • detective controls, including real-time monitoring, intrusion detection systems and regular security audits; and • responsive controls, such as defined incident- response teams, escalation pathways and disaster recovery plans. Cybersecurity therefore becomes a continuous activ- ity rather than a one-off technical installation. Com- panies must treat security as a governance function involving training, budgeting, board oversight and risk management. Consequences of cyber incidents A cyber incident is no longer confined to system fail- ure or temporary disruption. A cyber incident may now result in: • civil liability for failing to secure systems; • criminal liability under the Cyber Crimes Act; • data breach notification obligations under the Data Protection Act; and • contractual liability where third-party data or ser- vices are affected. By linking cybersecurity failures to personal data breaches and legal consequences, the law incentiv- ises organisations to implement robust digital defence systems as well as detection systems, thereby elevat- ing cybersecurity from being an IT concern to a busi- ness-wide priority. The Cyber Security Act reinforces this position by emphasising the protection of critical information infrastructure and the implementation of
measures designed to prevent and respond to cyber- threats. When read together with the Data Protec- tion Act, it becomes apparent that cybersecurity and data protection are not separate domains but closely connected aspects of the same regulatory objective, which is the protection of information, data subjects and systems. Corporate Transparency and Beneficial Ownership Moving on from changes in Zambia’s digital regula- tory framework, the Companies (Amendment) Act, No 23 of 2025 expands the requirements for disclosure of beneficial ownership of shares, explicitly requiring the disclosure of beneficial shareholders of compa- nies incorporated in Zambia. Expanded definition of beneficial ownership The expanded definition of beneficial ownership to include natural persons is intended to ensure that the ultimate natural persons on whose behalf shares are held are publicly disclosed. Prior to enactment of the Companies Act No 10 of 2017 and the amendment, this was a matter of private arrangement between the beneficial owner and the nominee shareholder. Beneficial ownership includes individuals who: • hold at least 5% of shares; • exercise effective control, directly or indirectly; • receive substantial economic benefit from the com- pany, even without formal shareholding; and • influence decision-making through agreements, nominees or other arrangements. This expanded scope captures informal and opaque ownership structures that previously remained undis- closed. From disclosure to active verification The law requires companies to maintain beneficial ownership information that is: • adequate – sufficiently detailed and descriptive of the ultimate owners; • accurate – verified using reliable documentation; and • up to date – reviewed regularly and updated upon any change.
618 CHAMBERS.COM
Powered by FlippingBook