Zambia Data Protection Act (2021)
The Zambia Data Protection Act No. 3 of 2021 establishes a comprehensive legal framework for data protection in Zambia. It creates the Office of the Data Protection Commissioner, establishes data processing principles, provides data subject rights, and regulates cross-border data transfers. Applies to processing of personal data by data controllers and processors within Zambia or processing data of persons in Zambia.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
Accountability
| Code | Title |
|---|---|
| ZM-DPA-REC.1 | Records of processing activities |
Breach Response
| Code | Title |
|---|---|
| ZM-DPA-BRC.1 | Personal data breach notification |
Consent
| Code | Title |
|---|---|
| ZM-DPA-CON.1 | Conditions for valid consent |
Cross-Border Transfer
| Code | Title |
|---|---|
| ZM-DPA-CBT.1 | Cross-border transfer of personal data |
Data Controller Obligations
Security, registration, and compliance obligations
| Code | Title |
|---|---|
| ZMDPA-OB-01 | Registration with Commissioner |
| ZMDPA-OB-02 | Security Safeguards |
| ZMDPA-OB-03 | Data Protection Impact Assessment |
| ZMDPA-OB-04 | Cross-Border Transfer Restrictions |
| ZMDPA-OB-05 | Breach Notification |
Data Subject Rights
| Code | Title |
|---|---|
| ZM-DPA-RTS.1 | Data subject right to information and access |
| ZM-DPA-RTS.2 | Right to rectification, erasure, and restriction |
| ZM-DPA-RTS.3 | Right to data portability |
| ZM-DPA-RTS.4 | Right to object and rights related to automated decision-making |
Enforcement
| Code | Title |
|---|---|
| ZM-DPA-ENF.1 | Sanctions and offences under the Act |
Enforcement and Penalties
CRTC enforcement, private right of action, and penalties
| Code | Title |
|---|---|
| BSA-ENF-1 | Anti-Structuring Prohibition |
| BSA-ENF-2 | Civil Money Penalties |
| BSA-ENF-3 | Criminal Penalties |
| CASL-ENF-01 | Administrative Monetary Penalties |
| CASL-ENF-02 | Compliance and Due Diligence |
| CASL-ENF-03 | Address Harvesting |
| ENF-1 | EPA Inspection Authority |
| ENF-2 | Civil Penalties |
| ENF-3 | Enforcement Actions |
| ENF-4 | Technical Assistance |
| RA10175-S10 | Law Enforcement Authority |
| RA10175-S21 | Jurisdiction |
| RA10175-S8 | Penalties |
| RIDTPPA-10 | Controller and Processor Contracts |
| RIDTPPA-11 | Data Minimisation and Purpose Limitation |
| RIDTPPA-9 | AG Enforcement |
| UKTSA-ENF-01 | Ofcom Information Powers |
| UKTSA-ENF-02 | Ofcom Inspection Powers |
| UKTSA-ENF-03 | Enforcement Notices |
| UKTSA-ENF-04 | Financial Penalties |
| UKTSA-ENF-05 | Security Breach Notification |
| ZMDPA-ENF-01 | Data Protection Commissioner Powers |
| ZMDPA-ENF-02 | Penalties for Non-Compliance |
| s.11 | Consent, Justification and Objection |
| s.5 | Notice to Data Principal |
| s.7 | Certain Legitimate Uses |
| s.8 | Accountability |
Governance
| Code | Title |
|---|---|
| ZM-DPA-DPO.1 | Appointment of a Data Protection Officer |
Lawfulness
| Code | Title |
|---|---|
| ZM-DPA-LAW.1 | Lawful basis for processing |
Localisation
| Code | Title |
|---|---|
| ZM-DPA-LOC.1 | Data localisation requirements for sensitive and critical data |
Marketing
| Code | Title |
|---|---|
| ZM-DPA-MKT.1 | Direct marketing and electronic communications |
Minors
| Code | Title |
|---|---|
| ZM-DPA-CHI.1 | Processing of children's personal data |
Principles
| Code | Title |
|---|---|
| ZM-DPA-PRI.1 | Principles of personal data processing |
Processor Obligations
| Code | Title |
|---|---|
| ZM-DPA-PRO.1 | Data processor contractual obligations |
Registration
| Code | Title |
|---|---|
| ZM-DPA-REG.1 | Registration of data controllers and data processors |
Regulator Engagement
| Code | Title |
|---|---|
| ZM-DPA-COM.1 | Cooperation with the Information Protection Commissioner |
Risk Assessment
| Code | Title |
|---|---|
| ZM-DPA-DPI.1 | Data Protection Impact Assessment for high-risk processing |
Security
| Code | Title |
|---|---|
| ZM-DPA-SEC.1 | Security of processing |
Sensitive Data
| Code | Title |
|---|---|
| ZM-DPA-SEN.1 | Processing of sensitive personal data |
Your Compliance Coverage
If you comply with Zambia Data Protection Act (2021), you already cover:
FTC GLBA Safeguards Rule (16 CFR Part 314)
19%
10 controls mapped
Compare →Nevada Gaming Control Board Cybersecurity Requirements
19%
10 controls mapped
Compare →Lloyd's Minimum Standards — Cyber Security
19%
10 controls mapped
Compare →+ 531 more: FTC Safeguards Rule (16 CFR Part 314) (19%), Trinidad and Tobago Data Protection Act 2011 (17%)
See all 534 mapped frameworks ↓Maps to 534 other frameworks
Frequently Asked Questions
What is Zambia Data Protection Act (2021)?
Zambia Data Protection Act (2021) is a compliance framework from Zambia with 20 domains and 53 controls. The Zambia Data Protection Act No. 3 of 2021 establishes a comprehensive legal framework for data protection in Zambia. It creates the Office of the Data Protection Commissioner, establishes data processing principles, provides data subject rights, and regulates cross-border data transfers. Applies to processing of personal data by data controllers and processors within Zambia or processing data of persons in Zambia. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Zambia Data Protection Act (2021) have?
Zambia Data Protection Act (2021) has 53 controls organised across 20 domains. The largest domains are Enforcement and Penalties (27 controls), Data Controller Obligations (5 controls), Data Subject Rights (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Zambia Data Protection Act (2021) map to?
Zambia Data Protection Act (2021) maps to 534 other compliance frameworks. The top mapping partners are FTC GLBA Safeguards Rule (16 CFR Part 314) (19% coverage), Nevada Gaming Control Board Cybersecurity Requirements (19% coverage), Lloyd's Minimum Standards — Cyber Security (19% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Zambia Data Protection Act (2021) compliance?
Start your Zambia Data Protection Act (2021) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Zambia Data Protection Act (2021) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 53 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required