The legal framework
Protection rests on the Data Protection Act 2021, which introduced a comprehensive framework with registration of data controllers. Implementation has been progressive, with the regulator building capacity since the Act's commencement. These statutes follow the familiar pattern: lawful basis, purpose limitation, security, and rights of access, correction and objection.
Key points
| Rights | Access, correction, objection, and erasure under the more recent statutes |
|---|---|
| Registration | Data controllers must often register with the regulator |
| Breach notification | Required under most of these Acts |
| Cross-border transfers | Permitted subject to adequacy or safeguards |
| Regulator | Office of the Data Protection Commissioner |
| Sectoral rules | Telecommunications and financial regulators impose additional confidentiality duties |
| Data localisation | Certain sensitive personal data must be processed within the country |
| Data protection officer | Required for certain controllers |
| Enforcement | Through the Commissioner under the responsible ministry |
In practice
- Write to the organisation first, citing the relevant statutory right; keep proof of the date.
- Set out clearly what you want: a copy of your data, deletion, or an end to marketing.
- If there is no adequate reply within the statutory period, complain to the regulator — it is free.
- For dating, health and fertility apps, ask specifically about third-party sharing and overseas transfers.
- Ask where your data is stored: localisation requirements apply to sensitive categories.
- Complain in writing to the Commissioner with dates and copies.
Cost and coverage
Complaints to the regulator are free.
Recent changes
Digital lending applications that harvest contact lists have become the most common subject of enforcement across the region, alongside unsolicited marketing.
Where to go
- Office of the Data Protection Commissioner — complaints and guidance.
- Telecommunications regulator for mobile and SMS abuse.
- Consumer protection body for related commercial disputes.
Worth knowing
Where a foreign platform is involved, the GDPR often applies in parallel if the company operates in Europe. Complaining in both places at once is legitimate and frequently faster. Zambia's localisation requirement is unusual and affects cloud services. Organisations relying on offshore processing of sensitive data may be in breach.
Official sources and links
- UN Human Rights Office — ratified treaties and country reviews
- ILO NATLEX — national legislation database
