0% found this document useful (0 votes)
10 views13 pages

Zambia Data Protection Act 2021 Guide

Uploaded by

henrhon1
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views13 pages

Zambia Data Protection Act 2021 Guide

Uploaded by

henrhon1
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Republic of Zambia

OFFICEOFTHEDATAPROTECTIONCOMMISSIONER

Zambia Data Protection


Act 2021
Quick Guide

PROMOTINGDATAPRIVACYAND
INCREASINGNATIONALDATAVALUE

August 2024
ii.
CONTENTS

Page
1. OVERVIEW 1

2. ADVANTAGES OF THE ZAMBIA PROJECTION ACT 2021 1

3. DATA PROTECTION ACT KEY PROVISIONS 1

4. DATA PROTECTION ACT 2

5. DATA PRIVACY AND SECURITY 2

6. PROCESSION OF PERSONAL DATA 2

7. WHO IS MOSTLY AFFECTED BY THE PROTECTION ACT 2

8. REGISTRATION OF DATA CONTROLLER, PROCESSORS 3

9. SENSITIZATION 3

10. PRINCIPLES OF DATA PROTECTION 3

11. DATA SUBJECT RIGHTS 5

12. TRANSFERS OUTSIDE ZAMBIA 5

13. DATA AUDITS 6

14. DATA BREACHES 6

15. DATA PROTECTION OFFICES 7

16. DATA RETENTION 7

17. DATA PROTECTION ACT OFFENCES AND PENALTIES 8

18. PARATUS 9

iii.
OVERVIEW porate or unincorporate body, with their knowledge, consent or connivance.

An Act to provide an effective system for the use and protection of personal data; SECTION 48: APPOINTMENT OF A DATA PROTECTION OFFICER:
regulate the collection, use, transmission, storage and otherwise processing of Depending on the intensity of personal data processing activities, organizations
personal data; establish the Office of the Data Protection Commissioner and are required to appoint a Data Protection Officer in accordance with the
provide for its functions; the registration of data controllers and licencing of data guidelines issued by the Data Protection Commissioner.
auditors; provide for the duties of data controllers and data processors; provide
SECTION 53: NONDISCLOSURE OF PERSONAL DATA
for the rights of data subjects; and provide for matters connected with, A data controller shall not disclose or share personal data collected unless it is
or incidental to, the foregoing. necessary to prevent:
· A threat to national security, defense or public order
· For an investigation

ADVANTAGES OF THE ZAMBIA DATA PROTECTION ACT 2021 PART IX : DATA SUBJECT RIGHTS
As a data subject has the right to:
· Obtain from the Data Controller or data Processor the reason why
The Zambia Data Protection Act 2021 comes with good deeds for the Zambian their data is collected.
republic and promotes good virtues in line with the global data protection · Know how long that data will be processed or stored.
standards such as the General Data Protection Act (GDPR) and other African · Be informed that their personal data has been disclosed to a third
countries and these are; party.
· Transfer their data from one data controller to another
· Object to processing of their data
Increased Transparency And Accountability For Data Controllers And · To lodge a complaint with the Data Protection Commissioner if they
Processors: The Act requires data controllers and processors to be transparent feel their rights have been infringed.
about their data processing activities and to be accountable for their compliance
with the Act. SECTION 70: STORAGE OF DATA OUTSIDE THE REPUBLIC
The Data Controller is required to store data on a Server or data centre in the
Enhanced Data Protection And Privacy For Individuals: The Act provides a Country. In exceptional cases, the Data Controller may store data outside for
number of safeguards for individuals' personal data, including the right to
justifiable reasons and if approved by the Data Protection Commissioner.
access, rectify, erase, restrict processing, data portability, and object to
processing.
SECTION 71: TRANSFER OF DATA TO LOCATIONS OUTSIDE THE
Enhanced Data Security And Reduced Cyber-attacks: the Act emphasizes REPUBLIC
on improving security measures where the data is stored there by reducing The Data Controller can not transfer outside the Country. In exceptional cases,
cyber-attacks and increasing systems up time. the Data Controller may transfer data outside for justifiable reasons and if
approved by the Data Protection Commissioner.
Support For Innovation And Economic Growth: The Act provides a clear and
predictable regulatory framework for data processing, which can help to SECTION 72: RIGHT TO COMPESATION
promote innovation and economic growth. The data subject has the right to be compensated if their rights are infringed
upon.
Support For Increased Jobs: the Act promotes data localization thereby
increasing the value of our data, increasing information technology directly and
indirectly. SECTION 76: DIRECTOR, MANAGER, SHAREHOLDER
The Act allows for prosecution of a Director, manager or shareholder if an
Protection Of Vulnerable Persons: The Act places specific restrictions on the offence under this Act is committed by a body cor
processing of personal data of vulnerable persons, such as children and people
with disabilities.

DATA PROTECTION ACT KEY PROVISIONS


SECTION 4 ESTABLISHMENT OF OFFICE OF THE DATA COMMISSIONER
The office of the data Protection Commissioner is charged with responsibility to
regulate and enforce the Data Protection Act fairly and transparently.

SECTION 12: PRINCIPLES RELATING TO PROCESSING OF DATA


Data Controllers and Processors are expected to ensure that the data is
processed fairly and transparently, processing the data in accordance with
principles stipulated without infringing on the rights of the data subject.

SECTION 14: PROCESSING OF SENSITIVE DATA


Sensitive data will only be processed for legal reasons or public interest and
where adequate measures to safeguard the rights and freedoms of the data
subject have been put in place.

SECTION 15: DATA CAN ONLY BE PROCEESED WITH CONSENT


Personal data shall only be processed if the data subject consents. The data
subject has the right to object to processing their data.

SECTION 17: PROCESSING OF CHILD AND VULNERABLE


PERSON'S PERSONAL DATA
Processing of a child's or vulnerable person can only be done if the guardian or
Parent has consent and it is the responsibility of the Data Controller to verify the
Consent.

SECTION 18: PROHIBITION OF PROCESSING OF DATA


A Data Controller or Processor cannot process personal data unless they are
registered with the Commission or exempted by the Data Protection
Commissioner.

SECTION 19: MANDATORY REGISTRATION OF DATA


CONTROLLERS
A person shall not control or process personal data without registering as a data
controller or a data processor under this Act.

SECTION 29: AUDITORS


Only licensed Auditors by the Commission shall provide Auditors' services and
the license is not transferrable.

Page 1
Page 2
Page 3
Page 4
Page 5
Page 6
12. DATA PROTECTION OFFICERS

Institutions will be required to have Data Protection Officers in-house or


subcontract the services of a Data protection officer to be handled by a firm or
company with Data Protection expertise and knowledge.
The Data Protection Officer (DPO) plays a crucial role in developing, monitoring
and managing data protection compliance in an organization. The DPO will be
required to have knowledge and expertise in data protection law.

Role of The Data Protection Officer


Their responsibilities encompass both proactive and reactive measures to
ensure compliance with data protection laws and to mitigate the impact of
breaches on individuals and the organization.

Effective Incident Response:


In the event of a data breach, a DPO's presence is indispensable. They lead
incident response efforts, ensure timely reporting to the Data Protection
Commissioner, and guide the organization through the necessary steps to
mitigate the impact of the breach.

Reporting to Regulatory Authorities:


DPOs play a pivotal role in liaising with Data Protection
[Link] are responsible for notifying the appropriate bodies,
complying with reporting timelines, and guiding the organization through
the incident response process. This ensures transparency and adherence
to regulatory requirements.

Data Security Threats:


DPOs play a critical role in mitigating these risks. This involves staying
vigilant, implementing robust security measures, and collaborating with IT,
legal, public relations, and other relevant teams to fortify the organization's
defenses.

Training and Awareness:


DPOs will conduct regular training sessions for employees on data
protection best practices and how to comply with data protection laws , to
recognize and report potential data breaches and promote awareness
about data protection within the organization.

Developing Privacy Governance


DPO will ensure development, implementation and monitoring of a privacy
governance framework of the organization so as to ensure that the
organization is in compliance with data protection rules. They will also
develop and ensure that the business has the appropriate policies and
procedures in place.

13. DATA RETENTION

Data retention refers to the policies and practices that organizations implement
to manage how long they keep personal data.
Data retention is a crucial aspect of data protection, ensuring that personal data
is kept only as long as necessary for legitimate purposes. Organizations must
develop and enforce data retention policies that comply with legal requirements,
balance business needs, and protect individuals' privacy. By doing so, they
minimize the risks associated with data breaches, non-compliance, and over-
retention of personal data.
The Data Protection Act requires that data be retained for a minimum of one (1)
year beyond the need for processing. However, depending on the industry, other
laws may impose specific retention requirements. For example, banking
regulations may require the retention of personal data records for a longer
period.

Page 7
DATA PROTECTION ACT OFFENCES AND PENALTIES
OFFENCES SANCTIONS/PENALTIES
Sec on 18 : Abroga ng the Principles of Data Maximum fine of ZMW 40,000,000 (100 million penalty units) OR 2% of
Processing by corporate bodies the previous fiscal year's annual turnover, whichever is greater.

Sec on 18 : Abroga ng the Principles of Data Maximum fine of ZMW 400,000 (one million penalty units ) OR up to
Processing by data controller or processor five years imprisonment, or both.
Sec on 19: Failure to register as a data Maximum fine of ZMW 200,000 (five hundred thousand penalty units)
controller or data processor or up to five years imprisonment, or both.
Sec on 24: Failure to follow condi ons of Maximum fine of ZMW 400,000 (one million penalty units) or five years
Suspension or cancella on of registra on imprisonment.
Sec on 26: failure to follow terms of Maximum fine of ZMW 400,000 (one million penalty units) or ten years
surrender of cer ficate imprisonment.
Sec on 53: Unlawful disclosure of Personal Maximum fine of ZMW 80,000 (two hundred thousand penalty units),
Data up to two years imprisonment, or both.

Sec on 55: Failure to comply as data Maximum fine of ZMW 800,000 (two million penalty units) or two
controller or processor by corporate body percent of the previous fiscal year's annual revenue, whichever is
greater.

Sec on 55: Failure to comply as data Maximum fine of ZMW 400,000 (one million penalty units) or up to ten
controller or processor by natural person years imprisonment, or both
Sec on 73: Unlawful disclosure of Sensi ve Maximum fine of ZMW 80,000 (two hundred thousand penalty units) or
Personal Data to up to two years imprisonment, or both.
Sec on 75: Any of the offences under the The court may:
Data Protec on Act i. pronounce the forfeiture of the medium containing the
personal data to which the offence relates
ii. order forfeiture or dele on where the medium containing the
personal data does not belong to the person convicted.
iii. on convic on prohibit Data controllers/ Processors from
controlling/ processing of personal data.
Sec on 76: Consent or Knowledge of The director, manager, shareholder or partner of a body corporate or
Director, Manager, Shareholder/partner of unincorporate body are liable on convic on to a penalty as provided in
body corporate or unincorporate body the Act for an offence commi ed with their knowledge, consent or
willingness.

Sec on 77: General penal es against a Where the specified fine is not granted,
person who commits an offense under the Maximum fine of ZMW120,000 (three hundred thousand penalty units)
Data Protec on Act or up to three years imprisonment, or both.
Sec on 78: Contravening the Code of Maximum fine of ZMW 80,000 (two hundred thousand penalty units) or
Conduct up to two years imprisonment, or both.
Sec on 79: Contravening the Guidelines Maximum fine of ZMW 80,000 (two hundred thousand penalty units) or
up to two years imprisonment, or both.

Page 8
Page 9

You might also like