Data Protection Act, 2021, transfer of personal data outside the Republic
Data Protection Act, 2021, ss. 70-71 (transfer of personal data outside the Republic)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 April 2021.
A cross border transfer rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Store and process personal data on a server or data centre located in Zambia unless the Minister has prescribed an exception, and do not store sensitive personal data outside Zambia without the data subject's explicit consent.
- Where you transfer personal data abroad under a standard contract or intra-group scheme the Commissioner approved, certify and periodically report to the Commissioner that the transfer is made under it, and carry the liability for harm caused by the transferee's non-compliance.
- Rely on the emergency route only for a person or entity providing health or emergency services, and on the country-or-organisation route only where the Commissioner is satisfied the transfer does not hamper enforcement of the Act.
What it reaches
Obligation class
Transfer, Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 70(1) requires a data controller to process and store personal data on a server or data centre located in the Republic. Section 70(2) lets the Minister prescribe categories of personal data that may be stored outside it. Section 70(3) keeps sensitive personal data on a server or data centre in the Republic despite that power.
Section 71(1) lets personal data outside those prescribed categories be transferred abroad where the data subject has consented and either the transfer is made under standard contracts or intra-group schemes the Commissioner has approved or the Minister has prescribed that transfers out are permissible, or where the Commissioner approves a particular transfer or set of transfers as permissible out of necessity.
Section 71(2) lets the Minister prescribe the criteria for those transfers only where the personal data will be subject to an adequate level of protection and enforcement by authorities with appropriate jurisdiction is effective, and section 71(3) has the Commissioner monitor the circumstances of data so transferred.
Section 71(4) permits transfer in an emergency to a person providing health or emergency services, where the data subject has explicitly consented to the transfer of sensitive personal data, and to an international organisation or country the Commissioner is satisfied about.
Section 71(6) requires a controller transferring under a standard contract or intra-group scheme to certify and periodically report to the Commissioner that it does so, and to bear liability for harm caused by the transferee's non-compliance. Section 1 leaves commencement to a statutory instrument appointed by the Minister. The Data Protection Act (Commencement) Order, 2021 brought the Act into operation on 1 April 2021, which is the day these provisions began to bind.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Official Act text as published by the National Assembly of Zambia (Parliament of Zambia)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.