Data Protection in Zambia

Collection and processing in Zambia

In order to collect or process personal data consent of the data subject must be obtained. A data subject may consent to such processing in writing. Prior to giving such consent, the data subject must be informed of the data subject’s right to withdraw the consent. Furthermore except as expressly provided in the DPA, a data controller is required to collect personal data directly from the data subject. The DPA provides additional rules in respect of collection and processing of personal data as set out below. 

A data controller or data processor shall ensure that personal data is:

  • processed lawfully, fairly and transparently;
  • collected for explicit, specified and legitimate purposes and not further processed in a manner incompatible with those purposes;
  • adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed;
  • accurate and where necessary, kept up to date, with every reasonable step taken to ensure that any inaccurate personal data is erased or rectified without delay;
  • stored in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed;
  • processed in accordance with the rights of a data subject; and
  • processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against any loss, destruction or damage, using appropriate technical or organisational measures. 

Subject to the other provisions of the DPA, a data controller may process personal data where:

  • the data subject has given consent to the processing of that data subject’s personal data;
  • the processing is necessary
    • for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
    • for compliance with a legal obligation to which the data controller is subject;
    • in order to protect the vital interests of the data subject or of another natural person;
    • for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
    • for the purposes of the legitimate interests pursued by the data controller or by a third party, except where such interests are overridden by the interest or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child; or
  • the processing relates to personal data which is manifestly made public by the data subject. 

A person shall not process sensitive personal data, unless:

  • processing is necessary for the establishment, exercise or defence of a legal claim or whenever a court is exercising a judicial function;
  • processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services; or
  • processing is necessary for reasons of public interest. 

Where a data subject is a child or a vulnerable person, that data subject’s right may be exercised by that data subject’s parents, legal guardian or a person exercising parental responsibility as the case may be. A data controller shall not process a child’s or vulnerable person’s personal data unless consent is given by the child’s or vulnerable person’s parent, legal guardian or a person exercising parental responsibility. A data controller shall, where the personal data of a child or a vulnerable person is involved, make every reasonable effort to verify that consent has been given or authorised, taking into account available technology. A data controller shall incorporate appropriate mechanisms for age verification and parental consent in the processing of personal data of a child.

Continue reading

  • no results

Previous topic
Back to top