Data Protection [No. 3 of 2021 87
# THE DATA PROTECTION ACT, 2021
# ARRANGEMENT OF SECTIONS
PART I
PRELIMINARY PROVISIONS
Section
- Short title and commencement
- Interpretation
- Application
PART II
OFFICE OF THE DATA PROTECTION COMMISSIONER
- Establishment of Office of Data Protection Commissioner
- Data protection Commissioner
- Appointment of Deputy Data Protection Commissioners and other staff
PART III
INSPECTORATE
- Inspector
- Power of inspectors
- Arrest without warrant
- Seizure of property
- Restoration of property
PART IV
PRINCIPLES AND RULES RELATING TO PROCESSING OF PERSONAL DATA
- Principles relating to processing of personal data
- Processing of personal data
- Processing of sensitive personal data
- Consent, justification and objection
- Collection of personal data
- Processing of child and vulnerable person’s personal data
- Offence and penalty for contravention of personal data obligation
Single copies of this Act may be obtained from the Government Printer, P.O. Box 30136, 10101 Lusaka, Price K80.00 each.
88 No. 3 of 2021] Data Protection
PART V
REGULATION OF DATA CONTROLLERS, DATA PROCESSORS AND DATA AUDITORS
- Prohibition from controlling or processing personal data without registration
- Application for registration as data processor or data controller
- Registration of data controller and data processor
- Renewal of certificate of registration
- Change in details of data controller or data processor
- Suspension and cancellation of registration
- Re-registration
- Surrender of certificate of registration
- Exemption from registration
- Power to forbear
PART VI
DATA AUDITORS
- Data auditors
- Application for licence
- Issue of licences
- Conditions of licence
- Variation of licence
- Surrender of licence
- Transfer of licence
- Suspension and cancellation
- Renewal of licence
- Functions of a data auditor
PART VII
EXEMPTION FROM PRINCIPLES AND RULES OF PROCESSING OF DATA
- National security, defence and public order
- Prevention, detection investigation and prosecution of contraventions of law
- Processing for purpose of legal proceedings
Data Protection [No. 3 of 2021 89
- Research, archiving or statistical purpose
- Journalistic purpose
- Processing to be lawful and legitimate
PART VIII
DUTIES OF DATA CONTROLLER AND DATA PROCESSOR
- Record of processing activities
- Data protection impact assessment
- Security of processing
- Appointment of data protection officer
- Notification of security breach
- Accountability
- Data retention
- Duties of data processor
- Non-disclosure of personal data
- Joint controllers
- Offence by data controller
- Personal data in legal proceedings
- Notification
PART IX
RIGHTS OF THE DATA SUBJECT
- Right of access and notification
- Right to rectification
- Right to erasure
- Right of objection
- Decision taken on basis of automatic data processing
- Right to restriction of processing
- Information when personal data collected directly from data subject
- Right to data portability
- Notification obligation
- Derogation from rights
- Complaints
- Appeals
90 No. 3 of 2021] Data Protection