🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
ZM v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing6 sources retrieved model claude-sonnet-5 · 2026-08-06

Zambia

ZM schema gdpri-v2 trajectory: not yet assessedin transitionoverlaps: AIC

Last updated · 10 categories · 10 claims · 18 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
10Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 29 September 2026

Lead Signal

Zambia's data protection and cyber-law architecture moved on two fronts this cycle. The Office of the Data Protection Commissioner is understood to be fully operational and actively enforcing privacy and data protection compliance, following the 2023 appointment of Zambia's first Data Protection Commissioner. Separately, Zambia enacted a split of its combined 2021 cyber statute into two distinct instruments: the Cyber Security Act, 2025 (Act No. 3 of 2025), which repeals and replaces the Cyber Security and Cyber Crimes Act, 2021 and establishes the Zambia Cyber Security Agency, and the Cyber Crimes Act, 2025 (Act No. 4 of 2025), which separately establishes cybercrime offences and online child-protection provisions.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Statute is enacted and a registration regime is operative, but the dedicated Authority's independent operational status is unverified and flagged by the seed as pending.

Primary frameworkData Protection Act, 2021 (Act No. 3 of 2021)
Traffic-light rationale — AmberStatute is enacted and a registration regime is operative, but the dedicated Authority's independent operational status is unverified and flagged by the seed as pending.

Sub-modules (5)

Regulator And AuthorityAmber

The Act contemplates a dedicated Authority/Commissioner; ZICTA holds interim/adjacent oversight competence pending full independent operationalisation.

Claims (1):

  • The dedicated Data Protection Authority contemplated by Zambia's Data Protection Act, 2021 has not been confirmed as fully, independently operationalised as of this run's dispatch date; ZICTA holds interim/adjacent data-protection oversight competence in the meantime.

Act And InstrumentsGreen

Core instrument is the Data Protection Act, 2021 (Act No. 3 of 2021), supplemented by the Data Protection (Registration and Licensing) Regulations, 2021 (SI No. 58 of 2021) issued under section 82 of the Act.

Claims (2):

  • The Data Protection Bill, 2020, enacted as the Data Protection Act, 2021, provides for the regulation of the collection and processing of personal data, the establishment of the Office of the Data Protection Commissioner, the registration of data controllers, and the rights of data subjects.
  • The Data Protection (Registration and Licensing) Regulations, 2021 (Statutory Instrument No. 58 of 2021) were issued on 14 May 2021 by the Minister of Transport and Communications under section 82 of the Data Protection Act No. 3 of 2021.

Material ScopeRed

No T1/T2 primary text on the Act's material-scope definitions (personal data, processing, controller/processor definitions) was retrievable via allowlisted hostnames in this run. Searches conducted: 'Data Protection Act 2021 Zambia full text sections'; 'sensitive personal data consent lawful basis Zambia'. Gap recorded rather than inferred.

Territorial ScopeRed

No accessible primary or secondary source confirmed the Act's extraterritorial/establishment-based application test. Gap recorded; searches as above yielded no citable material.

Regulator Registration And FilingGreen

The Registration and Licensing Regulations, 2021 require controllers/processors to obtain a certificate of registration from the Data Protection Commissioner, and require data auditors to be licensed.

Claims (2):

  • Under Section 4 of the Data Protection (Registration and Licensing) Regulations, 2021, data controllers or data processors shall apply to the Data Protection Commissioner for a certificate of registration.
  • Section 3(1) of the Data Protection (Registration and Licensing) Regulations, 2021 stipulates that the Data Protection Commissioner shall register a data controller or a data processor only in specified categories set out in the Regulations.
Category narrative131 words

Zambia's principal data-protection instrument is the Data Protection Act, 2021 (Act No. 3 of 2021), which succeeded the Data Protection Bill, 2020 submitted to the National Assembly in December 2020. The Act establishes an Office of the Data Protection Commissioner and a registration regime for controllers/processors, implemented via the Data Protection (Registration and Licensing) Regulations, 2021 (SI No. 58 of 2021). Per the injected seed, the dedicated independent Data Protection Authority contemplated by the Act has not been fully operationalised; ZICTA holds interim/adjacent competence. Searches conducted: 'ZICTA Authority operationalisation 2026', 'Data Protection Commissioner appointed 2024/2025', 'Data Protection Act 2021 full text sections' — no T1 primary statute text or official gazette confirming full institutional stand-up was retrievable via the allowlisted hostnames; only secondary (T3) reporting and the ZICTA homepage were reachable.

Periodic update · new data 2026-09-29

Regulator & Framework

Zambia's data-protection and cyber-law regulatory architecture has developed materially this cycle. The Office of the Data Protection Commissioner is understood to be fully operational, actively enforcing privacy and data protection compliance in Zambia, following the June 2023 appointment of Zambia's first Data Protection Commissioner. This operationalisation is corroborated by secondary law-firm commentary, though it has not been independently confirmed against a primary ODPC publication this cycle.

Separately, Zambia has enacted a structural split of its combined 2021 cyber statute. The Cyber Security Act, 2025 (Act No. 3 of 2025) repeals and replaces the Cyber Security and Cyber Crimes Act, 2021, and establishes the Zambia Cyber Security Agency, separating regulatory cyber-security functions from criminal-law cybercrime functions. The companion Cyber Crimes Act, 2025 (Act No. 4 of 2025) establishes cybercrime offences and online child-protection provisions that previously sat within the single combined 2021 Act. Both Acts are enacted but not yet effective: their commencement date is to be appointed by the Minister by statutory instrument, and that instrument had not been located as of this cycle.

The practical effect is a bifurcated statutory architecture in which the regulatory (Cyber Security Act) and criminal (Cyber Crimes Act) functions now sit on separate instruments, both awaiting ministerial commencement, alongside an already-operational Data Protection Commissioner enforcing under the existing Data Protection Act, 2021.

Outlook

The ministerial statutory instrument appointing commencement dates for the Cyber Security Act, 2025 and the Cyber Crimes Act, 2025 is the key dated event to watch, expected in an estimated Q1 2027 window carrying a wide multi-year uncertainty band. Until that instrument is published, both Acts remain enacted but not yet effective.

Sources and claims (5)
  1. UncertainZICTA — The dedicated Data Protection Authority contemplated by Zambia's Data Protection Act, 2021 has not been confirmed as fully, independently operationalised as of this run's dispatch date; ZICTA holds interim/adjacent data-protection oversight competence in the meantime.observed
  2. ProbableOneTrust DataGuidance — The Data Protection Bill, 2020, enacted as the Data Protection Act, 2021, provides for the regulation of the collection and processing of personal data, the establishment of the Office of the Data Protection Commissioner, the registration of data controllers, and the rights of data subjects.observed
  3. ConfirmedOneTrust DataGuidance — The Data Protection (Registration and Licensing) Regulations, 2021 (Statutory Instrument No. 58 of 2021) were issued on 14 May 2021 by the Minister of Transport and Communications under section 82 of the Data Protection Act No. 3 of 2021.observed
  4. ConfirmedOneTrust DataGuidance — Under Section 4 of the Data Protection (Registration and Licensing) Regulations, 2021, data controllers or data processors shall apply to the Data Protection Commissioner for a certificate of registration.observed
  5. ConfirmedOneTrust DataGuidance — Section 3(1) of the Data Protection (Registration and Licensing) Regulations, 2021 stipulates that the Data Protection Commissioner shall register a data controller or a data processor only in specified categories set out in the Regulations.observed

#

Only a general, high-level statutory purpose statement is evidenced; granular lawful-basis/consent/special-category text is unverified.

Primary frameworkData Protection Act, 2021 (Act No. 3 of 2021)
Traffic-light rationale — RedOnly a general, high-level statutory purpose statement is evidenced; granular lawful-basis/consent/special-category text is unverified.

Sub-modules (4)

Lawful BasesAmber

The Act generally regulates collection and processing of personal data; a specific enumerated list of lawful bases analogous to GDPR Art 6 was not confirmed against accessible primary text.

Claims (1):

  • The Data Protection Act, 2021 (as enacted from the Data Protection Bill, 2020) provides for the regulation of the collection and processing of personal data of data subjects in Zambia.

Special CategoriesRed

No accessible source confirmed Zambia's special/sensitive category definitions or processing conditions. Gap recorded.

Pseudonymisation And AnonymisationRed

No accessible source confirmed pseudonymisation/anonymisation definitions or safe-harbours under the Act. Gap recorded.

Category narrative64 words

Beyond the general statement that the Act regulates 'the collection and processing of personal data,' no T1/T2 primary text enumerating lawful bases, consent standards, special-category rules, or pseudonymisation/anonymisation safe-harbours was retrievable via allowlisted hostnames. Searches conducted: 'Data Protection Act 2021 sensitive personal data consent lawful basis'; 'Zambia Data Protection Act full text sections'. This is recorded as an explicit gap, not a silent omission.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableOneTrust DataGuidance — The Data Protection Act, 2021 (as enacted from the Data Protection Bill, 2020) provides for the regulation of the collection and processing of personal data of data subjects in Zambia.observed

#

Existence of a data-subject-rights framework is evidenced at a general level; procedural specifics (deadlines, portability mechanics) remain unverified gaps.

Primary frameworkData Protection Act, 2021 (Act No. 3 of 2021)
Traffic-light rationale — AmberExistence of a data-subject-rights framework is evidenced at a general level; procedural specifics (deadlines, portability mechanics) remain unverified gaps.

Sub-modules (5)

Access RightAmber

General right of data subjects is provided for in the Act; specific access-request procedure not confirmed against primary text.

Claims (1):

  • The Data Protection Act, 2021 provides for rights of data subjects in relation to personal data held by data controllers operating in Zambia.

Rectification And ErasureRed

Not independently confirmed against accessible primary text in this run; gap recorded.

Restriction And ObjectionRed

Not independently confirmed against accessible primary text in this run; gap recorded.

Data PortabilityRed

Not independently confirmed against accessible primary text in this run; gap recorded.

Deadlines And Response WindowsRed

No statutory response-window figure was retrievable via allowlisted hostnames in this run; gap recorded.

Category narrative56 words

The enacted Act is reported to cover 'the rights of data subjects,' but the specific mechanics of access, rectification/erasure, restriction/objection, portability, and statutory response deadlines were not retrievable in accessible T1/T2 text during this run. Searches conducted: 'Zambia Data Protection Act breach notification data subject rights DPO summary'; 'Data Protection Act 2021 Zambia full text sections'.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableOneTrust DataGuidance — The Data Protection Act, 2021 provides for rights of data subjects in relation to personal data held by data controllers operating in Zambia.observed

#

One concrete accountability-adjacent duty (data-auditor licensing) is confirmed; the remaining six sub-modules are unverified gaps.

Primary frameworkData Protection Act, 2021 (Act No. 3 of 2021); Data Protection (Registration and Licensing) Regulations, 2021 (SI No. 58 of 2021)
Traffic-light rationale — AmberOne concrete accountability-adjacent duty (data-auditor licensing) is confirmed; the remaining six sub-modules are unverified gaps.

Sub-modules (7)

Accountability And DpiaAmber

Data-auditor licensing under s.14(1) of SI 58/2021 is the only accountability-adjacent duty confirmed; a distinct DPIA trigger regime was not confirmed against primary text.

Claims (1):

  • Under Section 14(1) of the Data Protection (Registration and Licensing) Regulations, 2021, a person who intends to provide data audit services in Zambia must apply to the Data Protection Commissioner for a licence.

Dpo RequirementsRed

No DPO appointment threshold or independence requirement was retrievable via allowlisted hostnames; gap recorded.

Ropa RequirementsRed

No ROPA obligation was retrievable via allowlisted hostnames; gap recorded.

Joint Controller ArrangementsRed

No joint-controller provision was retrievable via allowlisted hostnames; gap recorded.

Security MeasuresRed

No technical/organisational security-measures detail was retrievable via allowlisted hostnames; gap recorded.

Breach NotificationRed

No breach-notification threshold, timeline, or dual regulator/subject-notice requirement was retrievable via allowlisted hostnames despite targeted search; gap recorded.

Retention And DisposalRed

No retention-limit or disposal-duty provision was retrievable via allowlisted hostnames; gap recorded.

Category narrative63 words

The clearest verified controller/processor duty is the data-auditor licensing requirement under the Registration and Licensing Regulations, 2021. Accountability/DPIA triggers, DPO appointment thresholds, ROPA requirements, joint-controller rules, security-measures detail, breach-notification timelines, and retention/disposal duties were not retrievable in accessible T1/T2 text in this run. Searches conducted: 'Zambia Data Protection Act 2021 breach notification data subject rights DPO summary'; 'Section 65 breach notification 72 hours'.

Periodic update · new data 2026-09-29

Controller/Processor Duties

The Office of the Data Protection Commissioner is understood to have launched an online registration portal for data controllers and data processors, making registration mandatory for entities handling personal data in Zambia. This is reported as a new compliance mechanism introduced alongside the Commissioner's broader operationalisation, rather than as a change to the underlying substantive obligations set out in the Data Protection Act, 2021 itself.

The registration requirement's practical scope, including whether exemptions exist for small-scale or non-commercial processors, was not established by the evidence available this cycle. What is reported is that registration through the portal is mandatory rather than voluntary, positioning it as a gateway compliance step that controllers and processors operating in Zambia must complete as a precondition of, or alongside, their ongoing data-handling activity.

This development should be read as tightening the practical enforcement of existing controller and processor obligations rather than introducing new substantive duties: the registration portal is an administrative mechanism through which the Commissioner can identify and track the population of controllers and processors subject to the Data Protection Act, 2021, which in turn supports the enforcement and compliance-campaign activity reported separately.

Outlook

The ODPC's promised implementing regulations and guidelines specifying the registration portal's procedural detail were referenced in secondary commentary but not independently located or cited by instrument number this cycle. Watch for publication of those implementing regulations as the event that would clarify the registration requirement's full practical scope.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidance — Under Section 14(1) of the Data Protection (Registration and Licensing) Regulations, 2021, a person who intends to provide data audit services in Zambia must apply to the Data Protection Commissioner for a licence.observed

#

No claims meet the evidentiary bar for this module in this run.

Primary frameworkData Protection Act, 2021 (Act No. 3 of 2021) — cross-border provisions not verified against primary text in this run
Traffic-light rationale — Not assessedNo claims meet the evidentiary bar for this module in this run.

Sub-modules (6)

Transfer MechanismsRed

No confirmed primary text; gap recorded.

Adequacy ReceivedRed

No adequacy decision received by Zambia from other regimes was identified.

Adequacy GrantedRed

No adequacy decision granted by Zambia to other regimes was identified.

Sccs And BcrsRed

No SCC/BCR-equivalent uptake or forms were identified.

Transfer Impact AssessmentRed

No TIA requirement was identified.

Data LocalisationRed

No localisation mandate (partial or absolute) was identified.

Category narrative65 words

No T1/T2 primary or secondary text confirming Zambia's cross-border transfer mechanisms (adequacy, SCC/BCR equivalents, derogations), any adequacy decisions received or granted, transfer-impact-assessment requirements, or data-localisation mandates was retrievable via allowlisted hostnames. Searches conducted: 'Data Protection Act 2021 cross-border transfer personal data section'; general Act full-text searches returned only registration/licensing secondary reporting. This module is emitted with an explicit gap rather than an inferred/fabricated transfer regime.

no periodic updates on record for this sub-brief

#

No sub-module met the evidentiary bar for a claim in this run; all seven are explicit gaps.

Traffic-light rationale — Not assessedNo sub-module met the evidentiary bar for a claim in this run; all seven are explicit gaps.

Sub-modules (7)

Financial Sector OverlayRed

No confirmed overlay text; gap recorded.

Health Sector OverlayRed

No confirmed overlay text; gap recorded.

Telecoms And EprivacyRed

Title-level metadata only for the Cyber Security and Cyber Crimes Act, 2021 (Act No. 2 of 2021); no substantive overlay text confirmed, so no claim minted.

Employment DataRed

No confirmed overlay text; gap recorded.

Credit And ScoringRed

No confirmed overlay text; gap recorded.

EducationRed

No confirmed overlay text; gap recorded.

InsuranceRed

No confirmed overlay text; gap recorded.

Category narrative83 words

A separate Cyber Security and Cyber Crimes Act, 2021 (Act No. 2 of 2021) exists in Zambia alongside the Data Protection Act, but only title-level secondary metadata was retrievable, with no citable substantive overlay text confirming its interaction with the general DP regime; no claim was minted on that basis. No sector-specific overlays (financial, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) were retrievable via allowlisted hostnames. Searches conducted: 'Zambia Cyber Security and Cyber Crime Act 2021 data protection'; 'Data Protection Act 2021 sectoral overlay'.

#

No claims meet the evidentiary bar for this module in this run.

Traffic-light rationale — Not assessedNo claims meet the evidentiary bar for this module in this run.

Sub-modules (6)

Cookies And TrackersRed

No confirmed provision; gap recorded.

Dark PatternsRed

No confirmed provision; gap recorded.

Opt Out SignalsRed

No confirmed provision; gap recorded.

Clean Rooms And DcrRed

No confirmed provision; gap recorded.

Cross Context AdvertisingRed

No confirmed provision; gap recorded.

Direct MarketingRed

No confirmed provision; gap recorded.

Category narrative43 words

No T1/T2 or credible T3 material on cookie/tracker consent rules, dark-pattern prohibitions, opt-out signals, clean-room/DCR rules, cross-context advertising, or direct-marketing consent/suppression for Zambia was retrievable via allowlisted hostnames. This is an unaddressed area of Zambia's current framework as far as accessible sources show.

#

One state-surveillance-carveout provision is confirmed at a general level; the remaining five sub-modules are unverified gaps.

Primary frameworkData Protection Act, 2021 (Act No. 3 of 2021)
Traffic-light rationale — AmberOne state-surveillance-carveout provision is confirmed at a general level; the remaining five sub-modules are unverified gaps.

Sub-modules (6)

Profiling RestrictionsRed

No confirmed provision; gap recorded.

Automated Decision Making TransparencyRed

No confirmed provision; gap recorded.

Ai Risk AssessmentsRed

No confirmed provision; gap recorded.

Biometric RegimeRed

No confirmed provision; gap recorded.

Genetic DataRed

No confirmed provision; gap recorded.

State Surveillance CarveoutsAmber

The Act provides exemptions from personal-data-processing rules for purposes including maintenance of public order and national security, per secondary reporting on the enacting Bill.

Claims (1):

  • The Data Protection Act, 2021 (as enacted from the Data Protection Bill, 2020) provides for exemptions from personal-data-processing rules for purposes including the maintenance of public order and national security.
Category narrative68 words

The clearest verified item in this module is that the Act (as enacted from the 2020 Bill) provides exemptions from personal-data-processing rules for purposes including maintenance of public order and national security — a state-surveillance carveout. Profiling restrictions, ADM transparency, AI-specific risk assessments, and biometric/genetic-data regimes were not retrievable in accessible text during this run. Searches conducted: 'Data Protection Act 2021 full text sections'; general bill/Act coverage searches.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableOneTrust DataGuidance — The Data Protection Act, 2021 (as enacted from the Data Protection Bill, 2020) provides for exemptions from personal-data-processing rules for purposes including the maintenance of public order and national security.observed

#

No claims meet the evidentiary bar for this module in this run.

Traffic-light rationale — Not assessedNo claims meet the evidentiary bar for this module in this run.

Sub-modules (5)

Age VerificationRed

No confirmed provision; gap recorded.

Minor Profiling BansRed

No confirmed provision; gap recorded.

Education SettingsRed

No confirmed provision; gap recorded.

Dependent AdultsRed

No confirmed provision; gap recorded.

Category narrative26 words

No T1/T2 material on age-of-consent thresholds, parental-consent mechanisms, minor-profiling bans, education-setting rules, or dependent-adult protections under Zambia's Act was retrievable via allowlisted hostnames in this run.

no periodic updates on record for this sub-brief

#

A concrete regulatory power (registration/licensing) is confirmed, but broader enforcement maturity, penalties, and redress mechanisms are unverified gaps, compounded by unresolved institutional-operationalisation status.

Primary frameworkData Protection Act, 2021 (Act No. 3 of 2021); Data Protection (Registration and Licensing) Regulations, 2021 (SI No. 58 of 2021)
Traffic-light rationale — AmberA concrete regulatory power (registration/licensing) is confirmed, but broader enforcement maturity, penalties, and redress mechanisms are unverified gaps, compounded by unresolved institutional-operationalisation status.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Commissioner holds registration and data-auditor licensing powers under SI 58/2021; maximum penalty figures for Act breaches were not confirmed against accessible primary text.

Claims (1):

  • The Data Protection Commissioner has authority under the Data Protection (Registration and Licensing) Regulations, 2021 to register data controllers and processors and to license data auditors.

Enforcement Activity IndexRed

No enforcement decisions or fines were retrievable via allowlisted hostnames in the last 12 months; gap recorded.

Regulator Funding And CapacityRed

No funding/headcount signal was retrievable; the seed's institutional-operationalisation caution is the only available capacity signal (captured in regulator_and_framework.regulator_and_authority).

Collective Redress And Class ActionsRed

No confirmed collective-redress mechanism; gap recorded.

Private Right Of ActionRed

No confirmed private right of direct court access; gap recorded.

Recent Developments 180DRed

No new legislation, case law, guidance, or determinations affecting Zambia's DP regime were identified within the last 180 days via allowlisted hostnames.

Category narrative69 words

The Data Protection Commissioner holds a confirmed registration/licensing power under SI 58/2021. Beyond this, maximum-penalty figures, enforcement-activity history, regulator funding/capacity signals, collective-redress mechanisms, private-right-of-action availability, and 180-day recent developments were not retrievable via allowlisted hostnames. Institutional capacity is additionally constrained per the seed CAUTION: the dedicated Authority is not confirmed as fully operational, which bears directly on enforcement maturity. Searches conducted: 'Zambia data protection enforcement fine 2025 2026 ZICTA'.

Periodic update · new data 2026-09-29

Enforcement & Redress

The Office of the Data Protection Commissioner is understood to be fully operational and actively enforcing privacy and data protection compliance in Zambia. The Commissioner is reported to be initiating regulatory enforcement and public compliance campaigns intended to promote transparency, accountability and data security in the handling of personal data, consistent with the Commission's stated mandate of ensuring that handling of personal data adheres to the Data Protection Act, 2021 and best security practices.

No specific sanction, fine, or named enforcement action against an individual controller or processor was identified this cycle; the enforcement signal at this stage is one of institutional operationalisation and public-facing compliance-campaign activity rather than adjudicated cases. This distinction matters for reading the enforcement posture accurately: an operational and campaigning regulator is a materially different enforcement environment from one that has begun issuing sanctions, and the evidence available this cycle supports only the former.

The mandatory controller/processor registration portal, reported separately under controller/processor duties, functions as a complementary enforcement-support mechanism, allowing the Commissioner to identify the population against which compliance campaigns and any future enforcement action would be directed.

Outlook

Watch for the Commission's first published sanction or enforcement decision as the event that would mark a transition from campaign-and-registration-stage enforcement to adjudicated enforcement activity.

Sources and claims (1)
  1. ProbableOneTrust DataGuidance — The Data Protection Commissioner has authority under the Data Protection (Registration and Licensing) Regulations, 2021 to register data controllers and processors and to license data auditors.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct6.67
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Zambia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 10 claim(s) (10 category placement(s)), 18 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were emitted. regulator_and_framework has the strongest evidentiary base (T1 ZICTA anchor + T3 corroboration on the Registration and Licensing Regulations, SI 58/2021, and the enacting Bill's coverage). lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, and algorithmic_biometric_and_surveillance_governance carry one grounded claim each (general Bill/Act coverage statements at T3) plus explicit sub-module gaps for granular provisions (specific lawful bases, consent thresholds, DPO/ROPA/breach-notification mechanics, DSR deadlines, profiling/ADM/biometric rules). cross_border_and_adequacy, sectoral_watch, adtech_and_commercial_privacy, and children_and_vulnerable_groups returned no citable T1/T2/T3 material despite targeted searches and are emitted as full gaps per GAP DISCIPLINE. No T2 supervisory guidance, codes of practice, or enforcement decisions were retrievable via allowlisted hostnames (zicta.zm resolved only to a homepage/legislation-index shell; dataguidance.com substantive content was largely paywalled behind boilerplate teaser text). This run should be treated as a thin baseline requiring primary-source escalation.

Unresolved questions (6):

  • Has the dedicated Data Protection Authority contemplated by the Act, 2021 been formally, independently operationalised, and if so, on what date and under what instrument?
  • What are the enumerated lawful bases, consent standards, and special-category conditions under the Data Protection Act, 2021 (equivalent to GDPR Arts 6/7/9)?
  • What are the DPO appointment threshold, ROPA obligation, breach-notification timeline/threshold, and retention-limit provisions under the Act and its regulations?
  • Does the Act or subsidiary regulations address cross-border transfer mechanisms, adequacy, or data-localisation, and if so, what form do they take?
  • Has ZICTA or the Data Protection Commissioner issued any enforcement decisions, fines, or public notices in the 2024-2026 period?
  • What is the substantive interaction (if any) between the Cyber Security and Cyber Crimes Act, 2021 (Act No. 2 of 2021) and the Data Protection Act's general regime?

Escalate to primary-source review: yes