ZambiaIn ForceCybercrime

Cyber Security Act, 2025 (No. 3 of 2025) (Zambia)

zm-cybersecurity-2025 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Cyber Security Act, 2025 (Act No. 3 of 2025) is the regulatory half of Zambia's 2025 cyber-law reform, enacted alongside the Cyber Crimes Act, 2025 (No. 4 of 2025) and brought into operation on 15 April 2025; together they repealed and replaced the Cyber Security and Cyber Crimes Act, 2021. Where the Cyber Crimes Act creates criminal offences, the Cyber Security Act focuses on institutional and infrastructure regulation. The Act establishes the Zambia Cyber Security Agency, responsible for coordinating national cyber security, regulating cyber-security service providers, and identifying information and information infrastructure deemed critical to particular sectors. Once information or infrastructure is classified as critical, the person in control must register as a 'controller' with the Agency within 30 days of designation. Controllers are required to store critical information or critical information infrastructure within Zambia unless the Agency grants explicit authorisation to host it elsewhere, a data-localisation requirement. The Act also provides for the licensing and oversight of security service providers and for incident response, reporting and national coordination functions. The framework has drawn criticism from digital-rights organisations over the breadth of the Agency's powers, the localisation mandate, and surveillance-related provisions, with concerns that the regulatory architecture could be used to monitor or control online activity. For the ATLPF library this instrument is tagged Cybercrime (as the cyber-security counterpart to the Cyber Crimes Act) and cross-referenced to the Cyber Crimes Act, 2025 and Zambia's Data Protection Act, 2021.

Key provisions
  1. Establishes the Zambia Cyber Security Agency to coordinate national cyber security and regulate the sector
  2. Identification and designation of critical information and critical information infrastructure (CII)
  3. Controllers of CII must register with the Agency within 30 days of designation
  4. Data-localisation: critical information/infrastructure must be stored in Zambia unless the Agency authorises foreign hosting
  5. Licensing and oversight of cyber-security service providers; incident response and reporting duties
  6. Enacted with the Cyber Crimes Act 2025; together repeal and replace the Cyber Security and Cyber Crimes Act 2021 (in operation 15 April 2025)
  7. Criticised by digital-rights groups over agency powers, localisation and surveillance concerns
Related instruments
Entry history
Entry history
  1. 26 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from the Parliament of Zambia / ZambiaLII official text (Act No. 3 of 2025, in operation 15 April 2025), Afriwise and Bowmans analyses, and CIPESA/ICNL commentary. Companion to the Cyber Crimes Act No. 4 of 2025; both repeal the Cyber Security and Cyber Crimes Act 2021.