The Cyber Security Act, 2025
ARRANGEMENT OF SECTIONS
PART I - PRELIMINARY
- Short title and commencement
- Interpretation
PART II - THE ZAMBIA CYBER SECURITY AGENCY
- Establishment of Zambia Cyber Security Agency
- Functions of Agency
- Director-General and other staff
PART III - CYBER INCIDENT RESPONSE TEAMS
- Zambia Cyber Incident Response Team
- Constitution of sectoral cyber incident response teams
PART IV - PROTECTION OF CRITICAL INFORMATION AND CRITICAL INFORMATION INFRASTRUCTURE
- Critical sector
- Designation of critical information or critical information infrastructure
- Categories of critical information and critical information infrastructure
- Registration of critical information and critical information infrastructure
- Hosting of critical information and critical information infrastructure
- Change in ownership of critical information or critical information infrastructure
- Auditing of critical information or critical information infrastructure
- Non-compliance to cyber audit requirements
- Report on cyber security situational awareness
- Duty to report cyber security incidents in respect of critical information and critical information infrastructure
- Power to investigate cyber security incident and cyber security threat
- Cyber security exercise
- Cyber Security Risk Register
PART V - INTERCEPTION OF COMMUNICATIONS
- Central Monitoring and Co-ordination Centre
- Prohibition of interception of communication
- Prohibition of use, manufacture or possession of interception device
- Registration of interception device
- Variation of certificate of registration
- Surrender of certificate of registration
- Transfer of certificate of registration
- Cancellation or suspension of certificate of registration
- Lawful interception
- Interception of communication to prevent bodily harm, loss of life or damage to property
- Prohibition of use, acquisition, etc of geolocation and interception information
- Interception of communication for purposes of determining location
- Technical assistance for purposes of determining location or illegal use of spectrum
- Prohibition of access and use of intercepted communication
- Disclosure of intercepted communication by law enforcement officer
- Privileged communication to retain privileged character
- Prohibition of random monitoring
- Interception of satellite transmission
- Assistance by electronic communications service provider
- Interception capability of electronic communications service provider
PART VI - LICENSING OF CYBER SECURITY SERVICE PROVIDERS
- Cyber security services
- Prohibition of providing cyber security service without licence
- Categories of licences
- Application for licence
- Grant of licence
- Rejection of application
- Variation of licence
- Surrender of licence
- Transfer of licence
- Renewal of licence
- Cancellation or suspension of licence
- Register of cyber security service provider
PART VII - INTERNATIONAL COOPERATION IN MAINTAINING CYBER SECURITY
- Identifying areas of cooperation
- Entering into agreement
PART VIII - INSPECTORATE
- Appointment of cyber security inspector
- Power to access, search and seize
- Appointment of cyber security technical expert
PART IX - GENERAL PROVISIONS
- Appeals
- Search and seizure by law enforcement officer
- Restoration of property
- Assistance
- Evidence obtained by unlawful interception not admissible in criminal proceedings
- Prohibition of obstruction of law enforcement officer
- Submission of information by controller
- General penalty
- Power of court to order cancellation of licence, forfeiture etc.
- Guidelines
- Standards
- Exemptions
- Compounding of certain offences by Agency
- Administrative penalty
- Regulations
- Repeal of Act No. 2 of 2021
SCHEDULE
GOVERNMENT OF ZAMBIA
ACT No. 3 of 2025
Date of Assent: 8th April, 2025
An Act to provide for cyber security in the Republic; establish the Zambia Cyber Security Agency and provide for its functions; provide for the regulation of cyber security service providers; provide for the constitution of the Zambia Cyber Incident Response Team and provide for its functions; provide for the constitution of sectoral cyber incident response teams; continue the existence of the Central Monitoring and Co ordination Centre; provide for the designation, protection and registration of critical information and critical information infrastructure; repeal and replace the Cyber Security and Cyber Crimes Act, 2021; and provide for matters connected with, or incidental to, the foregoing.
15th April, 2025
ENACTED by the Parliament of Zambia.