Docs The Cyber Security Act, 2025

The Cyber Security Act, 2025

ARRANGEMENT OF SECTIONS

PART I - PRELIMINARY

  1. Short title and commencement
  2. Interpretation

PART II - THE ZAMBIA CYBER SECURITY AGENCY

  1. Establishment of Zambia Cyber Security Agency
  2. Functions of Agency
  3. Director-General and other staff

PART III - CYBER INCIDENT RESPONSE TEAMS

  1. Zambia Cyber Incident Response Team
  2. Constitution of sectoral cyber incident response teams

PART IV - PROTECTION OF CRITICAL INFORMATION AND CRITICAL INFORMATION INFRASTRUCTURE

  1. Critical sector
  2. Designation of critical information or critical information infrastructure
  3. Categories of critical information and critical information infrastructure
  4. Registration of critical information and critical information infrastructure
  5. Hosting of critical information and critical information infrastructure
  6. Change in ownership of critical information or critical information infrastructure
  7. Auditing of critical information or critical information infrastructure
  8. Non-compliance to cyber audit requirements
  9. Report on cyber security situational awareness
  10. Duty to report cyber security incidents in respect of critical information and critical information infrastructure
  11. Power to investigate cyber security incident and cyber security threat
  12. Cyber security exercise
  13. Cyber Security Risk Register

PART V - INTERCEPTION OF COMMUNICATIONS

  1. Central Monitoring and Co-ordination Centre
  2. Prohibition of interception of communication
  3. Prohibition of use, manufacture or possession of interception device
  4. Registration of interception device
  5. Variation of certificate of registration
  6. Surrender of certificate of registration
  7. Transfer of certificate of registration
  8. Cancellation or suspension of certificate of registration
  9. Lawful interception
  10. Interception of communication to prevent bodily harm, loss of life or damage to property
  11. Prohibition of use, acquisition, etc of geolocation and interception information
  12. Interception of communication for purposes of determining location
  13. Technical assistance for purposes of determining location or illegal use of spectrum
  14. Prohibition of access and use of intercepted communication
  15. Disclosure of intercepted communication by law enforcement officer
  16. Privileged communication to retain privileged character
  17. Prohibition of random monitoring
  18. Interception of satellite transmission
  19. Assistance by electronic communications service provider
  20. Interception capability of electronic communications service provider

PART VI - LICENSING OF CYBER SECURITY SERVICE PROVIDERS

  1. Cyber security services
  2. Prohibition of providing cyber security service without licence
  3. Categories of licences
  4. Application for licence
  5. Grant of licence
  6. Rejection of application
  7. Variation of licence
  8. Surrender of licence
  9. Transfer of licence
  10. Renewal of licence
  11. Cancellation or suspension of licence
  12. Register of cyber security service provider

PART VII - INTERNATIONAL COOPERATION IN MAINTAINING CYBER SECURITY

  1. Identifying areas of cooperation
  2. Entering into agreement

PART VIII - INSPECTORATE

  1. Appointment of cyber security inspector
  2. Power to access, search and seize
  3. Appointment of cyber security technical expert

PART IX - GENERAL PROVISIONS

  1. Appeals
  2. Search and seizure by law enforcement officer
  3. Restoration of property
  4. Assistance
  5. Evidence obtained by unlawful interception not admissible in criminal proceedings
  6. Prohibition of obstruction of law enforcement officer
  7. Submission of information by controller
  8. General penalty
  9. Power of court to order cancellation of licence, forfeiture etc.
  10. Guidelines
  11. Standards
  12. Exemptions
  13. Compounding of certain offences by Agency
  14. Administrative penalty
  15. Regulations
  16. Repeal of Act No. 2 of 2021

SCHEDULE


GOVERNMENT OF ZAMBIA

ACT No. 3 of 2025

Date of Assent: 8th April, 2025

An Act to provide for cyber security in the Republic; establish the Zambia Cyber Security Agency and provide for its functions; provide for the regulation of cyber security service providers; provide for the constitution of the Zambia Cyber Incident Response Team and provide for its functions; provide for the constitution of sectoral cyber incident response teams; continue the existence of the Central Monitoring and Co ordination Centre; provide for the designation, protection and registration of critical information and critical information infrastructure; repeal and replace the Cyber Security and Cyber Crimes Act, 2021; and provide for matters connected with, or incidental to, the foregoing.

15th April, 2025

ENACTED by the Parliament of Zambia.

Type to search…