Zambia's Data Protection Act: what it actually means for a small business

Most small businesses in Zambia are already holding more personal data than they realize. A phone number logged against every mobile money sale, an NRC number taken for a layaway or credit arrangement, a customer's delivery address in a WhatsApp chat, a spreadsheet tracking who still owes what — all of that is personal data, and the Data Protection Act, 2021 covers it. The Act applies to anyone who collects, stores, or processes the personal data of people in Zambia, whether that's a bank or a five-person shop with a till and a notebook.
In practice, the Act asks for two things most businesses aren't yet doing. First, if you're formally collecting and processing personal data as part of how you run the business, you're expected to register as a data controller or processor with the Office of the Data Protection Commissioner (dataprotection.gov.zm) — the office reviews the application and, once approved, issues a certificate. Second, you need actual consent before you use someone's data beyond the transaction they gave it for. Adding a customer's number to a WhatsApp broadcast list or SMS blast because they once bought something from you isn't covered by the fact that they paid you — that's a separate use of their data, and it needs its own yes.
The gap that catches most small businesses isn't malicious — it's that customer data ends up scattered across a personal phone's WhatsApp, a shared Google Sheet with an open link, and a paper ledger, with no real answer to who can see it or what happens if a customer asks you to delete their record. A practical starting point: decide who in the business actually needs access to customer records and limit it to them, stop keeping customer lists in documents anyone with the link can open, get an explicit opt-in before adding a number to any marketing list, and have a real process — not just an intention — for deleting a customer's data if they ask.
We build access controls and consent tracking into the POS, invoicing, and CRM systems we set up, rather than treating them as a compliance step bolted on afterward — so a customer's data is only visible to the staff who need it, and marketing messages only go to people who actually opted in. If your business is still keeping customer records in a shared spreadsheet or a personal WhatsApp, that's usually the first gap worth closing, before it's a customer asking where their data went and nobody having a clear answer.