Data Security Compliance in Zambian Universities under the Data Protection Act (2021):

A Comparative Case Study of Representative Institutions

Authors

Abstract

This study assessed data security compliance in Zambian universities following the enactment of the Data Protection Act No. 3 of 2021, which established a legal framework for safeguarding personal information. Despite universities managing highly sensitive data, such as student records, biometrics, and academic credentials, there is limited empirical evidence on their institutional compliance with this legislation. This study aimed to evaluate the extent of data protection implementation, identify barriers to compliance, and propose evidence-based strategies for improvement.
A qualitative multiple-case study design was employed, involving two private and one Government universities. Data collection included 21 semi-structured interviews with key stakeholders, document analysis, and observational field notes. Thematic analysis was conducted following Braun and Clarke’s six-phase approach.
Findings revealed distinct disparities in compliance maturity. University B exhibited high compliance, characterized by robust policy frameworks, technical safeguards, and effective incident response protocols. University A showed moderate compliance, with general awareness but inconsistent implementation. University C demonstrated low compliance, lacking foundational governance structures and awareness of the Act. Three key patterns emerged: (1) a leadership-awareness versus operational-implementation gap, (2) a policy-practice disconnect due to poor communication and training, and (3) systemic resource constraints.
The study concludes that legal mandates alone are insufficient to ensure data security compliance. A shift towards a data protection culture, supported by adequate resources, capacity building, implementation guidelines, and regulatory oversight, is essential. The findings have implications for university governance, national policy, and the development of sustainable data protection frameworks in Zambia’s higher education sector.

DOI:  https://zenodo.org/records/18664512 

Published

2026-02-15

How to Cite

Chipasha, C., Arulanandham, R., & Tembo, S. (2026). Data Security Compliance in Zambian Universities under the Data Protection Act (2021):: A Comparative Case Study of Representative Institutions. Journal of Research for International Educators, 5(1). Retrieved from https://www.jorie.org/index.php/journal/article/view/51