1. Introduction and Legal Status
This Data & Privacy Policy explains how PVT Results collects, uses, stores, protects, validates, retains, discloses, and deletes data submitted through the platform.
This Policy has been updated to address legal compliance under Zambian law, including:
- the Data Protection Act, No. 3 of 2021, including sections 12, 14, 19, 20, 21, 46, 48, 49, 70, and 71;
- the Electoral Process Act, No. 35 of 2016, as amended by the Electoral Process (Amendment) Act, No. 32 of 2021, including section 89(1)(o);
- the Cyber Security and Cyber Crimes Act, No. 2 of 2021, including sections 23, 49, 60, 63, 73, and 76;
- the Electronic Communications and Transactions Act, No. 4 of 2021, where applicable to electronic records, communications, and transactions;
- the Information and Communications Technologies Act, No. 15 of 2009, where applicable to regulated communications services, including sections 67 and 68;
- the Constitution of Zambia, 1991, as amended by Act No. 2 of 2016, including Articles 1, 4, 45, 229, and 266.
PVT Results maintains, or will maintain where required, registration as a data controller and data processor with the Office of the Data Protection Commissioner in accordance with Data Protection Act sections 19, 20, and 21.
PVT Results has appointed, or will appoint where required, a Data Protection Officer responsible for compliance oversight, Data Protection Impact Assessments, breach coordination, and data-subject request management in accordance with Data Protection Act sections 46, 48, and 49.
Continued use of the platform after the effective date of this Policy constitutes acceptance of this Policy.
2. Policy Application
This Policy applies to:
- tenant organisations;
- tenant administrators;
- election agents;
- polling agents;
- verifiers;
- readers;
- observers and monitors;
- account users;
- support users;
- other authorised users of the platform.
This Policy applies to personal data, tenant data, evidence, audit logs, security data, support data, communications, exports, aggregated data, and validation records processed through the platform.
3. Types of Data We Process
The platform may process the following categories of data.
3.1 Tenant Data
Tenant Data means data submitted, uploaded, generated, reviewed, exported, or stored by an organisation in its workspace, including:
- polling-station results;
- candidate totals;
- rejected-ballot and spoiled-ballot figures;
- turnout figures;
- polling station, stream, ward, constituency, district, and province references;
- evidence sheets, forms, photographs, or scans;
- verifier comments;
- discrepancy notes;
- internal approval status;
- reports, exports, dashboards, and aggregates.
Tenant Data may include personal data or sensitive personal data where it contains names, signatures, identifiers, political affiliations, organisational roles, images, or comments relating to identifiable people.
3.2 User Account Data
User Account Data may include:
- name;
- email address;
- phone number where provided;
- organisation;
- role;
- login credentials or authentication identifiers;
- invitation status;
- access permissions;
- consent, acknowledgement, and account-status records.
3.3 Audit and Security Data
Audit and Security Data may include:
- login history;
- IP address;
- device and browser information;
- timestamps;
- submission history;
- edit history;
- evidence upload history;
- verifier actions;
- access logs;
- discrepancy flags;
- system alerts;
- incident and threat records.
3.4 Support and Communication Data
Support and Communication Data may include:
- messages;
- support requests;
- billing communications;
- onboarding information;
- administrative correspondence;
- data-protection requests and responses;
- complaint records.
3.5 Sensitive Personal Data
Election-related data may reveal or allow inference of sensitive personal data, including political opinions, political affiliation, campaign roles, observer roles, polling-agent roles, organisational affiliation, or other protected information.
Sensitive personal data is processed only where a lawful condition under Data Protection Act section 14 is satisfied, including explicit consent obtained by the relevant tenant where required, substantial public interest in democratic election integrity with appropriate safeguards, or necessity for the establishment, exercise, or defence of legal claims.
4. Tenant Ownership of Data
Each tenant retains ownership of its Tenant Data.
PVT Results does not claim ownership over polling-station results, uploaded evidence, internal verification notes, or tenant-specific reports.
By using the platform, each tenant grants PVT Results a limited, non-exclusive licence to host, store, process, validate, analyse, secure, display, back up, transmit, export, and retain Tenant Data solely for the purposes set out in this Policy, the Terms of Use, and any applicable service agreement.
This licence is subject to the Data Protection Act, including sections 12 and 14, and to any written agreement that imposes stricter controls.
5. No Sale of Data
PVT Results will not sell Tenant Data, User Account Data, uploaded evidence, audit logs, validation records, or personal data to third parties.
We will not sell data to advertisers, political parties, campaigns, consultants, media organisations, data brokers, or commercial third parties.
This prohibition supports the purpose-limitation and data-minimisation principles in Data Protection Act section 12.
6. Purposes and Legal Bases for Processing
PVT Results processes data for the following purposes:
- to provide, operate, secure, and improve the platform;
- to create and manage tenant workspaces;
- to assign users to polling districts, stations, streams, contests, and roles;
- to enable evidence-backed result capture;
- to perform arithmetic validation, verifier review, and discrepancy detection;
- to perform cross-tenant pooled validation under section 7;
- to generate dashboards, reports, and exports for authorised users;
- to maintain audit trails and support accountability;
- to detect misuse, fraud, manipulation, unauthorised access, credential compromise, and suspicious submission patterns;
- to comply with legal, regulatory, audit, contractual, and court obligations;
- to provide support and administrative communications;
- to investigate breach of the Terms of Use or this Policy.
The legal bases for processing may include:
- performance of a contract;
- legitimate interests in platform operation, security, evidence integrity, and service delivery;
- legal obligation;
- tenant-requested services;
- public-interest election monitoring where applicable and lawful;
- establishment, exercise, or defence of legal claims;
- consent or explicit consent where required.
Processing follows the Data Protection Act section 12 principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability.
7. Cross-Tenant Pooled Validation
PVT Results may compare submitted election result data across tenants for the same polling station, stream, contest, ward, constituency, district, province, or election event.
Pooled validation is used only to:
- identify inconsistent figures;
- detect possible data-entry errors;
- flag potential source manipulation or transcription issues;
- improve confidence in data accuracy;
- generate non-identifying alerts where submissions materially diverge;
- protect platform integrity.
Pooled validation is carried out on the basis of legitimate interests in maintaining the integrity and reliability of the platform and, where applicable, the substantial public interest in free, fair, credible, and transparent elections.
One tenant's identifiable submissions, evidence, users, internal comments, or verification records are not disclosed to another tenant through pooled validation unless the tenant authorises disclosure or disclosure is required by law.
The platform may generate alerts such as:
- "Your submitted result differs materially from other submissions for this polling station."
- "Evidence review recommended."
- "Arithmetic mismatch detected."
- "Broader divergence detected across comparable submissions."
- "Potential source or transcription issue."
A validation flag is a risk indicator only and does not constitute a finding of fraud, manipulation, or wrongdoing.
8. Data Isolation Between Tenants
Tenant workspaces are logically separated.
Users may access data only within their assigned workspace, role, and permissions.
Tenant administrators are responsible for assigning access appropriately and removing access when it is no longer required.
PVT Results personnel may access Tenant Data only when necessary for:
- platform operation;
- technical support;
- security monitoring;
- discrepancy investigation;
- compliance;
- legal obligations;
- enforcement of the Terms of Use or this Policy;
- service improvement consistent with this Policy.
Access is subject to confidentiality, logging, and role-based controls consistent with Data Protection Act section 12 and applicable cybersecurity requirements.
9. Data Retention
Unless a different period is agreed in writing with a tenant, PVT Results may retain Tenant Data, evidence, audit logs, validation records, and related election records for up to 10 years from the date of submission or the relevant election event.
The retention period supports:
- auditability;
- dispute review;
- election-petition or legal-claim support where applicable;
- investigation of discrepancies, manipulation, or fraudulent patterns;
- institutional memory for tenants;
- platform integrity and accountability;
- legal, regulatory, contractual, and security obligations.
PVT Results will maintain a documented Data Retention Schedule available on request. The schedule will apply the storage-limitation principle in Data Protection Act section 12 and will provide for periodic review, deletion, anonymisation, or archiving once relevant purposes are fulfilled, subject to legal holds.
Some records may be retained longer where required by law, court order, regulatory obligation, security incident, unpaid account, unresolved dispute, legal claim, or contractual obligation.
10. Personal Data Minimisation
Users and tenants must avoid uploading unnecessary personal data.
Unless expressly required for verification, users and tenants must not upload:
- National Registration Card numbers;
- full voter personal details;
- private home addresses;
- unnecessary phone numbers;
- biometric data;
- sensitive personal information unrelated to election monitoring;
- private communications not required for verification.
Where evidence contains unnecessary personal data, tenants should lawfully redact that information before upload where possible. Redaction must not obscure or alter the election result record required for verification.
This minimisation obligation supports Data Protection Act section 12.
11. Sensitive Personal Data
Election-related data may reveal political opinions, political affiliations, campaign roles, observer roles, polling-agent roles, or organisational affiliation.
PVT Results processes sensitive personal data only where a condition under Data Protection Act section 14 is satisfied.
Tenants are responsible for obtaining necessary explicit consent from data subjects, including agents, verifiers, observers, monitors, employees, volunteers, or representatives, before submitting sensitive personal data where consent is required.
Tenants must inform data subjects about the processing purposes, including evidence-backed result capture, audit trails, discrepancy detection, pooled validation, and legal compliance.
PVT Results will apply enhanced technical and organisational safeguards to protect sensitive personal data.
12. Data Protection Impact Assessments
PVT Results will conduct Data Protection Impact Assessments for high-risk processing activities where required, including large-scale processing of election data and cross-tenant pooled validation.
DPIAs will be conducted in accordance with Data Protection Act section 46, including section 46(1), section 46(2)(a)-(c), section 46(4), and section 46(5), where applicable.
Where the Act requires consultation with the Data Protection Commissioner before commencing high-risk processing, PVT Results will consult the Commissioner before that processing begins.
13. User Rights
Subject to applicable law, data subjects may have rights to:
- access personal data held about them;
- request correction or rectification of inaccurate personal data;
- request erasure where legally applicable;
- object to certain processing;
- restrict processing in certain circumstances;
- request portability where applicable;
- withdraw consent where processing is based on consent;
- complain to the relevant data-protection authority.
Requests should be submitted through the contact form with this message: "For the attention of the Data Protection Officer."
The platform may verify identity before responding.
Some requests may need to be handled through the relevant tenant administrator where the tenant controls the workspace and user relationship.
Responses will be handled in accordance with the Data Protection Act, including applicable rights, request, exemption, and complaint provisions.
14. Security Measures
PVT Results will implement reasonable technical and organisational safeguards to protect data, which may include:
- role-based access control;
- authentication controls;
- encryption in transit;
- encryption at rest where supported and appropriate;
- audit logs;
- access monitoring;
- backups;
- administrative access controls;
- secure development practices;
- incident response procedures;
- periodic review of security controls.
No system can guarantee absolute security against all risks or threats. Users and tenants must protect credentials and report suspected compromise without delay.
Security controls are informed by the Data Protection Act section 12 and by the Cyber Security and Cyber Crimes Act, including sections 49, 60, 63, and 73. If any platform component is declared or treated as critical information infrastructure, incident reporting and controls will also be handled with reference to Cyber Security and Cyber Crimes Act section 23.
15. Breach Notification
If PVT Results becomes aware of a personal data breach, it will investigate promptly and take appropriate remedial action.
Where required by Data Protection Act section 49, PVT Results will notify the Data Protection Commissioner within 24 hours of becoming aware of the breach and will notify affected tenants or data subjects as legally required.
Tenants must promptly notify PVT Results if they suspect unauthorised access, credential compromise, data leakage, evidence manipulation, unauthorised export, or misuse of the platform.
16. Service Providers and Sub-Processors
PVT Results may use trusted service providers or sub-processors to host, secure, operate, maintain, analyse, or support the platform.
Service providers may process data only as authorised by PVT Results and must be subject to confidentiality, security, and data-protection obligations consistent with the Data Protection Act.
PVT Results will conduct appropriate due diligence and maintain contractual safeguards for service providers.
Where regulated communications services are involved, service quality, consumer information, and complaint-handling expectations may be informed by the Information and Communications Technologies Act, sections 67 and 68.
17. International Storage and Transfers
Where data is stored, processed, backed up, externalised, transferred, or accessed outside Zambia, PVT Results will take reasonable steps to ensure that the transfer or processing is lawful and protected by appropriate safeguards.
Cross-border transfer of personal data will be handled subject to Data Protection Act sections 70 and 71.
PVT Results will use one or more lawful transfer conditions where required, which may include:
- an adequate level of protection in the destination jurisdiction;
- prior informed consent of the data subject where applicable;
- standard contractual clauses or equivalent safeguards approved where required;
- encryption and transfer-impact assessment where appropriate;
- another condition or exception expressly permitted by law.
Tenants with specific data-residency requirements must enter into a written agreement with PVT Results.
PVT Results will assess whether any processing or dataset constitutes critical information or critical information infrastructure under the Cyber Security and Cyber Crimes Act and will align with applicable localisation, security, or incident-reporting obligations where required.
18. Aggregated, Anonymised, and De-Identified Data
PVT Results may use aggregated, anonymised, or de-identified data to:
- improve platform performance;
- improve validation rules;
- understand system usage;
- improve election workflow design;
- produce non-identifying statistical insights;
- strengthen discrepancy detection;
- support research into electoral processes and integrity in anonymised form.
Such data will not reasonably identify a tenant, user, agent, observer, monitor, candidate representative, or other individual unless permitted by the tenant, required by law, or necessary for security, enforcement, or legal claims.
19. Disclosure of Data
PVT Results may disclose data only where:
- authorised by the tenant;
- necessary to provide the platform;
- required by law, court order, statutory obligation, or lawful authority;
- necessary to investigate misuse, fraud, manipulation, unlawful public-result announcements, or security incidents;
- necessary to enforce the Terms of Use or this Policy;
- necessary to protect the rights, safety, or integrity of the platform, tenants, users, or the public;
- part of a merger, acquisition, restructuring, or transfer of the platform, subject to appropriate safeguards.
PVT Results will not disclose one tenant's private workspace data to another tenant merely because submissions relate to the same polling station.
Disclosures to ECZ, the Data Protection Commissioner, ZICTA, law-enforcement agencies, courts, or other competent authorities may be made in response to lawful requests, court orders, regulatory obligations, or statutory requirements.
Disclosure will be handled consistently with the Data Protection Act, the Electoral Process Act, the Cyber Security and Cyber Crimes Act, and any applicable court order or statutory requirement.
20. Data Export and Deletion
Tenants may request export of their Tenant Data in a reasonable format supported by the platform.
Deletion requests may be subject to:
- the retention policy in section 9;
- legal obligations;
- audit requirements;
- unresolved disputes;
- security investigations;
- backup retention cycles;
- contractual obligations;
- court orders or regulatory holds.
Where immediate deletion is not possible, access may be restricted, data may be archived, or data may be anonymised where appropriate.
Deletion and export requests will be handled in accordance with the Data Protection Act and any applicable enterprise agreement.
21. Tenant Administrator Responsibilities
Tenant administrators must:
- assign roles carefully;
- remove users who no longer require access;
- ensure agents and verifiers understand data submission and evidence requirements;
- obtain required consents, including explicit consent for sensitive personal data where required;
- inform data subjects of processing purposes, including pooled validation;
- avoid uploading unnecessary personal data;
- apply lawful redaction where appropriate without obscuring required election records;
- verify data before organisation-wide release or public use;
- report suspected misuse, unauthorised access, credential compromise, data leakage, or evidence manipulation immediately;
- ensure public communications based on platform data are lawful, accurate, and include required methodology and disclaimers.
These responsibilities support Data Protection Act sections 12 and 14 and the electoral compliance obligations described in section 22.
22. Electoral Compliance and Unauthorised Result Announcements
Under Electoral Process Act section 89(1)(o), as inserted by the Electoral Process (Amendment) Act, No. 32 of 2021, a person must not announce and declare election results without lawful authority.
PVT Results data, validations, discrepancy flags, reports, dashboards, exports, or pooled insights must not be used to announce, declare, or represent results as official election results, or to mislead the public or any person into believing that platform output is official or authoritative.
Platform data and tools are provided strictly for internal verification, parallel tabulation, evidence preservation, and discrepancy detection by authorised or accredited organisations, agents, observers, and monitors.
Any public statement based on platform data must:
- identify the tenant making the statement;
- explain methodology, coverage, sample size, confidence level, or limitations where applicable;
- state that the work is an independent parallel exercise;
- state that it is not an official declaration;
- include the mandatory disclaimer required by the Terms of Use.
Violation of this section may result in immediate suspension or termination of access, withholding of data or exports, preservation of records, indemnity exposure, and reporting to ECZ, Zambia Police, the Data Protection Commissioner, ZICTA, or another relevant authority where required or authorised by law.
23. Children and Minors
The platform is not intended for use by children.
Tenants must not create accounts for minors unless they have lawful authority and PVT Results has expressly approved such use in writing.
For purposes of this Policy, a child is understood consistently with the Constitution of Zambia, Article 266, as a person who is below or has attained the age of eighteen years.
24. Changes to this Policy
PVT Results may update this Policy from time to time to reflect changes in law, technology, platform operations, security practices, accepted practices, or legal advice.
Material changes will be communicated through the platform, website, email, or another reasonable method.
Continued use of the platform after the effective date of an updated Policy constitutes acceptance of the updated Policy.
25. Contact
For privacy, data-protection, access, correction, deletion, consent, complaint, or other data-subject requests, contact:
For Data Protection Officer attention, contact the office using the contact form and include this message: "For the attention of the Data Protection Officer."
26. Version, Governing Law, and Acknowledgement
This Policy is Version 2.0, updated on June 16, 2026, for alignment with the Data Protection Act, the Electoral Process Act as amended by Act No. 32 of 2021, the Cyber Security and Cyber Crimes Act, applicable electronic communications and transactions law, the Information and Communications Technologies Act where applicable, and the Constitution of Zambia.
This Policy and any disputes arising from it are governed by the laws of the Republic of Zambia, unless a signed agreement states otherwise.
By using the platform, each user and tenant confirms that they have read, understood, and agree to be bound by this Policy, including the electoral compliance obligations in section 22 and the PVT Results Terms of Use.