Knowledge hub

Frequently Asked Questions

Compliance with the Zimbabwe Cyber and Data Protection Act [Chapter 12:07] and S.I. 155 of 2024.

The Act

A counsel brief on the Authority, licensing, the DPO, data-subject rights, security, and penalties.

01 What is the statutory foundation of the Act, and what does POTRAZ do?

The enactment of the Cyber and Data Protection Act [Chapter 12:07] represents a strategic pivot from an era of unregulated data processing to a formal, statutory-led digital economy. For any enterprise operating in Zimbabwe, this framework is the bedrock of institutional trust. By harmonizing the secure use of Information and Communication Technologies (ICTs) with the fundamental rights enshrined in the Constitution—specifically the Section 57 Right to Privacy—the Act provides the legal certainty required for both domestic growth and international digital trade.

Under Section 5, the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is designated as the Data Protection Authority. Its powers are extensive and designed for active oversight:

  • Regulatory Supervision: Establishing the specific conditions and rules for the lawful processing of personal data.
  • Enforcement and Litigation: Promoting fair processing and, in consultation with the Minister, bringing legal action against administrative acts that violate privacy principles.
  • Inquiry and Investigation: Exercising the power to conduct audits, request documents, and call upon experts to investigate breaches or non-compliance.
  • Complaint Resolution: Acting as the primary tribunal for data subjects to lodge complaints regarding unauthorized or unfair processing.
  • International Cooperation: Facilitating cross-border enforcement and participating in regional forums to align Zimbabwe with global best practices.

As defined in Section 2, the primary object of the Act is to increase cybersecurity to build confidence and trust in the secure use of ICTs by data controllers, their representatives, and data subjects. It serves to protect the Declaration of Rights while fostering a technology-driven business environment.

So what? The Authority’s independence, codified in Section 6(2), ensures that it is not subject to the direction or control of any person or authority. Compliance is no longer a matter of political alignment but a strict legal mandate. Organizations must build verifiable, audit-proof compliance architectures, as the Authority functions as an independent regulator capable of enforcing the law without external interference.
02 How do licensing, notification, and operational tiers work?

In the Zimbabwean jurisdiction, automated processing is not a default right; it is a regulated privilege. The Act mandates a formal notification process that serves as a prerequisite for the lawful processing of personal information, ensuring the Authority maintains a comprehensive Register of Data Processing (Section 23).

The Act differentiates between standard and high-risk processing activities:

Feature General Notification (Section 20) Special Authorization (Section 22)
Trigger Prior to starting any wholly or partly automated data processing operation. Processing that poses “specific risks” to the fundamental rights of individuals.
Prerequisite Mandatory for all controllers or representatives serving a specific purpose. Requires explicit approval from the Authority before commencement.
Public registry Listed in the public-facing Register of Data Processing. Subject to prior inspection of security and organizational measures (Section 21(3)).

Organizations are categorized into operational tiers which dictate fee structures and reporting depth. A licence or notification is valid for 12 months. Business continuity depends on the 3-month renewal rule: applications for renewal must be submitted at least three months prior to expiry. Failure to adhere to this window risks the immediate suspension of lawful processing rights.

A valid notification under Section 21 must include the legal basis for processing, the categories of data subjects, the sensitive nature of any data involved, retention periods, and planned transborder data flows. For cross-border transfers, the Authority assesses “adequacy” based on the third party’s reputation, the laws of the recipient country, and the professional security standards they observe (Section 28(2)).

So what? The 3-month renewal rule is a critical trap for the unprepared. Operating with an expired notification is a statutory offence. Organizations must integrate these regulatory dates into their enterprise risk-management calendars to prevent the catastrophic cessation of data-driven services.
03 What is the Data Protection Officer framework?

The DPO is the structural bridge between the organization, the data subject, and POTRAZ. Far from being a mere administrative role, the DPO is a legally mandated architect of privacy, required to act with total independence to ensure the organization meets its statutory duties.

While the Authority may exempt certain controllers from notification if a DPO is appointed, the appointment itself is mandatory for many tiers and must be formally communicated using Form DP2. Any change in the status, resignation, or replacement of a DPO must be notified to the Authority within 14 days.

The DPO’s duties (Section 20(6)) include:

  • Ensuring internal compliance with the Act and subsequent regulations.
  • Acting as the primary point of contact for data-subject requests (access, correction, deletion).
  • Whistleblower oversight: Per Section 31, the DPO is instrumental in managing the internal whistleblowing system and must ensure fairness, proportionality, and openness when employees report conduct contrary to the law.
So what? There is a profound risk in “dual-hatting” the DPO role. Appointing a Chief Information Officer or an internal auditor as DPO often creates a conflict of interest. A CIO focuses on data utility and system uptime, whereas a DPO must prioritize data-subject rights even if it hinders system efficiency. An independent DPO is the best defence against Section 31 liabilities, particularly the rule that an implicated person must be informed of an accusation as soon as possible.
04 What rights do data subjects have, and how is sensitive data protected?

The Act enforces a radical shift in the power dynamic between corporations and individuals. Data subjects are no longer passive participants; they are legally empowered owners of their information.

The five core rights (Section 14):

  1. Information: the right to know how and why data is used.
  2. Access: the right to obtain a copy of held information.
  3. Objection: the right to oppose processing, including an absolute right to object to direct marketing (Section 15) free of charge.
  4. Correction: the right to rectify false or misleading information.
  5. Deletion: the right to demand the removal of inaccurate or unlawfully held data.

While Section 10(2) allows for implied consent for non-sensitive data among adults, Section 11 sets a high bar for sensitive data (genetic, biometric, health, or racial origin), requiring explicit written consent. Section 11(5) provides narrow exceptions where consent is not required, including:

  • Compliance with employment-law obligations.
  • Protecting the vital interests of the subject if they are physically or legally incapable of consenting.
  • Processing data already made public by the subject.
  • National-security compliance or the defence of legal claims.

Under Sections 26 and 27, the rights of children (under 18) and the incapacitated are exercised exclusively by parents or legal guardians. Any processing of a child’s data is subject to the strictest oversight to prevent exploitation.

So what? The absolute right to object to direct marketing means that any commercial outreach strategy that does not include a free, simple opt-out mechanism is illegal. For the strategic marketer, this necessitates a move toward permission-based engagement to avoid regulatory friction.
05 What security standards and breach windows apply?

Section 18 mandates that controllers implement technical and organizational measures to safeguard data against unauthorized access, accidental loss, or alteration. Security is not a fixed target but a scalable obligation based on the “appropriate security level.”

In determining whether security is adequate, the Authority considers the current state of technological development, implementation costs, the sensitivity of the data, and the specific risks posed to data subjects.

To the Authority

Notify POTRAZ of any security breach within 24 hours using Form DP3 (Section 19).

To the data subject

Section 19 requires notification in high-risk cases. A 72-hour benchmark is best practice; only the 24-hour Authority rule is strictly statutory.

Under Section 18(5), a controller who subcontracts processing must have a written contract with the processor. The controller is legally liable for ensuring the processor maintains the same stringent security measures required by the Act.

So what? The 24-hour reporting rule is among the most aggressive in the world. It is designed for national cyber-readiness—allowing the State to respond to systemic threats. Failure to report within this window is a standalone statutory offence, regardless of whether the breach itself was preventable.
06 What offences, penalties, and criminal liability apply?

The Act introduces a dual-layer liability model: administrative fines for the entity and criminal imprisonment for individuals.

Violating sections related to sensitive data (11), security duties (18), or transborder flow (28) carries fines up to Level 11 and imprisonment for up to 7 years (Section 33).

The amended Criminal Law Code (Sections 163–164) targets specific acts:

  • Hacking: unauthorized access (Fine Level 10 / 5 years).
  • Unlawful acquisition of data: intercepting private transmissions (Fine Level 14 / 5 years).
  • Transmission of intimate images (164E): distribution without consent to cause humiliation (5 years).

Aggravating circumstances (Section 163F) escalate penalties to Level 14 fines or 20 years’ imprisonment if the offence involves essential services (banking, electricity), State security, or causes considerable economic loss.

Section 31 requires a whistleblowing system built on fairness, proportionality, and openness. Section 33(1) extends personal liability to staff, contractors, and experts of the Authority and the controller. That personal exposure makes internal whistleblowing systems and robust training a survival requirement for employees and executives alike.

Final statement Compliance with Chapter 12:07 is an ongoing architectural duty. Organizations that fail to implement these procedural and security mandates face a dual threat of financial ruin through Level 14 penalties and the personal imprisonment of their leadership. Faithfulness to the source law is the only path to digital resilience in Zimbabwe.

Definitions

01What is a Data Subject?

A Data Subject is an identifiable natural person whose personal information, often referred to as personal data, is collected, stored, or otherwise processed by an organization or individual in a manner that can identify them directly or indirectly.

02What is a Data Controller?

A Data Controller is an entity, either an organization or an individual, that determines the purposes and means by which personal data is collected, processed, stored, and managed.

03What is a Data Processor?

A Data Processor refers to a natural person or legal person, who processes data for and on behalf of the controller and under the controller’s instruction, except for the persons who, under the direct employment or similar authority of the controller, are authorised to process the data.

04What is a Data Protection Officer (DPO)?

A Data Protection Officer (DPO) is a professional responsible for overseeing data protection strategies and ensuring compliance with data protection laws and regulations. The DPO acts as a point of contact for data subjects and regulatory authorities, ensuring that data protection rights are respected and upheld.

General

01What is Processing of Personal Data?

Processing of Personal Data refers to any operation performed on personal data, whether automated or manual, including collection, recording, organization, storage, modification, retrieval, use, disclosure, dissemination, alignment, restriction, erasure, or destruction. It encompasses actions such as gathering data from individuals, structuring it for accessibility, updating or modifying it, sharing it with third parties, or deleting it when no longer needed.

02Which companies are exempt from licensing?

Companies that are exempt from licensing as a Data Controller under the Cyber & Data Protection Act should confirm their position against the Act and any POTRAZ exemption. If you process personal data for a defined purpose, assume notification applies until the Authority says otherwise.

03What rights do data subjects have?

Data subjects have several key rights under the Act:

  • Right to Access: request access to personal data held by organizations.
  • Right to Rectification: request corrections or updates if data is inaccurate or incomplete.
  • Right to Erasure / Right to be Forgotten: request deletion when the data is no longer necessary, consent is withdrawn, or processing is unlawful.
  • Right to Object: object to processing on specific grounds, including direct marketing.
  • Rights related to automated decision-making and profiling: object to automated decisions that significantly affect them, unless the decision is necessary for a contract, authorized by law, or based on explicit consent.
  • Right to Withdraw Consent: withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
04As a Data Controller, what are my obligations when I receive a data-subject request?
  • Respond promptly: reply without undue delay.
  • Provide access: give the data subject a copy of their personal data upon request.
  • Ensure accuracy: assess and correct or complete data when rectification is requested, then notify the subject.
  • Honour erasure: delete personal data where it is no longer necessary, consent is withdrawn, and no other legal basis remains.

Myth busting

01What if I don’t store any data in software systems?

Even if you don’t store data in software systems, you are still subject to data protection laws if you handle personal data in any form, including manual records. Personal data, whether digital or paper, must be processed securely and in compliance with applicable regulations.

02What if it is historical data or archives we no longer use?

If the data is historical or archived and no longer actively used, you are not necessarily exempt. Personal data still in your possession must be handled in accordance with data protection laws if it can identify an individual.

03What if I don’t know how to qualify the data and number of data subjects?

Start with a data audit. Assess the types, volume, and sensitivity of the data you process, whether it is actively used or archived, and the risk level. If uncertain, consult a data protection expert before choosing a licence tier.

04What if I just leave it? Surely the Authority cannot police everyone.

Neglecting your obligations as a data controller can lead to serious consequences. The Authority has the right to enforce the law. Non-compliance can lead to hefty fines and imprisonment.

05Can I claim I did not understand the law?

Claiming ignorance, misunderstanding, or a different interpretation is unlikely to be a valid defence. You are expected to know and comply with the Act. Ignorance is often treated as negligence and can lead to fines, imprisonment, and reputational damage.

06But the data I collect is mine. Can I do whatever I please?

Personal data is protected by law even if you collected it. The Cyber and Data Protection Act does not allow you to freely use or manipulate personal data as you please. You must handle it lawfully, securely, and transparently.

07Can the regulator decide which licence tier I should be in?

Yes. Under Section 7(1)(c) of the CDPA, POTRAZ has the legal mandate to determine and approve the appropriate licensing tier based on the nature and scale of your data-processing activities.

08What if I applied for a lower-tier licence, but the regulator approved a higher tier?

The regulator is not bound by your application. Applicants must provide accurate details about the volume of data subjects they process. If POTRAZ determines that your scale exceeds a lower tier, it can require a higher-tier licence.

09Can I challenge the regulator’s decision to place me in a higher tier?

Yes, but you bear the burden of proof. You must provide verifiable evidence that your processing fits a lower tier. The safer course is to comply, obtain the required licence, and seek clarification from a compliant position.

10Can I ignore the regulator’s decision and keep my preferred tier?

No. Operating with an incorrect licence is non-compliance and can lead to fines or imprisonment.

11Can I delete excess records and apply for a lower-tier licence?

Deleting records solely to fit a lower tier could be seen as an attempt to evade compliance. If an audit finds that you previously processed a higher volume of data subjects, you may still be required to keep the higher-tier licence.