Notify POTRAZ of any security breach within 24 hours using Form DP3 (Section 19).
Knowledge hub
Compliance with the Zimbabwe Cyber and Data Protection Act [Chapter 12:07] and S.I. 155 of 2024.
A counsel brief on the Authority, licensing, the DPO, data-subject rights, security, and penalties.
The enactment of the Cyber and Data Protection Act [Chapter 12:07] represents a strategic pivot from an era of unregulated data processing to a formal, statutory-led digital economy. For any enterprise operating in Zimbabwe, this framework is the bedrock of institutional trust. By harmonizing the secure use of Information and Communication Technologies (ICTs) with the fundamental rights enshrined in the Constitution—specifically the Section 57 Right to Privacy—the Act provides the legal certainty required for both domestic growth and international digital trade.
Under Section 5, the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is designated as the Data Protection Authority. Its powers are extensive and designed for active oversight:
As defined in Section 2, the primary object of the Act is to increase cybersecurity to build confidence and trust in the secure use of ICTs by data controllers, their representatives, and data subjects. It serves to protect the Declaration of Rights while fostering a technology-driven business environment.
In the Zimbabwean jurisdiction, automated processing is not a default right; it is a regulated privilege. The Act mandates a formal notification process that serves as a prerequisite for the lawful processing of personal information, ensuring the Authority maintains a comprehensive Register of Data Processing (Section 23).
The Act differentiates between standard and high-risk processing activities:
| Feature | General Notification (Section 20) | Special Authorization (Section 22) |
|---|---|---|
| Trigger | Prior to starting any wholly or partly automated data processing operation. | Processing that poses “specific risks” to the fundamental rights of individuals. |
| Prerequisite | Mandatory for all controllers or representatives serving a specific purpose. | Requires explicit approval from the Authority before commencement. |
| Public registry | Listed in the public-facing Register of Data Processing. | Subject to prior inspection of security and organizational measures (Section 21(3)). |
Organizations are categorized into operational tiers which dictate fee structures and reporting depth. A licence or notification is valid for 12 months. Business continuity depends on the 3-month renewal rule: applications for renewal must be submitted at least three months prior to expiry. Failure to adhere to this window risks the immediate suspension of lawful processing rights.
A valid notification under Section 21 must include the legal basis for processing, the categories of data subjects, the sensitive nature of any data involved, retention periods, and planned transborder data flows. For cross-border transfers, the Authority assesses “adequacy” based on the third party’s reputation, the laws of the recipient country, and the professional security standards they observe (Section 28(2)).
The DPO is the structural bridge between the organization, the data subject, and POTRAZ. Far from being a mere administrative role, the DPO is a legally mandated architect of privacy, required to act with total independence to ensure the organization meets its statutory duties.
While the Authority may exempt certain controllers from notification if a DPO is appointed, the appointment itself is mandatory for many tiers and must be formally communicated using Form DP2. Any change in the status, resignation, or replacement of a DPO must be notified to the Authority within 14 days.
The DPO’s duties (Section 20(6)) include:
The Act enforces a radical shift in the power dynamic between corporations and individuals. Data subjects are no longer passive participants; they are legally empowered owners of their information.
The five core rights (Section 14):
While Section 10(2) allows for implied consent for non-sensitive data among adults, Section 11 sets a high bar for sensitive data (genetic, biometric, health, or racial origin), requiring explicit written consent. Section 11(5) provides narrow exceptions where consent is not required, including:
Under Sections 26 and 27, the rights of children (under 18) and the incapacitated are exercised exclusively by parents or legal guardians. Any processing of a child’s data is subject to the strictest oversight to prevent exploitation.
Section 18 mandates that controllers implement technical and organizational measures to safeguard data against unauthorized access, accidental loss, or alteration. Security is not a fixed target but a scalable obligation based on the “appropriate security level.”
In determining whether security is adequate, the Authority considers the current state of technological development, implementation costs, the sensitivity of the data, and the specific risks posed to data subjects.
Notify POTRAZ of any security breach within 24 hours using Form DP3 (Section 19).
Section 19 requires notification in high-risk cases. A 72-hour benchmark is best practice; only the 24-hour Authority rule is strictly statutory.
Under Section 18(5), a controller who subcontracts processing must have a written contract with the processor. The controller is legally liable for ensuring the processor maintains the same stringent security measures required by the Act.
The Act introduces a dual-layer liability model: administrative fines for the entity and criminal imprisonment for individuals.
Violating sections related to sensitive data (11), security duties (18), or transborder flow (28) carries fines up to Level 11 and imprisonment for up to 7 years (Section 33).
The amended Criminal Law Code (Sections 163–164) targets specific acts:
Aggravating circumstances (Section 163F) escalate penalties to Level 14 fines or 20 years’ imprisonment if the offence involves essential services (banking, electricity), State security, or causes considerable economic loss.
Section 31 requires a whistleblowing system built on fairness, proportionality, and openness. Section 33(1) extends personal liability to staff, contractors, and experts of the Authority and the controller. That personal exposure makes internal whistleblowing systems and robust training a survival requirement for employees and executives alike.
A Data Subject is an identifiable natural person whose personal information, often referred to as personal data, is collected, stored, or otherwise processed by an organization or individual in a manner that can identify them directly or indirectly.
A Data Controller is an entity, either an organization or an individual, that determines the purposes and means by which personal data is collected, processed, stored, and managed.
A Data Processor refers to a natural person or legal person, who processes data for and on behalf of the controller and under the controller’s instruction, except for the persons who, under the direct employment or similar authority of the controller, are authorised to process the data.
A Data Protection Officer (DPO) is a professional responsible for overseeing data protection strategies and ensuring compliance with data protection laws and regulations. The DPO acts as a point of contact for data subjects and regulatory authorities, ensuring that data protection rights are respected and upheld.
Processing of Personal Data refers to any operation performed on personal data, whether automated or manual, including collection, recording, organization, storage, modification, retrieval, use, disclosure, dissemination, alignment, restriction, erasure, or destruction. It encompasses actions such as gathering data from individuals, structuring it for accessibility, updating or modifying it, sharing it with third parties, or deleting it when no longer needed.
Companies that are exempt from licensing as a Data Controller under the Cyber & Data Protection Act should confirm their position against the Act and any POTRAZ exemption. If you process personal data for a defined purpose, assume notification applies until the Authority says otherwise.
Data subjects have several key rights under the Act:
Even if you don’t store data in software systems, you are still subject to data protection laws if you handle personal data in any form, including manual records. Personal data, whether digital or paper, must be processed securely and in compliance with applicable regulations.
If the data is historical or archived and no longer actively used, you are not necessarily exempt. Personal data still in your possession must be handled in accordance with data protection laws if it can identify an individual.
Start with a data audit. Assess the types, volume, and sensitivity of the data you process, whether it is actively used or archived, and the risk level. If uncertain, consult a data protection expert before choosing a licence tier.
Neglecting your obligations as a data controller can lead to serious consequences. The Authority has the right to enforce the law. Non-compliance can lead to hefty fines and imprisonment.
Claiming ignorance, misunderstanding, or a different interpretation is unlikely to be a valid defence. You are expected to know and comply with the Act. Ignorance is often treated as negligence and can lead to fines, imprisonment, and reputational damage.
Personal data is protected by law even if you collected it. The Cyber and Data Protection Act does not allow you to freely use or manipulate personal data as you please. You must handle it lawfully, securely, and transparently.
Yes. Under Section 7(1)(c) of the CDPA, POTRAZ has the legal mandate to determine and approve the appropriate licensing tier based on the nature and scale of your data-processing activities.
The regulator is not bound by your application. Applicants must provide accurate details about the volume of data subjects they process. If POTRAZ determines that your scale exceeds a lower tier, it can require a higher-tier licence.
Yes, but you bear the burden of proof. You must provide verifiable evidence that your processing fits a lower tier. The safer course is to comply, obtain the required licence, and seek clarification from a compliant position.
No. Operating with an incorrect licence is non-compliance and can lead to fines or imprisonment.
Deleting records solely to fit a lower tier could be seen as an attempt to evade compliance. If an audit finds that you previously processed a higher volume of data subjects, you may still be required to keep the higher-tier licence.