Zimbabwe's Data Protection Act: What Every Business Must Do Now
In September 2024, Zimbabwe's government promulgated Statutory Instrument 155 of 2024 — the Data Protection (Registration of Data Controllers and Processors) Regulations. The regulations set a compliance deadline of 12 March 2025 for all organisations that collect, store, or process personal data to register with POTRAZ and appoint a Data Protection Officer.
That deadline has passed. Enforcement is now active.
If your business runs a website with a contact form, stores customer records, manages employee HR data, or operates any system that handles personal information about Zimbabwean citizens, this law applies to you. The penalties for non-compliance include fines and up to seven years in prison.
This post explains what the law requires, who it covers, what the registration process involves, and what you need to do if your business has not yet acted.
1. The Legal Framework: What Laws Are We Talking About?
Zimbabwe's data protection regime is built on two instruments:
The Cyber and Data Protection Act (CDPA), Chapter 12:07
The CDPA was passed by Parliament in 2021 and came into force in March 2022. It is the primary legislation governing how organisations collect, process, store, and transfer personal data in Zimbabwe. The Act:
- Defines personal data, data controllers, and data processors
- Sets out the rights of data subjects (the people whose data is being held)
- Establishes the obligations of organisations handling that data
- Creates POTRAZ (the Postal and Telecommunications Regulatory Authority of Zimbabwe) as the data protection regulator
- Sets out penalties for breaches
The CDPA sits alongside the Cybercrime and Cybersecurity Act of 2021, which covers criminal conduct in digital environments.
Statutory Instrument 155 of 2024
The CDPA established the framework, but the 2024 regulations put the compliance machinery in place. S.I. 155 of 2024 specifies:
- Who must register — all data controllers and processors
- How to register — the process and documentation required
- How much it costs — tiered licence fees based on organisation size
- When to register — the March 12, 2025 deadline
- Consequences of not registering — criminal and civil penalties
2. Does This Apply to Your Business?
The short answer for most Zimbabwean businesses is yes. The law applies to any organisation — private company, NGO, government entity, or individual — that:
- Collects personal data from customers, users, employees, or any other individuals
- Stores personal data on any system — a spreadsheet, a database, a cloud platform, a paper file
- Processes personal data in any way — analysing it, sharing it, using it to send communications
Personal data under the CDPA means any information that can be used to identify a living person: names, phone numbers, email addresses, ID numbers, physical addresses, biometric data, financial records, location data, IP addresses, and more.
Common business scenarios that trigger compliance
| Business Type | What Triggers It |
|---|---|
| E-commerce website | Customer names, addresses, purchase history |
| Restaurant / retail | Loyalty programme data, payment records |
| Professional services firm | Client contact details, engagement records |
| HR department (any company) | Employee records, payroll data, leave records |
| School or university | Student enrolment data, academic records |
| Healthcare provider | Patient records, medical history |
| NGO | Beneficiary data, donor information |
| Software developer / SaaS company | User accounts, usage logs, any data from your clients' systems |
| Marketing agency | Contact lists, campaign response data |
| Property or rental business | Tenant personal details, identity documents |
If you operate any of the above — or anything similar — the law applies to you regardless of your company size.
3. What the Law Requires You to Do
Step 1: Determine Your Role — Controller or Processor?
The CDPA distinguishes between two types of organisations:
Data Controller — an organisation that decides why and how personal data is collected and used. If you run a customer database and decide what information to collect and what to do with it, you are a data controller.
Data Processor — an organisation that processes data on behalf of a controller. If you are a software company that hosts a system for a client and their customer data sits in your infrastructure, you are a data processor in relation to that client's data (and possibly a controller for your own user data).
Many organisations are both — a company with its own customer database is a controller, and if it also handles data for clients, it is a processor in that capacity. Both roles require registration.
Step 2: Register with POTRAZ
All data controllers and processors must register with POTRAZ through its data protection portal. Registration requires submitting:
- Organisation details — company name, registration number, physical address, contact details
- Description of processing activities — what categories of personal data you handle and for what purposes
- Security measures — a description of the technical and organisational security measures in place to protect the data
- Data Protection Officer details — name and contact information for the DPO you have appointed (see Step 3)
- Payment of the applicable licence fee
Licences are valid for 12 months and must be renewed annually.
Step 3: Appoint a Data Protection Officer (DPO)
Every registered organisation must appoint a Data Protection Officer — a designated person responsible for overseeing data protection compliance within the organisation. The DPO:
- Monitors the organisation's compliance with the CDPA
- Acts as the point of contact with POTRAZ
- Receives and responds to data subject requests (requests from individuals to access, correct, or delete their data)
- Advises the organisation on data protection obligations
- Investigates and reports data breaches
The DPO does not have to be a lawyer, but they should understand both the organisation's data processing activities and the requirements of the CDPA. For smaller organisations, the DPO role can be assigned to an existing employee alongside their other duties. For organisations handling particularly sensitive data (healthcare, financial services), a more specialist DPO is advisable.
The DPO's contact details must be published — accessible to employees and customers so they know who to contact about data protection matters.
Step 4: Audit Your Data Processing Activities
Before or alongside registration, every organisation should conduct a data mapping exercise — identifying:
- What categories of personal data you hold
- Where it is stored (servers, cloud platforms, devices, paper files)
- Who has access to it internally
- Whether it is shared with third parties (suppliers, cloud service providers, payment processors)
- How long you retain it and when it is deleted
- What security measures protect it
This audit is both a compliance requirement (POTRAZ may request it during an inspection) and a practical foundation for implementing the CDPA's substantive requirements.
4. Licence Fees: What Registration Costs
S.I. 155 of 2024 establishes tiered registration fees based on the size and nature of the organisation:
| Tier | Organisation Type | Annual Fee (USD) |
|---|---|---|
| Tier 1 | Small organisations / sole traders | $50 |
| Tier 2 | Medium-sized organisations | $250 |
| Tier 3 | Large organisations | $1,000 |
| Tier 4 | Very large organisations / those handling sensitive data at scale | $2,500 |
The tier applicable to a given organisation depends on factors including revenue, number of data subjects, and sensitivity of the data processed. POTRAZ guidance should be consulted to determine the correct tier for your organisation. For most SMEs, Tier 1 or Tier 2 applies.
5. The Substantive Data Protection Obligations
Registration is not the end of compliance — it is the beginning. The CDPA imposes ongoing obligations on all registered controllers and processors:
Lawful Basis for Processing
You must have a lawful basis for collecting and using personal data. The main lawful bases under the CDPA are:
- Consent — the data subject has given clear, informed, freely given consent
- Contract — processing is necessary to fulfil a contract with the data subject
- Legal obligation — processing is required by law (e.g. tax records)
- Legitimate interests — processing is necessary for legitimate business purposes, balanced against the data subject's rights
Collecting data "just in case it might be useful later" is not a lawful basis.
Data Subject Rights
The CDPA gives individuals rights over their personal data that organisations must be able to fulfil:
- Right of access — individuals can request to see what data you hold about them
- Right to correction — individuals can request that inaccurate data be corrected
- Right to deletion ("right to be forgotten") — individuals can request deletion of their data in certain circumstances
- Right to object — individuals can object to certain types of processing, including direct marketing
- Right to data portability — individuals can request their data in a machine-readable format
Your systems and processes must be capable of responding to these requests. If a customer emails asking to see all the data you hold about them, you need to be able to produce it.
Data Breach Notification
If personal data is breached — accessed, lost, disclosed, or destroyed without authorisation — the CDPA requires you to notify POTRAZ and, where appropriate, the affected data subjects. Breach notification must happen within 72 hours of becoming aware of the breach where feasible.
Data Transfers
Transferring personal data outside Zimbabwe to third-party service providers (cloud platforms, international payment processors, offshore analytics tools) must comply with the CDPA's provisions on cross-border data transfers. Where a recipient country does not have equivalent data protection standards, additional safeguards are required.
6. Penalties for Non-Compliance
The CDPA and S.I. 155 of 2024 carry serious consequences for non-compliance:
- Failure to register: criminal offence, fine and/or up to 7 years imprisonment
- Breach of data protection principles: civil and criminal liability
- Failure to notify a breach: penalty determined by POTRAZ
- POTRAZ enforcement actions: audits, investigations, enforcement notices, suspension of processing activities
POTRAZ has the power to conduct inspections, demand documentation, and issue enforcement notices. Following the March 2025 registration deadline, POTRAZ has signalled that it will move from awareness-building to active enforcement — targeting organisations that have not registered and investigating complaints from data subjects.
The 7-year imprisonment provision is not a hypothetical — it reflects the severity with which the Zimbabwean legislature treated deliberate non-compliance with data protection obligations.
7. What This Means if You Build Software
If you are a software developer, technology company, or digital agency, the CDPA has additional layers of relevance beyond your own data handling obligations:
You Are Probably a Data Processor for Your Clients
If you build, host, or maintain any system that stores your clients' customer or employee data, you are a data processor under the CDPA. This means:
- You must be registered with POTRAZ in your own right as a processor
- Your contracts with clients should include a Data Processing Agreement (DPA) — a formal document specifying how you will handle their data, what security measures you maintain, and what you will do in the event of a breach
- You cannot use the client data you process for any purpose other than what the client has authorised
You Must Build Compliant Systems for Clients
If you build software for clients that collect or process personal data, that software should be built with privacy by design — data protection built in from the architecture stage, not bolted on afterwards. This includes:
- Collecting only the minimum data necessary for the stated purpose
- Encrypting personal data at rest and in transit
- Building access controls so only authorised personnel can access personal data
- Logging access and changes to sensitive records
- Building deletion workflows so personal data can be removed when no longer needed
- Making it easy for the client to respond to data subject requests
Clients who are later found non-compliant because of gaps in systems you built for them will hold you accountable. Getting privacy-by-design right protects both your clients and your own commercial relationships.
8. What to Do Right Now
If your business has not yet registered, here is the practical checklist:
- Go to POTRAZ's data protection portal and create an organisation account
- Conduct a basic data audit — list every type of personal data you collect, where it is stored, and who accesses it
- Designate a DPO — identify the person in your organisation who will take on this responsibility and ensure they understand the role
- Determine your licence tier — assess which tier applies based on your organisation's size and data processing volume
- Complete the registration application and pay the annual fee
- Update your privacy policy — your website and any apps you operate should have a current privacy policy explaining what data you collect, why, and how individuals can exercise their rights
- Implement a breach response plan — so you know exactly what to do if data is compromised, within the 72-hour notification window
- Review any third-party data processors — cloud providers, payment gateways, email platforms — and ensure appropriate data processing agreements are in place
Conclusion
Zimbabwe's Data Protection Act is not new — the framework has been in place since 2022. What changed in 2024 was the activation of the registration regime that makes compliance a legal requirement with criminal consequences. The March 2025 deadline has passed, and POTRAZ is now in enforcement mode.
For most Zimbabwean businesses, the cost and effort of compliance is manageable — a Tier 1 registration costs $50 per year, and the DPO appointment can be an internal role. The risk of ignoring it, however, is not manageable.
At Genesisoft, we build systems for Zimbabwean businesses that handle personal data every day — customer portals, HR platforms, e-commerce systems, mobile apps. Every system we build incorporates data protection principles from the architecture stage. If you need help understanding what the CDPA means for your specific software systems, or if you are building something new and want to ensure it is compliant from day one, reach out to our team.
Need a technical review of your platform's data protection posture, or building a new system that will handle personal data? Get in touch with the Genesisoft team — we build compliant-by-design software for Zimbabwean businesses.
Genesisoft Team
Genesisoft Team
The Genesisoft team writes about web development, AI, mobile apps, and digital transformation for Zimbabwean businesses.