Specific CDPA obligations: privacy notices, consent, contracts, breaches, CCTV, children
Fifteen questions on what compliance actually requires. Privacy notices, lawful grounds and consent, processor contracts, the 24-hour breach notification, subject access requests, erasure against tax retention, biometrics, CCTV signage, children's data, DPIAs and foreign hosting.
The licence and the DPO appointment are the visible part of compliance. The obligations in this section are the part an inspector actually reads: the notice on your website, the ground you rely on to process payroll, the clause in your accountant's contract, the record of processing activities, and the calendar you follow when a laptop goes missing.
Do I need a privacy notice on my website and forms in Zimbabwe?
Yes. Sections 15 and 16 of the Cyber and Data Protection Act require you to tell people, when you collect their information, who you are, why you are collecting it, whether answering is compulsory, who you will share it with, and their rights to access and correct their data and to object. One plain-language page, plus a short line on paper forms and a notice at your counter, does the job.
Section 15 applies where data is collected directly from the person and requires the controller to provide, at the latest at the time of collection, its identity and address, the purposes of processing, "the existence of the right to object, by request and free of charge" to processing for direct marketing, whether replying is compulsory …
Do I need consent to process personal data under Zimbabwe's CDPA, including payroll?
Not for everything. Consent is the main ground under section 10 of the Cyber and Data Protection Act, but the section also allows processing without consent to comply with a legal obligation, to protect vital interests, for public-interest tasks, where the data is evidence in proving an offence, and for your legitimate interests where they do not override the person's rights. Payroll rests on your legal duties and legitimate interests plus the agreement the employee gave when hired.
Section 10 provides that personal information "may only be processed if the data subject or a competent person … consents to the processing", and then lists the exceptions: processing necessary for "compliance with an obligation to which the controller is subject by … a law", for "protecting the vital interests of the data subject", for "…
Do I need written contracts with my accountant, payroll bureau and IT company under SI 155?
Yes. Section 10 of SI 155 of 2024 requires a written data processing agreement between the data controller and every data processor, and section 18 of the Cyber and Data Protection Act requires the controller to bind processors by contract to appropriate security. Your accountant, payroll bureau, IT company, cloud provider, courier and marketing agency are all processors if they handle personal information for you.
Section 18 requires the controller to choose a processor providing sufficient guarantees of technical and organisational security and to ensure, by contract, that the processor acts only on the controller's instructions. Section 10 of SI 155 lists among the controller's obligations maintaining a "written data processing agreement or contr…
Do I have to report every data breach to POTRAZ within 24 hours?
To POTRAZ, yes. Section 19 of the Cyber and Data Protection Act requires the data controller to notify the Authority within 24 hours of any security breach affecting the data it processes, on Form DP3. To the affected individuals, notification is required within 72 hours only where the breach is likely to result in a high risk to their rights and freedoms.
Section 19: "The data controller shall notify the Authority within twenty-four (24) hours of any security breach affecting data he or she processes." SI 155 prescribes Form DP3, requires the controller to answer POTRAZ's follow-up information requests within 14 days, and provides for POTRAZ to close its investigation within 21 days of not…
Do I have to give a customer all the data I hold about them (data subject access request)?
Yes. Section 14 of the Cyber and Data Protection Act gives every person the right to access their personal information, to have false or misleading data corrected or deleted, and to object to processing. Verify their identity, search all your systems, give them their data with the purposes and recipients, and do it promptly; the first copy should be free.
Section 14 lists the data subject's rights: to "be informed of the use to which their personal information is to be put", to "access their personal information in custody of data controller or data processor", to "object to the processing of all or part of their personal information", to "correction of false or misleading personal informa…
Must I delete a customer's data on request if I need it for tax records?
No, not the records the law requires you to keep. Deletion rights under section 14 of the Cyber and Data Protection Act cover data that is false, misleading, excessive or held without a lawful basis; they do not override statutory retention duties under tax, labour or other laws. Explain what you must keep, stop every other use, and delete the rest.
Section 14 gives the right to "deletion of false or misleading data" and to object to processing; section 7 requires that data be kept "for no longer than necessary" for the purpose. Section 10 allows processing without consent where necessary "for compliance with an obligation to which the controller is subject by … a law", which include…
Is written consent required for fingerprint or biometric attendance systems in Zimbabwe?
Yes. Biometric data is sensitive data under sections 11 and 12 of the Cyber and Data Protection Act. You need written consent from each employee, or a basis in employment law, plus a notification to POTRAZ under SI 155 of 2024 that you process biometric data. Be ready to show why a less intrusive method was not enough.
Section 11 provides that "no data controller shall process sensitive data unless the data subject has given consent in writing", with narrow exceptions including obligations under employment law. Section 12 specifically governs genetic, biometric and health data and repeats the written-consent rule with its own list of exceptions. Section…
Do I need CCTV signs under Zimbabwe's data protection law?
Yes. CCTV footage of identifiable people is personal information under the Cyber and Data Protection Act, so you must tell people they are being recorded and by whom, have a clear purpose, limit who can view footage and keep it only for a short period. Visible signs at the entrance are how you meet the information duty.
Sections 15 and 16 require the controller to inform data subjects of its identity and the purpose of processing at the time of collection; for CCTV that is a sign at the point where people enter the camera's view. Section 7 requires that data be adequate, relevant, not excessive and kept no longer than necessary, which rules out cameras i…
Is parental consent required for children's data under Zimbabwe's CDPA?
Yes. A child under the Cyber and Data Protection Act is anyone under 18, and SI 155 of 2024 requires the consent of a parent or legal guardian before processing a child's personal information, regular data protection impact assessments, and data protection by design and by default. Automated profiling of children for advertising is prohibited outright.
Section 3 of the Act defines a child as "any person under the age of eighteen years", and section 26 provides that a child's rights under the Act are exercised by the parent or legal guardian. Section 10 of SI 155 lists the controller's obligations where children's data is processed: obtain "the consent of the parent or legal guardian", c…
Is a Data Protection Impact Assessment (DPIA) mandatory in Zimbabwe?
For children's data, yes: SI 155 of 2024 requires regular data protection impact assessments. More generally, risk assessments are part of the security measures every data controller must have under section 16 of SI 155, and a DPIA is the sensible way to show POTRAZ that you thought before starting any high-risk processing such as biometrics, location tracking, large health databases or profiling.
Section 10 of SI 155 requires "regular data protection impact assessments" where children's data is processed. Section 16 of SI 155 requires the controller's security measures to include "conducting risk assessments", "development and implementation of organisational policies" and regular testing. Section 14 of SI 155 makes advising on im…
Do I need POTRAZ approval to use Google Workspace, Microsoft 365 or a South African server?
You must notify POTRAZ, not seek permission for each transfer. Storing personal information outside Zimbabwe is a trans-border transfer under sections 28 and 29 of the Cyber and Data Protection Act. You need a lawful basis for the transfer, a written processing agreement with the provider, and you must notify POTRAZ of your international transfers as part of your processing activities.
Section 28 permits the transfer of personal information to a country that "ensures an adequate level of protection", assessed by reference to the nature of the data, the purpose and duration of processing, the recipient country's laws and the security measures in place. Section 29 permits transfers to countries without adequate protection…
Do I have to stop using WhatsApp for customer communication under the CDPA?
No, but you must control it. Use a WhatsApp Business account on a company-controlled number, keep customer lists in your own system rather than only in chats, give staff a simple rule that customer data never sits on personal phones or personal accounts, and delete conversations according to your retention rule.
Nothing in the Cyber and Data Protection Act names any messaging service; the duties are the general ones. Section 18 requires appropriate security (a personal phone with no lock, no backup and no company control fails that test). Section 15 requires you to tell people why you hold their number and that they can object to marketing free o…
Do I have to keep a record of processing activities under Zimbabwe's CDPA?
Yes, in practice. Section 10 of SI 155 of 2024 requires you to notify POTRAZ of your processing activities, your licence application must describe them, and a POTRAZ inspector's first document request is exactly this list. For most SMEs it fits on one page.
Section 10 of SI 155 obliges the controller to notify the Authority of "all processing activities", of modifications to indirectly collected data, of international transfers and of biometric or genetic processing. Section 24 of the Act requires the controller to be able to demonstrate compliance (accountability), and section 7 requires th…
Can I buy or use a purchased customer list under Zimbabwe's data protection law?
Only if the people knew and agreed. When you receive personal information from a third party you must still inform the individuals, at the latest when you first use the data, who you are, why you have it and their rights, and SI 155 of 2024 requires you to notify POTRAZ about modifications to indirectly collected data. Buying or selling customer lists without the people's knowledge is unlawful for both sides.
Section 16 of the Act imposes the information duties on a controller that obtains data other than directly from the data subject: identity, purposes, the categories of data, recipients and the existence of rights, to be given "at the time of recording or, if disclosure to a third party is envisaged, no later than the time of first disclos…
What is the right order: POTRAZ licence first, or Data Protection Officer first?
Both are required, but a sensible order exists. First appoint the Data Protection Officer and file Form DP2, because everything else is their job. Second apply for the POTRAZ data controller licence on Form DP1, because processing unlicensed is the most serious offence. Third build the evidence: processing record, privacy notice, processor contracts, security basics and the breach plan.
SI 155 requires both the licence and the DPO, and the licence application needs the DPO's details, which is why the DPO comes first in practice. The penalties point the same way: no licence is level 11 or seven years; no DPO is level 7 or two years; but the DPO is the person who will keep you out of every other offence in section 33 of th…
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.