Penalties

What are the consequences of CDPA non-compliance for directors and managers?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Offences under the Cyber and Data Protection Act and SI 155 of 2024 can be prosecuted against the data controller and, depending on the facts, against the officers who caused or permitted the contravention. POTRAZ's 2026 enforcement messaging speaks of fines or prison for responsible executives; boards should therefore govern the issue and minute that they did.

What the law says

Section 33 imposes imprisonment as well as fines, and imprisonment can only be served by individuals; Zimbabwean criminal law applies corporate offences to the directors and officers who knew of and consented to them. Section 24 requires the controller to demonstrate accountability, which in a company means governance at board level. Separately, the cybercrime offences in the Act (unlawful acquisition, disclosure or interference with data, sections 163A and following) can be committed personally by a manager who, for example, takes a customer database to a new employer.

Example

The board of a Harare insurance broker receives the DPO's quarterly report showing that two processors have not signed agreements and that the licence renewal is due; it minutes a decision to complete both within 30 days and does so. A year later an inspector asks how the board oversees data protection; the minutes answer the question. At another broker, the DPO's reports were never tabled and the renewal lapsed; the directors' claim that they "left it to compliance" is exactly the kind of statement that shows they permitted the failure.

In practice

Add CDPA compliance to the board or management agenda at least quarterly: licence status, DPO report, incidents, training, open risks. Approve the budget, record the decisions, and keep the minutes with the compliance file.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.