Does the CDPA apply to sole traders and informal traders in Zimbabwe?
Short answer
Yes. The Cyber and Data Protection Act applies to sole traders and informal traders in Zimbabwe because it covers "any natural person or legal person" who decides why and how personal information is used. Being unregistered as a company does not take you outside the law.
What the law says
Section 3 defines the data controller as a natural or legal person, so an individual trading under their own name is covered. The only processing the Act and SI 155 leave outside the licence regime is for "personal, family or household affairs" (SI 155 section 8). A business activity is never "household", even when it is run from a kitchen table or a market stall.
Example
A hairdresser in Chitungwiza keeps 230 clients' names, numbers and appointment histories in her phone and sends WhatsApp reminders. A tuck-shop owner in Mbare runs a credit book with the names, numbers and amounts owed by 90 regulars. Both are data controllers with more than 50 data subjects; both are Tier 1 (USD 50 a year); and both are exposed if the phone or the book is lost or misused. The Act does not ask whether they have a company registration number.
In practice
For a very small trader, compliance is modest: a Tier 1 licence, a certified DPO (an external shared DPO is the sensible route, see Q40), a one-line privacy notice at the counter or in the WhatsApp profile, a phone lock and backup, and a habit of deleting old customer data. The cost of ignoring it is the same criminal offence that applies to a bank.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.