Who must comply

Does the Cyber and Data Protection Act cover paper records in Zimbabwe?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes. The Cyber and Data Protection Act covers paper records that form part of a filing system, not only data on computers. Customer application forms, visitors' books, credit ledgers and staff files in a cabinet are all "processing" of personal information under Zimbabwean law.

What the law says

The Act applies to the processing of personal information "wholly or partly by automated means" and to non-automated processing where the information forms part of, or is intended to form part of, a filing system. The security duty in section 18 requires "appropriate technical and organisational measures" against loss, destruction and unauthorised access; for paper that means locks, access rules and shredding rather than encryption. The 24-hour breach notification duty in section 19 applies to a lost box of files just as to a hacked server.

Example

A private school in Marondera keeps admission forms for 400 pupils (including birth certificates, parents' IDs and medical conditions) in an unlocked storeroom. A former clerk removes a box of files during a salary dispute. That is a security breach involving children's data and health data. The school must notify POTRAZ within 24 hours and, because the risk to the families is high, notify the parents within 72 hours. The fact that nothing was on a computer changes nothing.

In practice

List your paper holdings in your record of processing activities, lock cabinets, limit keys, keep a visitors' book that does not display previous visitors' details, and shred records when the retention period ends. Where possible, scan and destroy paper you must keep long-term, so that access can be controlled and logged.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.