Who must comply

Am I a data controller or a data processor under Zimbabwe's Cyber and Data Protection Act?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

You are a data controller when you decide why and how personal information is processed, and a data processor when you handle it on another organisation's instructions. Most service businesses in Zimbabwe are both at the same time, and the distinction decides who needs a licence, who signs what contract and who reports a breach.

What the law says

Section 3 of the Act defines the data controller as the person who determines the purpose and means of processing, and the data processor as the person who processes personal information on the controller's behalf. Section 18 requires the controller to choose a processor that provides sufficient security guarantees and to bind it by written contract; SI 155 section 10 repeats the requirement for a "written data processing agreement or contract". Liability for the processing rests with the controller, which is why processors' contracts matter.

Example

A payroll bureau in Harare processes salaries for 40 client companies covering 6,000 employees. For that data it is a processor: each client must sign a processing agreement with it, and if the bureau is hacked it must tell each client immediately so they can meet their own 24-hour POTRAZ deadline. For its own 15 staff and 40 client contacts, the bureau is a controller in its own right, needs its own Tier 1 licence and its own DPO. The same is true of IT hosting firms, call centres, debt collectors and marketing agencies.

In practice

Write down, for each activity, whether you decide the purpose (controller) or follow instructions (processor). License yourself as a controller for your own data, sign processing agreements in both directions, and make sure your breach plan covers both roles.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.