What are the data protection fines in Zimbabwe in US dollars?
Short answer
Zimbabwe's Cyber and Data Protection Act uses the Standard Scale of Fines: level 7 is USD 400, level 11 is USD 1,000 and level 14 (used for cybercrimes such as hacking) is USD 5,000, payable in local currency at the interbank rate. The dollar amounts are small; the same offences carry imprisonment of up to two, seven or ten years and more.
What the law says
The Criminal Law (Codification and Reform) (Standard Scale of Fines) Notice, SI 14A of 2023, sets level 1 at USD 5 rising to level 14 at USD 5,000, with level 7 at USD 400 and level 11 at USD 1,000; the notice states that fines are "expressed in United States dollars but payable in the equivalent Zimbabwean dollars at the prevailing interbank rate", and Government updates the scale from time to time. Section 33 of the Act attaches level 7 / two years to staff who process contrary to instructions and level 11 / seven years to controllers who breach the core duties; SI 155 attaches the same two levels to the DPO and licence offences. The cybercrime sections (163 and following) go up to level 14 with ten to twenty years.
Example
A Bulawayo retailer calculates that the "fine for no licence is only USD 1,000" and budgets for it instead of complying. Its lawyer points out that the same section allows seven years' imprisonment "or both", that a conviction gives the company and possibly its directors a criminal record, that POTRAZ can suspend its licence, and that its insurer's cyber policy excludes losses arising from unlicensed processing. The USD 1,000 was never the real number.
In practice
Read the penalties as "criminal offence" rather than as a price list. The financial exposure that matters is the disruption of a stop order, the cost of a breach handled badly and the loss of customers who ask whether you are licensed.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.