Your obligations

Must I delete a customer's data on request if I need it for tax records?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

No, not the records the law requires you to keep. Deletion rights under section 14 of the Cyber and Data Protection Act cover data that is false, misleading, excessive or held without a lawful basis; they do not override statutory retention duties under tax, labour or other laws. Explain what you must keep, stop every other use, and delete the rest.

What the law says

Section 14 gives the right to "deletion of false or misleading data" and to object to processing; section 7 requires that data be kept "for no longer than necessary" for the purpose. Section 10 allows processing without consent where necessary "for compliance with an obligation to which the controller is subject by … a law", which includes the Income Tax Act's record-keeping requirements and labour-law retention rules. So the correct answer to a deletion request is usually partial: retain what the law requires, for as long as it requires, for that purpose only.

Example

A former customer of a Bulawayo electronics retailer asks for "everything about me to be deleted". The retailer must keep the invoices and hire-purchase agreement for the period required by tax law, so it tells him so in writing, confirms that his details have been removed from the marketing list and the loyalty programme, deletes the copy of his ID that it no longer needs, and records the request and its response. His remaining data is flagged "retention only: no marketing, no profiling".

In practice

Write a one-page retention schedule (customer accounts, invoices, staff files, applicants' CVs, CCTV, marketing lists) with the legal or business reason for each period. Then a deletion request becomes a routine: delete what the schedule allows, restrict what it does not, and explain both to the person.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.