Knowledge base · 15 questions

Does Zimbabwe's Cyber and Data Protection Act apply to my business?

Fifteen questions on scope. Whether the Cyber and Data Protection Act reaches small businesses, sole traders, NGOs, churches, schools, B2B companies, paper files, WhatsApp lists and foreign sellers, and whether you are a data controller or a data processor.

Zimbabwe only · CDPA, SI 155 of 2024, Implementation Guidelines 2025 Reviewed 9 September 2026

Almost every question in this section has the same answer: yes, it applies. Zimbabwe's Cyber and Data Protection Act [Chapter 12:07] is drawn around what you do with people's information, not around how large you are, whether you make a profit, or whether the records sit on a server or in a filing cabinet. What changes with size is your POTRAZ licence tier, and therefore your fee.

Does the Cyber and Data Protection Act apply to small businesses in Zimbabwe?

Yes, the Cyber and Data Protection Act (CDPA) applies to small businesses in Zimbabwe. There is no small-business exemption in the Act or in SI 155 of 2024; what changes with size is the POTRAZ licence tier and therefore the fee, which starts at USD 50 a year.

Section 3 of the Act defines a data controller as any natural or legal person who determines the purpose and means of processing personal information, and the Act applies to processing "wholly or partly by automated means" as well as to manual filing systems. SI 155 of 2024 then requires every data controller to be licensed, and its First…

Read the full answer, with the law and an example

Do I need a POTRAZ data controller licence if I only have employees and no customer database?

Yes. If your employee records alone cover 50 or more people, you need a POTRAZ data controller licence. Staff files are personal information, and by holding them you are a data controller under Zimbabwe's Cyber and Data Protection Act.

"Personal information" under section 3 of the Act includes any information relating to an identifiable person, and the Act's section 11 list of sensitive data expressly covers health and criminal-history information, both of which sit in a typical HR file (sick notes, police clearances). SI 155's tiers are counted in "data subjects", not …

Read the full answer, with the law and an example

Is a business with fewer than 50 data subjects exempt from the POTRAZ licence in Zimbabwe?

Partly. The POTRAZ licence tiers in SI 155 of 2024 start at 50 data subjects, so a business holding data on fewer than 50 people does not fall into any fee tier and is not, on the face of the Regulations, required to hold a data controller licence. It is not, however, exempt from the Cyber and Data Protection Act itself.

The First Schedule to SI 155 defines Tier 1 as "a minimum of 50 or a maximum of 1000 data subjects". No tier covers 1 to 49, and no fee is listed for that range. But the Act's obligations (lawful processing under section 10, written consent for sensitive data under section 11, security under section 18, breach notification under section 1…

Read the full answer, with the law and an example

Does the CDPA apply to sole traders and informal traders in Zimbabwe?

Yes. The Cyber and Data Protection Act applies to sole traders and informal traders in Zimbabwe because it covers "any natural person or legal person" who decides why and how personal information is used. Being unregistered as a company does not take you outside the law.

Section 3 defines the data controller as a natural or legal person, so an individual trading under their own name is covered. The only processing the Act and SI 155 leave outside the licence regime is for "personal, family or household affairs" (SI 155 section 8). A business activity is never "household", even when it is run from a kitche…

Read the full answer, with the law and an example

Does data protection law in Zimbabwe apply to B2B companies with no consumer customers?

Yes. Zimbabwe's Cyber and Data Protection Act applies to B2B companies because they hold personal information about individuals even when their customers are companies: their own staff, the contact persons at each client, suppliers' representatives and any sole traders they deal with.

Personal information under section 3 is information about an identifiable natural person. A company's registration number, VAT number or turnover is not personal information. But "Tendai Moyo, Procurement Manager, +263 77…" is. The Act does not distinguish between consumer-facing and business-facing controllers; SI 155 counts data subject…

Read the full answer, with the law and an example

Does the Cyber and Data Protection Act cover paper records in Zimbabwe?

Yes. The Cyber and Data Protection Act covers paper records that form part of a filing system, not only data on computers. Customer application forms, visitors' books, credit ledgers and staff files in a cabinet are all "processing" of personal information under Zimbabwean law.

The Act applies to the processing of personal information "wholly or partly by automated means" and to non-automated processing where the information forms part of, or is intended to form part of, a filing system. The security duty in section 18 requires "appropriate technical and organisational measures" against loss, destruction and una…

Read the full answer, with the law and an example

Is keeping customer numbers on WhatsApp "processing personal data" under Zimbabwe's CDPA?

Yes. Saving a customer's number, sending a WhatsApp broadcast or keeping order history in a chat is "processing" personal information under Zimbabwe's Cyber and Data Protection Act. The law regulates what you do with people's information, not the tool you use to do it.

"Processing" in section 3 of the Act covers any operation on personal information, including collection, recording, storage, use, disclosure and erasure. Section 15 requires you to inform people, when you collect their data, of your identity, the purpose and their right to object, "by request and free of charge", to processing for direct …

Read the full answer, with the law and an example

Do NGOs, churches and schools need a POTRAZ data controller licence in Zimbabwe?

Yes. NGOs, churches, schools and sports clubs in Zimbabwe need a POTRAZ data controller licence and a Data Protection Officer. SI 155 of 2024 contains no exemption for non-profit organisations, and POTRAZ's 2026 inspection programme names them as priority sectors.

The Act defines the data controller by what it does (determining purposes and means), not by whether it makes a profit. Section 11 treats information revealing religious beliefs as sensitive data, so a church membership register is sensitive by definition and needs written consent. Section 3 defines a child as anyone under 18, and SI 155 …

Read the full answer, with the law and an example

Who is exempt from the POTRAZ data controller licence under SI 155 of 2024?

Very few organisations. Section 8 of SI 155 of 2024 exempts processing for personal, family or household affairs and processing purely for journalistic, historical or archival purposes, and treats law-enforcement processing separately. No trading business, NGO, school or clinic falls under any of these exemptions.

Section 8 of SI 155 lists the exempt purposes. It also adds that entities processing for law enforcement and journalistic purposes are still "required to register with the Authority, and to comply with data protection principles"; the exemption is from the ordinary licence and fee regime, not from the Act. Processing for historical or arc…

Read the full answer, with the law and an example

Does a foreign company selling online to Zimbabweans need to comply with the CDPA and POTRAZ?

Yes. A foreign company that collects and uses the personal information of people in Zimbabwe must comply with the Cyber and Data Protection Act for that processing, and POTRAZ expects it to be licensed and to appoint a Data Protection Officer who knows Zimbabwean law.

The Act regulates the processing of personal information in Zimbabwe and of Zimbabwean data subjects; its cybercrime chapter (section 166 of the amended Criminal Law Code) expressly extends jurisdiction to conduct affecting computer systems and people in Zimbabwe. SI 155 requires every data controller to hold a licence and appoint a DPO w…

Read the full answer, with the law and an example

Am I a data controller or a data processor under Zimbabwe's Cyber and Data Protection Act?

You are a data controller when you decide why and how personal information is processed, and a data processor when you handle it on another organisation's instructions. Most service businesses in Zimbabwe are both at the same time, and the distinction decides who needs a licence, who signs what contract and who reports a breach.

Section 3 of the Act defines the data controller as the person who determines the purpose and means of processing, and the data processor as the person who processes personal information on the controller's behalf. Section 18 requires the controller to choose a processor that provides sufficient security guarantees and to bind it by writt…

Read the full answer, with the law and an example

Who is responsible under the CDPA when agents or sales reps collect customer data for my business?

You are. If agents or commission sales people collect customer information for your business and you decide what happens to it, you are the data controller under the Cyber and Data Protection Act and they act on your behalf. Their mistakes are your data breaches, reportable to POTRAZ within 24 hours.

The controller is the person who determines the purpose and means of processing (section 3), which is you, not the agent. Section 18 requires you to ensure that anyone acting under your authority processes personal information only on your instructions and under appropriate security. Section 15 requires the person collecting the data to i…

Read the full answer, with the law and an example

Is there a turnover threshold for POTRAZ data protection registration in Zimbabwe?

No. There is no turnover or revenue threshold for POTRAZ data protection registration. SI 155 of 2024 sets the licence tiers by the number of people whose personal information you hold, not by turnover, staff count or company type.

The First Schedule to SI 155 defines the four tiers purely by data subjects: Tier 1 (50 to 1,000), Tier 2 (1,001 to 100,000), Tier 3 (100,001 to 500,000) and Tier 4 (more than 500,000). The Second Schedule attaches the fees (USD 50, 300, 500 and 2,500). Nothing in the Act or the Regulations refers to revenue, and nothing exempts start-ups…

Read the full answer, with the law and an example

When did the POTRAZ licence and DPO requirements start in Zimbabwe, and are they enforced?

The Cyber and Data Protection Act has been in force since December 2021, the POTRAZ licence and Data Protection Officer obligations came in with SI 155 on 13 September 2024, and POTRAZ started mandatory, risk-based inspections on 1 September 2026. The grace periods have expired.

SI 155 provides that "persons that are controlling data by the date of promulgation of these regulations shall submit their applications for a data controller licence within 6 months from the date of promulgation", which gave existing controllers until 12 March 2025. DPOs had to be appointed "within 90 days from the date of promulgation",…

Read the full answer, with the law and an example

Is POTRAZ data protection compliance really necessary or just another tax?

It is necessary, and it is not primarily a revenue measure. POTRAZ licence fees run from USD 50 to USD 2,500 a year depending on tier; the real weight of the Cyber and Data Protection Act is that it gives your customers and staff enforceable rights and gives POTRAZ the power to inspect and prosecute.

Section 33 of the Act makes contraventions of the core duties (sensitive data, section 11; controller duties, section 13; security, section 18; accountability, section 24; cross-border transfers, section 28) offences punishable by "a fine not exceeding level 11 or imprisonment for a period not exceeding seven years or both". SI 155 adds o…

Read the full answer, with the law and an example

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.