Your obligations

Is a Data Protection Impact Assessment (DPIA) mandatory in Zimbabwe?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

For children's data, yes: SI 155 of 2024 requires regular data protection impact assessments. More generally, risk assessments are part of the security measures every data controller must have under section 16 of SI 155, and a DPIA is the sensible way to show POTRAZ that you thought before starting any high-risk processing such as biometrics, location tracking, large health databases or profiling.

What the law says

Section 10 of SI 155 requires "regular data protection impact assessments" where children's data is processed. Section 16 of SI 155 requires the controller's security measures to include "conducting risk assessments", "development and implementation of organisational policies" and regular testing. Section 14 of SI 155 makes advising on impact assessments a DPO function. Section 24 of the Act requires the controller to demonstrate accountability, which a documented DPIA does directly.

Example

A Harare bus company plans to install GPS trackers and in-cab cameras in 80 buses to monitor drivers. The DPO runs a three-page DPIA: what is processed (location, video of drivers and passengers), why (safety, fuel theft), legal basis (legitimate interests and staff consent for the cab camera), risks (constant surveillance of drivers, passengers filmed without notice, footage misuse), and mitigations (cameras face the road not the cab except on incident, signs on buses, 14-day retention, access limited to two managers, staff consultation). Management signs it. When the drivers' union raises the issue, the company has an answer; when POTRAZ asks, it has a document.

In practice

Do a DPIA whenever a new system involves children, health, biometrics, location, large volumes, profiling or sharing with new parties. Keep it short and honest: what, why, what could go wrong for people, what you will do about it, who signed off. Our compliance software includes a Zimbabwean DPIA template built around SI 155.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.