Compliance tools

Can I use Excel, Google Sheets and WhatsApp for customer data under Zimbabwe's CDPA?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Excel and Google Sheets, yes, provided access is limited, files are protected and you can show a retention rule. WhatsApp is the dangerous one: customer lists on staff members' personal phones mean no control, no deletion when they leave and no way to answer a customer's access request under section 14 of the Cyber and Data Protection Act.

What the law says

Section 18 requires "appropriate technical and organisational measures" against loss and unauthorised access; the measures must fit the risk, not a particular brand of software. Section 7 requires that data be kept accurate and no longer than necessary. Section 14 gives every person the right to access, correct and delete their information, which you can only honour if you know where it is. Section 19 makes a lost phone with customer data a breach notifiable within 24 hours. Google Sheets stored abroad also engages sections 28 and 29 on trans-border transfers.

Example

A wedding-hire business in Harare keeps its 900 past clients in a Google Sheet shared with two staff, password-protected, backed up, with a rule that entries older than three years are deleted each January, and a privacy line on its booking form. That is a proportionate, defensible setup for a Tier 1 controller. Its competitor keeps the same information in three employees' personal WhatsApp chats; when one employee leaves and starts her own business with the contacts, the competitor cannot even list what was taken.

In practice

Business data lives only on business-controlled accounts and devices: a company Google Workspace or Microsoft account with two-factor authentication, a WhatsApp Business number owned by the company, and a written rule that customer data never sits in personal chats. Record where each dataset lives in your processing record so that access requests and deletion can actually be done.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.