Who must comply

Does a foreign company selling online to Zimbabweans need to comply with the CDPA and POTRAZ?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes. A foreign company that collects and uses the personal information of people in Zimbabwe must comply with the Cyber and Data Protection Act for that processing, and POTRAZ expects it to be licensed and to appoint a Data Protection Officer who knows Zimbabwean law.

What the law says

The Act regulates the processing of personal information in Zimbabwe and of Zimbabwean data subjects; its cybercrime chapter (section 166 of the amended Criminal Law Code) expressly extends jurisdiction to conduct affecting computer systems and people in Zimbabwe. SI 155 requires every data controller to hold a licence and appoint a DPO with "knowledge of national data protection laws" (section 13). Transfers of the data out of Zimbabwe are governed by sections 28 (adequate protection) and 29 (exceptions such as consent and contractual necessity).

Example

A South African e-commerce platform ships to Harare and Bulawayo, holds 30,000 Zimbabwean customer accounts, and runs its servers in Cape Town. For that processing it is a Tier 2 data controller (USD 300 a year), needs a DPO certified under the POTRAZ scheme (USD 1,450 for a non-citizen, or a certified Zimbabwean appointee), must notify POTRAZ of the international transfer, and must give Zimbabwean customers a privacy notice meeting sections 15 and 16. Its local courier partner will also be a data processor under a written agreement.

In practice

Appoint a local representative or a certified Zimbabwean DPO, apply on Forms DP1 and DP2, document the legal basis for the cross-border transfer, and expect Zimbabwean banks and payment providers to ask for the licence number.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.