Penalties

What happens if I do not report a data breach to POTRAZ?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Failing to notify POTRAZ within 24 hours is itself a breach of section 19 of the Cyber and Data Protection Act and of SI 155, on top of whatever security failure caused the incident. Breaching the security duty in section 18 carries the top penalty (level 11 or seven years), and breaches rarely stay secret.

What the law says

Section 19 requires notification to the Authority "within twenty-four (24) hours of any security breach"; SI 155 prescribes Form DP3, requires responses to POTRAZ's follow-up questions within 14 days, and, with POTRAZ's 2025 Breach Notification Guidelines, requires notification of affected individuals within 72 hours where the breach is likely to result in a high risk to them. Section 33 penalises breaches of the section 18 security duty at level 11 or seven years. Concealing a breach also undermines any argument that your measures were "appropriate".

Example

A Harare microfinance company's loan system is hacked and 12,000 borrowers' ID numbers and phone numbers are taken. Management decides to "fix it quietly". Three weeks later borrowers start receiving fraudulent EcoCash requests quoting their loan details and complain to POTRAZ and to the press. POTRAZ's investigation now covers the hack, the absence of a 24-hour notification, the absence of a 72-hour notice to borrowers, and the company's security. A competitor hit by the same gang notified POTRAZ within a day, warned its borrowers within two, and is treated as a victim that behaved correctly.

In practice

Have the breach plan and a pre-filled Form DP3 ready before anything happens. When something does, notify within 24 hours with what you know, say what is still being investigated, update POTRAZ as facts emerge, and tell affected people promptly with practical advice. Cooperation is your best mitigation.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.