Your obligations

Is parental consent required for children's data under Zimbabwe's CDPA?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes. A child under the Cyber and Data Protection Act is anyone under 18, and SI 155 of 2024 requires the consent of a parent or legal guardian before processing a child's personal information, regular data protection impact assessments, and data protection by design and by default. Automated profiling of children for advertising is prohibited outright.

What the law says

Section 3 of the Act defines a child as "any person under the age of eighteen years", and section 26 provides that a child's rights under the Act are exercised by the parent or legal guardian. Section 10 of SI 155 lists the controller's obligations where children's data is processed: obtain "the consent of the parent or legal guardian", conduct "regular data protection impact assessments", implement "data protection by design and data protection by default", and refrain from automated profiling of children's behaviour for advertising.

Example

A Harare tutoring app enrols 3,000 pupils aged 12 to 17 directly, with their own phone numbers, and uses their study patterns to target ads for exam-prep products. Every element is a problem: no parental consent, no impact assessment, and prohibited advertising profiling. After redesign, a parent or guardian creates the account and consents, the app collects only what teaching requires, the DPO records an annual impact assessment, and advertising to pupils is switched off. A football academy in Bulawayo does the same on paper: a parental consent form at registration, medical information kept separately, and photos published only with written parental permission.

In practice

If you serve under-18s (schools, clubs, clinics, apps, churches' youth groups), build an age check and a parental-consent step, keep the consents, run a short impact assessment each year, and design your data collection to the minimum. Children's data also raises the stakes of any breach, so security and the 24-hour plan matter more.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.