Penalties

Can POTRAZ enforce the CDPA against a foreign company?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Against your Zimbabwean operations, assets, local representatives and directors, yes; and the practical lever is market access, because Zimbabwean banks, payment providers and partners increasingly ask for a POTRAZ licence. Foreign firms serving Zimbabweans generally find it simpler to license, appoint a local Data Protection Officer and comply.

What the law says

The Act applies to the processing of personal information in Zimbabwe and of Zimbabwean data subjects, and its cybercrime chapter (section 166 of the amended Criminal Law Code) asserts jurisdiction over offences committed wholly or partly in Zimbabwe, by Zimbabwean nationals or residents, or against Zimbabwean computer systems. SI 155 licenses every data controller processing such data. Enforcement abroad depends on cooperation with foreign authorities (section 6 includes facilitating cross-border cooperation), but enforcement against local presence, local processors and local partners needs no cooperation at all.

Example

A Dubai-based betting platform takes deposits from 40,000 Zimbabweans through local payment aggregators. It has no POTRAZ licence. In 2026 the aggregators, themselves inspected as financial institutions, ask every merchant for its data controller licence and DPO details and suspend those that cannot provide them. The platform's Zimbabwean revenue stops until it licenses (Tier 2), appoints a certified local DPO and documents the cross-border transfer under sections 28 and 29.

In practice

If you serve Zimbabwean customers from abroad, appoint a local representative and a POTRAZ-certified DPO, file Forms DP1 and DP2, and document the lawful basis for transferring the data to your home servers. Compliance is cheaper than losing your payment rails.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.