Your obligations

Do I have to keep a record of processing activities under Zimbabwe's CDPA?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes, in practice. Section 10 of SI 155 of 2024 requires you to notify POTRAZ of your processing activities, your licence application must describe them, and a POTRAZ inspector's first document request is exactly this list. For most SMEs it fits on one page.

What the law says

Section 10 of SI 155 obliges the controller to notify the Authority of "all processing activities", of modifications to indirectly collected data, of international transfers and of biometric or genetic processing. Section 24 of the Act requires the controller to be able to demonstrate compliance (accountability), and section 7 requires that data be adequate, relevant, not excessive and kept no longer than necessary, which you can only show if you know what you hold. The record is also the source for Form DP1, the privacy notice and the tier count.

Example

A Gweru hardware store's record has seven rows: staff (files, payroll, medical certificates; legal obligation and employment; kept during employment plus the statutory period; payroll bureau as processor); job applicants (CVs; legitimate interests; deleted after six months); customers (invoices, account details; legal obligation and contract; kept as tax law requires); loyalty list (names, phones; consent; deleted after two years' inactivity; SMS gateway as processor); suppliers' contacts; CCTV (security; 30 days; two supervisors); WhatsApp Business (customer enquiries; consent; chats deleted quarterly). Column totals give a data subject count of about 2,400: Tier 2.

In practice

Build the record before anything else; every other document flows from it. Columns: activity, data types, whose data, purpose, legal ground, recipients and processors, storage location (and whether abroad), retention, security, approximate number of people. Review it quarterly and after any new system.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.