The law
The Cyber and Data Protection Act (Chapter 12:07) is Zimbabwe’s data protection law. Statutory Instrument 155 of 2024 makes registration as a licensed Data Controller with POTRAZ mandatory and requires you to appoint a Data Protection Officer. CDPG 1 of 2025 makes staff data protection training mandatory. POTRAZ inspections begin on 1 September 2026.
Last updated 2026-08-28. Lioncap Ventures, Harare, Zimbabwe.
The Cyber and Data Protection Act (Chapter 12:07) governs how organisations in Zimbabwe collect, hold, use and share personal data. Personal data means any information that identifies a living person, which is a wider category than most organisations expect. Your payroll file is personal data. So is your customer database, your patient file, your class register, your membership list, your visitor book and your CCTV recordings.
The Act draws a distinction between two roles. A data controller decides why and how personal data is used. A data processor handles personal data on someone else’s instructions. Most organisations are controllers for their own staff and customer data, and some are processors as well for work they do on behalf of clients. The two roles carry different obligations, so establishing which one applies to you is the first thing any compliance exercise does.
The Act also singles out special category data, which is information that carries a higher risk if it is exposed. Health information is special category data. So is children’s data, and processing it makes a formal data protection impact assessment mandatory rather than optional.
SI 155 of 2024 is the regulation that turned the Act into an enforceable licensing regime. Two obligations matter most.
The first is the licence. Registering as a licensed Data Controller with POTRAZ is now mandatory, and operating without a licence is an offence. The application is made on Form DP1 and the licence fee scales with how many records you hold.
The second is the appointment of a Data Protection Officer. A licensed data controller must appoint an officer to oversee compliance with the Act, and that officer is notified to POTRAZ by name. It is a named accountability, not a policy statement.
CDPG 1 of 2025 is the POTRAZ assessment guideline set, and its most practical consequence for employers is that staff data protection training is mandatory. Anyone in your organisation who handles personal data has to be trained, and inspectors ask for the training records as evidence.
This is the requirement organisations most often discover late, because it is the one that cannot be produced on the day. A policy can be drafted quickly. A training record showing that your staff were trained cannot be backdated. We run sessions off hours so the working day is not disrupted, and the attendance record becomes part of your inspection file.
From 1 September 2026, POTRAZ can inspect organisations against the Act. These are the core obligations that inspection is measured against.
As a controller you need a POTRAZ Data Controller licence, an appointed Data Protection Officer and the full set of policies. As a processor you need POTRAZ registration, data processing agreements with each controller you act for, security controls and a breach procedure.
If you are both, you carry both sets of obligations at once: the licence, the officer and the policies for your own data, plus the registration, the agreements, the security controls and the breach procedure for the data you handle on behalf of others. Payroll bureaux, medical aid administrators, marketing agencies, debt collectors and IT service providers commonly land here.
Overseas email and cloud storage can move personal data outside Zimbabwe, and so can sending customer details to an overseas supplier, a processing partner or a head office in another country. Those are cross border transfers, they have to be assessed, and they may need notification to POTRAZ.
Most organisations are surprised to learn they make such transfers at all. If your email runs on an international provider, or your accounting or booking system stores data in a foreign data centre, personal data is leaving the country. The impact assessment evaluates each flow and documents the safeguard that applies to it.
A recurring misconception is that data protection is a digital concern. It is not. Inspectors look at filing rooms, registers and archives, and paper files have to meet the same standard as digital ones: controlled access, a documented retention period and a secure store.
The same applies to how personal details move between people. Sending them over ordinary email or a personal messaging account is one of the most common inspection findings, and it breaches the rules on transmitting sensitive data. A secure channel and a documented procedure are the fix.
Once inspections begin on 1 September 2026, being unlicensed or undocumented exposes an organisation to enforcement action and penalties under the Act. Operating as an unlicensed controller is an offence in its own right, independently of whether any personal data has actually been mishandled.
The practical risk is broader than the penalty. An organisation that cannot show a licence, a record of processing or a training record when an inspector asks is also an organisation that cannot show a client, a partner or an insurer that it handles their data properly. The safest path is to get licensed and inspection ready. If you have already missed a step, the essentials can be fast tracked.
It is Zimbabwe’s data protection law, Chapter 12:07. It governs how organisations collect, hold, use and share personal data, sets out the duties of data controllers and data processors, and gives POTRAZ the mandate to license and inspect. Statutory Instrument 155 of 2024 and CDPG 1 of 2025 sit under it and set the operating requirements.
SI 155 of 2024 makes registration as a licensed Data Controller with POTRAZ mandatory, and requires a licensed controller to appoint a Data Protection Officer who is notified to POTRAZ by name. Operating as an unlicensed controller is an offence.
Yes. Staff who handle personal data must be trained under CDPG 1 of 2025, the POTRAZ assessment guidelines, and inspectors ask for the training records. It is the requirement most often left until last, and it is the one that cannot be produced retrospectively on inspection day.
Yes. The Act applies according to what you hold, not how large you are. A business with a handful of staff still holds personal data in its payroll and customer records, so it is still a data controller. Size affects your licence tier and therefore your fee, not whether the law applies.
Yes. CCTV recordings are personal data. Signage, a documented purpose and a retention rule are required, and they form part of the policy set we prepare.
A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.
Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.