For operators

Data protection for logistics, freight and shipping operators in Zimbabwe

A Zimbabwean logistics or freight operator is a data controller and must license with POTRAZ. Consignor and consignee details, customs identity data and driver telematics are all personal data, and sending a consignment abroad sends personal information with it, which section 10(2)(c) of Statutory Instrument 155 of 2024 requires you to notify.

Last updated 2026-09-02. Lioncap Ventures, Harare, Zimbabwe.

Key facts

Typical position
Controller for your own account customers and staff, processor for work done on a shipper’s instructions
The defining obligation
Section 10(2)(c) of SI 155: notify any intention to transfer or share data outside Zimbabwe
The transfer rules
Sections 28 and 29 of the Act, with section 28 named in the section 33(2) offence
Telematics
Vehicle tracking tied to a named driver is personal data about that driver
Processor agreements
Section 10(4)(f): a written agreement with every subcontracted carrier and platform
Inspections began
1 September 2026

Why a freight business is a data controller

Operators think of themselves as moving goods, not data, and that framing is exactly what causes the obligation to be missed. Every consignment carries a set of named individuals with it: somebody sent it, somebody is receiving it, somebody cleared it and somebody drove it.

The test in section 4(1) of Statutory Instrument 155 of 2024 is whether you determine the purposes and means of processing personal data. A freight business decides what is recorded on a waybill, what identity documents are gathered for clearance, how long the records are kept and who they are passed to. That is controller activity.

Biometric clocking at a depot brings section 10(2)(d) into play, which requires you to notify the Authority of processing involving biometric and genetic data. It is one of the more common undocumented systems in the sector.

Every cross-border shipment is also a data transfer

This is the obligation that defines the sector, and it is structural rather than incidental. You cannot move a consignment across a border without moving personal information across it too, because the receiving side needs to know who the goods are for.

Section 10(2)(c) of Statutory Instrument 155 of 2024 requires a data controller to notify the Authority of any intention to transfer or share information of data subjects outside Zimbabwe. Note that the notifiable event is the intention. For an operator that runs regular corridors, this is something to deal with as a standing matter rather than shipment by shipment.

Section 28 of the Cyber and Data Protection Act (Chapter 12:07) then governs the transfer of personal information outside Zimbabwe, and section 29 deals with transfers to a country that does not assure an adequate level of protection. Contravening section 28 is one of the five sections named in section 33(2), which carries a fine of up to level 11 or imprisonment of up to seven years or both.

Foreign customs authorities
Clearance in the destination country requires consignee identity data. This is a transfer, and it is generally unavoidable, which is why it needs to be notified and described rather than argued away.
Overseas agents and correspondents
A partner handling the consignment at the other end receives the consignee’s name, address and contact details, and often the consignor’s too.
Airlines, shipping lines and rail operators
Carrier documentation carries named parties, and the carrier is frequently a foreign entity.
Cross-border tracking platforms
Where the track and trace system, TMS or customs software is hosted outside Zimbabwe, that is a continuing transfer rather than a single event.
Group and regional offices
A regional office able to read Zimbabwean consignment records is sharing data outside Zimbabwe even if nothing is exported.

The practical position is not that cross-border freight is unlawful. It is that the intention to transfer is notified properly, that what actually crosses is limited to what the receiving party genuinely needs, that the arrangement with each recipient is papered, and that your customer terms and privacy notice say plainly where consignment data goes. Most operators are doing the transfers already and have simply never documented them.

Controller, processor, or both

Freight forwarding sits awkwardly across the two roles and the answer differs by engagement, so it is worth settling deliberately rather than assuming one label covers the business.

Where you decide what data is collected and how it is handled, for your own account customers, your staff and your drivers, you are a controller. Where you handle personal data strictly on a shipper’s instructions and for the shipper’s purposes, you are acting as a processor for that work. A forwarder arranging clearance under its own professional judgement is generally making controller decisions even though it is acting for a client.

Most operators are both at once. The classification is settled engagement by engagement at the consultation, because it changes what your customer terms need to say and it changes which written agreements you need under section 10(4)(f).

Driver telematics is personal data about a person

Vehicle tracking is usually procured as fleet management, asset protection or fuel control. Once a vehicle is tied to a named driver on a shift, the tracking record is information about where that identified person was, minute by minute, including during rest periods and sometimes outside working hours.

That does not make tracking unlawful. Operators have obvious and legitimate reasons for it: cargo security, route compliance, driver safety on long-haul corridors, and accident investigation. What it does mean is that the processing has to be proportionate to those purposes, and that drivers have to know about it.

Section 10(3) of Statutory Instrument 155 of 2024 is also worth noting here: a data subject may not be subjected to a decision based solely on automated processing which produces legal effects, without their consent or a provision established by law. An automated driver scoring system that triggers a sanction with no human review engages that provision.

The carriers and platforms you pass data to

Section 10(4)(f) requires a written data processing agreement, contract or legal instrument with each data processor, ensuring the processor maintains the necessary security measures. Logistics runs on subcontracting, so this obligation bites harder here than in most sectors and is met less often.

Section 10(4)(a) makes the controller accountable for a representative, agent, assignee, processor, recipient or data protection officer who contravenes the regulations or the Act, and section 33(6) of the Act makes the controller liable for fines incurred by its agent or assignee. A subcontracted driver mishandling a consignee list is your exposure, which is the commercial reason to paper these relationships as well as the legal one.

Counting data subjects across consignments

Tier is set by the number of individuals whose personal data you hold, and in logistics that number is driven by consignees rather than by customers. Every delivery adds at least one named recipient, and those records persist long after the goods do.

An operator with a few hundred account customers can easily be holding data on tens of thousands of consignees once a few years of waybills are counted, plus drivers, former drivers, subcontractors and the contact people at every client.

Tier 1, up to 1,000 records
$50 licence fee
Tier 2, 1,001 – 100,000 records
$300 licence fee
Tier 3, 100,001 – 500,000 records
$500 licence fee
Tier 4, over 500,000 records
$2,500 licence fee

The $30 application fee applies from Tier 2 upwards. A Tier 1 organisation does not pay it, and it is not charged again on an annual renewal. Every POTRAZ figure above is exclusive of VAT, which POTRAZ adds on its own invoice at a rate we do not set. That is why we quote our service fee and the POTRAZ fees as two separate numbers and never give you a single all-in total. You pay POTRAZ exactly what POTRAZ bills us, with no markup.

Where operators most often come up short

These are the findings that recur in the sector, and none of them requires new systems to fix.

Every engagement begins with a $90 consultation, a one hour working session in which our data protection officers confirm your controller or processor status, map the records you hold, your sites and systems and the partners you share data with, and confirm your exact licence tier. The $90 is credited in full toward your compliance package when you proceed. Packages start at $250.

Frequently asked questions

Does a logistics or freight company in Zimbabwe need a POTRAZ licence?

Yes. A freight or logistics operator determines what personal data is recorded on waybills and clearance documents, what identity data is gathered, how long it is kept and who it is passed to, which is the controller test in section 4(1) of Statutory Instrument 155 of 2024. Section 8 exempts only personal, family or household affairs, law enforcement, and journalistic, historical or archival purposes. There is no transport or freight exemption.

Is sending consignee details to a foreign agent a cross-border transfer?

Yes. Section 10(2)(c) of Statutory Instrument 155 of 2024 requires you to notify the Authority of any intention to transfer or share data subject information outside Zimbabwe, and section 28 of the Cyber and Data Protection Act (Chapter 12:07) governs the transfer itself, with section 29 covering countries that do not assure an adequate level of protection. Sending a consignee’s name, address and contact details to an overseas agent, carrier or customs authority is such a transfer. It is generally unavoidable in cross-border freight, which is precisely why it needs to be notified and documented rather than treated as invisible.

Is vehicle tracking data personal data?

Where the vehicle is tied to a named driver, yes. The trace is information about where that identified person was and when. Tracking remains lawful for genuine purposes such as cargo security, route compliance and driver safety, but it must be proportionate to those purposes, drivers must be told about it, access to traces should be restricted and logged, and a retention period should be set rather than keeping every trace indefinitely.

Are our subcontracted carriers data processors?

Where they handle consignee data on your instructions, yes, and section 10(4)(f) of Statutory Instrument 155 of 2024 requires a written data processing agreement, contract or legal instrument with each of them. Section 10(4)(a) then makes you accountable for a processor, agent or recipient who contravenes, and section 33(6) of the Act makes you liable for fines incurred by your agent or assignee, so the paperwork protects you as much as it satisfies the regulation.

Which POTRAZ tier does a logistics operator fall into?

It is set by the number of data subjects, which in logistics is dominated by consignees rather than by account customers. Every delivery adds a named recipient and those records outlast the shipment. An operator with a few hundred account customers is often holding data on tens of thousands of individuals once several years of waybills, plus drivers and client contacts, are counted, which typically places it at Tier 2 or above.

Do we need consent for proof of delivery photographs?

The practical issues are notice, proportionality and retention rather than consent alone. Tell recipients that a delivery photograph is taken and why, frame the shot on the goods and the delivery point rather than on people where that is possible, avoid capturing documents and bystanders, and set a retention period so that images are not held indefinitely after the delivery is proven and any dispute window has closed.

How long can we keep copies of customers’ identity documents?

Only as long as there is a purpose for holding them. Identity copies gathered for a specific customs entry or a know your client check should have a defined retention period tied to that purpose and to any record-keeping requirement that applies to you, after which they are disposed of. Clearance files holding passport copies from closed entries years ago are a common finding and are difficult to justify.

Get inspection-ready

A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.

Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.