For operators
A Zimbabwean logistics or freight operator is a data controller and must license with POTRAZ. Consignor and consignee details, customs identity data and driver telematics are all personal data, and sending a consignment abroad sends personal information with it, which section 10(2)(c) of Statutory Instrument 155 of 2024 requires you to notify.
Last updated 2026-09-02. Lioncap Ventures, Harare, Zimbabwe.
Operators think of themselves as moving goods, not data, and that framing is exactly what causes the obligation to be missed. Every consignment carries a set of named individuals with it: somebody sent it, somebody is receiving it, somebody cleared it and somebody drove it.
The test in section 4(1) of Statutory Instrument 155 of 2024 is whether you determine the purposes and means of processing personal data. A freight business decides what is recorded on a waybill, what identity documents are gathered for clearance, how long the records are kept and who they are passed to. That is controller activity.
Biometric clocking at a depot brings section 10(2)(d) into play, which requires you to notify the Authority of processing involving biometric and genetic data. It is one of the more common undocumented systems in the sector.
This is the obligation that defines the sector, and it is structural rather than incidental. You cannot move a consignment across a border without moving personal information across it too, because the receiving side needs to know who the goods are for.
Section 10(2)(c) of Statutory Instrument 155 of 2024 requires a data controller to notify the Authority of any intention to transfer or share information of data subjects outside Zimbabwe. Note that the notifiable event is the intention. For an operator that runs regular corridors, this is something to deal with as a standing matter rather than shipment by shipment.
Section 28 of the Cyber and Data Protection Act (Chapter 12:07) then governs the transfer of personal information outside Zimbabwe, and section 29 deals with transfers to a country that does not assure an adequate level of protection. Contravening section 28 is one of the five sections named in section 33(2), which carries a fine of up to level 11 or imprisonment of up to seven years or both.
The practical position is not that cross-border freight is unlawful. It is that the intention to transfer is notified properly, that what actually crosses is limited to what the receiving party genuinely needs, that the arrangement with each recipient is papered, and that your customer terms and privacy notice say plainly where consignment data goes. Most operators are doing the transfers already and have simply never documented them.
Freight forwarding sits awkwardly across the two roles and the answer differs by engagement, so it is worth settling deliberately rather than assuming one label covers the business.
Where you decide what data is collected and how it is handled, for your own account customers, your staff and your drivers, you are a controller. Where you handle personal data strictly on a shipper’s instructions and for the shipper’s purposes, you are acting as a processor for that work. A forwarder arranging clearance under its own professional judgement is generally making controller decisions even though it is acting for a client.
Most operators are both at once. The classification is settled engagement by engagement at the consultation, because it changes what your customer terms need to say and it changes which written agreements you need under section 10(4)(f).
Vehicle tracking is usually procured as fleet management, asset protection or fuel control. Once a vehicle is tied to a named driver on a shift, the tracking record is information about where that identified person was, minute by minute, including during rest periods and sometimes outside working hours.
That does not make tracking unlawful. Operators have obvious and legitimate reasons for it: cargo security, route compliance, driver safety on long-haul corridors, and accident investigation. What it does mean is that the processing has to be proportionate to those purposes, and that drivers have to know about it.
Section 10(3) of Statutory Instrument 155 of 2024 is also worth noting here: a data subject may not be subjected to a decision based solely on automated processing which produces legal effects, without their consent or a provision established by law. An automated driver scoring system that triggers a sanction with no human review engages that provision.
Section 10(4)(f) requires a written data processing agreement, contract or legal instrument with each data processor, ensuring the processor maintains the necessary security measures. Logistics runs on subcontracting, so this obligation bites harder here than in most sectors and is met less often.
Section 10(4)(a) makes the controller accountable for a representative, agent, assignee, processor, recipient or data protection officer who contravenes the regulations or the Act, and section 33(6) of the Act makes the controller liable for fines incurred by its agent or assignee. A subcontracted driver mishandling a consignee list is your exposure, which is the commercial reason to paper these relationships as well as the legal one.
Tier is set by the number of individuals whose personal data you hold, and in logistics that number is driven by consignees rather than by customers. Every delivery adds at least one named recipient, and those records persist long after the goods do.
An operator with a few hundred account customers can easily be holding data on tens of thousands of consignees once a few years of waybills are counted, plus drivers, former drivers, subcontractors and the contact people at every client.
The $30 application fee applies from Tier 2 upwards. A Tier 1 organisation does not pay it, and it is not charged again on an annual renewal. Every POTRAZ figure above is exclusive of VAT, which POTRAZ adds on its own invoice at a rate we do not set. That is why we quote our service fee and the POTRAZ fees as two separate numbers and never give you a single all-in total. You pay POTRAZ exactly what POTRAZ bills us, with no markup.
These are the findings that recur in the sector, and none of them requires new systems to fix.
Every engagement begins with a $90 consultation, a one hour working session in which our data protection officers confirm your controller or processor status, map the records you hold, your sites and systems and the partners you share data with, and confirm your exact licence tier. The $90 is credited in full toward your compliance package when you proceed. Packages start at $250.
Yes. A freight or logistics operator determines what personal data is recorded on waybills and clearance documents, what identity data is gathered, how long it is kept and who it is passed to, which is the controller test in section 4(1) of Statutory Instrument 155 of 2024. Section 8 exempts only personal, family or household affairs, law enforcement, and journalistic, historical or archival purposes. There is no transport or freight exemption.
Yes. Section 10(2)(c) of Statutory Instrument 155 of 2024 requires you to notify the Authority of any intention to transfer or share data subject information outside Zimbabwe, and section 28 of the Cyber and Data Protection Act (Chapter 12:07) governs the transfer itself, with section 29 covering countries that do not assure an adequate level of protection. Sending a consignee’s name, address and contact details to an overseas agent, carrier or customs authority is such a transfer. It is generally unavoidable in cross-border freight, which is precisely why it needs to be notified and documented rather than treated as invisible.
Where the vehicle is tied to a named driver, yes. The trace is information about where that identified person was and when. Tracking remains lawful for genuine purposes such as cargo security, route compliance and driver safety, but it must be proportionate to those purposes, drivers must be told about it, access to traces should be restricted and logged, and a retention period should be set rather than keeping every trace indefinitely.
Where they handle consignee data on your instructions, yes, and section 10(4)(f) of Statutory Instrument 155 of 2024 requires a written data processing agreement, contract or legal instrument with each of them. Section 10(4)(a) then makes you accountable for a processor, agent or recipient who contravenes, and section 33(6) of the Act makes you liable for fines incurred by your agent or assignee, so the paperwork protects you as much as it satisfies the regulation.
It is set by the number of data subjects, which in logistics is dominated by consignees rather than by account customers. Every delivery adds a named recipient and those records outlast the shipment. An operator with a few hundred account customers is often holding data on tens of thousands of individuals once several years of waybills, plus drivers and client contacts, are counted, which typically places it at Tier 2 or above.
The practical issues are notice, proportionality and retention rather than consent alone. Tell recipients that a delivery photograph is taken and why, frame the shot on the goods and the delivery point rather than on people where that is possible, avoid capturing documents and bystanders, and set a retention period so that images are not held indefinitely after the delivery is proven and any dispute window has closed.
Only as long as there is a purpose for holding them. Identity copies gathered for a specific customs entry or a know your client check should have a defined retention period tied to that purpose and to any record-keeping requirement that applies to you, after which they are disposed of. Clearance files holding passport copies from closed entries years ago are a common finding and are difficult to justify.
A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.
Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.