Lawfulness and consent
Personal information must be processed lawfully and fairly, normally on the basis of the data subject's consent or another lawful ground set out in the Act.
Compliance Guide
The Data Protection Act (Chapter 11:12) of 2021 sets out how organisations operating in Zimbabwe must collect, secure and share personal information. This guide summarises the key requirements, the role of POTRAZ, and the steps organisations take to reach and evidence compliance.
The Act regulates the processing of personal information and data by both public and private bodies in Zimbabwe. It applies to any data controller or processor that collects, stores, uses or shares information relating to identifiable individuals, whether customers, employees, patients, subscribers or citizens.
In practice this covers banks and microfinance institutions, mobile money operators and telecoms, insurers, medical and educational institutions, retailers, NGOs, and government entities and parastatals. Organisations that hold biometric, health, financial or children's data carry heavier obligations because the Act treats these categories as sensitive.
The Act also intersects with the Cyber and Data Protection framework more broadly, including obligations around cyber security incidents and lawful interception, so compliance work is usually planned alongside an organisation's wider security programme.
Personal information must be processed lawfully and fairly, normally on the basis of the data subject's consent or another lawful ground set out in the Act.
Data must be collected for a specified, explicit and legitimate purpose, and not further processed in a way incompatible with that purpose.
Only data that is adequate, relevant and not excessive may be collected, and it must be kept accurate and up to date.
Personal information may not be retained longer than is necessary for the purpose for which it was collected.
Controllers must implement appropriate technical and organisational measures to protect data against loss, unauthorised access, alteration and disclosure.
Controllers remain responsible for compliance, including for processing carried out on their behalf by third parties under a written arrangement.
Data controllers are required to register with POTRAZ as the Data Protection Authority before processing personal information.
The Act provides for the appointment of a Data Protection Officer to oversee compliance, handle data subject queries and act as the contact point with POTRAZ.
Stricter conditions apply to sensitive information such as health, biometric, genetic, financial and criminal data, as well as data relating to children.
Transferring personal information outside Zimbabwe requires an adequate level of protection in the destination jurisdiction, or another basis permitted by the Act.
Security breaches affecting personal information must be reported to the Authority, and affected data subjects informed where the breach is likely to cause harm.
Individuals may access their information, request correction or deletion, object to certain processing, and complain to the Authority.
The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is designated as the Data Protection Authority under the Act. It registers and licenses data controllers, issues guidance and codes of conduct, receives breach notifications, and investigates complaints from data subjects.
Organisations should expect to demonstrate compliance rather than assert it. That means maintaining registration records, processing records, policies, agreements with processors, and evidence that security controls and staff training are in place and current.
This guide is general information about the Data Protection Act (Chapter 11:12) and is not legal advice. Organisations should confirm their specific obligations with qualified legal counsel and with POTRAZ.
We run Data Protection Act gap assessments, prepare the policies and records POTRAZ expects to see, and support organisations through remediation and ongoing compliance.