Compliance Guide

Zimbabwe Data Protection Act compliance

The Data Protection Act (Chapter 11:12) of 2021 sets out how organisations operating in Zimbabwe must collect, secure and share personal information. This guide summarises the key requirements, the role of POTRAZ, and the steps organisations take to reach and evidence compliance.

What the Act covers and who it applies to

The Act regulates the processing of personal information and data by both public and private bodies in Zimbabwe. It applies to any data controller or processor that collects, stores, uses or shares information relating to identifiable individuals, whether customers, employees, patients, subscribers or citizens.

In practice this covers banks and microfinance institutions, mobile money operators and telecoms, insurers, medical and educational institutions, retailers, NGOs, and government entities and parastatals. Organisations that hold biometric, health, financial or children's data carry heavier obligations because the Act treats these categories as sensitive.

The Act also intersects with the Cyber and Data Protection framework more broadly, including obligations around cyber security incidents and lawful interception, so compliance work is usually planned alongside an organisation's wider security programme.

Core data protection principles

Lawfulness and consent

Personal information must be processed lawfully and fairly, normally on the basis of the data subject's consent or another lawful ground set out in the Act.

Purpose limitation

Data must be collected for a specified, explicit and legitimate purpose, and not further processed in a way incompatible with that purpose.

Minimisation and accuracy

Only data that is adequate, relevant and not excessive may be collected, and it must be kept accurate and up to date.

Storage limitation

Personal information may not be retained longer than is necessary for the purpose for which it was collected.

Security safeguards

Controllers must implement appropriate technical and organisational measures to protect data against loss, unauthorised access, alteration and disclosure.

Accountability

Controllers remain responsible for compliance, including for processing carried out on their behalf by third parties under a written arrangement.

Key obligations for data controllers

Registration with the Authority

Data controllers are required to register with POTRAZ as the Data Protection Authority before processing personal information.

Appointing a Data Protection Officer

The Act provides for the appointment of a Data Protection Officer to oversee compliance, handle data subject queries and act as the contact point with POTRAZ.

Sensitive data controls

Stricter conditions apply to sensitive information such as health, biometric, genetic, financial and criminal data, as well as data relating to children.

Cross-border transfers

Transferring personal information outside Zimbabwe requires an adequate level of protection in the destination jurisdiction, or another basis permitted by the Act.

Breach notification

Security breaches affecting personal information must be reported to the Authority, and affected data subjects informed where the breach is likely to cause harm.

Data subject rights

Individuals may access their information, request correction or deletion, object to certain processing, and complain to the Authority.

The role of POTRAZ

The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is designated as the Data Protection Authority under the Act. It registers and licenses data controllers, issues guidance and codes of conduct, receives breach notifications, and investigates complaints from data subjects.

Organisations should expect to demonstrate compliance rather than assert it. That means maintaining registration records, processing records, policies, agreements with processors, and evidence that security controls and staff training are in place and current.

Compliance checklist for Zimbabwean organisations

  • Maintain a record of the personal and sensitive data you hold, where it is stored, and who can access it.
  • Confirm and document a lawful basis for each processing activity, and record how consent is obtained.
  • Register as a data controller with POTRAZ and keep the registration current.
  • Appoint a Data Protection Officer with a defined mandate and reporting line.
  • Publish a clear privacy notice covering purpose, retention, sharing, transfers and data subject rights.
  • Put written data processing agreements in place with vendors, hosting providers and outsourced partners.
  • Define and enforce retention and secure disposal schedules for each data category.
  • Apply access control, encryption, logging and backup controls proportionate to the sensitivity of the data.
  • Assess cross-border transfers and document the safeguards relied on.
  • Establish a documented breach detection, escalation and notification procedure, and test it.
  • Implement a process to receive and respond to data subject requests within reasonable timeframes.
  • Train staff on handling personal information, phishing and social engineering.
  • Review compliance at least annually, and after any significant system or supplier change.

Consequences of non-compliance

  • Non-compliance with the Act can attract fines and, in serious cases, criminal liability for responsible persons.
  • Unlawful disclosure or misuse of personal information carries specific penalties under the Act.
  • Beyond legal exposure, breaches in Zimbabwe increasingly result in regulatory scrutiny, contract loss and reputational damage.

This guide is general information about the Data Protection Act (Chapter 11:12) and is not legal advice. Organisations should confirm their specific obligations with qualified legal counsel and with POTRAZ.

Where you stand against the Act

We run Data Protection Act gap assessments, prepare the policies and records POTRAZ expects to see, and support organisations through remediation and ongoing compliance.