Cyber and Data Protection Act [Chapter 12:07]
zw-cdpa-2021 · Act
The Cyber and Data Protection Act [Chapter 12:07] (No. 5 of 2021) is Zimbabwe's primary statute governing both personal data protection and cybercrime. It was gazetted on 3 December 2021 and came into operation on 11 March 2022 pursuant to GN 492/2022. The Act consolidates Zimbabwe's approach to data protection and cyber security within a single piece of legislation. Note for ATLPF editors: the Brief identified the regulator as 'Zimbabwe Data Protection Authority (ZDPA)'. Research confirms no independent ZDPA body exists. The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is designated under the Act as the Data Protection Authority and carries out data protection functions alongside its existing telecommunications mandate. The Act applies to data controllers processing personal data in Zimbabwe, and to controllers based outside Zimbabwe where the means used for processing are situated within the country. Data controllers must process data fairly and lawfully, collect data only for specified and legitimate purposes, ensure accuracy, and implement appropriate security measures against unauthorised access, loss, or destruction. Data subjects are granted rights of access to their personal data, correction of inaccurate data, deletion, and objection to processing. Data controllers must notify POTRAZ as the Data Protection Authority of any security breach within 24 hours of discovery. The Act establishes special protections for sensitive categories of data including health data, data relating to religious or political beliefs, and biometric information. POTRAZ, as Data Protection Authority, is responsible for promoting and enforcing fair data processing, maintaining a register of data controllers, investigating complaints, advising the Minister on privacy and data protection matters, and facilitating cross-border cooperation in enforcement. In September 2024, the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 were issued, introducing mandatory registration and licensing for data controllers, with licences valid for 12-month periods and subject to renewal, and requiring the appointment of data protection officers. The Act also contains cybercrime provisions covering offences including unauthorised access to computer systems, data interference, electronic fraud, and related crimes, reflecting its dual-purpose structure as both a data protection and cyber security statute.
- POTRAZ designated as Data Protection Authority responsible for registration of data controllers, enforcement, and cross-border cooperation
- Data breach notification required within 24 hours of discovery by data controllers
- Data subjects granted rights of access, correction, deletion, and objection to processing
- Sensitive categories of data (health, biometric, religious and political beliefs) subject to enhanced protections
- 2024 Licensing Regulations require mandatory registration and licensing of data controllers (12-month renewable licences) and appointment of Data Protection Officers
- Cross-border data transfers restricted to jurisdictions providing adequate protection
- Cybercrime: amends sections 162 - 166 of the Criminal Law (Codification and Reform) Act [Chapter 9:23] to create offences including hacking/unlawful access, unlawful interference with computer data or systems, and unlawful acquisition, disclosure or misuse of data, passwords or PINs
- Cybercrime: criminalises transmission of threatening, false or incitatory data messages, cyberbullying and harassment (e.g. threatening data messages punishable by up to level 10 fine and/or 5 years' imprisonment), and a range of computer-related financial crimes
- Establishes a Cyber Security Centre and amends the Criminal Procedure and Evidence Act to provide investigative and evidence-collection powers for cybercrime