Zimbabwe
Southern Africa
Zimbabwe regulates personal data through the Cyber and Data Protection Act [Chapter 12:07] (No. 5 of 2021), gazetted on 3 December 2021 and in operation from 11 March 2022. The Act is a dual-purpose instrument, consolidating both personal data protection and cybercrime within a single statute. It applies to controllers processing personal data in Zimbabwe and to controllers outside the country where the means used for processing are situated within it. Controllers must process data fairly and lawfully, collect for specified and legitimate purposes, ensure accuracy, and implement appropriate security measures. Data subjects hold rights of access, correction, deletion, and objection. The Act imposes a notably short breach-notification window, controllers must notify the Data Protection Authority within 24 hours of discovery, stricter than the 72-hour norm elsewhere, and establishes special protections for sensitive categories including health, biometric, and religious or political-belief data. Cross-border transfers are restricted to jurisdictions providing adequate protection. The framework was significantly built out in September 2024 by the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024, which introduced mandatory registration and licensing of data controllers (12-month renewable licences) and required the appointment of data protection officers. Institutionally, rather than create an independent regulator, the Act designates the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) as the Data Protection Authority. POTRAZ maintains the register of controllers, enforces fair processing, investigates complaints, advises the Minister, and facilitates cross-border cooperation. With a primary Act, 2024 licensing regulations, and a designated, active authority, Zimbabwe has a working, in-force regime, albeit one where data protection is supervised by the telecoms regulator.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 2 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 4 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 1 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Interception of Communications Act [Chapter 11:20] (Act No. 6 of 2007) (Zimbabwe)
Enacted 3 Aug 2007
Banking (Money Transmission, Mobile Banking and Mobile Money Interoperability) (Amendment) Regulations, 2025 (S.I. 17 of 2025)
Enacted 1 Jan 2025
Banking (Money Transmission, Mobile Banking and Mobile Money Interoperability) Regulations, 2020 (S.I. 80 of 2020)
Enacted 1 Jan 2020
Guidelines for Retail Payment Systems and Instruments (August 2017)
Enacted 1 Aug 2017
National Payment Systems Act [Chapter 24:23] (Act No. 21 of 2001)
Enacted 1 Jan 2001
Zimbabwe National Artificial Intelligence Strategy 2026 - 2030
Enacted 13 Mar 2026
Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (SI 155 of 2024) (Zimbabwe)
Enacted 13 Sept 2024
Cyber and Data Protection Act [Chapter 12:07]
Enacted 3 Dec 2021
Data protection is supervised by the telecoms regulator (POTRAZ) rather than a dedicated, independent authority, and the 24-hour breach-notification window is unusually demanding. ATLPF now holds both the Cyber and Data Protection Act and SI 155 of 2024, making Zimbabwe a multi-instrument jurisdiction; no further subsidiary instruments are outstanding at this time.