Zimbabwe
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Zimbabwe — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Data can leave Zimbabwe, but only after several steps. Tell the regulator first. Run a risk assessment. Get clear permission from each person. Show that the destination country protects data properly. Almost every organisation that holds personal data also needs a licence, renewed every year. Breaking the rules is a crime, not just a fine.
Data governance in Zimbabwe
The eight things that decide how you handle data about people in Zimbabwe. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it can reach a foreign company. The law applies to a company with no permanent presence in Zimbabwe if the equipment it uses to handle the data sits in Zimbabwe. If that is you, you must appoint a representative based in Zimbabwe. There is no size or revenue floor to fall below. A sports club with a membership list is covered on the same terms as a bank. In March 2026 the regulator said the licence duty covers organisations 'permanently established in Zimbabwe or otherwise'.
- What you have to do here:
- Appoint a representative
The Cyber and Data Protection Act asks where your equipment is. It does not ask who you are aiming at, which is the test Europe uses. Zimbabwe's test is narrower on paper. A foreign service with no equipment in Zimbabwe can argue it falls outside the law. But the law never says what counts as equipment. And the regulator's own Regulatory Notice 1 of 2026 reads the licence duty as reaching beyond companies permanently based in the country. Whenever the equipment test catches you, you must appoint a representative based in Zimbabwe. There is one more gap. Zimbabwean laws do not bind the State unless they say so, and this one does not. So government ministries and agencies can argue they need no licence, even though the regulator's guidance says they do.
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], Act No. 5 of 2021, section 4
ictministry.gov.zw
“to the processing and storage of data by a controller who is not permanently established in Zimbabwe, if the means used, whether electronic or otherwise is located in Zimbabwe, and such processing and storage is not for the purposes of the mere transit of data through Zimbabwe.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweRegulatory Notice 1 of 2026 — Compliance with the Cyber and Data Protection Act [Chapter 12:07], March 2026
potraz.zw
“The Data Controller licensing requirement applies to non-exempt natural and legal persons permanently established in Zimbabwe or otherwise that process personal data using both print and electronic means, including surveillance or biometric systems.”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024 — Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024, sections 3 and 4
potraz.zw
Link checked 18 August 2026
Where the data is allowed to live
Yes, but not freely, and not quietly. You may only send personal data out of Zimbabwe if the destination protects it about as well as Zimbabwe does. You must also notify the regulator before the data moves. Storing data in a cloud service counts as sending it abroad. So does letting a colleague in another country log in and download it. We found only one outright 'stays here' rule, and it covers the servers behind Zimbabwe's own .zw web addresses.
- What you have to do here:
- Put a transfer safeguard in place
The Cyber and Data Protection Act sets the rule. Data may not leave unless the country receiving it protects that data well enough. There are six narrow exceptions. They cover consent, a contract with the person, and a contract with someone else made in the person's interest. They also cover public interest or legal claims, saving someone's life, and data from public registers. The regulator's guideline on sending data abroad, issued on 13 November 2024, goes well beyond the Act. It treats cloud hosting as a transfer. It does the same for suppliers abroad, shared group databases, and staff logging in from other countries. The Act also holds two powers nobody has used yet. The regulator can name kinds of data work whose data may not go abroad at all. We found no such list as of August 2026. The second power belongs to the Minister in charge of the Cyber Security and Monitoring Centre. That centre sits in the President's Office. The Minister can issue directions on how transfers are handled. By industry: we found no rule forcing data to stay in Zimbabwe in banking, insurance, securities, health, gaming or mapping. The central bank's July 2026 guideline on digital financial services says where data sits must follow requirements the Reserve Bank of Zimbabwe defines. It does not say what those requirements are, and we found no separate document setting them out.
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], sections 28 and 29 (transborder flow)
ictministry.gov.zw
“a data controller may not transfer personal information about a data subject to a third party who is in a foreign country unless an adequate level of protection is ensured in the country of the recipient”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweCyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information, CDPG 5 of 2024
potraz.zw
“Storing personal data in the cloud also constitutes a transfer outside Zimbabwe if the cloud server is accessible outside Zimbabwe.”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 111 of 2023 — Postal and Telecommunications (Domain Names Registration and Management) Regulations, 2023, section 4(3)
potraz.zw
“The primary servers of the Registry shall be in Zimbabwe housed at any Data Centre that connects to the Harare Internet Exchange (HIX) and shall have regional or international redundancy.”
Link checked 18 August 2026
- Official sourceReserve Bank of Zimbabwe, National Payment Systems DepartmentGuidelines on Digital Financial Services (DFS) Security in Zimbabwe, July 2026, paragraph 7.2(b)
rbz.co.zw
“Data residency must comply with RBZ-defined jurisdictional requirements.”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Zimbabwe.
Sending data out of the country
You need permission, granted one transfer at a time. There is no tick-box contract. Before data leaves you must do five things. Tell the regulator. Give it a written risk assessment. Get the person's express agreement, after telling them where the data is going and who will hold it. Show that the destination country protects data properly. And sign a data-sharing agreement with whoever receives it. There is no published list of approved countries and no government contract template to sign. If you were already sending data abroad before the law, you must go back and put it right.
- What you have to do here:
- Assess high-risk projects · Written vendor contract
- Ways to send data out:
- Government sign-off needed · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life
The regulator's guideline says you may not send data abroad unless you have told the Authority first. It also refers to the letter asking for permission in advance. So this works as a permission system, not a simple notice. There are five things you must have. One: a data protection impact assessment, sent in with your notice. Two: express consent. You give the person the destination country, the company receiving the data, the security measures, where it will be stored and for how long. Three: proof that the destination country protects data well enough. That is judged on its laws, its data regulator and its international promises. Four: written records of your security measures, both organisational and technical. Five: a data-sharing agreement with a specific data protection clause in it. You do not need consent where the transfer is needed for a contract with the person, for an important public interest, or for legal claims. You also do not need it where the data comes from a public register. You must still tell the regulator. Two gaps matter. There is no published list of approved countries, so each transfer is judged on its own. And the guideline is not law. It rests on a power that lets the regulator say where transfers are not allowed. That power does not obviously stretch to demanding permission for every transfer. The regulator applies the guideline anyway, so follow it. A court might not agree with all of it.
Sources
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweCyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information, CDPG 5 of 2024, paragraphs 3 and 5
potraz.zw
“Data controllers are prohibited from cross-border data transfers unless they have notified the Authority. The data controller must first notify the authority of their intention to transfer data and must satisfy the following conditions before transferring data from Zimbabwe”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024, section 10(2)(c) — duty to notify the Authority of any intention to transfer data abroad
potraz.zw
“A data controller shall notify the Authority of the following— ... (c) any intention to transfer or share information of data subject outside Zimbabwe;”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], section 29 (transfers where protection is not adequate)
ictministry.gov.zw
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
The telecoms regulator does double duty as the data protection authority. Its full name is the Postal and Telecommunications Regulatory Authority of Zimbabwe. It is real and it is working. It handed out 570 licences at a ceremony in June 2025, runs an online licensing portal and has published seven guidelines. It got a new board in March 2026, and that same month it publicly warned organisations still holding data without a licence. What is missing is punishment. The penalties in the law are criminal, so they need a prosecution in court. No prosecutions or fines have been made public.
- What it costs if you get it wrong:
- Criminal liability
The Cyber and Data Protection Act makes the Postal and Telecommunications Regulatory Authority of Zimbabwe the data protection authority. Here is what we can see it doing as of August 2026. It held its first licence handover on 6 June 2025, with more than 500 people there, and gave out 570 licences. They went to law firms, medical practices, municipalities, schools, churches, homeowners' associations, state-owned companies and ministries. It runs a live licensing portal at dclicensing.potraz.zw. It has published guidelines on licensing, data protection officers, consent, breach reporting, sending data abroad and children's data. It has a 2026 training calendar for data protection officers. It announced a new board in March 2026. And it published Regulatory Notice 1 of 2026, chasing organisations with no licence. Its independence is an open question rather than a settled fact. The Act says the Authority takes no direction from anyone when it acts as the data protection authority. But the President appoints its board. It must also follow the responsible Minister's general policy directions under the Postal and Telecommunications Act. There is also the Cyber Security and Monitoring of Interception of Communications Centre. It sits inside the Office of the President. It has no public website and publishes nothing, so we cannot see what it does. We call enforcement 'waking' rather than 'active'. The licensing side is clearly running. The punishment side has produced nothing we can see.
Sources
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweData Controller License Handover Ceremony, 17 June 2025 — 570 licences issued on 6 June 2025
potraz.gov.zw
“A total of 570 data controllers received their licences — a group that included law firms, doctors' practices, health centres, municipalities, schools, churches, homeowners' associations, small and medium enterprises, corporations, parastatals, and government ministries.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweRegulatory Notice 1 of 2026 — Compliance with the Cyber and Data Protection Act, March 2026
potraz.zw
“POTRAZ has noted with concern that some organisations continue to process personal data without the requisite licence, despite the lapse of the March 2025 compliance deadline.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], sections 5, 6 and 33
ictministry.gov.zw
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabwePOTRAZ Data Controller Licencing and Registration System (live portal)
dclicensing.potraz.zw
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and a maximum, and the minimum is the precise one. Every business must keep its books and business records for at least six years. The tax authority must be able to inspect them and pull them back, including from a computer. Financial firms must keep security logs for at least five years. The maximum is vague. You must not keep personal data in a form that identifies people for longer than the purpose needs. Where the two clash, the fixed minimum wins, because keeping the record is a separate legal duty.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
The minimum comes from tax law. The tax authority says business records must be kept for at least six years. That covers ledgers, invoices, credit and debit notes and computer records. An officer must be able to inspect them. You must be able to produce them, as originals or copies, including from a computer or similar media. This is a rule about access, not about where the data sits. But it does mean an archive held abroad has to be produced on demand. The Reserve Bank of Zimbabwe's July 2026 guideline on digital financial services adds another minimum. It requires at least five years of archived security logs that cannot be altered. They are used for incident investigation and regulator audits. It also requires quarterly summaries of breaches and risk exposure. The maximum comes from the Cyber and Data Protection Act. Data must not be kept in a form that identifies people for longer than the purpose needs. No fixed maximum period is set anywhere. One point about deletion. The right to have data deleted is unusually narrow here. It covers only false or misleading data about the person. It is not a general right to be erased. So the maximum is enforced by the regulator, not by the people whose data you hold.
Sources
- Official sourceZimbabwe Revenue AuthorityRecord-keeping requirements
zimra.co.zw
“That these records be kept for a minimum period of six (6) years ... That, where these records are kept on computer, the officer should have access to these records for inspection and/or retrieval from such computer or other computer related gadgets or media.”
Link checked 18 August 2026
- Official sourceReserve Bank of ZimbabweGuidelines on Digital Financial Services (DFS) Security in Zimbabwe, July 2026, paragraph 8.2(b)
rbz.co.zw
“At least five (5) years of archived logs for incident investigation and regulatory audit.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], sections 7, 13 and 14
ictministry.gov.zw
“retained in a form that allows for the identification of data subjects, for no longer than necessary with a view to the purposes for which the data is collected or further processed.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Three clocks, and they do not line up. You have 24 hours to tell the data protection regulator about a personal data breach. The clock starts on a suspected breach, not only a confirmed one. You have 72 hours to tell the people affected if the breach is likely to harm them seriously. If you are a bank, a payment provider or a mobile money operator, you have only 3 hours to tell the central bank. After that you owe the data regulator answers to its questions within 14 days, and a closing investigation report within 21 days.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Clock one. The Cyber and Data Protection Act gives you 24 hours to tell the Authority about any security breach affecting data you hold. The regulator's breach guideline starts that clock when you become aware of a breach, actual or suspected. A phone call does not count. You must send Form DP3, addressed to the Director-General. Clock two. The 2024 regulations give you 72 hours to tell the people affected. That applies where the breach is likely to put their rights and freedoms at high risk. Clock three. The Reserve Bank of Zimbabwe sets a three-hour deadline. It applies to banks, non-bank financial institutions, controlling companies and payment system providers. They must report a confirmed cyber security incident within three hours of spotting it. Its July 2026 guideline on digital financial services repeats that deadline. The deadline covers fraud, platform downtime and customer data being exposed. Its list of punishments puts failure to report within 3 hours in the severe band, alongside suspension of services and losing your licence. The 24-hour and 3-hour clocks are the ones that break operations. A Zimbabwean bank hit by a data breach at 6pm on a Friday owes the central bank a report by 9pm that night. It owes the data regulator a completed form by 6pm on Saturday.
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], section 19
ictministry.gov.zw
“The data controller shall notify the Authority within twenty-four (24) hours of any security breach affecting data he or she processes.”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024, section 17 — breach notification, 72-hour subject notice, 14-day and 21-day follow-ups
potraz.zw
“Where the detected breach is likely to result in a high risk of adversely affecting individuals' rights and freedoms, the controller shall also inform those data subjects within 72 hours.”
Link checked 18 August 2026
- Official sourceReserve Bank of ZimbabweCybersecurity and Resilience Guideline, August 2025, paragraph 8.11
rbz.co.zw
“Institutions should report all confirmed cybersecurity incidents to the Reserve Bank within three hours of detection, or as soon as the institution becomes aware of the incident.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweCyber and Data Protection Implementation Guideline on Data Breach Notification and Handling, CDPG 3 of 2024
potraz.zw
“a data controller shall notify the Authority in writing within twenty-four (24) hours after becoming aware of an actual or suspected data breach.”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that ruin weekends. First, you need a government licence just to hold personal data. It expires every twelve months, and the original deadline was 12 March 2025, so most organisations are already late. Second, your data protection officer must pass a course approved by the regulator that costs 1,250 US dollars a head. Third, a child is anyone under 18, so a parent must agree before you handle a 17-year-old's data. Fourth, the punishment is criminal: up to seven years in prison, while the cash fine tops out around 1,000 US dollars. Fifth, the deletion right only covers false or misleading information, so 'delete my account' is not a legal right here.
- What you have to do here:
- Register or notify · Appoint a data protection officer · Get a parent's consent for children · Hold a security certificate
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine
Trap one is the licence. The 2024 regulations make it a crime to hold personal information without one. A licence lasts twelve months, and you must apply to renew at least three months before it expires. The price depends on how many people you hold data about. Tier 1 covers 50 to 1,000 people and costs 50 US dollars. Tier 2 covers 1,001 to 100,000 people and costs 300 US dollars. Tier 3 covers 100,001 to 500,000 people and costs 500 US dollars. Tier 4 covers more than 500,000 people and costs 2,500 US dollars. Tiers 2 to 4 pay a 30 US dollar application fee on top. The only exemptions are personal or household use, law enforcement, and journalism, history or archiving. The last two still have to register. Trap two is the data protection officer. You had 90 days from the regulations to appoint one. They must have skills in data science, analytics, information security, systems audit, law or audit. They must pass a certification course approved by the regulator. It costs 1,250 US dollars for Zimbabweans and 1,450 US dollars for foreign nationals. You then pay for their continuing training. If you change officer, or their contact details change, you must tell the regulator within 14 days. Trap three is children. The Act says a child is anyone under eighteen. You cannot handle a child's data without a parent's or guardian's consent. You must take reasonable steps to check that the consent is real. You must run regular impact assessments. And software alone cannot make decisions that affect a child's rights. Trap four is criminal exposure. Breaking the rules on sensitive data, on your own duties, on security, on accountability, or on sending data abroad is a crime. It carries up to seven years in prison. A court can also seize and destroy whatever the data is stored on, even if that equipment belongs to someone else. The top fine is only 1,000 US dollars under the standard scale set in February 2023. So the deterrent is prison and seizure, not money. Trap five is that the law itself is badly drafted. The Act says it must be read alongside a 'Protection of Personal Information Act [Chapter 10:27]'. No law of that name exists. Chapter 10:27 was the Access to Information and Protection of Privacy Act. The government's own National Information and Communication Technology Policy cites the Act under the wrong chapter number, 11:12. The guidelines carry a lot of weight that the Act does not clearly give them, and guidelines are not law.
Sources
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024, sections 3 to 13 and Second Schedule (fees)
potraz.zw
“A data controller shall appoint a DPO within 90 days from the date of promulgation of these regulations or date of termination of the DPO contract.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], sections 3, 4(1), 14 and 33
ictministry.gov.zw
“Any data controller, his or her representative, agent or assignee who contravenes section 11, 13, 18(4), 24 and 28 shall be guilty of an offence and liable to a fine not exceeding level 11 or to imprisonment for a period not exceeding seven years or to both such fine and such imprisonment.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweRegulatory Notice 1 of 2026 — confirms the licensing deadline was 12 March 2025 and has lapsed
potraz.zw
Link checked 18 August 2026
- Secondary sourceVeritas Zimbabwe (reproduction of the Government Gazette Extraordinary of 22 February 2023)Statutory Instrument 14A of 2023 — Criminal Law (Codification and Reform) (Standard Scale of Fines) Notice, 2023 (level 11 = US$1,000)
veritaszim.net
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesNational ICT Policy 2022-2027 — cites the Act as 'Data Protection Act [Chapter 11:12]', the wrong chapter number
ictministry.gov.zw
Link checked 18 August 2026
What's changing next
The near-term change is enforcement, not new law. From 1 September 2026 the regulator says it will inspect organisations. It will check that you hold a licence and have appointed a data protection officer. It works down a published list that starts with financial institutions, insurers, local authorities and health care providers. Longer term, Zimbabwe's national artificial intelligence plan for 2026 to 2030 promises policies to keep data in the country. It says critical data must sit on local infrastructure. That is a plan, not a law, and nothing has been written yet.
Three things are confirmed. First, the inspection campaign starting 1 September 2026. The published order is financial institutions, insurance companies, local authorities, health care providers, mining businesses, religious organisations, schools, colleges and professional bodies. After those come government ministries, departments and agencies. Last come non-governmental and private voluntary organisations. Second, the National Artificial Intelligence Strategy for 2026 to 2030, launched with a foreword by the President. It promises to upgrade the national data centres to Tier IV. It promises policies to keep data in the country. And it says critical data must sit on local, secure infrastructure. Third, the National Information and Communication Technology Policy for 2022 to 2027. It raises a possible rule that sensitive data must be encrypted end to end, with the keys held in Zimbabwe. It also proposes taking data protection away from the telecoms regulator and giving it to a separate authority. Three unused powers could change things overnight, with no public consultation. The telecoms regulator can name kinds of data work whose data may not go abroad at all. The Minister in charge of the Cyber Security and Monitoring Centre can issue directions on how transfers out of Zimbabwe are handled. That centre sits in the President's Office. And the Reserve Bank of Zimbabwe's July 2026 guideline already points to requirements about where data must sit. It has not defined them yet. It could switch them on for banks and payment firms with a single circular.
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesZimbabwe National Artificial Intelligence Strategy 2026-2030
ictministry.gov.zw
“Data Sovereignty: The principle that a nation's data is subject to the laws and governance structures of that nation. It asserts national control over digital assets and is a cornerstone of our strategy. Policies should be formulated to govern what data can be uploaded to foreign AI models to protect national and organizational security, insisting that critical data must reside on local, secure infrastructure.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesNational ICT Policy 2022-2027, data sovereignty policy statement
ictministry.gov.zw
“On cross border data flows, attendant regulations could be enacted to require end-to-end encryption of sensitive data and local hosting of associated encryption keys (where data localization is preferred.)”
Link checked 18 August 2026
- Secondary sourceVeritas ZimbabweBill Watch 27-2026, 28 July 2026 — POTRAZ inspections from 1 September 2026 and the sector priority order
veritaszim.net
Link checked 18 August 2026
- Official sourceReserve Bank of ZimbabweGuidelines on Digital Financial Services (DFS) Security in Zimbabwe, July 2026 — undefined 'RBZ-defined jurisdictional requirements' for data residency
rbz.co.zw
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data needs a copy kept in the country
Official name: Postal and Telecommunications (Domain Names Registration and Management) Regulations, 2023 · Statutory Instrument 111 of 2023 · Directly binding regulation
The only rule we found that forces data to stay physically in Zimbabwe. The main servers running Zimbabwe's national .zw internet address registry must sit in a Zimbabwean data centre wired into the Harare Internet Exchange. Backup copies abroad are allowed. This binds the registry operator and its accredited registrars. It does not bind an ordinary business that simply owns a .zw address.
Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority
How this country controls where data goes: No restriction
What you have to do
- Keep the data in the countryThe primary servers of the national .zw domain registry must be physically in Zimbabwe, in a data centre connected to the Harare Internet Exchange. Backup copies elsewhere in the region or abroad are expressly allowed. That is why a copy may leave even though the main servers may not.
- Register or notifyThe registry itself must hold an Application Services Provider licence from the regulator.
- Secure the dataRegistrars must not disclose domain holders' personal data and must keep stored personal data secure. New registration information must reach the registry within 24 hours of being created.
What it costs if you get it wrong
- Loss of your licenceBreach of the accreditation conditions by a registrar or reseller
Sources
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 111 of 2023, sections 4 and 17 (Government Gazette of 16 June 2023)
potraz.zw
“The primary servers of the Registry shall be in Zimbabwe housed at any Data Centre that connects to the Harare Internet Exchange (HIX) and shall have regional or international redundancy.”
Link checked 18 August 2026
Cyber security rules
Official name: Cybersecurity and Resilience Guideline (August 2025), read with the Guidelines on Digital Financial Services (DFS) Security in Zimbabwe (July 2026) · Issued under the Banking Act [Chapter 24:20], the Microfinance Act [Chapter 24:30] and the National Payment Systems Act [Chapter 24:23] · Regulator guideline
Banks, microfinance lenders, payment providers and mobile money operators answer to the central bank as well as the data regulator. The main duty is a three-hour incident report, one of the shortest anywhere. They must also keep five years of tamper-proof logs. They must tell the central bank before moving critical functions to the cloud. And they must follow rules about where data sits that the central bank has promised but not yet published.
Enforced by Reserve Bank of Zimbabwe
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Report cyber incidents — within 3 hoursReport every confirmed cyber security incident to the Reserve Bank within three hours of spotting it. The 2026 digital financial services guideline widens this to any confirmed or suspected compromise. That includes fraud, platform downtime and customer data being exposed.
- Keep logs — 5 yearsAt least five years of immutable archived logs, including privileged access logs, kept accessible to the Reserve Bank on request.
- Written vendor contractCloud contracts must spell out how you will follow data protection law when storing, using and sending personal data.
- Put a transfer safeguard in placeBefore you move critical functions abroad, assess the risk of the country involved and how your data will be kept separate.
- Independent auditAnnual cyber resilience self-assessment as at 31 December, submitted to the Reserve Bank by 15 February, plus quarterly incident and breach reports.
- Keep the data in the countryNot a real duty yet. The July 2026 guideline says where data sits must follow requirements the Reserve Bank defines. It does not say what they are, and we found no document setting them out as of August 2026. The central bank could switch this on at any time.
What it costs if you get it wrong
- Order to stopSevere breach, including failure to report an incident within three hours
- Loss of your licenceSevere breach, including a data breach or customer fraud caused by negligence
- Fixed maximum fineModerate breach, such as repeated failure to patch known vulnerabilities. The guideline says 'monetary penalties' without stating a ceiling.
Sources
- Official sourceReserve Bank of ZimbabweCybersecurity and Resilience Guideline, August 2025, paragraphs 2.1-2.2, 5.12-5.13 and 8.10-8.12
rbz.co.zw
“This guideline applies to all banking institutions, non-bank financial institutions, controlling companies, payment system providers and other entities, regulated in terms of the laws and regulations administered by the Reserve Bank”
Link checked 18 August 2026
- Official sourceReserve Bank of Zimbabwe, National Payment Systems DepartmentGuidelines on Digital Financial Services (DFS) Security in Zimbabwe, July 2026 (effective 17 July 2026)
rbz.co.zw
“Report any confirmed or suspected compromise, whether technical or fraud-related to RBZ via designated channels. For example, fraud, platform downtime, customer data compromise, among others, must be reported within 3 hours”
Link checked 18 August 2026
Telecoms data needs a copy kept in the country (Telecoms)
Official name: Interception of Communications Act [Chapter 11:20], as amended by section 37 of the Cyber and Data Protection Act · Cap. 11:20, amended by Act No. 5 of 2021 section 37 · Act of parliament
A unit in the President's Office is the only lawful channel for intercepting communications in Zimbabwe. So every telecoms and internet provider must keep interception capability inside the country. The unit also advises providers on security and runs the national cyber contact point. It publishes nothing, so we cannot see what it does day to day.
Enforced by Cyber Security and Monitoring of Interception of Communications Centre — not yet operational
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryAll lawful interception must run through a single national facility inside the Office of the President. Telecoms and internet providers therefore have to keep an interception-capable connection inside Zimbabwe, whatever else they do with their data.
- Report cyber incidentsThe centre operates the national round-the-clock cyber contact point and gives technical direction to service providers.
What it costs if you get it wrong
- Criminal liabilityFailure by a service provider to comply with interception obligations under the Interception of Communications Act
- Loss of your licenceBreach of telecoms licence conditions
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], section 37 — amendments to the Interception of Communications Act creating the Cyber Security and Monitoring of Interception of Communications Centre
ictministry.gov.zw
“There shall be established a unit in the Office of the President, which shall be called the Cyber Security and Monitoring of Interception of Communications Centre. ... The functions of the Cyber Security and Monitoring Centre shall be to— (a) be the sole facility through which authorised interceptions shall be effected”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024, section 16(6) — the centre and the national cyber incident response team advise controllers on security measures
potraz.zw
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: Cyber and Data Protection Act [Chapter 12:07] · Act No. 5 of 2021 · Act of parliament
Zimbabwe's general data protection law. It makes the telecoms regulator the data protection authority. It gives you 24 hours to report a breach. Before data leaves the country, you must show the destination protects it well enough. Serious breaches are a crime carrying up to seven years in prison. Cash fines are small. The prison term and the power to seize and destroy storage equipment are the real risk.
Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life
What you have to do
- Get consentWritten consent is required for sensitive information, including political affiliation, sex life, criminal history and health.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people object
- Let people delete their dataUnusually narrow. The right covers only false or misleading data. It is not a general right to be deleted.
- Limit automated decisionsSoftware alone cannot make a decision that has legal effects on someone, unless they consent or the law allows it.
- Secure the data
- Report breaches to the regulator — within 24 hours
- Delete data after a periodNo fixed period. Keep data in a form that identifies people only for as long as the purpose needs.
- Put a transfer safeguard in place
- Appoint a representativeRequired if your company is not permanently based in Zimbabwe but uses equipment located there.
- Appoint a data protection officer
- Keep records of how you use dataYou must tell the Authority before you run any automated data work. The notice has a detailed list of what to include.
- Get a parent's consent for children — applies at: under 18
What it costs if you get it wrong
- Criminal liability: level 11 fine (US$1 000) or 7 years imprisonment, or both — about $1 thousandBreach of the sensitive-data, controller-duty, security, accountability or cross-border transfer provisions
- Criminal liability: level 7 fine (US$400) or 2 years imprisonment, or both — about $400Breach by staff of the Authority, or by an expert, contractor or subcontractor
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], Act No. 5 of 2021 (full text)
ictministry.gov.zw
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweData Protection Act 5 of 2021 (regulator's own copy)
potraz.zw
Link checked 18 August 2026
Telecoms rules
Official name: Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 · Statutory Instrument 155 of 2024 · Directly binding regulation
Zimbabwe is one of very few countries where you need a government licence simply to hold personal data. The licence lasts twelve months and is priced by how many people you hold data on. The original compliance deadline of 12 March 2025 has already passed. You must also appoint a data protection officer who has passed a regulator-approved course.
Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Register or notify — applies at: Anyone who decides the purpose or means of processing personal data, or profits from it. Exempt: personal or household use, law enforcement, and journalistic, historical or archival purposes — the last two must still register., from 12 March 2025Licence valid 12 months. Renewal at least 3 months before expiry. Tier 1 (50-1,000 people) US$50. Tier 2 (1,001-100,000) US$300. Tier 3 (100,001-500,000) US$500. Tier 4 (over 500,000) US$2,500. Tiers 2 to 4 pay a US$30 application fee on top.
- Appoint a data protection officer — from 12 December 2024Appoint one within 90 days of the regulations. They must have the right skills and pass a certification course approved by the telecoms regulator. It costs US$1,250 for Zimbabweans and US$1,450 for foreign nationals. The employer pays for their continuing training.
- Hold a security certificateThe certification duty falls on the data protection officer in person. Training providers must themselves be accredited, at US$5,000 a year.
- Report breaches to the regulator — within 24 hoursUse Form DP3. It must be in writing; a phone call is not accepted. Answer follow-up questions within 14 days. Send a closing investigation report within 21 days.
- Tell affected people — applies at: Where the breach is likely to result in a high risk to individuals' rights and freedoms, within 72 hours
- Keep records of how you use dataTell the Authority about all your data work. Tell it about changes to data you collected from other sources. Tell it about any plan to send data abroad, and about any use of biometric or genetic data.
- Written vendor contractYou must have a written agreement with every company that handles data for you.
- Get a parent's consent for children — applies at: under 18
- Assess high-risk projects — applies at: Controllers processing children's dataRun assessments regularly. Build data protection into your product from the start and by default.
- Secure the data
What it costs if you get it wrong
- Criminal liability: level 11 fine (US$1 000) or 7 years imprisonment, or both — about $1 thousandProcessing without a licence, failing to renew, submitting false information, breaching controller duties, security or breach notification
- Criminal liability: level 7 fine (US$400) or 2 years imprisonment, or both — about $400Failure to appoint a data protection officer
Sources
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024 (full text, Government Gazette of 13 September 2024)
potraz.zw
“Persons that are controlling data by the date of promulgation of these regulations shall submit their applications for a data controller licence within 6 months from the date of promulgation of these regulations.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweRegulatory Notice 1 of 2026 — Compliance with the Cyber and Data Protection Act
potraz.zw
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Cyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information · CDPG 5 of 2024 · Regulator guideline
The regulator's guideline on sending data abroad is stricter than the Act it explains. It treats cloud storage, suppliers abroad, shared group databases and staff logging in from abroad as exports. Before anything moves, it wants prior notice, a submitted risk assessment, express consent, proof the destination protects data well enough, and a signed data-sharing agreement. Guidelines are not law, so parts of this are arguable. The regulator applies them anyway.
Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims
What you have to do
- Put a transfer safeguard in placeTell the regulator before the transfer. Show that the destination country protects data well enough. That is judged on its laws, its data regulator and its international promises.
- Assess high-risk projectsA data protection impact assessment must be completed and submitted with the notification.
- Get consentGet express consent first. Tell the person the destination country, the company receiving the data, the security measures, where it is stored and for how long. Consent is not needed for a contract with the person, an important public interest, legal claims, or public registers. You must still tell the regulator.
- Written vendor contractYou must sign a data-sharing agreement with every recipient abroad. It must contain a specific data protection clause.
- Keep records of how you use dataKeep a list of the personal data you send out of Zimbabwe. Assess, audit and inspect the recipients regularly.
What it costs if you get it wrong
- Criminal liability: level 11 fine (US$1 000) or 7 years imprisonment, or both — about $1 thousandContravening the cross-border transfer requirements in section 28 of the Act
Sources
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweCyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information, CDPG 5 of 2024, issued 13 November 2024
potraz.zw
“In the letter requesting prior authorization, the data controller or processor who intends to transfer data outside must demonstrate to the Authority fulfillment of the requirements above.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], section 28(3) — the power the guideline is issued under
ictministry.gov.zw
“The Authority shall lay down the categories of processing operations for which and the circumstances in which the transfer of data to countries outside the Republic of Zimbabwe is not authorised.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact date the Cyber and Data Protection Act came into force
We recorded 3 December 2021, but no government copy of the Act shows a start date on its face. The parliamentary website blocks automated access. Treat that date as approximate. There is no doubt that the Act is in force. If the exact date matters to your case, ask a Zimbabwean lawyer.
That compliance inspections begin on 1 September 2026 with the published sector priority order
Our only source is a Veritas Zimbabwe bulletin of 28 July 2026. We found nothing matching on the regulator's own site. This matters a lot if it is true, so we record it. Confirm the date with the regulator before you plan around it.
Whether any organisation has actually been prosecuted, fined or ordered to stop processing under the Act
Punishments here are criminal, so the State would bring the case and the regulator would not publish it. We found no enforcement decisions, prosecutions or announcements about punishment on any government site. We can show that licensing is happening. We cannot show whether anyone has been punished.
What the Reserve Bank's 'RBZ-defined jurisdictional requirements' for where data has to be stored actually are
The July 2026 guideline on digital financial services says you must follow these requirements. It never says what they are. We found no circular, directive or standard from the central bank that sets them out. Either they do not exist yet, or they are unpublished. If you are a bank or a payment firm, ask the Reserve Bank of Zimbabwe directly.
Whether the standard scale of fines has been revised since February 2023
We record the top fine as US$1,000, from the standard scale set in February 2023. Our copy of that scale comes from Veritas, which reproduces the Government Gazette. We could not find a government-hosted copy. Later changes may exist that we could not see, and the Ministry of Justice site was unreachable. Check the current figure before you rely on it.
Whether the public register of licensed and registered data controllers required by the 2024 regulations is actually published
The 2024 regulations say the register of licensed organisations must be open to inspection at the Authority's offices or on its website. We found no register on the regulator's site, only the application portal. Ask at its offices if you need to check whether a company is licensed.
Whether health, insurance, securities, education, gambling or mapping have their own data storage or localisation rules
We found no rule about data storage or keeping data in the country for these industries, checked on 18 August 2026. This is a weak negative. The insurance and pensions regulator publishes its circulars behind a document viewer we could not read. The securities regulator's site refused our requests. If you work in one of these industries, check with your regulator before you rely on this.
Whether telecoms licence conditions or subscriber registration rules require subscriber data to be held inside Zimbabwe
We could not open the subscriber registration rules. The regulator's legislation page lists only two sets of rules, both from 2023. A condition forcing subscriber data to stay in Zimbabwe may sit in individual licences, which are not published in full. If you hold a telecoms licence, read your own licence conditions.
The regulator's guidelines on licensing of data controllers and on appointment of data protection officers, in full
Both guidelines are published only as scanned images, so we could not read their text. What we describe here comes from the underlying regulations and from the regulator's own summaries. Read the guidelines themselves before you rely on the detail.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.