Skip to the content
Global Data RulesData governance rules, country by country

Zimbabwe

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Zimbabwe — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Zimbabwe, but only after several steps. Tell the regulator first. Run a risk assessment. Get clear permission from each person. Show that the destination country protects data properly. Almost every organisation that holds personal data also needs a licence, renewed every year. Breaking the rules is a crime, not just a fine.

Data governance in Zimbabwe

The eight things that decide how you handle data about people in Zimbabwe. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it can reach a foreign company. The law applies to a company with no permanent presence in Zimbabwe if the equipment it uses to handle the data sits in Zimbabwe. If that is you, you must appoint a representative based in Zimbabwe. There is no size or revenue floor to fall below. A sports club with a membership list is covered on the same terms as a bank. In March 2026 the regulator said the licence duty covers organisations 'permanently established in Zimbabwe or otherwise'.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, but not freely, and not quietly. You may only send personal data out of Zimbabwe if the destination protects it about as well as Zimbabwe does. You must also notify the regulator before the data moves. Storing data in a cloud service counts as sending it abroad. So does letting a colleague in another country log in and download it. We found only one outright 'stays here' rule, and it covers the servers behind Zimbabwe's own .zw web addresses.

What you have to do here:
Put a transfer safeguard in place

What to do: Get the paperwork for one of the routes below signed before any data leaves Zimbabwe.

Sending data out of the country

You need permission, granted one transfer at a time. There is no tick-box contract. Before data leaves you must do five things. Tell the regulator. Give it a written risk assessment. Get the person's express agreement, after telling them where the data is going and who will hold it. Show that the destination country protects data properly. And sign a data-sharing agreement with whoever receives it. There is no published list of approved countries and no government contract template to sign. If you were already sending data abroad before the law, you must go back and put it right.

What you have to do here:
Assess high-risk projects · Written vendor contract
Ways to send data out:
Government sign-off needed · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

The telecoms regulator does double duty as the data protection authority. Its full name is the Postal and Telecommunications Regulatory Authority of Zimbabwe. It is real and it is working. It handed out 570 licences at a ceremony in June 2025, runs an online licensing portal and has published seven guidelines. It got a new board in March 2026, and that same month it publicly warned organisations still holding data without a licence. What is missing is punishment. The penalties in the law are criminal, so they need a prosecution in court. No prosecutions or fines have been made public.

What it costs if you get it wrong:
Criminal liability

How long you must keep it — and when to delete it

There is a minimum and a maximum, and the minimum is the precise one. Every business must keep its books and business records for at least six years. The tax authority must be able to inspect them and pull them back, including from a computer. Financial firms must keep security logs for at least five years. The maximum is vague. You must not keep personal data in a form that identifies people for longer than the purpose needs. Where the two clash, the fixed minimum wins, because keeping the record is a separate legal duty.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Three clocks, and they do not line up. You have 24 hours to tell the data protection regulator about a personal data breach. The clock starts on a suspected breach, not only a confirmed one. You have 72 hours to tell the people affected if the breach is likely to harm them seriously. If you are a bank, a payment provider or a mobile money operator, you have only 3 hours to tell the central bank. After that you owe the data regulator answers to its questions within 14 days, and a closing investigation report within 21 days.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that ruin weekends. First, you need a government licence just to hold personal data. It expires every twelve months, and the original deadline was 12 March 2025, so most organisations are already late. Second, your data protection officer must pass a course approved by the regulator that costs 1,250 US dollars a head. Third, a child is anyone under 18, so a parent must agree before you handle a 17-year-old's data. Fourth, the punishment is criminal: up to seven years in prison, while the cash fine tops out around 1,000 US dollars. Fifth, the deletion right only covers false or misleading information, so 'delete my account' is not a legal right here.

What you have to do here:
Register or notify · Appoint a data protection officer · Get a parent's consent for children · Hold a security certificate
What it costs if you get it wrong:
Criminal liability · Fixed maximum fine

What's changing next

The near-term change is enforcement, not new law. From 1 September 2026 the regulator says it will inspect organisations. It will check that you hold a licence and have appointed a data protection officer. It works down a published list that starts with financial institutions, insurers, local authorities and health care providers. Longer term, Zimbabwe's national artificial intelligence plan for 2026 to 2030 promises policies to keep data in the country. It says critical data must sit on local infrastructure. That is a plan, not a law, and nothing has been written yet.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data needs a copy kept in the country

Official name: Postal and Telecommunications (Domain Names Registration and Management) Regulations, 2023 · Statutory Instrument 111 of 2023 · Directly binding regulation

In forceA copy must stay

The only rule we found that forces data to stay physically in Zimbabwe. The main servers running Zimbabwe's national .zw internet address registry must sit in a Zimbabwean data centre wired into the Harare Internet Exchange. Backup copies abroad are allowed. This binds the registry operator and its accredited registrars. It does not bind an ordinary business that simply owns a .zw address.

In force since 16 June 2023

Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority

How this country controls where data goes: No restriction

Finance

Cyber security rules

Official name: Cybersecurity and Resilience Guideline (August 2025), read with the Guidelines on Digital Financial Services (DFS) Security in Zimbabwe (July 2026) · Issued under the Banking Act [Chapter 24:20], the Microfinance Act [Chapter 24:30] and the National Payment Systems Act [Chapter 24:23] · Regulator guideline

In forceYes, with paperwork

Banks, microfinance lenders, payment providers and mobile money operators answer to the central bank as well as the data regulator. The main duty is a three-hour incident report, one of the shortest anywhere. They must also keep five years of tamper-proof logs. They must tell the central bank before moving critical functions to the cloud. And they must follow rules about where data sits that the central bank has promised but not yet published.

In force since 1 August 2025Enforced from 17 July 2026

Enforced by Reserve Bank of Zimbabwe

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Telecoms

Telecoms data needs a copy kept in the country (Telecoms)

Official name: Interception of Communications Act [Chapter 11:20], as amended by section 37 of the Cyber and Data Protection Act · Cap. 11:20, amended by Act No. 5 of 2021 section 37 · Act of parliament

In forceA copy must stay

A unit in the President's Office is the only lawful channel for intercepting communications in Zimbabwe. So every telecoms and internet provider must keep interception capability inside the country. The unit also advises providers on security and runs the national cyber contact point. It publishes nothing, so we cannot see what it does day to day.

In force since 3 December 2021

Enforced by Cyber Security and Monitoring of Interception of Communications Centre — not yet operational

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: Cyber and Data Protection Act [Chapter 12:07] · Act No. 5 of 2021 · Act of parliament

In forceYes, with paperwork

Zimbabwe's general data protection law. It makes the telecoms regulator the data protection authority. It gives you 24 hours to report a breach. Before data leaves the country, you must show the destination protects it well enough. Serious breaches are a crime carrying up to seven years in prison. Cash fines are small. The prison term and the power to seize and destroy storage equipment are the real risk.

In force since 3 December 2021

Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life

Telecoms rules

Official name: Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 · Statutory Instrument 155 of 2024 · Directly binding regulation

In forceYes, with paperwork

Zimbabwe is one of very few countries where you need a government licence simply to hold personal data. The licence lasts twelve months and is priced by how many people you hold data on. The original compliance deadline of 12 March 2025 has already passed. You must also appoint a data protection officer who has passed a regulator-approved course.

In force since 13 September 2024Enforced from 12 March 2025

Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Cloud and outsourcing rules

Official name: Cyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information · CDPG 5 of 2024 · Regulator guideline

In forceYes, with paperwork

The regulator's guideline on sending data abroad is stricter than the Act it explains. It treats cloud storage, suppliers abroad, shared group databases and staff logging in from abroad as exports. Before anything moves, it wants prior notice, a submitted risk assessment, express consent, proof the destination protects data well enough, and a signed data-sharing agreement. Guidelines are not law, so parts of this are arguable. The regulator applies them anyway.

In force since 13 November 2024

Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims

Who you would hear from

  • POTRAZ

    General data protection, data controller licensing, data protection officer certification, breach notification, cross-border transfer, telecoms and the .zw domain registry

    Clearly working. It gave out 570 licences at a public ceremony on 6 June 2025. It runs an online licensing portal at dclicensing.potraz.zw. It has published guidelines on licensing, data protection officers, consent, breach handling, sending data abroad and children's data. It seated a new board in March 2026. It published Regulatory Notice 1 of 2026, chasing organisations with no licence. And it announced compliance inspections from 1 September 2026. No prosecutions or fines have been made public, which is why we rate enforcement as waking rather than active. Its independence is open to question. The President appoints its board, and it must follow the responsible Minister's general policy directions under the Postal and Telecommunications Act.

  • Makes regulations under the Cyber and Data Protection Act; owns the National ICT Policy and the National Artificial Intelligence Strategy

  • Banks, microfinance institutions, payment system providers and mobile money operators — cybersecurity, incident reporting, log retention and cloud outsourcing

    Actively issuing binding guidance. It published the Cybersecurity and Resilience Guideline in August 2025. Its Digital Financial Services Security Guidelines took effect on 17 July 2026. It publishes a list of punishments that runs up to taking away your licence.

  • Sole national lawful interception facility; advises service providers on cyber security; sits in the Office of the President

    A 2021 law set it up. It has no public website, publishes no decisions and issues no public guidance. The only proof it exists is the law itself and references to it in the 2024 regulations. We cannot show that it is staffed or active. The link here goes to the ministry that publishes the governing law, not to the centre itself.

  • ZIMRA

    Six-year minimum retention of business books and records, and the right to inspect and retrieve them from computer systems

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact date the Cyber and Data Protection Act came into force

    We recorded 3 December 2021, but no government copy of the Act shows a start date on its face. The parliamentary website blocks automated access. Treat that date as approximate. There is no doubt that the Act is in force. If the exact date matters to your case, ask a Zimbabwean lawyer.

  • That compliance inspections begin on 1 September 2026 with the published sector priority order

    Our only source is a Veritas Zimbabwe bulletin of 28 July 2026. We found nothing matching on the regulator's own site. This matters a lot if it is true, so we record it. Confirm the date with the regulator before you plan around it.

  • Whether any organisation has actually been prosecuted, fined or ordered to stop processing under the Act

    Punishments here are criminal, so the State would bring the case and the regulator would not publish it. We found no enforcement decisions, prosecutions or announcements about punishment on any government site. We can show that licensing is happening. We cannot show whether anyone has been punished.

  • What the Reserve Bank's 'RBZ-defined jurisdictional requirements' for where data has to be stored actually are

    The July 2026 guideline on digital financial services says you must follow these requirements. It never says what they are. We found no circular, directive or standard from the central bank that sets them out. Either they do not exist yet, or they are unpublished. If you are a bank or a payment firm, ask the Reserve Bank of Zimbabwe directly.

  • Whether the standard scale of fines has been revised since February 2023

    We record the top fine as US$1,000, from the standard scale set in February 2023. Our copy of that scale comes from Veritas, which reproduces the Government Gazette. We could not find a government-hosted copy. Later changes may exist that we could not see, and the Ministry of Justice site was unreachable. Check the current figure before you rely on it.

  • Whether the public register of licensed and registered data controllers required by the 2024 regulations is actually published

    The 2024 regulations say the register of licensed organisations must be open to inspection at the Authority's offices or on its website. We found no register on the regulator's site, only the application portal. Ask at its offices if you need to check whether a company is licensed.

  • Whether health, insurance, securities, education, gambling or mapping have their own data storage or localisation rules

    We found no rule about data storage or keeping data in the country for these industries, checked on 18 August 2026. This is a weak negative. The insurance and pensions regulator publishes its circulars behind a document viewer we could not read. The securities regulator's site refused our requests. If you work in one of these industries, check with your regulator before you rely on this.

  • Whether telecoms licence conditions or subscriber registration rules require subscriber data to be held inside Zimbabwe

    We could not open the subscriber registration rules. The regulator's legislation page lists only two sets of rules, both from 2023. A condition forcing subscriber data to stay in Zimbabwe may sit in individual licences, which are not published in full. If you hold a telecoms licence, read your own licence conditions.

  • The regulator's guidelines on licensing of data controllers and on appointment of data protection officers, in full

    Both guidelines are published only as scanned images, so we could not read their text. What we describe here comes from the underlying regulations and from the regulator's own summaries. Read the guidelines themselves before you rely on the detail.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.