Skip to the content
Global Data RulesData governance rules, country by country

Zimbabwe

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Zimbabwe, but only after several hoops: tell the regulator first, run a risk assessment, get each person's clear permission, and show the destination country protects data properly. Almost every organisation that holds personal data also needs a licence, renewed every year. Breaking the rules is a crime, not just a fine.

Data governance in Zimbabwe

The eight things that decide how you handle data about people in Zimbabwe. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it can reach a foreign company. The law applies to an organisation with no permanent presence in Zimbabwe if the equipment it uses to handle the data sits in Zimbabwe. If that is you, you must appoint a representative based in Zimbabwe. There is no size or revenue floor to fall below: a sports club with a membership list is covered on the same terms as a bank. In March 2026 the regulator said the licence duty covers organisations 'permanently established in Zimbabwe or otherwise'.

High confidenceNational rulesAppoint a local representativeRegister or notify

Where the data is allowed to live

Yes, but not freely, and not quietly. You may only send personal data out of Zimbabwe if the destination protects it about as well as Zimbabwe does, and you must notify the regulator before the data moves. Storing data in a cloud service counts as sending it abroad. So does letting a colleague in another country log in and download it. Only one outright 'stays here' rule was found, and it covers the servers behind Zimbabwe's own .zw web addresses.

High confidenceYes, with paperworkApproval each timePut a transfer safeguard in place

Sending data out of the country

The model is case-by-case permission, not a tick-box contract. Before data leaves you must notify the regulator, hand it a written risk assessment, get the person's express agreement after telling them where the data is going and who will hold it, show that the destination country protects data properly, and sign a data-sharing agreement with whoever receives it. There is no published list of approved countries and no government contract template to sign. If you were already sending data abroad before the law, you must go back and regularise it.

High confidenceApproval each timeGovernment sign-off neededExplicit consentNeeded for a contractImportant public interestLegal claimsSomeone's life is at riskAssess high-risk projectsWritten vendor contract

The regulator, and whether it actually acts

The telecoms regulator, POTRAZ, doubles as the data protection authority. It is real and it is working. It handed out 570 data controller licences at a ceremony in June 2025, runs an online licensing portal, has published seven guidelines, got a new board in March 2026, and issued a public warning that same month to organisations still processing data without a licence. What is missing is punishment. The penalties in the law are criminal, so they need a prosecution in court, and no prosecutions or fines have been made public.

High confidenceWaking upCriminal liability

How long you must keep it — and when to delete it

There is a floor and a ceiling, and the floor is the specific one. Every business must keep its books and business records for at least six years, and the tax authority must be able to inspect and retrieve them, including from a computer. Financial firms must keep security logs for at least five years. The ceiling is vague: personal data must not be kept in a form that identifies people for longer than the purpose needs. Where the two collide, the fixed minimum wins, because keeping the record is a separate legal duty.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

Three clocks, and they do not line up. You have 24 hours to tell the data protection regulator about a personal data breach — and the clock starts on a suspected breach, not just a confirmed one. You have 72 hours to tell the people affected if the breach is likely to seriously harm them. If you are a bank, a payment provider or a mobile money operator you have only 3 hours to tell the central bank. After that you owe the data regulator answers to its questions within 14 days and a closing investigation report within 21 days.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that ruin weekends. First, you need a government licence just to hold personal data, it expires every twelve months, and the original deadline was 12 March 2025 — so most organisations are already late. Second, your data protection officer must pass a course approved by the regulator that costs 1,250 US dollars a head. Third, a child is anyone under 18, so a parent must agree before you process a 17-year-old's data. Fourth, the punishment is criminal: up to seven years in prison, while the cash fine tops out around 1,000 US dollars. Fifth, the deletion right only covers false or misleading information, so 'delete my account' is not a legal right here.

High confidenceRegister or notifyAppoint a data protection officerGet a parent's consent for childrenHold a security certificateCriminal liabilityFixed maximum fine

What's changing next

The near-term change is enforcement, not new law. The regulator announced that from 1 September 2026 it will inspect organisations to check they hold a licence and have appointed a data protection officer, working down a list that starts with financial institutions, insurers, local authorities and health care providers. Longer term, Zimbabwe's national artificial intelligence plan for 2026 to 2030 promises data localisation policies and says critical data must sit on local infrastructure. That is a plan, not a law, and nothing has been written yet.

Medium confidenceIn forceGovernment policy document

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Postal and Telecommunications (Domain Names Registration and Management) Regulations, 2023

Directly binding regulation · Statutory Instrument 111 of 2023

In forceA copy must stay

The only hard 'must physically stay in Zimbabwe' rule found. The main servers running Zimbabwe's national .zw internet address registry have to sit in a Zimbabwean data centre wired into the Harare Internet Exchange. Backup copies abroad are allowed. This binds the registry operator and accredited registrars, not ordinary businesses that merely own a .zw address.

In force since 16 June 2023

Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority

Transfer model: No restriction

High confidence
Finance

Cybersecurity and Resilience Guideline (August 2025), read with the Guidelines on Digital Financial Services (DFS) Security in Zimbabwe (July 2026)

Regulator guideline · Issued under the Banking Act [Chapter 24:20], the Microfinance Act [Chapter 24:30] and the National Payment Systems Act [Chapter 24:23]

In forceYes, with paperwork

Banks, microfinance lenders, payment providers and mobile money operators answer to the central bank as well as the data regulator. The headline duty is a three-hour incident report — one of the shortest anywhere. They must also keep five years of tamper-proof logs, tell the central bank before moving critical functions to the cloud, and follow data residency rules the central bank has promised but not yet published.

In force since 1 August 2025But only enforceable from 17 July 2026

Enforced by Reserve Bank of Zimbabwe

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed

High confidence
Telecoms

Interception of Communications Act [Chapter 11:20], as amended by section 37 of the Cyber and Data Protection Act

Act of parliament · Cap. 11:20, amended by Act No. 5 of 2021 section 37

In forceA copy must stay

A unit in the President's Office is the only lawful channel for intercepting communications in Zimbabwe, so every telecoms and internet provider must keep interception capability inside the country. The unit also advises providers on security and runs the national cyber contact point. It publishes nothing, so what it actually does day to day cannot be observed from outside.

In force since 3 December 2021

Enforced by Cyber Security and Monitoring of Interception of Communications Centre — not yet operational

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Cyber and Data Protection Act [Chapter 12:07]

Act of parliament · Act No. 5 of 2021

In forceYes, with paperwork

Zimbabwe's general data protection law. It designates the telecoms regulator as the data protection authority, sets a 24-hour breach clock, requires an adequacy assessment before data leaves the country, and makes serious breaches a criminal offence carrying up to seven years in prison. Cash fines are small; the prison term and the power to seize and destroy storage media are the real risk.

In force since 3 December 2021

Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk

High confidence

Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024

Directly binding regulation · Statutory Instrument 155 of 2024

In forceYes, with paperwork

Zimbabwe is one of very few countries where you need a government licence simply to hold personal data. The licence lasts twelve months, is priced by how many people you hold data on, and the original compliance deadline of 12 March 2025 has already passed. You must also appoint a data protection officer who has passed a regulator-approved course.

In force since 13 September 2024But only enforceable from 12 March 2025

Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed

High confidence

Cyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information

Regulator guideline · CDPG 5 of 2024

In forceYes, with paperwork

The regulator's transfer guideline is stricter than the Act it explains. It treats cloud storage, offshore processors, intra-group databases and offshore staff logins as exports, and requires prior notification plus a submitted risk assessment, express consent, an adequacy demonstration and a signed data-sharing agreement before anything moves. Guidelines are not law, so parts of this are arguable — but the regulator applies them.

In force since 13 November 2024

Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims

High confidence

Who you would hear from

  • POTRAZ

    General data protection, data controller licensing, data protection officer certification, breach notification, cross-border transfer, telecoms and the .zw domain registry

    Clearly operational. Issued 570 data controller licences at a public ceremony on 6 June 2025, runs an online licensing portal at dclicensing.potraz.zw, has published guidelines on licensing, data protection officers, consent, breach handling, cross-border transfer and children's data, seated a new board in March 2026, published Regulatory Notice 1 of 2026 chasing unlicensed organisations, and announced compliance inspections from 1 September 2026. No prosecutions or fines have been made public, which is why enforcement is rated waking rather than active. Its independence is contestable: the board is appointed by the President and must follow the responsible Minister's general policy directives under the Postal and Telecommunications Act.

  • Makes regulations under the Cyber and Data Protection Act; owns the National ICT Policy and the National Artificial Intelligence Strategy

  • Banks, microfinance institutions, payment system providers and mobile money operators — cybersecurity, incident reporting, log retention and cloud outsourcing

    Actively issuing binding guidance: Cybersecurity and Resilience Guideline in August 2025, Digital Financial Services Security Guidelines effective 17 July 2026, with a published sanctions ladder up to licence revocation.

  • Sole national lawful interception facility; advises service providers on cyber security; sits in the Office of the President

    Established by statute in 2021 but it has no public website, publishes no decisions and issues no public guidance. Its existence is documented only in the legislation and in cross-references from the 2024 regulations. We cannot evidence that it is staffed or active; the link given is to the ministry that publishes the governing statute, not to the centre itself.

  • ZIMRA

    Six-year minimum retention of business books and records, and the right to inspect and retrieve them from computer systems

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact date the Cyber and Data Protection Act came into force

    The Act is numbered 5 of 2021 and we recorded 3 December 2021, but neither the ministry's copy nor the regulator's copy of the Act carries a gazette or commencement date on its face, and the parliamentary website blocks automated access. Treat the date as indicative; the fact that the Act is in force is not in doubt.

  • That compliance inspections begin on 1 September 2026 with the published sector priority order

    The only source is a Veritas Zimbabwe bulletin of 28 July 2026. No matching notice was found on the regulator's own site, and its search index returned nothing for 'inspection'. High-value if true, so it is recorded, but it carries no government backlink.

  • Whether any organisation has actually been prosecuted, fined or ordered to stop processing under the Act

    Penalties are criminal and would be prosecuted by the State rather than published by the regulator. No enforcement decisions, prosecutions or press statements about sanctions were found on any government site. We can evidence licensing activity but not sanctioning activity; we cannot prove the negative.

  • What the Reserve Bank's 'RBZ-defined jurisdictional requirements' for data residency actually are

    The July 2026 digital financial services guideline requires compliance with them but does not define them, and no separate circular, directive or prudential standard defining them was found in the central bank's published guidelines, circulars or national payment systems pages. Either they do not yet exist or they are unpublished.

  • Whether the standard scale of fines has been revised since February 2023

    Level 11 is recorded as US$1,000 from Statutory Instrument 14A of 2023. That instrument is cited from a Veritas reproduction of the Government Gazette Extraordinary, not from a government-hosted copy, and later amending notices may exist. The Ministry of Justice site was unreachable.

  • Whether the public register of licensed and registered data controllers required by the 2024 regulations is actually published

    Section 9 of Statutory Instrument 155 of 2024 requires the register to be inspectable at the Authority's premises or on its website. No register was located on the regulator's site, only the application portal.

  • Whether health, insurance, securities, education, gambling or mapping have their own data storage or localisation rules

    No sector-specific storage or localisation rule was found in any of these areas, checked on 18 August 2026. This is a weak negative: the insurance and pensions regulator publishes its circulars behind a JavaScript document centre we could not enumerate, the securities regulator's site refused automated requests, and no general web search engine was available during this run, so coverage of these sectors is thinner than for banking and telecoms.

  • Whether telecoms licence conditions or subscriber registration rules require subscriber data to be held inside Zimbabwe

    The regulator's legislation page lists only two statutory instruments from 2023, and the subscriber registration regulations were not among the documents we could open. A localisation condition may exist in individual licence templates that are not published in full.

  • The regulator's guidelines on licensing of data controllers and on appointment of data protection officers, in full

    Both are published only as scanned images with no extractable text. Their substance is described here from the underlying statutory instrument and from the regulator's own summaries, not from the guideline text itself.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Put this next to another country

Zimbabwe versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.