Zimbabwe
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Data can leave Zimbabwe, but only after several hoops: tell the regulator first, run a risk assessment, get each person's clear permission, and show the destination country protects data properly. Almost every organisation that holds personal data also needs a licence, renewed every year. Breaking the rules is a crime, not just a fine.
Data governance in Zimbabwe
The eight things that decide how you handle data about people in Zimbabwe. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it can reach a foreign company. The law applies to an organisation with no permanent presence in Zimbabwe if the equipment it uses to handle the data sits in Zimbabwe. If that is you, you must appoint a representative based in Zimbabwe. There is no size or revenue floor to fall below: a sports club with a membership list is covered on the same terms as a bank. In March 2026 the regulator said the licence duty covers organisations 'permanently established in Zimbabwe or otherwise'.
Section 4(2)(b) of the Cyber and Data Protection Act uses a 'means used' test, not the targeting test familiar from Europe. That is narrower on paper: a purely foreign service with no equipment in Zimbabwe is arguably outside it. But 'means' is undefined, and the regulator's own Regulatory Notice 1 of 2026 reads the licensing duty as extending beyond entities permanently established in the country. Section 4(3) requires a representative established in Zimbabwe whenever subsection (2)(b) bites. Statutes in Zimbabwe do not bind the State unless they say so, and this one does not, so government ministries and agencies arguably fall outside the licensing duty even though the regulator's guidance says otherwise.
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], Act No. 5 of 2021, section 4
ictministry.gov.zw
“to the processing and storage of data by a controller who is not permanently established in Zimbabwe, if the means used, whether electronic or otherwise is located in Zimbabwe, and such processing and storage is not for the purposes of the mere transit of data through Zimbabwe.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweRegulatory Notice 1 of 2026 — Compliance with the Cyber and Data Protection Act [Chapter 12:07], March 2026
potraz.zw
“The Data Controller licensing requirement applies to non-exempt natural and legal persons permanently established in Zimbabwe or otherwise that process personal data using both print and electronic means, including surveillance or biometric systems.”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024 — Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024, sections 3 and 4
potraz.zw
Link checked 18 August 2026
Where the data is allowed to live
Yes, but not freely, and not quietly. You may only send personal data out of Zimbabwe if the destination protects it about as well as Zimbabwe does, and you must notify the regulator before the data moves. Storing data in a cloud service counts as sending it abroad. So does letting a colleague in another country log in and download it. Only one outright 'stays here' rule was found, and it covers the servers behind Zimbabwe's own .zw web addresses.
Sections 28 and 29 of the Act set the frame: no transfer unless an adequate level of protection is ensured in the recipient country, with six narrow escape hatches in section 29 (consent, contract necessity, third-party contract in the person's interest, public interest or legal claims, vital interests, and public registers). The regulator's Implementation Guideline on Cross Border Transfer of Personal Information (CDPG 5 of 2024, issued 13 November 2024) goes considerably further than the statute, treating cloud hosting, offshore processors, intra-group databases and offshore staff access as transfers. Two dormant switches sit in section 28: subsection (3) lets the regulator declare categories of processing for which transfer abroad is simply not authorised — no such list was found as of August 2026 — and subsection (4) lets the Minister responsible for the presidential Cyber Security and Monitoring Centre issue directions on how transfers are to be handled. Sector position: no localisation was found in banking, insurance, securities, health, gaming or mapping. The central bank's July 2026 digital financial services guideline says data residency 'must comply with RBZ-defined jurisdictional requirements' but does not state what those requirements are, and no separate instrument defining them was located.
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], sections 28 and 29 (transborder flow)
ictministry.gov.zw
“a data controller may not transfer personal information about a data subject to a third party who is in a foreign country unless an adequate level of protection is ensured in the country of the recipient”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweCyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information, CDPG 5 of 2024
potraz.zw
“Storing personal data in the cloud also constitutes a transfer outside Zimbabwe if the cloud server is accessible outside Zimbabwe.”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 111 of 2023 — Postal and Telecommunications (Domain Names Registration and Management) Regulations, 2023, section 4(3)
potraz.zw
“The primary servers of the Registry shall be in Zimbabwe housed at any Data Centre that connects to the Harare Internet Exchange (HIX) and shall have regional or international redundancy.”
Link checked 18 August 2026
- Official sourceReserve Bank of Zimbabwe, National Payment Systems DepartmentGuidelines on Digital Financial Services (DFS) Security in Zimbabwe, July 2026, paragraph 7.2(b)
rbz.co.zw
“Data residency must comply with RBZ-defined jurisdictional requirements.”
Link checked 18 August 2026
Sending data out of the country
The model is case-by-case permission, not a tick-box contract. Before data leaves you must notify the regulator, hand it a written risk assessment, get the person's express agreement after telling them where the data is going and who will hold it, show that the destination country protects data properly, and sign a data-sharing agreement with whoever receives it. There is no published list of approved countries and no government contract template to sign. If you were already sending data abroad before the law, you must go back and regularise it.
The regulator's guideline states that controllers 'are prohibited from cross-border data transfers unless they have notified the Authority' and refers to 'the letter requesting prior authorization', which in practice makes this a permission regime rather than a notification one. The five preconditions are: a data protection impact assessment submitted with the notification; express consent after disclosure of the destination country, the recipient organisation, the security measures, the storage location and the storage duration; a demonstration of adequacy judged on the destination's laws, its supervisory authority and its international commitments; documented organisational and technical measures; and a data-sharing agreement containing a specific data protection clause. Consent is not needed where the transfer is necessary for a contract with the person, for an important public interest or legal claims, or comes from a public register — but the regulator must still be notified. Two important gaps: no adequacy list has been published, so 'adequate protection' is assessed transfer by transfer, and the guideline itself is not law. It is issued under a power in section 28(3) that allows the regulator to say where transfers are NOT authorised, which is not obviously wide enough to support a general prior-authorisation requirement. Treat it as binding in practice and arguable in court.
Sources
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweCyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information, CDPG 5 of 2024, paragraphs 3 and 5
potraz.zw
“Data controllers are prohibited from cross-border data transfers unless they have notified the Authority. The data controller must first notify the authority of their intention to transfer data and must satisfy the following conditions before transferring data from Zimbabwe”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024, section 10(2)(c) — duty to notify the Authority of any intention to transfer data abroad
potraz.zw
“A data controller shall notify the Authority of the following— ... (c) any intention to transfer or share information of data subject outside Zimbabwe;”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], section 29 (transfers where protection is not adequate)
ictministry.gov.zw
Link checked 18 August 2026
The regulator, and whether it actually acts
The telecoms regulator, POTRAZ, doubles as the data protection authority. It is real and it is working. It handed out 570 data controller licences at a ceremony in June 2025, runs an online licensing portal, has published seven guidelines, got a new board in March 2026, and issued a public warning that same month to organisations still processing data without a licence. What is missing is punishment. The penalties in the law are criminal, so they need a prosecution in court, and no prosecutions or fines have been made public.
Section 5 of the Act designates the Postal and Telecommunications Regulatory Authority of Zimbabwe as the Data Protection Authority. Observable evidence of activity as of August 2026: an inaugural licence handover on 6 June 2025 attended by more than 500 delegates at which 570 licences were issued to law firms, medical practices, municipalities, schools, churches, homeowners' associations, parastatals and ministries; a live licensing portal at dclicensing.potraz.zw; guidelines on licensing, data protection officers, consent, breach notification, cross-border transfer and children's data; a 2026 data protection officer training calendar; a new board announced in March 2026; and Regulatory Notice 1 of 2026 chasing unlicensed organisations. Independence is a fair question rather than a settled fact: section 6(2) says the Authority is not subject to direction when acting as data protection authority, but the POTRAZ board is appointed by the President and must comply with the responsible Minister's general policy directives under the Postal and Telecommunications Act. Separately, the Cyber Security and Monitoring of Interception of Communications Centre sits inside the Office of the President; it has no public website and publishes nothing, so its activity cannot be observed. Rated 'waking' rather than 'active' because the licensing machine is clearly running while the sanction machine has produced no visible output.
Sources
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweData Controller License Handover Ceremony, 17 June 2025 — 570 licences issued on 6 June 2025
potraz.gov.zw
“A total of 570 data controllers received their licences — a group that included law firms, doctors' practices, health centres, municipalities, schools, churches, homeowners' associations, small and medium enterprises, corporations, parastatals, and government ministries.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweRegulatory Notice 1 of 2026 — Compliance with the Cyber and Data Protection Act, March 2026
potraz.zw
“POTRAZ has noted with concern that some organisations continue to process personal data without the requisite licence, despite the lapse of the March 2025 compliance deadline.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], sections 5, 6 and 33
ictministry.gov.zw
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabwePOTRAZ Data Controller Licencing and Registration System (live portal)
dclicensing.potraz.zw
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling, and the floor is the specific one. Every business must keep its books and business records for at least six years, and the tax authority must be able to inspect and retrieve them, including from a computer. Financial firms must keep security logs for at least five years. The ceiling is vague: personal data must not be kept in a form that identifies people for longer than the purpose needs. Where the two collide, the fixed minimum wins, because keeping the record is a separate legal duty.
Floor: the tax authority states that business records including ledgers, invoices, credit and debit notes and computer records must be kept for a minimum of six years, be open to inspection by an officer, and be retrievable in original or copied form, including from a computer or related media. That is an access duty rather than a storage-location duty, but in practice it means offshore archives must be producible on demand. The Reserve Bank's July 2026 digital financial services guideline requires at least five years of archived immutable security logs for incident investigation and regulatory audit, plus quarterly breach and risk exposure summaries. Ceiling: section 7(1)(c) and section 13 of the Act both require data to be retained in identifiable form for no longer than necessary for the purpose. No fixed maximum period is set anywhere. Note that the deletion right in section 14 is unusually narrow — it covers only 'false or misleading' data about the person, not a general right to erasure — so the ceiling is enforced by the regulator rather than by individuals.
Sources
- Official sourceZimbabwe Revenue AuthorityRecord-keeping requirements
zimra.co.zw
“That these records be kept for a minimum period of six (6) years ... That, where these records are kept on computer, the officer should have access to these records for inspection and/or retrieval from such computer or other computer related gadgets or media.”
Link checked 18 August 2026
- Official sourceReserve Bank of ZimbabweGuidelines on Digital Financial Services (DFS) Security in Zimbabwe, July 2026, paragraph 8.2(b)
rbz.co.zw
“At least five (5) years of archived logs for incident investigation and regulatory audit.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], sections 7, 13 and 14
ictministry.gov.zw
“retained in a form that allows for the identification of data subjects, for no longer than necessary with a view to the purposes for which the data is collected or further processed.”
Link checked 18 August 2026
If something goes wrong
Three clocks, and they do not line up. You have 24 hours to tell the data protection regulator about a personal data breach — and the clock starts on a suspected breach, not just a confirmed one. You have 72 hours to tell the people affected if the breach is likely to seriously harm them. If you are a bank, a payment provider or a mobile money operator you have only 3 hours to tell the central bank. After that you owe the data regulator answers to its questions within 14 days and a closing investigation report within 21 days.
Clock one: section 19 of the Act requires notification to the Authority within 24 hours of any security breach affecting data the controller processes; the regulator's breach guideline reads this as running from awareness of an 'actual or suspected' breach, and oral notification is not accepted — it must be Form DP3 addressed to the Director-General. Clock two: regulation 17(3) of Statutory Instrument 155 of 2024 requires the controller to inform affected individuals within 72 hours where the breach is likely to result in a high risk to their rights and freedoms. Clock three: the Reserve Bank requires all banking institutions, non-bank financial institutions, controlling companies and payment system providers to report confirmed cybersecurity incidents within three hours of detection, a deadline repeated in the July 2026 digital financial services guideline for fraud, platform downtime and customer data compromise, with a table of sanctions that puts 'failure to report within 3hrs' in the severe band alongside suspension of services and licence revocation. The 24-hour and 3-hour clocks are the ones that break operations: a Zimbabwean bank suffering a data breach at 6pm on a Friday owes the central bank a report by 9pm that night and the data regulator a completed form by 6pm Saturday.
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], section 19
ictministry.gov.zw
“The data controller shall notify the Authority within twenty-four (24) hours of any security breach affecting data he or she processes.”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024, section 17 — breach notification, 72-hour subject notice, 14-day and 21-day follow-ups
potraz.zw
“Where the detected breach is likely to result in a high risk of adversely affecting individuals' rights and freedoms, the controller shall also inform those data subjects within 72 hours.”
Link checked 18 August 2026
- Official sourceReserve Bank of ZimbabweCybersecurity and Resilience Guideline, August 2025, paragraph 8.11
rbz.co.zw
“Institutions should report all confirmed cybersecurity incidents to the Reserve Bank within three hours of detection, or as soon as the institution becomes aware of the incident.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweCyber and Data Protection Implementation Guideline on Data Breach Notification and Handling, CDPG 3 of 2024
potraz.zw
“a data controller shall notify the Authority in writing within twenty-four (24) hours after becoming aware of an actual or suspected data breach.”
Link checked 18 August 2026
What catches people out
Five things that ruin weekends. First, you need a government licence just to hold personal data, it expires every twelve months, and the original deadline was 12 March 2025 — so most organisations are already late. Second, your data protection officer must pass a course approved by the regulator that costs 1,250 US dollars a head. Third, a child is anyone under 18, so a parent must agree before you process a 17-year-old's data. Fourth, the punishment is criminal: up to seven years in prison, while the cash fine tops out around 1,000 US dollars. Fifth, the deletion right only covers false or misleading information, so 'delete my account' is not a legal right here.
Trap one, licensing: Statutory Instrument 155 of 2024 makes it an offence to process personal information without a data controller licence. Licences run twelve months and renewal must be applied for at least three months before expiry. Tiers are by headcount of data subjects — Tier 1 (50 to 1,000) costs US$50, Tier 2 (1,001 to 100,000) US$300, Tier 3 (100,001 to 500,000) US$500 and Tier 4 (over 500,000) US$2,500, plus a US$30 application fee for Tiers 2 to 4. Only personal or household use, law enforcement and journalistic, historical or archival purposes are exempt, and the last two must still register. Trap two, the data protection officer: one had to be appointed within 90 days of the regulations, must hold skills in data science, analytics, information security, systems audit, law or audit, must complete a regulator-approved certification course at US$1,250 for Zimbabweans or US$1,450 for foreigners, and must be kept in continuing professional development at the employer's cost. Changes of officer or of the officer's contact details must be notified within 14 days. Trap three, children: the Act defines a child as anyone under eighteen and the regulations forbid processing children's data without a parent or guardian's consent, require reasonable verification of that consent, require regular impact assessments, and ban automated decisions affecting children's rights. Trap four, criminal exposure: section 33 makes contravention of the sensitive-data, controller-duties, security, accountability and cross-border rules an offence carrying up to seven years' imprisonment, and a court may order seizure and destruction of the media holding the data even if it belongs to someone else. The level 11 fine ceiling is only US$1,000 under the standard scale set in February 2023, so the deterrent is the prison term and the seizure power, not the money. Trap five, drafting quality: section 4(1) says the Act must be read alongside a 'Protection of Personal Information Act [Chapter 10:27]' — no statute of that name exists; Chapter 10:27 was the Access to Information and Protection of Privacy Act. The government's own National ICT Policy cites the Act under the wrong chapter number, 11:12. Guidelines are doing a lot of work that the statute does not clearly authorise, and they are not law.
Sources
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024, sections 3 to 13 and Second Schedule (fees)
potraz.zw
“A data controller shall appoint a DPO within 90 days from the date of promulgation of these regulations or date of termination of the DPO contract.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], sections 3, 4(1), 14 and 33
ictministry.gov.zw
“Any data controller, his or her representative, agent or assignee who contravenes section 11, 13, 18(4), 24 and 28 shall be guilty of an offence and liable to a fine not exceeding level 11 or to imprisonment for a period not exceeding seven years or to both such fine and such imprisonment.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweRegulatory Notice 1 of 2026 — confirms the licensing deadline was 12 March 2025 and has lapsed
potraz.zw
Link checked 18 August 2026
- Secondary sourceVeritas Zimbabwe (reproduction of the Government Gazette Extraordinary of 22 February 2023)Statutory Instrument 14A of 2023 — Criminal Law (Codification and Reform) (Standard Scale of Fines) Notice, 2023 (level 11 = US$1,000)
veritaszim.net
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesNational ICT Policy 2022-2027 — cites the Act as 'Data Protection Act [Chapter 11:12]', the wrong chapter number
ictministry.gov.zw
Link checked 18 August 2026
What's changing next
The near-term change is enforcement, not new law. The regulator announced that from 1 September 2026 it will inspect organisations to check they hold a licence and have appointed a data protection officer, working down a list that starts with financial institutions, insurers, local authorities and health care providers. Longer term, Zimbabwe's national artificial intelligence plan for 2026 to 2030 promises data localisation policies and says critical data must sit on local infrastructure. That is a plan, not a law, and nothing has been written yet.
Confirmed pipeline. First, the inspection campaign from 1 September 2026, with a published priority order: financial institutions, insurance companies, local authorities, health care providers, mining enterprises, religious organisations, schools and tertiary institutions and professional bodies, government ministries departments and agencies, then non-governmental and private voluntary organisations. Second, the National Artificial Intelligence Strategy 2026-2030, launched under the President's foreword, commits to upgrading national data centres to Tier IV and building 'data localisation policies', and defines data sovereignty as 'insisting that critical data must reside on local, secure infrastructure'. Third, the National ICT Policy 2022-2027 flags a possible requirement for end-to-end encryption of sensitive data with local hosting of the encryption keys, and separately proposes moving the data protection mandate out of POTRAZ into a standalone authority. Dormant switches that could change the picture overnight, with no consultation: section 28(3) lets POTRAZ declare categories of processing for which transfer abroad is not authorised; section 28(4) lets the Minister responsible for the presidential Cyber Security and Monitoring Centre issue directions on how transfers out of Zimbabwe are implemented; and the Reserve Bank's July 2026 guideline already refers to 'RBZ-defined jurisdictional requirements' for data residency that have not yet been defined, so the central bank can turn on a financial-sector residency rule by circular.
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesZimbabwe National Artificial Intelligence Strategy 2026-2030
ictministry.gov.zw
“Data Sovereignty: The principle that a nation's data is subject to the laws and governance structures of that nation. It asserts national control over digital assets and is a cornerstone of our strategy. Policies should be formulated to govern what data can be uploaded to foreign AI models to protect national and organizational security, insisting that critical data must reside on local, secure infrastructure.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesNational ICT Policy 2022-2027, data sovereignty policy statement
ictministry.gov.zw
“On cross border data flows, attendant regulations could be enacted to require end-to-end encryption of sensitive data and local hosting of associated encryption keys (where data localization is preferred.)”
Link checked 18 August 2026
- Secondary sourceVeritas ZimbabweBill Watch 27-2026, 28 July 2026 — POTRAZ inspections from 1 September 2026 and the sector priority order
veritaszim.net
Link checked 18 August 2026
- Official sourceReserve Bank of ZimbabweGuidelines on Digital Financial Services (DFS) Security in Zimbabwe, July 2026 — undefined 'RBZ-defined jurisdictional requirements' for data residency
rbz.co.zw
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Postal and Telecommunications (Domain Names Registration and Management) Regulations, 2023
Directly binding regulation · Statutory Instrument 111 of 2023
The only hard 'must physically stay in Zimbabwe' rule found. The main servers running Zimbabwe's national .zw internet address registry have to sit in a Zimbabwean data centre wired into the Harare Internet Exchange. Backup copies abroad are allowed. This binds the registry operator and accredited registrars, not ordinary businesses that merely own a .zw address.
Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority
Transfer model: No restriction
What it makes you do
- Keep the data in the countryThe primary servers of the national .zw domain registry must be physically in Zimbabwe, in a data centre connected to the Harare Internet Exchange. Regional or international backup copies are expressly allowed, which is what makes this a mirror rather than a closed rule.
- Register or notifyThe registry itself must hold an Application Services Provider licence from the regulator.
- Secure the dataRegistrars must not disclose domain holders' personal data and must keep stored personal data secure; new registration information must reach the registry within 24 hours of creation.
What it costs if you get it wrong
- Loss of your licenceBreach of the accreditation conditions by a registrar or reseller
Sources
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 111 of 2023, sections 4 and 17 (Government Gazette of 16 June 2023)
potraz.zw
“The primary servers of the Registry shall be in Zimbabwe housed at any Data Centre that connects to the Harare Internet Exchange (HIX) and shall have regional or international redundancy.”
Link checked 18 August 2026
Cybersecurity and Resilience Guideline (August 2025), read with the Guidelines on Digital Financial Services (DFS) Security in Zimbabwe (July 2026)
Regulator guideline · Issued under the Banking Act [Chapter 24:20], the Microfinance Act [Chapter 24:30] and the National Payment Systems Act [Chapter 24:23]
Banks, microfinance lenders, payment providers and mobile money operators answer to the central bank as well as the data regulator. The headline duty is a three-hour incident report — one of the shortest anywhere. They must also keep five years of tamper-proof logs, tell the central bank before moving critical functions to the cloud, and follow data residency rules the central bank has promised but not yet published.
Enforced by Reserve Bank of Zimbabwe
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Report cyber incidents — within 3 hoursAll confirmed cybersecurity incidents to the Reserve Bank within three hours of detection. The 2026 digital financial services guideline extends this to any confirmed or suspected compromise, including fraud, platform downtime and customer data compromise.
- Keep logs — 5 yearsAt least five years of immutable archived logs, including privileged access logs, kept accessible to the Reserve Bank on request.
- Written vendor contractCloud contracts must contain explicit provisions for compliance with data protection law covering storage, processing and transmission of personal data.
- Put a transfer safeguard in placeAssess jurisdictional risk and data segregation before outsourcing critical functions abroad.
- Independent auditAnnual cyber resilience self-assessment as at 31 December, submitted to the Reserve Bank by 15 February, plus quarterly incident and breach reports.
- Keep the data in the countryNot yet a real duty. The July 2026 guideline says data residency must comply with 'RBZ-defined jurisdictional requirements' without saying what they are. No instrument defining them was found as of August 2026. Treat as a dormant switch.
What it costs if you get it wrong
- Order to stopSevere breach, including failure to report an incident within three hours
- Loss of your licenceSevere breach, including a data breach or customer fraud caused by negligence
- Fixed maximum fineModerate breach, such as repeated failure to patch known vulnerabilities. The guideline says 'monetary penalties' without stating a ceiling.
Sources
- Official sourceReserve Bank of ZimbabweCybersecurity and Resilience Guideline, August 2025, paragraphs 2.1-2.2, 5.12-5.13 and 8.10-8.12
rbz.co.zw
“This guideline applies to all banking institutions, non-bank financial institutions, controlling companies, payment system providers and other entities, regulated in terms of the laws and regulations administered by the Reserve Bank”
Link checked 18 August 2026
- Official sourceReserve Bank of Zimbabwe, National Payment Systems DepartmentGuidelines on Digital Financial Services (DFS) Security in Zimbabwe, July 2026 (effective 17 July 2026)
rbz.co.zw
“Report any confirmed or suspected compromise, whether technical or fraud-related to RBZ via designated channels. For example, fraud, platform downtime, customer data compromise, among others, must be reported within 3 hours”
Link checked 18 August 2026
Interception of Communications Act [Chapter 11:20], as amended by section 37 of the Cyber and Data Protection Act
Act of parliament · Cap. 11:20, amended by Act No. 5 of 2021 section 37
A unit in the President's Office is the only lawful channel for intercepting communications in Zimbabwe, so every telecoms and internet provider must keep interception capability inside the country. The unit also advises providers on security and runs the national cyber contact point. It publishes nothing, so what it actually does day to day cannot be observed from outside.
Enforced by Cyber Security and Monitoring of Interception of Communications Centre — not yet operational
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryAll lawful interception must run through a single national facility inside the Office of the President. Telecoms and internet providers therefore have to keep an interception-capable connection inside Zimbabwe, whatever else they do with their data.
- Report cyber incidentsThe centre operates the national round-the-clock cyber contact point and gives technical direction to service providers.
What it costs if you get it wrong
- Criminal liabilityFailure by a service provider to comply with interception obligations under the Interception of Communications Act
- Loss of your licenceBreach of telecoms licence conditions
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], section 37 — amendments to the Interception of Communications Act creating the Cyber Security and Monitoring of Interception of Communications Centre
ictministry.gov.zw
“There shall be established a unit in the Office of the President, which shall be called the Cyber Security and Monitoring of Interception of Communications Centre. ... The functions of the Cyber Security and Monitoring Centre shall be to— (a) be the sole facility through which authorised interceptions shall be effected”
Link checked 18 August 2026
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024, section 16(6) — the centre and the national cyber incident response team advise controllers on security measures
potraz.zw
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Cyber and Data Protection Act [Chapter 12:07]
Act of parliament · Act No. 5 of 2021
Zimbabwe's general data protection law. It designates the telecoms regulator as the data protection authority, sets a 24-hour breach clock, requires an adequacy assessment before data leaves the country, and makes serious breaches a criminal offence carrying up to seven years in prison. Cash fines are small; the prison term and the power to seize and destroy storage media are the real risk.
Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk
What it makes you do
- Get consentWritten consent is required for sensitive information, including political affiliation, sex life, criminal history and health.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people object
- Let people delete their dataUnusually narrow: the right covers only false or misleading data, not a general right to erasure.
- Limit automated decisionsNo decision based solely on automated processing with legal effects without consent or a legal basis.
- Secure the data
- Report breaches to the regulator — within 24 hours
- Delete data after a periodNo fixed period. Identifiable form only for as long as the purpose requires.
- Put a transfer safeguard in place
- Appoint a local representativeRequired where the controller is not permanently established in Zimbabwe but uses means located in Zimbabwe.
- Appoint a data protection officer
- Keep records of processingPrior notification to the Authority of automated processing operations, with a detailed content list.
- Get a parent's consent for children — applies at: under 18
What it costs if you get it wrong
- Criminal liability: level 11 fine (US$1 000) or 7 years imprisonment, or both — about $1 thousandBreach of the sensitive-data, controller-duty, security, accountability or cross-border transfer provisions
- Criminal liability: level 7 fine (US$400) or 2 years imprisonment, or both — about $400Breach by staff of the Authority, or by an expert, contractor or subcontractor
Sources
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], Act No. 5 of 2021 (full text)
ictministry.gov.zw
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweData Protection Act 5 of 2021 (regulator's own copy)
potraz.zw
Link checked 18 August 2026
Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024
Directly binding regulation · Statutory Instrument 155 of 2024
Zimbabwe is one of very few countries where you need a government licence simply to hold personal data. The licence lasts twelve months, is priced by how many people you hold data on, and the original compliance deadline of 12 March 2025 has already passed. You must also appoint a data protection officer who has passed a regulator-approved course.
Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Register or notify — applies at: Anyone who decides the purpose or means of processing personal data, or profits from it. Exempt: personal or household use, law enforcement, and journalistic, historical or archival purposes — the last two must still register., from 12 March 2025Licence valid 12 months. Renewal at least 3 months before expiry. Tier 1 (50-1,000 people) US$50; Tier 2 (1,001-100,000) US$300; Tier 3 (100,001-500,000) US$500; Tier 4 (over 500,000) US$2,500; plus a US$30 application fee for Tiers 2 to 4.
- Appoint a data protection officer — from 12 December 2024Within 90 days of the regulations. Must hold relevant skills and pass a POTRAZ-approved certification course costing US$1,250 for Zimbabweans and US$1,450 for foreign nationals, with continuing professional development paid for by the employer.
- Hold a security certificateThe certification duty falls on the data protection officer personally; training providers must themselves be accredited at US$5,000 a year.
- Report breaches to the regulator — within 24 hoursForm DP3. Written only; oral notification is not accepted. Answers to follow-up questions within 14 days and a closing investigation report within 21 days.
- Tell affected people — applies at: Where the breach is likely to result in a high risk to individuals' rights and freedoms, within 72 hours
- Keep records of processingNotify the Authority of all processing activities, of indirect collection changes, of any intention to transfer data abroad, and of any biometric or genetic processing.
- Written vendor contractA written data processing agreement with every processor is mandatory.
- Get a parent's consent for children — applies at: under 18
- Assess high-risk projects — applies at: Controllers processing children's dataRegular assessments, plus data protection by design and by default.
- Secure the data
What it costs if you get it wrong
- Criminal liability: level 11 fine (US$1 000) or 7 years imprisonment, or both — about $1 thousandProcessing without a licence, failing to renew, submitting false information, breaching controller duties, security or breach notification
- Criminal liability: level 7 fine (US$400) or 2 years imprisonment, or both — about $400Failure to appoint a data protection officer
Sources
- Official sourceGovernment Printer, Harare (published by POTRAZ)Statutory Instrument 155 of 2024 (full text, Government Gazette of 13 September 2024)
potraz.zw
“Persons that are controlling data by the date of promulgation of these regulations shall submit their applications for a data controller licence within 6 months from the date of promulgation of these regulations.”
Link checked 18 August 2026
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweRegulatory Notice 1 of 2026 — Compliance with the Cyber and Data Protection Act
potraz.zw
Link checked 18 August 2026
Cyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information
Regulator guideline · CDPG 5 of 2024
The regulator's transfer guideline is stricter than the Act it explains. It treats cloud storage, offshore processors, intra-group databases and offshore staff logins as exports, and requires prior notification plus a submitted risk assessment, express consent, an adequacy demonstration and a signed data-sharing agreement before anything moves. Guidelines are not law, so parts of this are arguable — but the regulator applies them.
Enforced by Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims
What it makes you do
- Put a transfer safeguard in placeNotify the regulator before the transfer and demonstrate adequacy of the destination country's laws, supervisory authority and international commitments.
- Assess high-risk projectsA data protection impact assessment must be completed and submitted with the notification.
- Get consentExpress consent after disclosure of the destination country, the recipient organisation, the security measures, the storage location and the storage duration. Not required for contract necessity, public interest or legal claims, or public registers — but the regulator must still be told.
- Written vendor contractA data-sharing agreement with a specific data protection clause is mandatory with every offshore recipient.
- Keep records of processingKeep an inventory of personal data transferred out of Zimbabwe and run regular transfer impact assessments, audits and inspections of recipients.
What it costs if you get it wrong
- Criminal liability: level 11 fine (US$1 000) or 7 years imprisonment, or both — about $1 thousandContravening the cross-border transfer requirements in section 28 of the Act
Sources
- Official sourcePostal and Telecommunications Regulatory Authority of ZimbabweCyber and Data Protection Implementation Guideline on Cross Border Transfer of Personal Information, CDPG 5 of 2024, issued 13 November 2024
potraz.zw
“In the letter requesting prior authorization, the data controller or processor who intends to transfer data outside must demonstrate to the Authority fulfillment of the requirements above.”
Link checked 18 August 2026
- Official sourceMinistry of Information Communication Technology, Postal and Courier ServicesCyber and Data Protection Act [Chapter 12:07], section 28(3) — the power the guideline is issued under
ictministry.gov.zw
“The Authority shall lay down the categories of processing operations for which and the circumstances in which the transfer of data to countries outside the Republic of Zimbabwe is not authorised.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact date the Cyber and Data Protection Act came into force
The Act is numbered 5 of 2021 and we recorded 3 December 2021, but neither the ministry's copy nor the regulator's copy of the Act carries a gazette or commencement date on its face, and the parliamentary website blocks automated access. Treat the date as indicative; the fact that the Act is in force is not in doubt.
That compliance inspections begin on 1 September 2026 with the published sector priority order
The only source is a Veritas Zimbabwe bulletin of 28 July 2026. No matching notice was found on the regulator's own site, and its search index returned nothing for 'inspection'. High-value if true, so it is recorded, but it carries no government backlink.
Whether any organisation has actually been prosecuted, fined or ordered to stop processing under the Act
Penalties are criminal and would be prosecuted by the State rather than published by the regulator. No enforcement decisions, prosecutions or press statements about sanctions were found on any government site. We can evidence licensing activity but not sanctioning activity; we cannot prove the negative.
What the Reserve Bank's 'RBZ-defined jurisdictional requirements' for data residency actually are
The July 2026 digital financial services guideline requires compliance with them but does not define them, and no separate circular, directive or prudential standard defining them was found in the central bank's published guidelines, circulars or national payment systems pages. Either they do not yet exist or they are unpublished.
Whether the standard scale of fines has been revised since February 2023
Level 11 is recorded as US$1,000 from Statutory Instrument 14A of 2023. That instrument is cited from a Veritas reproduction of the Government Gazette Extraordinary, not from a government-hosted copy, and later amending notices may exist. The Ministry of Justice site was unreachable.
Whether the public register of licensed and registered data controllers required by the 2024 regulations is actually published
Section 9 of Statutory Instrument 155 of 2024 requires the register to be inspectable at the Authority's premises or on its website. No register was located on the regulator's site, only the application portal.
Whether health, insurance, securities, education, gambling or mapping have their own data storage or localisation rules
No sector-specific storage or localisation rule was found in any of these areas, checked on 18 August 2026. This is a weak negative: the insurance and pensions regulator publishes its circulars behind a JavaScript document centre we could not enumerate, the securities regulator's site refused automated requests, and no general web search engine was available during this run, so coverage of these sectors is thinner than for banking and telecoms.
Whether telecoms licence conditions or subscriber registration rules require subscriber data to be held inside Zimbabwe
The regulator's legislation page lists only two statutory instruments from 2023, and the subscriber registration regulations were not among the documents we could open. A localisation condition may exist in individual licence templates that are not published in full.
The regulator's guidelines on licensing of data controllers and on appointment of data protection officers, in full
Both are published only as scanned images with no extractable text. Their substance is described here from the underlying statutory instrument and from the regulator's own summaries, not from the guideline text itself.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Put this next to another country
Zimbabwe versus
Compare