Zimbabwean entities that collect personal information have until 1 September 2026 to comply with the Cyber and Data Protection Act, as the regulator prepares to start mandatory inspections.
Vengai Madzima, a senior partner at a Harare law firm, explained that the Post and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) will begin data protection assessments and inspections on that date for entities not covered by exemptions. This applies to government departments, businesses, universities and financial institutions that handle details such as identity, finances, health or employment records.
To become compliant, a data controller must obtain an annual licence from POTRAZ. The licence category depends on the volume of personal data processed. Organisations must also appoint a certified data protection officer responsible for compliance audits, employee training and liaising with the regulator.
If a data breach occurs, controllers have 24 hours to report it to the Data Protection Authority. When the breach poses a real risk to individuals, those affected must be notified within 72 hours.
Not all processing is covered. Exemptions include personal or household activities, certain law enforcement functions, and work done for historical or journalistic purposes, among others.
Madzima noted that compliance is not a once-off task. Data controllers must collect personal information only for legitimate reasons, keep it secure, and retain it only for as long as necessary.
With the deadline days away, Harare businesses and public bodies should review their data protection measures and ensure they have the required licence, officer and breach response plans in place.

