Skip to content

Privacy Hub · plain-language reference

← Privacy Hub

Zimbabwe’s Cyber and Data Protection Act (CDPA)

Also known as: act no. 5 of 2021, cdpa, chapter 12:07, cyber and data protection act, zimbabwe data protection law

The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s primary data-protection statute. It establishes core rules for processing personal information, identifies POTRAZ as the Data Protection Authority and addresses security, individual rights, controller and processor duties, cross-border transfers and offences. Regulations and POTRAZ guidance add important operational detail.

ZW_CDPA
EU_GDPR
GB_UK_GDPR
v2 · published 31 Jul 2026

Term explanation

At a glance

Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] is the primary statute at the centre of the country’s data-protection framework. It deals with both cyber matters and personal-information governance. Privacy Hub uses “CDPA” as a short label, but article sources should identify the exact instrument and provision.

The Act should not be read alone. Binding subsidiary regulations and POTRAZ implementation guidelines provide operational requirements on areas such as licensing, DPO appointments, security, breach reporting and cross-border transfers.

In plain language

The Act contains rules on data quality, lawful and fair processing, purpose limitation, consent and other conditions for processing, sensitive information, controller and processor duties, security, information for data subjects, rights, breach notification, regulatory notifications, accountability and transborder data flows. It also designates POTRAZ as the Data Protection Authority.

Its scope includes processing and storage wholly or partly by automated means and contains a territorial rule for some controllers not permanently established in Zimbabwe where means used are located in Zimbabwe, excluding mere transit. Scope questions should be assessed against the actual activity rather than the organisation’s address alone.

Why it matters

The Act is primary legislation. SI 155 of 2024 is binding subsidiary legislation made under the Act and creates detailed licensing, DPO, security and breach rules. POTRAZ’s Cyber and Data Protection Implementation Guidelines provide interpretation and operational direction. They are important but should be labelled as guidance and read with the binding instruments.

National strategies, policies and draft regulations can signal future direction but do not create present duties unless and until the law gives them force. Privacy Hub articles should label each source as binding law, guidance, policy or draft.

A practical example

A Zimbabwe business uses an overseas cloud service and collects customer information through an app. It should consider the Act’s controller, transparency, security and transfer provisions; SI 155’s applicable licensing, DPO and security requirements; and relevant POTRAZ transfer guidance. A GDPR template alone will not answer those questions.

General principles

What this means for organisations

An organisation may need to determine whether it is a controller or processor, map its processing, identify a lawful condition, inform people, protect information, contract appropriately with processors, manage rights requests, assess high-risk work, prepare for incidents and evaluate overseas transfers. Licensing, registration, DPO and notification obligations require separate scope checks.

The framework contains legal terms and cross-references that can be difficult to operationalise. A full compliance assessment should trace each conclusion to the Act, applicable regulations and current guidance rather than copying a checklist from another jurisdiction.

Do not treat the CDPA as a renamed GDPR

The Zimbabwe framework shares familiar concepts with other privacy laws, but wording, thresholds, institutions and procedures differ. A GDPR-derived programme may provide useful governance foundations, yet it does not prove Zimbabwe compliance. Conversely, a Zimbabwe-specific control may not satisfy EU or UK requirements. Where instruments appear inconsistent or ambiguous, say so and route the issue to professional review rather than inventing a harmonised rule.

Practical next steps

Start with a data and role map. Check licensing and DPO scope, processing purposes, notices, processor agreements, security measures, breach readiness, individual-rights handling and international data access. Record exact sources and review dates. Use legal advice where the application or consequences are uncertain.

Related terms: POTRAZ; personal information; controller; DPO; privacy notice; data breach; cross-border transfer

Jurisdiction guidance

Select more lenses from the Hub landing page to compare across jurisdictions.

GLOBAL
Global baseline

No jurisdiction-specific guidance is published for this lens yet.

Sources & citations

Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.


Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.