Zimbabwe’s Cyber and Data Protection Act (CDPA)
Also known as: act no. 5 of 2021, cdpa, chapter 12:07, cyber and data protection act, zimbabwe data protection law
The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s primary data-protection statute. It establishes core rules for processing personal information, identifies POTRAZ as the Data Protection Authority and addresses security, individual rights, controller and processor duties, cross-border transfers and offences. Regulations and POTRAZ guidance add important operational detail.
Term explanation
At a glance
Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] is the primary statute at the centre of the country’s data-protection framework. It deals with both cyber matters and personal-information governance. Privacy Hub uses “CDPA” as a short label, but article sources should identify the exact instrument and provision.
The Act should not be read alone. Binding subsidiary regulations and POTRAZ implementation guidelines provide operational requirements on areas such as licensing, DPO appointments, security, breach reporting and cross-border transfers.
In plain language
The Act contains rules on data quality, lawful and fair processing, purpose limitation, consent and other conditions for processing, sensitive information, controller and processor duties, security, information for data subjects, rights, breach notification, regulatory notifications, accountability and transborder data flows. It also designates POTRAZ as the Data Protection Authority.
Its scope includes processing and storage wholly or partly by automated means and contains a territorial rule for some controllers not permanently established in Zimbabwe where means used are located in Zimbabwe, excluding mere transit. Scope questions should be assessed against the actual activity rather than the organisation’s address alone.
Why it matters
The Act is primary legislation. SI 155 of 2024 is binding subsidiary legislation made under the Act and creates detailed licensing, DPO, security and breach rules. POTRAZ’s Cyber and Data Protection Implementation Guidelines provide interpretation and operational direction. They are important but should be labelled as guidance and read with the binding instruments.
National strategies, policies and draft regulations can signal future direction but do not create present duties unless and until the law gives them force. Privacy Hub articles should label each source as binding law, guidance, policy or draft.
A practical example
A Zimbabwe business uses an overseas cloud service and collects customer information through an app. It should consider the Act’s controller, transparency, security and transfer provisions; SI 155’s applicable licensing, DPO and security requirements; and relevant POTRAZ transfer guidance. A GDPR template alone will not answer those questions.
General principles
What this means for organisations
An organisation may need to determine whether it is a controller or processor, map its processing, identify a lawful condition, inform people, protect information, contract appropriately with processors, manage rights requests, assess high-risk work, prepare for incidents and evaluate overseas transfers. Licensing, registration, DPO and notification obligations require separate scope checks.
The framework contains legal terms and cross-references that can be difficult to operationalise. A full compliance assessment should trace each conclusion to the Act, applicable regulations and current guidance rather than copying a checklist from another jurisdiction.
Do not treat the CDPA as a renamed GDPR
The Zimbabwe framework shares familiar concepts with other privacy laws, but wording, thresholds, institutions and procedures differ. A GDPR-derived programme may provide useful governance foundations, yet it does not prove Zimbabwe compliance. Conversely, a Zimbabwe-specific control may not satisfy EU or UK requirements. Where instruments appear inconsistent or ambiguous, say so and route the issue to professional review rather than inventing a harmonised rule.
Practical next steps
Start with a data and role map. Check licensing and DPO scope, processing purposes, notices, processor agreements, security measures, breach readiness, individual-rights handling and international data access. Record exact sources and review dates. Use legal advice where the application or consequences are uncertain.
Related terms: POTRAZ; personal information; controller; DPO; privacy notice; data breach; cross-border transfer
Jurisdiction guidance
Select more lenses from the Hub landing page to compare across jurisdictions.
No jurisdiction-specific guidance is published for this lens yet.
Related terms
- Cross-border transfer of personal data — cross-border transfer
- Data controller — controller
- Data Protection Officer (DPO) — DPO
- Personal data and personal information — personal information
- Personal-data breach — data breach
- POTRAZ and its data-protection role — POTRAZ
- Privacy notice — privacy notice
Sources & citations
Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.
- ACT — Cyber and Data Protection Act (Chapter 12 07) (ACT)
ACT · primary · Read in the Legal Library
- CDPG 1 of 2025 — Compliance Assessments (CDPG-1-2025-CA)
CDPG-1-2025-CA · cites · Read in the Legal Library
- SI 155 of 2024 — Licensing of Data Controllers & Appointment of DPOs (SI155)
SI155 · cites · Read in the Legal Library
Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.