Privacy Hub · plain-language reference
Public-interest · plain language
Guides
Short guides for people who need to understand the law without becoming lawyers. Written for organisations of any size and for the people whose data they hold.
Featured comparative guide
GDPR vs Zimbabwe CDPA — a side-by-side comparison
Controllers, DPOs, breach clocks, lawful bases, penalties — how the EU GDPR maps to Zimbabwe’s Cyber and Data Protection Act.
zimbabwe
SI 155 in plain English
The 2024 regulations that put teeth into Zimbabwe's Cyber and Data Protection Act — what they actually require of your organisation.
Updated 19 Jul 2026
roles
Do you need a DPO?
A Data Protection Officer is not optional in most jurisdictions. Here is how to tell whether you must appoint one.
Updated 19 Jul 2026
incidents
The 24-hour breach rule
Zimbabwe's CDPA gives you 24 hours to tell POTRAZ about a personal-data breach — half the time of GDPR. Here is what to do.
Updated 19 Jul 2026
accountability
What is a RoPA?
A Record of Processing Activities is the single most useful compliance artefact you will build. It is also the one most often missing.
Updated 19 Jul 2026
Looking for a single term instead? Browse the A–Z of privacy terms. Want to see how the law lands country by country? Open the Africa Privacy-Law Tracker.