Skip to content

Privacy Hub · plain-language reference

← Guides

Comparative guide · Zimbabwe · European Union

GDPR vs Zimbabwe CDPA — a side-by-side comparison

A translation layer for international compliance teams working across the EU General Data Protection Regulation (GDPR) and Zimbabwe’s Cyber and Data Protection Act (CDPA, Chapter 12:07). Same direction of travel; different clocks, different regulator, and a licensing regime the GDPR doesn’t have.

The five things that trip people up

  1. The breach clock is 24 hours under the CDPA, not 72.
  2. Every licensed data controller must appoint a DPO — the trigger is broader than the GDPR’s.
  3. Zimbabwean data controllers must be licensed by POTRAZ; there is a live fee schedule.
  4. Cross-border transfers hinge on POTRAZ adequacy or safeguards, not the European Commission’s adequacy list.
  5. Penalties can include criminal liability for responsible individuals — not just administrative fines.

Concept-by-concept mapping

ConceptEU GDPRZimbabwe CDPA
Governing lawRegulation (EU) 2016/679 (General Data Protection Regulation), in force since 25 May 2018.Cyber and Data Protection Act [Chapter 12:07] (2021), Zimbabwe's first consolidated data-protection statute.
RegulatorNational Data Protection Authorities (e.g. CNIL, ICO pre-Brexit) coordinated by the European Data Protection Board.Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), designated as the Data Protection Authority.
Data ControllerNatural or legal person who alone or jointly determines the purposes and means of processing (Art. 4(7)).The 'data controller' — same functional concept: the person who determines purpose and means of processing personal information (s.3).
Data ProcessorProcesses personal data on behalf of the controller (Art. 4(8)); contractual controls in Art. 28.Recognised distinctly from the controller; controllers must contract processors on written terms consistent with the Act.
Data Protection Officer (DPO)Mandatory where the controller is a public authority or where core activities involve large-scale monitoring or special-category data (Art. 37).Every licensed data controller must appoint a DPO — the CDPA trigger is broader than GDPR's 'core activities' test.

Not sure whether you need one? Run the free POTRAZ tier + DPO checker.

Licensing / registrationNo general registration requirement; some Member States retained notification regimes.Data controllers must be licensed by POTRAZ under a tiered fee schedule; licensing is a live compliance obligation, not a formality.
Lawful basesSix bases in Art. 6: consent, contract, legal obligation, vital interests, public task, legitimate interests.Comparable grounds: consent, contract necessity, legal obligation, vital interests, public interest, and legitimate interests of the controller.
Sensitive / special-category dataArt. 9 special categories: health, biometrics, race, religion, sexual orientation, trade-union membership, etc.'Sensitive data' includes health, genetic/biometric data, race, religion, political opinions, criminal records, and children's data.
Data-subject rightsAccess, rectification, erasure, restriction, portability, objection, and rights around automated decisions (Arts. 15–22).Rights of access, correction, deletion, and objection are provided; portability and automated-decision rights are more narrowly framed.
Notice / transparencyArts. 13–14 prescribe the exact information a controller must give the data subject at collection.Controllers must provide a privacy notice with equivalent core elements — identity, purpose, recipients, rights, retention.

The free Privacy Notice grader scores a notice against the CDPA Playbook.

Data Protection Impact Assessment (DPIA)Required for 'high-risk' processing (Art. 35); prior consultation with the DPA where residual risk remains.DPIAs are required for processing that presents specific risks — the trigger list is issued by POTRAZ.
Personal-data breach notificationNotify the DPA within 72 hours of becoming aware; notify data subjects without undue delay where risk is high (Arts. 33–34).Notify POTRAZ and affected data subjects within 24 hours of becoming aware of the breach — a materially tighter clock than the GDPR's 72.

Different clocks mean different runbooks — plan for the shortest applicable window.

Cross-border transfersAllowed to 'adequate' jurisdictions or under safeguards (SCCs, BCRs, derogations).Transfers require either an adequacy determination by POTRAZ or appropriate contractual/organisational safeguards; consent-based transfers are constrained.
Children's dataDigital-services consent age set by each Member State (13–16); parental verification required.Processing children's data attracts heightened protection; parental/guardian consent is expected.
PenaltiesUp to €20 million or 4% of global annual turnover, whichever is higher (Art. 83).Fines, licence sanctions and — in serious cases — criminal liability including custodial sentences for responsible individuals.

The CDPA penalty calculator gives an indicative range for a scenario.

Extra-territorial reachApplies to non-EU controllers offering goods/services to, or monitoring, EU data subjects (Art. 3).Applies to processing carried out in Zimbabwe and, in practice, to controllers targeting Zimbabwean data subjects — the extra-territorial edges are still being tested.

If you already run a GDPR programme

Most of the muscle transfers. Your RoPA, your DPIA template, your subject-rights workflow, your processor register — all reusable. The gaps to close, in order:

  • Licensing. Confirm whether the Zimbabwean entity (or the processing you do into Zimbabwe) triggers POTRAZ licensing, and budget for it.
  • DPO appointment. Under the CDPA the requirement is broader. Formalise the appointment and notify POTRAZ as required.
  • Breach runbook. Compress the internal escalation clock to fit a 24-hour outbound window to POTRAZ. Rehearse it.
  • Transfers. Re-paper cross-border flows from Zimbabwe on POTRAZ-aligned terms; don’t assume EU SCCs are sufficient on their own.
  • Notice. Localise your privacy notice against the CDPA elements — plain language, Zimbabwean regulator named, rights aligned.

Free tools that use this mapping

Scope note. This guide is a plain-language mapping, not legal advice. The GDPR text is authoritative in the EU; the CDPA text (and POTRAZ’s statutory instruments) is authoritative in Zimbabwe. Where a specific decision matters, read the primary sources and consult a Zimbabwean data-protection practitioner.


Want more country-by-country detail? Open the Africa Privacy-Law Tracker.