Comparative guide · Zimbabwe · European Union
GDPR vs Zimbabwe CDPA — a side-by-side comparison
A translation layer for international compliance teams working across the EU General Data Protection Regulation (GDPR) and Zimbabwe’s Cyber and Data Protection Act (CDPA, Chapter 12:07). Same direction of travel; different clocks, different regulator, and a licensing regime the GDPR doesn’t have.
The five things that trip people up
- The breach clock is 24 hours under the CDPA, not 72.
- Every licensed data controller must appoint a DPO — the trigger is broader than the GDPR’s.
- Zimbabwean data controllers must be licensed by POTRAZ; there is a live fee schedule.
- Cross-border transfers hinge on POTRAZ adequacy or safeguards, not the European Commission’s adequacy list.
- Penalties can include criminal liability for responsible individuals — not just administrative fines.
Concept-by-concept mapping
| Concept | EU GDPR | Zimbabwe CDPA |
|---|---|---|
| Governing law | Regulation (EU) 2016/679 (General Data Protection Regulation), in force since 25 May 2018. | Cyber and Data Protection Act [Chapter 12:07] (2021), Zimbabwe's first consolidated data-protection statute. |
| Regulator | National Data Protection Authorities (e.g. CNIL, ICO pre-Brexit) coordinated by the European Data Protection Board. | Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), designated as the Data Protection Authority. |
| Data Controller | Natural or legal person who alone or jointly determines the purposes and means of processing (Art. 4(7)). | The 'data controller' — same functional concept: the person who determines purpose and means of processing personal information (s.3). |
| Data Processor | Processes personal data on behalf of the controller (Art. 4(8)); contractual controls in Art. 28. | Recognised distinctly from the controller; controllers must contract processors on written terms consistent with the Act. |
| Data Protection Officer (DPO) | Mandatory where the controller is a public authority or where core activities involve large-scale monitoring or special-category data (Art. 37). | Every licensed data controller must appoint a DPO — the CDPA trigger is broader than GDPR's 'core activities' test. Not sure whether you need one? Run the free POTRAZ tier + DPO checker. |
| Licensing / registration | No general registration requirement; some Member States retained notification regimes. | Data controllers must be licensed by POTRAZ under a tiered fee schedule; licensing is a live compliance obligation, not a formality. |
| Lawful bases | Six bases in Art. 6: consent, contract, legal obligation, vital interests, public task, legitimate interests. | Comparable grounds: consent, contract necessity, legal obligation, vital interests, public interest, and legitimate interests of the controller. |
| Sensitive / special-category data | Art. 9 special categories: health, biometrics, race, religion, sexual orientation, trade-union membership, etc. | 'Sensitive data' includes health, genetic/biometric data, race, religion, political opinions, criminal records, and children's data. |
| Data-subject rights | Access, rectification, erasure, restriction, portability, objection, and rights around automated decisions (Arts. 15–22). | Rights of access, correction, deletion, and objection are provided; portability and automated-decision rights are more narrowly framed. |
| Notice / transparency | Arts. 13–14 prescribe the exact information a controller must give the data subject at collection. | Controllers must provide a privacy notice with equivalent core elements — identity, purpose, recipients, rights, retention. The free Privacy Notice grader scores a notice against the CDPA Playbook. |
| Data Protection Impact Assessment (DPIA) | Required for 'high-risk' processing (Art. 35); prior consultation with the DPA where residual risk remains. | DPIAs are required for processing that presents specific risks — the trigger list is issued by POTRAZ. |
| Personal-data breach notification | Notify the DPA within 72 hours of becoming aware; notify data subjects without undue delay where risk is high (Arts. 33–34). | Notify POTRAZ and affected data subjects within 24 hours of becoming aware of the breach — a materially tighter clock than the GDPR's 72. Different clocks mean different runbooks — plan for the shortest applicable window. |
| Cross-border transfers | Allowed to 'adequate' jurisdictions or under safeguards (SCCs, BCRs, derogations). | Transfers require either an adequacy determination by POTRAZ or appropriate contractual/organisational safeguards; consent-based transfers are constrained. |
| Children's data | Digital-services consent age set by each Member State (13–16); parental verification required. | Processing children's data attracts heightened protection; parental/guardian consent is expected. |
| Penalties | Up to €20 million or 4% of global annual turnover, whichever is higher (Art. 83). | Fines, licence sanctions and — in serious cases — criminal liability including custodial sentences for responsible individuals. The CDPA penalty calculator gives an indicative range for a scenario. |
| Extra-territorial reach | Applies to non-EU controllers offering goods/services to, or monitoring, EU data subjects (Art. 3). | Applies to processing carried out in Zimbabwe and, in practice, to controllers targeting Zimbabwean data subjects — the extra-territorial edges are still being tested. |
If you already run a GDPR programme
Most of the muscle transfers. Your RoPA, your DPIA template, your subject-rights workflow, your processor register — all reusable. The gaps to close, in order:
- Licensing. Confirm whether the Zimbabwean entity (or the processing you do into Zimbabwe) triggers POTRAZ licensing, and budget for it.
- DPO appointment. Under the CDPA the requirement is broader. Formalise the appointment and notify POTRAZ as required.
- Breach runbook. Compress the internal escalation clock to fit a 24-hour outbound window to POTRAZ. Rehearse it.
- Transfers. Re-paper cross-border flows from Zimbabwe on POTRAZ-aligned terms; don’t assume EU SCCs are sufficient on their own.
- Notice. Localise your privacy notice against the CDPA elements — plain language, Zimbabwean regulator named, rights aligned.
Free tools that use this mapping
- POTRAZ tier + DPO checker
Which licensing tier applies, and whether you must appoint a DPO.
- Privacy Notice grader
Grade a notice against the CDPA Playbook and see what’s missing.
- CDPA Penalty Calculator
Indicative penalty range for a scenario under the CDPA.
- Data Protection Needs Assessment
A fast baseline of your privacy posture with a ranked gap list.
Scope note. This guide is a plain-language mapping, not legal advice. The GDPR text is authoritative in the EU; the CDPA text (and POTRAZ’s statutory instruments) is authoritative in Zimbabwe. Where a specific decision matters, read the primary sources and consult a Zimbabwean data-protection practitioner.
Want more country-by-country detail? Open the Africa Privacy-Law Tracker.