Skip to content

Privacy Hub · plain-language reference

← Guides

incidents

The 24-hour breach rule

Updated 19 Jul 2026

The 24-hour breach rule

Zimbabwe's Cyber and Data Protection Act (s. 21) and SI 155 of 2024 require notification to POTRAZ within 24 hours of becoming aware of a personal-data breach. Affected data subjects must be notified within 72 hours where the breach is likely to result in harm.

This is stricter than the UK / EU GDPR standard of 72 hours to the authority.

What "aware" means

You are "aware" when a person in your organisation has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised. Suspicion is not enough; investigation of a credible signal is.

The minimum notification content

  • Nature of the breach (categories and approximate numbers of data subjects and records).
  • Contact point (usually your DPO).
  • Likely consequences.
  • Measures taken or proposed to address the breach and mitigate harm.

Do this now, before an incident

  1. Nominate an incident lead and a communications lead.
  2. Draft the notification template so you are not writing it in the first hour.
  3. Rehearse the timeline: detection → triage → notification. 24 hours goes quickly.

Looking for something practical? Explore the free privacy tools.