Law / Zimbabwe

Cyber and Data Protection Act, Insertion of Computer-Misuse Offences into the Criminal Law Code

Cyber and Data Protection Act [Chapter 12:07] (No. 5 of 2021) s. 35, substituting ss. 163-166 of the Criminal Law (Codification and Reform) Act [Chapter 9:23]

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 11 March 2022.

A computer misuse rule binding public and private bodies.

As of 7 September 2026.

What it requires

  • Do not access data, a computer programme, or a computer system if you know or suspect you must obtain prior authority to access it and have not obtained that authority.
  • Do not intercept a private data transmission, overcome or circumvent a protective security measure, or acquire data within or transmitted to or from a computer system without lawful authority.
  • Do not damage, delete, alter, or block access to computer data, or interfere with the functioning of a computer or information system, without lawful authority.
  • Do not communicate, disclose, or use an access code, password, or programme designed to gain unauthorised access to data or a computer system.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Section 163 (Hacking): a fine not exceeding level 10 or imprisonment not exceeding five years, or both, rising to level 14 or imprisonment not exceeding ten years in aggravating circumstances defined in section 163F. Section 163A (Unlawful acquisition of data): a fine not exceeding level 14 or imprisonment not exceeding five years, or both, rising to ten years aggravated; unlawful possession of unlawfully acquired data carries the same penalty. Section 163B (Unlawful interference with data): a fine not exceeding level 10 or imprisonment not exceeding five years, or both, rising to level 14 or ten years aggravated. Section 163C (Unlawful interference with a computer system): a fine not exceeding level 14 or imprisonment not exceeding ten years, or both, rising to twenty years aggravated. Section 163D (Unlawful disclosure of a data code): a fine not exceeding level 12 or imprisonment not exceeding ten years, or both (ten years where the data forms part of a database or involves national security or an essential service). Section 163E (Unlawful use of data or devices): a fine not exceeding level 12 or imprisonment not exceeding ten years, or both, for acquiring or supplying an access-defeating code or programme, and a fine not exceeding level 10 or imprisonment not exceeding five years, or both, for assembling or using malicious software, each rising to level 12 or ten years aggravated. Fines are expressed by level on the Criminal Law Code's standard scale rather than in a stated currency amount, so no monetary penalty_structure is recorded here.

Who enforces it

Enforcement body

Zimbabwe Republic Police and the courts, under the Criminal Law (Codification and Reform) Act [Chapter 9:23]

What it reaches

Obligation class

Access restriction, Prohibition, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 163 (Hacking) makes it an offence for a person who knows or suspects they must obtain prior authority to access data, a computer programme, a data storage medium, or a computer system, to intentionally and unlawfully secure access without that authority, liable to a fine not exceeding level 10 or imprisonment not exceeding five years, or both, rising to level 14 or ten years in aggravating circumstances.

Section 163A (Unlawful acquisition of data) penalises intercepting a private data transmission, overcoming or circumventing a protective security measure to prevent access, or acquiring data within or transmitted to or from a computer system, at a fine not exceeding level 14 or imprisonment not exceeding five years, or both (ten years aggravated); possessing data known to have been unlawfully acquired is a separate, identically punished offence.

Section 163B (Unlawful interference with data or a data storage medium) and section 163C (Unlawful interference with a computer system) penalise damaging, deleting, altering, blocking access to, or otherwise interfering with computer data or the functioning of a computer or information system, at up to level 10 or five years for data interference (level 14 or ten years aggravated) and up to level 14 or ten years for system interference (twenty years aggravated).

Section 163D (Unlawful disclosure of a data code) penalises communicating an access code or password to a person not authorised to use it, or creating, altering or destroying such a code, at a fine not exceeding level 12 or imprisonment not exceeding ten years, or both, unless the act is authorised by law.

Section 163E (Unlawful use of data or devices) penalises acquiring, possessing, or supplying an access code, password, or programme designed to commit an offence under the Act, at up to level 12 or ten years, and assembling or using malicious software to damage data or systems, at up to level 10 or five years (level 12 or ten years aggravated).

None of these sections defines "unlawfully" or "authority" by reference to a public, unauthenticated web page; each turns on whether the accused knew or suspected they lacked authority, or overcame a protective security measure, to access or acquire the data.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Cyber and Data Protection Act
No. 5 of 2021, s. 35 (inserting ss. 163-163F into the Criminal Law (Codification and Reform) Act), official text as gazetted on 11 March 2022, reproduced by Veritas Zimbabwe

Back to the example  ·  Lint your app