Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024
Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations 2024 (Statutory Instrument 155 of 2024)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 13 September 2024.
An enforcement supervision rule binding public and private bodies.
As of 7 September 2026.
What it requires
- Obtain a data controller licence from the Data Protection Authority before processing personal information, if you decide the means, purpose or outcome of processing, decide what data to collect or from whom, or obtain commercial gain from the processing.
- Appoint a certified data protection officer and notify the Authority of the appointment in writing.
- Notify the Authority of your processing activities, any intended cross-border transfer of personal data, and any processing of biometric or genetic data.
- Obtain the consent of a parent or legal guardian before processing a child's personal information, and do not subject a child's data to automated decision-making that affects the child's rights.
- Report a personal data breach to the Authority within 24 hours of becoming aware of it, and inform affected data subjects within 72 hours if the breach is likely to pose a high risk to their rights and freedoms.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Processing personal information without a data controller licence (s. 3(3)), continuing to process after the six-month transition period without a licence (s. 4(6)), submitting false information in a licence application (s. 7), contravening a data controller's obligations under s. 10, contravening the security-of-data duties of s. 16, or contravening the breach-notification duties of s. 17, are each an offence liable to a fine not exceeding level 11 or imprisonment not exceeding seven years, or both. Failing to appoint a data protection officer under s. 12(1) carries a lighter penalty of a fine not exceeding level 7 or imprisonment not exceeding two years, or both. Fines are expressed by level on the Criminal Law Code's standard scale rather than in a stated currency amount, so no monetary penalty_structure is recorded here.
Who enforces it
Enforcement body
Data Protection Authority (Postal and Telecommunications Regulatory Authority)
What it reaches
Obligation class
Licensing, Biometric, Consent, Breach notice, Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Made under section 32 of the Cyber and Data Protection Act, this statutory instrument requires any person who decides the means, purpose or outcome of processing, decides what data to collect or from whom, or obtains commercial gain from processing personal information, to hold a data controller licence from the Authority (ss. 3-4), tiered by the number of data subjects processed (s. 6), and to appoint a certified data protection officer (s. 12).
A data controller must notify the Authority of processing activities, any intended cross-border transfer, and any processing of biometric or genetic data (s. 10(2)), must obtain parental or guardian consent before processing a child's personal information and may not subject a child's data to automated decision-making affecting the child's rights (s. 10(5)).
Personal data breaches must be reported to the Authority within 24 hours of the controller becoming aware of them, and, where the breach is likely to result in a high risk to individuals' rights and freedoms, affected data subjects must also be informed within 72 hours (s. 17).
Data controllers processing personal data only for personal, family or household affairs, law enforcement, or journalistic, historical or archival purposes are exempt from licensing, though the latter two must still register with the Authority (s. 8).
When LexLint raises it
crawls_webtrains_modelsautomated_outreachhigh_risk_decisionsprocesses_biometrics
Read the law
Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations
2024, Statutory Instrument 155 of 2024, official text reproduced by Veritas Zimbabwe