Cyber and Data Protection Act, security breach notification
Cyber and Data Protection Act, No. 5 of 2021, s. 19 (security breach notification)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 11 March 2022.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Data Protection Authority within 24 hours of discovering a security breach affecting personal data you process.
- Treat every security breach affecting the data you process as notifiable under section 19: the Act sets no risk threshold below which the duty falls away.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 19 requires the data controller to notify the Authority within twenty-four hours of any security breach affecting data he or she processes. The section attaches the duty to any security breach affecting the data, with no risk threshold below which it falls away and no separate duty to the data subject; the duty to tell an affected data subject comes from regulation 17(3) of the 2024 Regulations instead, on its own separate period. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachprocesses_biometricsoperates_essential_service
Read the law
Cyber and Data Protection Act
No. 5 of 2021, official text as gazetted with the correct title and chapter number on 11 March 2022, reproduced by Veritas Zimbabwe
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.