Law / Zimbabwe

Cyber and Data Protection Act, transfer of personal information outside Zimbabwe

Cyber and Data Protection Act, No. 5 of 2021, ss. 28-29 (transfer outside Zimbabwe)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 11 March 2022.

A cross border transfer rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Before transferring personal data outside Zimbabwe, confirm an adequate level of protection exists in the recipient's country or that the transfer is solely to carry out tasks within your competence as controller.
  • Assess adequacy on all the circumstances before the transfer, weighing the nature of the data, the purpose and duration of the processing, who the recipient is, the data protection laws in force there, and the professional rules and security measures complied with.
  • Check the categories and circumstances the Authority has laid down as not authorised before transferring personal information out of Zimbabwe.

What it reaches

Obligation class

Transfer

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 28(1) bars a data controller from transferring personal information about a data subject to a third party in a foreign country unless an adequate level of protection is ensured in the recipient's country or within the recipient international organisation, and unless the data is transferred solely to allow tasks covered by the controller's competence to be carried out.

Section 28(2) makes adequacy a question of all the circumstances, weighing the nature of the data, the purpose and duration of the proposed processing, the recipient, the data protection laws in force there, and the professional rules and security measures complied with. Section 28(3) lets the Authority lay down the categories of processing operations and the circumstances in which a transfer out of Zimbabwe is not authorised.

Section 29 governs a transfer to a country that does not assure an adequate level of protection. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • processes_biometrics

Read the law

Cyber and Data Protection Act
No. 5 of 2021, official text as gazetted with the correct title and chapter number on 11 March 2022, reproduced by Veritas Zimbabwe

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app