Law / Zimbabwe

Cyber and Data Protection Act, the Authority, offences and appeals

Cyber and Data Protection Act, No. 5 of 2021, ss. 5-7, 30-34 (the Authority, offences and appeals)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 11 March 2022.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Expect the Postal and Telecommunications Regulatory Authority, acting as the Data Protection Authority, to supervise your processing, and expect a right of appeal against its decision under section 34.
  • Note that contravening the sensitive-data rule in section 11, the controller's duties in section 13, section 18(4), accountability in section 24 or the transfer rule in section 28 is an offence carrying a fine up to level 11 or up to seven years' imprisonment, or both.
  • Note that on conviction a court may order the seizure of the media holding the data the offence relates to, or its deletion.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Section 33(2): a data controller, representative, agent or assignee who contravenes section 11 (sensitive data consent), section 13 (duties of controller), section 18(4) (security), section 24 (accountability) or section 28 (transborder transfer) is guilty of an offence, liable to a fine not exceeding level 11 or imprisonment not exceeding seven years, or both. Section 33(1): a member of staff of the Authority, or an expert, contractor or sub-contractor, who violates the Act is liable to a fine not exceeding level 7 or imprisonment not exceeding two years, or both. Fines are expressed on the Criminal Law Code's standard scale of fines by level rather than in a stated currency amount, so no monetary penalty_structure is recorded here.

Who enforces it

Enforcement body

Postal and Telecommunications Regulatory Authority, designated as Zimbabwe's Data Protection Authority

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 5 designates the Postal and Telecommunications Regulatory Authority as the Data Protection Authority and section 6 sets its functions. Section 30 provides for a code of conduct and section 31 for whistleblowers, and section 32 is the regulation-making power the 2024 Licensing Regulations were made under.

Section 33(1) makes a member of the Authority's staff, or an expert, contractor or sub-contractor, who violates the Act liable to a fine not exceeding level 7 or imprisonment not exceeding two years or both, and section 33(2) makes a data controller, representative, agent or assignee who contravenes section 11, 13, 18(4), 24 or 28 liable to a fine not exceeding level 11 or imprisonment not exceeding seven years or both.

On conviction the court may order the seizure of the media holding the data or its deletion. Section 34 gives any person aggrieved by a decision of the Authority a right of appeal. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • high_risk_decisions

Read the law

Cyber and Data Protection Act
No. 5 of 2021, official text as gazetted with the correct title and chapter number on 11 March 2022, reproduced by Veritas Zimbabwe

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app