Cyber and Data Protection Act [Chapter 12:07]
Cyber and Data Protection Act, No. 5 of 2021 (Zimbabwe)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 11 March 2022.
A comprehensive regime rule binding public and private bodies.
As of 7 September 2026.
What it requires
- Process personal data necessarily, fairly, lawfully and for specified, legitimate purposes before a crawler or AI training pipeline collects or uses personal data of a person in Zimbabwe.
- Obtain the data subject's written consent, withdrawable at any time, before processing sensitive data such as race, political opinion, religion, trade union membership, sex life, health or criminal history.
- Do not process genetic data, biometric data or health data at all unless the data subject has given written consent.
- Notify the Data Protection Authority within 24 hours of discovering a security breach affecting personal data you process.
- Give a data subject notice of who is responsible for processing and why, and let them access, object to, correct, or have deleted false or misleading personal data about them.
- Before transferring personal data outside Zimbabwe, confirm an adequate level of protection exists in the recipient's country or that the transfer is solely to carry out tasks within your competence as controller.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Section 33(2): a data controller, representative, agent or assignee who contravenes section 11 (sensitive data consent), section 13 (duties of controller), section 18(4) (security), section 24 (accountability) or section 28 (transborder transfer) is guilty of an offence, liable to a fine not exceeding level 11 or imprisonment not exceeding seven years, or both. Section 33(1): a member of staff of the Authority, or an expert, contractor or sub-contractor, who violates the Act is liable to a fine not exceeding level 7 or imprisonment not exceeding two years, or both. Fines are expressed on the Criminal Law Code's standard scale of fines by level rather than in a stated currency amount, so no monetary penalty_structure is recorded here.
Who enforces it
Enforcement body
Postal and Telecommunications Regulatory Authority, designated as Zimbabwe's Data Protection Authority
What it reaches
Obligation class
Consent, Biometric, Data subject rights, Transfer, Breach notice, Disclosure, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Every data controller or processor must ensure personal data is processed necessarily, fairly and lawfully (s. 8), collected for specified and legitimate purposes (s. 9), and, for sensitive data (including data revealing race, political opinion, religion, trade union membership, sex life, and health, genetic, or criminal history), only with the data subject's written consent, withdrawable at any time (s. 11).
Genetic data, biometric data and health data may not be processed at all unless the data subject has given written consent (s. 12). A data controller must notify the Authority of a security breach within 24 hours of discovering it (s. 19). A data subject has the right to be informed, to access their data, to object to processing, and to correct or delete false or misleading data (s. 14).
Transferring personal data outside Zimbabwe requires an adequate level of protection in the recipient's country or the transfer to be solely for tasks within the controller's competence (s. 28).
Any data controller, representative, agent or assignee who contravenes sections 11 (sensitive data), 13 (duties of controller), 18(4) (security), 24 (accountability) or 28 (transborder transfer) is guilty of an offence, liable to a fine not exceeding level 11 or imprisonment not exceeding seven years, or both (s. 33(2)); a member of staff of the Authority, or any expert, contractor or sub-contractor who violates the Act is liable to a fine not exceeding level 7 or imprisonment not exceeding two years, or both (s. 33(1)). The Act does not describe a private civil right of action for a data subject in the text reviewed.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachhigh_risk_decisionsprocesses_biometrics
Read the law
Cyber and Data Protection Act
No. 5 of 2021, official text as gazetted with the correct title and chapter number on 11 March 2022, reproduced by Veritas Zimbabwe