Cyber and Data Protection Regulations 2024, security breach notification
Statutory Instrument 155 of 2024, regulation 17 (security breach notification)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 13 September 2024.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Report a personal data breach to the Authority within 24 hours of becoming aware of it, on Form DP3 in the Fourth Schedule.
- Inform the affected data subjects within 72 hours of the breach where it is likely to result in a high risk of adversely affecting individuals' rights and freedoms.
- Keep robust breach detection, investigation and internal reporting procedures in place, and keep a record of all personal data breaches.
- Answer the Authority's information request about a data breach within 14 days of that request, and cooperate with its enquiries or investigations.
- Finish the data breach investigation and submit your report within 21 days from the date of notification.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Regulation 17(1) requires a data controller to report a personal data breach to the Authority within 24 hours of becoming aware of the breach affecting the data being processed by it or by its data processor, and regulation 17(2) requires the report to be made on Form DP3 in the Fourth Schedule.
Regulation 17(3) requires the controller also to inform the affected data subjects within 72 hours where the detected breach is likely to result in a high risk of adversely affecting individuals' rights and freedoms. Regulation 17(4) requires robust breach detection, investigation and internal reporting procedures and a record of all personal data breaches.
Regulation 17(5) requires the controller to cooperate with the Authority's enquiries or investigations, to answer an information request on a data breach within fourteen days, and to conclude the investigation and submit a report within twenty-one days from the date of notification. Regulation 17(6) makes contravening the regulation an offence.
The Regulations were made by the Minister of Information Communications Technology, Postal and Courier Services in consultation with the Authority under section 32 of the Cyber and Data Protection Act, and took effect on their publication on 13 September 2024.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachprocesses_biometricsoperates_essential_service
Read the law
Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations
2024, Statutory Instrument 155 of 2024, official text reproduced by Veritas Zimbabwe
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.