Law / Zimbabwe

Zimbabwe

5 of 6 named instruments researched to a stage, across four of the six areas of law we track: 5 in force. As of 7 September 2026.

When they take effect5 of 5 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 2 instruments (2 in force) 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 2
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law2 instruments, 2 in force

Research summary (192 words)

Zimbabwe's comprehensive personal-data statute is the Cyber and Data Protection Act [Chapter 12:07] (Act No. 5 of 2021), gazetted with its correct title and chapter number on 11 March 2022, which designates the Postal and Telecommunications Regulatory Authority as the Data Protection Authority and binds any data controller or processor using automated or non-automated means in Zimbabwe to process personal data lawfully, fairly and transparently, with heightened consent duties for sensitive data and for genetic, biometric and health data.

Delegated legislation, the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (Statutory Instrument 155 of 2024), requires a data controller to be licensed and to appoint a certified data protection officer, and sets a 24-hour breach notification duty to the Authority and a 72-hour duty to affected data subjects for high-risk breaches.

Enforcement combines criminal fines and imprisonment on a fine-level scale (level 7 to level 11 depending on the provision) with no express private civil right of action located in the text reviewed. Cross-border transfer requires an adequate level of protection in the recipient country or organisation, a moderate rather than a localisation-style restriction.

Comprehensive regime

Cyber and Data Protection Act [Chapter 12:07]

Cyber and Data Protection Act, No. 5 of 2021 (Zimbabwe)Cyber and Data Protection Act

In force since 11 March 2022. Binds public and private bodies.

What this law does

Every data controller or processor must ensure personal data is processed necessarily, fairly and lawfully (s. 8), collected for specified and legitimate purposes (s. 9), and, for sensitive data (including data revealing race, political opinion, religion, trade union membership, sex life, and health, genetic, or criminal history), only with the data subject's written consent, withdrawable at any time (s. 11).

Genetic data, biometric data and health data may not be processed at all unless the data subject has given written consent (s. 12). A data controller must notify the Authority of a security breach within 24 hours of discovering it (s. 19). A data subject has the right to be informed, to access their data, to object to processing, and to correct or delete false or misleading data (s. 14).

Transferring personal data outside Zimbabwe requires an adequate level of protection in the recipient's country or the transfer to be solely for tasks within the controller's competence (s. 28).

Any data controller, representative, agent or assignee who contravenes sections 11 (sensitive data), 13 (duties of controller), 18(4) (security), 24 (accountability) or 28 (transborder transfer) is guilty of an offence, liable to a fine not exceeding level 11 or imprisonment not exceeding seven years, or both (s. 33(2)); a member of staff of the Authority, or any expert, contractor or sub-contractor who violates the Act is liable to a fine not exceeding level 7 or imprisonment not exceeding two years, or both (s. 33(1)). The Act does not describe a private civil right of action for a data subject in the text reviewed.

What it requires

Enforcement supervision

Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024

Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations 2024 (Statutory Instrument 155 of 2024)Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations

In force since 13 September 2024. Binds public and private bodies.

What this law does

Made under section 32 of the Cyber and Data Protection Act, this statutory instrument requires any person who decides the means, purpose or outcome of processing, decides what data to collect or from whom, or obtains commercial gain from processing personal information, to hold a data controller licence from the Authority (ss. 3-4), tiered by the number of data subjects processed (s. 6), and to appoint a certified data protection officer (s. 12).

A data controller must notify the Authority of processing activities, any intended cross-border transfer, and any processing of biometric or genetic data (s. 10(2)), must obtain parental or guardian consent before processing a child's personal information and may not subject a child's data to automated decision-making affecting the child's rights (s. 10(5)).

Personal data breaches must be reported to the Authority within 24 hours of the controller becoming aware of them, and, where the breach is likely to result in a high risk to individuals' rights and freedoms, affected data subjects must also be informed within 72 hours (s. 17).

Data controllers processing personal data only for personal, family or household affairs, law enforcement, or journalistic, historical or archival purposes are exempt from licensing, though the latter two must still register with the Authority (s. 8).

What it requires

Scraping law1 instrument, 1 in force

Research summary (319 words)

Zimbabwe has no scraping-specific statute, so general law governs each dimension separately.

The Cyber and Data Protection Act [Chapter 12:07] (No. 5 of 2021) repealed and substituted sections 163 to 166 of the Criminal Law (Codification and Reform) Act [Chapter 9:23], creating a hacking offence keyed to whether the accused knew or suspected they needed prior authority to access the data, programme or system (s. 163), and separate offences for unlawful acquisition of data by intercepting, overcoming a protective security measure, or acquiring data (s. 163A), unlawful interference with data (s. 163B), unlawful interference with a computer system (s. 163C), unlawful disclosure of a data code (s. 163D), and unlawful use of data or devices such as access codes or malicious software (s. 163E); no reported Zimbabwean case construes any of these sections' application to a web scraper reading a public, unauthenticated page.

No Zimbabwe court has ruled on the enforceability of a browsewrap or clickwrap terms of service against a scraper.

The Copyright and Neighbouring Rights Act [Chapter 26:05] (Act 11 of 2000, in force 10 September 2004) permits fair dealing for research or private study unless it results in copies of substantially the same material reaching more than one person at the same time (s. 24), but enacts no text-and-data-mining exception; its definition of "literary work" extends to "tables and compilations" alongside computer programs (s. 2), so a database is protected only as a compilation-type literary work rather than through a separate sui generis database right.

Personal-data reach over scraped public personal data is governed by the Cyber and Data Protection Act, researched in full under the privacy topic; its application provisions carry no publicly-available-data exemption, and processing genetic, biometric or health data is prohibited without written consent.

No Zimbabwe statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and no provision assigns legal weight to a robots.txt directive or states an AI-training-specific rule.

Computer misuse

Cyber and Data Protection Act, Insertion of Computer-Misuse Offences into the Criminal Law Code

Cyber and Data Protection Act [Chapter 12:07] (No. 5 of 2021) s. 35, substituting ss. 163-166 of the Criminal Law (Codification and Reform) Act [Chapter 9:23]Cyber and Data Protection Act

In force since 11 March 2022. Binds public and private bodies.

What this law does

Section 163 (Hacking) makes it an offence for a person who knows or suspects they must obtain prior authority to access data, a computer programme, a data storage medium, or a computer system, to intentionally and unlawfully secure access without that authority, liable to a fine not exceeding level 10 or imprisonment not exceeding five years, or both, rising to level 14 or ten years in aggravating circumstances.

Section 163A (Unlawful acquisition of data) penalises intercepting a private data transmission, overcoming or circumventing a protective security measure to prevent access, or acquiring data within or transmitted to or from a computer system, at a fine not exceeding level 14 or imprisonment not exceeding five years, or both (ten years aggravated); possessing data known to have been unlawfully acquired is a separate, identically punished offence.

Section 163B (Unlawful interference with data or a data storage medium) and section 163C (Unlawful interference with a computer system) penalise damaging, deleting, altering, blocking access to, or otherwise interfering with computer data or the functioning of a computer or information system, at up to level 10 or five years for data interference (level 14 or ten years aggravated) and up to level 14 or ten years for system interference (twenty years aggravated).

Section 163D (Unlawful disclosure of a data code) penalises communicating an access code or password to a person not authorised to use it, or creating, altering or destroying such a code, at a fine not exceeding level 12 or imprisonment not exceeding ten years, or both, unless the act is authorised by law.

Section 163E (Unlawful use of data or devices) penalises acquiring, possessing, or supplying an access code, password, or programme designed to commit an offence under the Act, at up to level 12 or ten years, and assembling or using malicious software to damage data or systems, at up to level 10 or five years (level 12 or ten years aggravated).

None of these sections defines "unlawfully" or "authority" by reference to a public, unauthenticated web page; each turns on whether the accused knew or suspected they lacked authority, or overcame a protective security measure, to access or acquire the data.

What it requires

Age gating law1 instrument, 1 in force

Research summary (205 words)

Zimbabwe's Censorship and Entertainments Control Act [Chapter 10:04] (in force 1 December 1967) establishes the Board of Censors, which may approve a film or public entertainment subject to a condition that it not be exhibited or given to persons of a Board-specified age or sex; no person of that specified age or sex may then be present, and the person in charge of the venue must display the restriction and must not advertise the film or entertainment without it.

The age threshold under this scheme is set case by case in the Board's approval condition rather than fixed by the Act at a single statutory number, and the Act's supply and possession restrictions on undesirable or prohibited publications, pictures, statues and records bind the public generally rather than gating access by age. No provision reaches an online or on-demand service, a social-media platform, or an app store.

The Broadcasting Services Act [Chapter 12:06] gives the Broadcasting Authority of Zimbabwe content-standard and licence-condition powers over broadcasting licensees but names no age threshold or minor-access duty in the provisions reviewed. No separate statute addressing social-media minor access, app-store age verification, or an age-appropriate design duty for a service likely to be accessed by children has been located.

Adult content age verification (AV)

Censorship and Entertainments Control Act, Age-Restricted Admission and Display Duty

Censorship and Entertainments Control Act [Chapter 10:04], ss. 27-28Censorship and Entertainments Control Act, official text reproduced by Veritas Zimbabwe

In force since 1 December 1967. Binds private bodies.

What this law does

Where the Board of Censors has approved a film, film advertisement, or public entertainment subject to a condition that it not be exhibited or given to persons of a specified age or sex, no person of that specified age or sex may be present at the place where it is being exhibited or given, subject to a defence for a person present in the course of employment or outside the admitted area (s. 27(1)).

A person who contravenes this is liable to a fine not exceeding level four or imprisonment not exceeding three months, or both (s. 27(2)). Separately, where the Board has imposed such a condition, the person in charge of the place or premises must cause the relevant restriction to be prominently displayed, and no person may publish or exhibit an advertisement of the film or entertainment unless the restriction is published or exhibited with it (s. 28(1)).

The age at which admission is restricted is set by the Board's approval condition for each film, advertisement or entertainment rather than fixed by the Act itself at a single statutory number.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (320 words)

Zimbabwe has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Copyright and Neighbouring Rights Act [Chapter 26:05] (Act 11 of 2000, in force 10 September 2004) is the only enacted law reaching an aggregator's reproduction of news content.

Section 30(2) lets an article published in a newspaper or periodical, or in a broadcast, on a current economic, political, or religious topic be reproduced in the press or in a broadcast or cable programme without the author's authorisation, if the right of reproduction has not been expressly reserved and sufficient acknowledgement is given; this express-reservation proviso is the closest the Act comes to an author-side opt-out, though it predates the concept of a machine-readable reservation and is not framed as one.

Section 29 separately excuses fair dealing for the purposes of criticism, review, or reporting current events, subject to sufficient acknowledgement, except where the work is used to report current events by means of an audio-visual work, a sound recording, a broadcast, or a programme-carrying signal, and except that using a photograph to report current events is never fair dealing; section 31 excuses a quotation from a literary or musical work, including a quotation from an article in a journal that summarises the work, where the quotation is compatible with fair practice, does not exceed the extent justified by the purpose, and is sufficiently acknowledged.

The Act's neighbouring-rights provisions reach performers and broadcasting organisations, not print or online news publishers as such, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or reported case addresses whether a hyperlink is a communication to the public or whether framing or inline display changes the answer, and the Act predates the concept of a machine-readable text-and-data-mining opt-out; no reported Zimbabwe decision applies section 29 or 31 to a systematic news aggregator rather than a traditional newspaper or broadcaster.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.