Law / Zimbabwe

Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024

Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations 2024 (Statutory Instrument 155 of 2024), licensing, the data protection officer and security (ss. 3-9 and 11-16)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 September 2024.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain a data controller licence from the Data Protection Authority before processing personal information, if you decide the means, purpose or outcome of processing, decide what data to collect or from whom, or obtain commercial gain from the processing.
  • Appoint a certified data protection officer and notify the Authority of the appointment in writing.
  • Notify the Authority of your processing activities, any intended cross-border transfer of personal data, and any processing of biometric or genetic data.
  • Appoint the data protection officer within ninety days of the Regulations' promulgation or of a contract ending, and tell the Authority in writing within fourteen days of any change to the officer's number, email address or physical address, or of their dismissal or resignation.
  • Process personal data securely by appropriate technical and organisational measures, including risk assessments, organisational policies, physical and technical measures across all data phases, and processes to test how effective they are and to make the improvements they show are needed.
  • Give your data protection officer continuous professional development training so their certification is maintained.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Processing personal information without a data controller licence (s. 3(3)), continuing to process after the six-month transition period without a licence (s. 4(6)), submitting false information in a licence application (s. 7), contravening a data controller's obligations under s. 10, contravening the security-of-data duties of s. 16, or contravening the breach-notification duties of s. 17, are each an offence liable to a fine not exceeding level 11 or imprisonment not exceeding seven years, or both. Failing to appoint a data protection officer under s. 12(1) carries a lighter penalty of a fine not exceeding level 7 or imprisonment not exceeding two years, or both. Fines are expressed by level on the Criminal Law Code's standard scale rather than in a stated currency amount, so no monetary penalty_structure is recorded here.

Who enforces it

Enforcement body

Data Protection Authority (Postal and Telecommunications Regulatory Authority)

What it reaches

Obligation class

Licensing, Governance, Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Regulation 3(1) bars any person from processing personal information for the purposes regulation 3(2) lists unless licensed with the Authority, and regulation 3(2) catches anyone who processes personal information intending to decide the means, purpose or outcome of the processing, to decide what personal data should be collected, to decide which individuals to collect it from, or to obtain commercial gain or other benefit from it.

Regulation 4 requires a written application in Form DP1, regulation 6 tiers the licence by the number of data subjects processed, and regulations 8 and 9 set the exemptions and the register of licensed controllers.

Regulation 10(1) requires continuous professional development training for the data protection officer, regulation 10(2) requires the Authority to be notified of all processing activities, of any modification of personal information collected indirectly, of any intention to transfer or share a data subject's information outside Zimbabwe, and of any processing involving biometric and genetic data, and regulation 10(4) makes the controller accountable for its representatives and processors and requires appropriate technical and organisational measures and a written data processing agreement.

Regulation 12 requires a data protection officer to be appointed and the Authority notified in Form DP2, within ninety days of the Regulations' promulgation or of a contract ending, with any change of the officer's contact details or their dismissal or resignation notified within fourteen days.

Regulation 16 requires personal data to be processed securely by appropriate technical and organisational measures, including risk assessments, organisational policies, physical and technical measures across all data phases, and processes to test their effectiveness.

The Regulations were made by the Minister of Information Communications Technology, Postal and Courier Services in consultation with the Authority under section 32 of the Cyber and Data Protection Act, and took effect on their publication on 13 September 2024.

When LexLint raises it

  • crawls_web
  • trains_models
  • automated_outreach
  • high_risk_decisions
  • processes_biometrics

Read the law

Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations
2024, Statutory Instrument 155 of 2024, official text reproduced by Veritas Zimbabwe

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app