Cyber and Data Protection Act [Chapter 12:07]
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 11 March 2022.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Process personal data necessarily, fairly, lawfully and for specified, legitimate purposes before a crawler or AI training pipeline collects or uses personal data of a person in Zimbabwe.
- Notify the Authority before any wholly or partly automated processing operation, and notify it again of any modification to the information you gave.
- State in that notification the date and the instrument permitting the processing, who you are, what the processing is called and what it is for, the categories of data and of data subjects, the safeguards on disclosure to third parties, how data subjects are informed and can exercise access, any linked processing, the retention period, an assessment of whether your security measures are adequate, any data processor you use, and the transfers you plan.
- Notify the Authority of the appointment of your data protection officer, and have the officer ensure compliance, handle requests made to you and work with the Authority.
- Take the security measures section 18 requires, keep your processing open as section 23 requires, and be accountable for it as section 24 requires.
What it reaches
Obligation class
Consent, Security, Governance, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 8 requires personal information to be processed necessarily, fairly and lawfully, and section 9 requires it to be collected for specified and legitimate purposes. Section 10 governs non-sensitive data. Section 13 sets the duties of the data controller and section 15 the disclosures owed when data is collected directly from the data subject. Section 17 fixes the authority to process and section 18 the security of processing.
Section 20 requires the controller to notify the Authority before any wholly or partly automated operation, to notify any modification of the information given, and to notify the appointment of a data protection officer, and lets the Authority exempt categories where there is no apparent risk to data subjects' rights or where an officer has been appointed.
Section 21 fixes the thirteen items the notification must state and lets the Authority inspect and assess the security and organisational measures before the processing or transfer begins. Section 23 requires openness of processing and section 24 accountability. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.
When LexLint raises it
crawls_webtrains_modelsautomated_outreachhigh_risk_decisionsprocesses_biometrics
Read the law
Cyber and Data Protection Act
No. 5 of 2021, official text as gazetted with the correct title and chapter number on 11 March 2022, reproduced by Veritas Zimbabwe
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.