Law / Zimbabwe

Zimbabwe

12 of 13 named instruments researched to a stage, across four of the six areas of law we track: 12 in force. As of 19 September 2026.

When they take effect12 of 12 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 7 instruments (7 in force) 2023: 0 instruments 2024: 3 instruments (3 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 9
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law9 instruments, 9 in force

Research summary (192 words)

Zimbabwe's comprehensive personal-data statute is the Cyber and Data Protection Act [Chapter 12:07] (Act No. 5 of 2021), gazetted with its correct title and chapter number on 11 March 2022, which designates the Postal and Telecommunications Regulatory Authority as the Data Protection Authority and binds any data controller or processor using automated or non-automated means in Zimbabwe to process personal data lawfully, fairly and transparently, with heightened consent duties for sensitive data and for genetic, biometric and health data.

Delegated legislation, the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (Statutory Instrument 155 of 2024), requires a data controller to be licensed and to appoint a certified data protection officer, and sets a 24-hour breach notification duty to the Authority and a 72-hour duty to affected data subjects for high-risk breaches.

Enforcement combines criminal fines and imprisonment on a fine-level scale (level 7 to level 11 depending on the provision) with no express private civil right of action located in the text reviewed. Cross-border transfer requires an adequate level of protection in the recipient country or organisation, a moderate rather than a localisation-style restriction.

Breach notification

Cyber and Data Protection Act, security breach notification

Cyber and Data Protection Act, No. 5 of 2021, s. 19 (security breach notification)Cyber and Data Protection Act

In force since 11 March 2022. Binds public and private bodies.

What this law does

Section 19 requires the data controller to notify the Authority within twenty-four hours of any security breach affecting data he or she processes. The section attaches the duty to any security breach affecting the data, with no risk threshold below which it falls away and no separate duty to the data subject; the duty to tell an affected data subject comes from regulation 17(3) of the 2024 Regulations instead, on its own separate period. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.

What it requires

Cyber and Data Protection Regulations 2024, security breach notification

Statutory Instrument 155 of 2024, regulation 17 (security breach notification)Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations

In force since 13 September 2024. Binds public and private bodies.

What this law does

Regulation 17(1) requires a data controller to report a personal data breach to the Authority within 24 hours of becoming aware of the breach affecting the data being processed by it or by its data processor, and regulation 17(2) requires the report to be made on Form DP3 in the Fourth Schedule.

Regulation 17(3) requires the controller also to inform the affected data subjects within 72 hours where the detected breach is likely to result in a high risk of adversely affecting individuals' rights and freedoms. Regulation 17(4) requires robust breach detection, investigation and internal reporting procedures and a record of all personal data breaches.

Regulation 17(5) requires the controller to cooperate with the Authority's enquiries or investigations, to answer an information request on a data breach within fourteen days, and to conclude the investigation and submit a report within twenty-one days from the date of notification. Regulation 17(6) makes contravening the regulation an offence.

The Regulations were made by the Minister of Information Communications Technology, Postal and Courier Services in consultation with the Authority under section 32 of the Cyber and Data Protection Act, and took effect on their publication on 13 September 2024.

What it requires

Comprehensive regime

Cyber and Data Protection Act [Chapter 12:07]

Cyber and Data Protection Act, No. 5 of 2021 (Zimbabwe), general duties (ss. 8-10, 13, 15-18 and 20-27)Cyber and Data Protection Act

In force since 11 March 2022. Binds public and private bodies.

What this law does

Section 8 requires personal information to be processed necessarily, fairly and lawfully, and section 9 requires it to be collected for specified and legitimate purposes. Section 10 governs non-sensitive data. Section 13 sets the duties of the data controller and section 15 the disclosures owed when data is collected directly from the data subject. Section 17 fixes the authority to process and section 18 the security of processing.

Section 20 requires the controller to notify the Authority before any wholly or partly automated operation, to notify any modification of the information given, and to notify the appointment of a data protection officer, and lets the Authority exempt categories where there is no apparent risk to data subjects' rights or where an officer has been appointed.

Section 21 fixes the thirteen items the notification must state and lets the Authority inspect and assess the security and organisational measures before the processing or transfer begins. Section 23 requires openness of processing and section 24 accountability. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.

What it requires

Cross border transfer

Cyber and Data Protection Act, transfer of personal information outside Zimbabwe

Cyber and Data Protection Act, No. 5 of 2021, ss. 28-29 (transfer outside Zimbabwe)Cyber and Data Protection Act

In force since 11 March 2022. Binds public and private bodies.

What this law does

Section 28(1) bars a data controller from transferring personal information about a data subject to a third party in a foreign country unless an adequate level of protection is ensured in the recipient's country or within the recipient international organisation, and unless the data is transferred solely to allow tasks covered by the controller's competence to be carried out.

Section 28(2) makes adequacy a question of all the circumstances, weighing the nature of the data, the purpose and duration of the proposed processing, the recipient, the data protection laws in force there, and the professional rules and security measures complied with. Section 28(3) lets the Authority lay down the categories of processing operations and the circumstances in which a transfer out of Zimbabwe is not authorised.

Section 29 governs a transfer to a country that does not assure an adequate level of protection. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.

What it requires

Data subject rights

Cyber and Data Protection Act, rights of the data subject

Cyber and Data Protection Act, No. 5 of 2021, ss. 14-16, 25-26 (rights of the data subject)Cyber and Data Protection Act

In force since 11 March 2022. Binds public and private bodies.

What this law does

Section 14 gives a data subject the right to be informed of the use to which their personal information is to be put, to access the personal information a data controller or data processor holds about them, to object to the processing of all or part of it, to have false or misleading personal information corrected, and to have false or misleading data about them deleted.

Sections 15 and 16 fix the disclosures owed when data is collected directly from the data subject and the information the controller must hold. Section 25 governs a decision taken on the basis of automatic data processing, and section 26 the representation of a data subject who is a child. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.

What it requires

Enforcement supervision

Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024

Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations 2024 (Statutory Instrument 155 of 2024), licensing, the data protection officer and security (ss. 3-9 and 11-16)Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations

In force since 13 September 2024. Binds public and private bodies.

What this law does

Regulation 3(1) bars any person from processing personal information for the purposes regulation 3(2) lists unless licensed with the Authority, and regulation 3(2) catches anyone who processes personal information intending to decide the means, purpose or outcome of the processing, to decide what personal data should be collected, to decide which individuals to collect it from, or to obtain commercial gain or other benefit from it.

Regulation 4 requires a written application in Form DP1, regulation 6 tiers the licence by the number of data subjects processed, and regulations 8 and 9 set the exemptions and the register of licensed controllers.

Regulation 10(1) requires continuous professional development training for the data protection officer, regulation 10(2) requires the Authority to be notified of all processing activities, of any modification of personal information collected indirectly, of any intention to transfer or share a data subject's information outside Zimbabwe, and of any processing involving biometric and genetic data, and regulation 10(4) makes the controller accountable for its representatives and processors and requires appropriate technical and organisational measures and a written data processing agreement.

Regulation 12 requires a data protection officer to be appointed and the Authority notified in Form DP2, within ninety days of the Regulations' promulgation or of a contract ending, with any change of the officer's contact details or their dismissal or resignation notified within fourteen days.

Regulation 16 requires personal data to be processed securely by appropriate technical and organisational measures, including risk assessments, organisational policies, physical and technical measures across all data phases, and processes to test their effectiveness.

The Regulations were made by the Minister of Information Communications Technology, Postal and Courier Services in consultation with the Authority under section 32 of the Cyber and Data Protection Act, and took effect on their publication on 13 September 2024.

What it requires

Cyber and Data Protection Act, the Authority, offences and appeals

Cyber and Data Protection Act, No. 5 of 2021, ss. 5-7, 30-34 (the Authority, offences and appeals)Cyber and Data Protection Act

In force since 11 March 2022. Binds public and private bodies.

What this law does

Section 5 designates the Postal and Telecommunications Regulatory Authority as the Data Protection Authority and section 6 sets its functions. Section 30 provides for a code of conduct and section 31 for whistleblowers, and section 32 is the regulation-making power the 2024 Licensing Regulations were made under.

Section 33(1) makes a member of the Authority's staff, or an expert, contractor or sub-contractor, who violates the Act liable to a fine not exceeding level 7 or imprisonment not exceeding two years or both, and section 33(2) makes a data controller, representative, agent or assignee who contravenes section 11, 13, 18(4), 24 or 28 liable to a fine not exceeding level 11 or imprisonment not exceeding seven years or both.

On conviction the court may order the seizure of the media holding the data or its deletion. Section 34 gives any person aggrieved by a decision of the Authority a right of appeal. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.

What it requires

Sensitive categories

Cyber and Data Protection Act, sensitive, genetic, biometric and health data

Cyber and Data Protection Act, No. 5 of 2021, ss. 11-12 (sensitive information and genetic, biometric and health data)Cyber and Data Protection Act

In force since 11 March 2022. Binds public and private bodies.

What this law does

Section 11(1) bars a data controller from processing sensitive data unless the data subject has given consent in writing, and section 11(2) lets the data subject withdraw that consent at any time, without explanation and free of charge. Section 11(3) lets the Authority determine the circumstances in which the prohibition cannot be lifted even with consent.

Section 11(5) disapplies the consent requirement where the processing is necessary to carry out the controller's obligations and specific rights in employment law, to protect vital interests where the data subject cannot consent, in the legitimate activities of a not-for-profit body confined to its members, to comply with national security laws, for legal claims with appropriate guarantees, where the data subject has made the data public, for scientific research on the Authority's conditions, or where a law authorises it for a substantial public interest.

Section 12 bars the processing of genetic data, biometric sensitive data and health data altogether unless the data subject has given written consent. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.

What it requires

Cyber and Data Protection Regulations 2024, children's information and automated decisions

Statutory Instrument 155 of 2024, regulation 10 (children's information and automated decisions)Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations

In force since 13 September 2024. Binds public and private bodies.

What this law does

Regulation 10(5)(a) bars a data controller from processing a child's personal information without the consent of the child's parent or legal guardian, and regulation 10(5)(b) requires reasonable efforts to verify that the consent was given or authorised by that parent or guardian, taking available technology into account.

Regulation 10(5)(d) requires regular data protection impact assessments to identify and mitigate privacy risks to children, regulation 10(5)(e) requires data protection by design and by default when processing children's data, and regulation 10(5)(f) bars subjecting children's data to automated decision making that has the effect of affecting the children's rights.

Regulation 10(3) separately bars subjecting any data subject to a decision based solely on automated processing which produces legal effects concerning them, without that data subject's consent or a provision established by law. Regulation 10(6) makes contravening the regulation an offence carrying a fine up to level 11 or up to seven years' imprisonment, or both.

The Regulations were made by the Minister of Information Communications Technology, Postal and Courier Services in consultation with the Authority under section 32 of the Cyber and Data Protection Act, and took effect on their publication on 13 September 2024.

What it requires

Scraping law1 instrument, 1 in force

Research summary (319 words)

Zimbabwe has no scraping-specific statute, so general law governs each dimension separately.

The Cyber and Data Protection Act [Chapter 12:07] (No. 5 of 2021) repealed and substituted sections 163 to 166 of the Criminal Law (Codification and Reform) Act [Chapter 9:23], creating a hacking offence keyed to whether the accused knew or suspected they needed prior authority to access the data, programme or system (s. 163), and separate offences for unlawful acquisition of data by intercepting, overcoming a protective security measure, or acquiring data (s. 163A), unlawful interference with data (s. 163B), unlawful interference with a computer system (s. 163C), unlawful disclosure of a data code (s. 163D), and unlawful use of data or devices such as access codes or malicious software (s. 163E); no reported Zimbabwean case construes any of these sections' application to a web scraper reading a public, unauthenticated page.

No Zimbabwe court has ruled on the enforceability of a browsewrap or clickwrap terms of service against a scraper.

The Copyright and Neighbouring Rights Act [Chapter 26:05] (Act 11 of 2000, in force 10 September 2004) permits fair dealing for research or private study unless it results in copies of substantially the same material reaching more than one person at the same time (s. 24), but enacts no text-and-data-mining exception; its definition of "literary work" extends to "tables and compilations" alongside computer programs (s. 2), so a database is protected only as a compilation-type literary work rather than through a separate sui generis database right.

Personal-data reach over scraped public personal data is governed by the Cyber and Data Protection Act, researched in full under the privacy topic; its application provisions carry no publicly-available-data exemption, and processing genetic, biometric or health data is prohibited without written consent.

No Zimbabwe statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and no provision assigns legal weight to a robots.txt directive or states an AI-training-specific rule.

Computer misuse

Cyber and Data Protection Act, Insertion of Computer-Misuse Offences into the Criminal Law Code

Cyber and Data Protection Act [Chapter 12:07] (No. 5 of 2021) s. 35, substituting ss. 163-166 of the Criminal Law (Codification and Reform) Act [Chapter 9:23]Cyber and Data Protection Act

In force since 11 March 2022. Binds public and private bodies.

What this law does

Section 163 (Hacking) makes it an offence for a person who knows or suspects they must obtain prior authority to access data, a computer programme, a data storage medium, or a computer system, to intentionally and unlawfully secure access without that authority, liable to a fine not exceeding level 10 or imprisonment not exceeding five years, or both, rising to level 14 or ten years in aggravating circumstances.

Section 163A (Unlawful acquisition of data) penalises intercepting a private data transmission, overcoming or circumventing a protective security measure to prevent access, or acquiring data within or transmitted to or from a computer system, at a fine not exceeding level 14 or imprisonment not exceeding five years, or both (ten years aggravated); possessing data known to have been unlawfully acquired is a separate, identically punished offence.

Section 163B (Unlawful interference with data or a data storage medium) and section 163C (Unlawful interference with a computer system) penalise damaging, deleting, altering, blocking access to, or otherwise interfering with computer data or the functioning of a computer or information system, at up to level 10 or five years for data interference (level 14 or ten years aggravated) and up to level 14 or ten years for system interference (twenty years aggravated).

Section 163D (Unlawful disclosure of a data code) penalises communicating an access code or password to a person not authorised to use it, or creating, altering or destroying such a code, at a fine not exceeding level 12 or imprisonment not exceeding ten years, or both, unless the act is authorised by law.

Section 163E (Unlawful use of data or devices) penalises acquiring, possessing, or supplying an access code, password, or programme designed to commit an offence under the Act, at up to level 12 or ten years, and assembling or using malicious software to damage data or systems, at up to level 10 or five years (level 12 or ten years aggravated).

None of these sections defines "unlawfully" or "authority" by reference to a public, unauthenticated web page; each turns on whether the accused knew or suspected they lacked authority, or overcame a protective security measure, to access or acquire the data.

What it requires

Age gating law1 instrument, 1 in force

Research summary (205 words)

Zimbabwe's Censorship and Entertainments Control Act [Chapter 10:04] (in force 1 December 1967) establishes the Board of Censors, which may approve a film or public entertainment subject to a condition that it not be exhibited or given to persons of a Board-specified age or sex; no person of that specified age or sex may then be present, and the person in charge of the venue must display the restriction and must not advertise the film or entertainment without it.

The age threshold under this scheme is set case by case in the Board's approval condition rather than fixed by the Act at a single statutory number, and the Act's supply and possession restrictions on undesirable or prohibited publications, pictures, statues and records bind the public generally rather than gating access by age. No provision reaches an online or on-demand service, a social-media platform, or an app store.

The Broadcasting Services Act [Chapter 12:06] gives the Broadcasting Authority of Zimbabwe content-standard and licence-condition powers over broadcasting licensees but names no age threshold or minor-access duty in the provisions reviewed. No separate statute addressing social-media minor access, app-store age verification, or an age-appropriate design duty for a service likely to be accessed by children has been located.

Adult content age verification (AV)

Censorship and Entertainments Control Act, Age-Restricted Admission and Display Duty

Censorship and Entertainments Control Act [Chapter 10:04], ss. 27-28Censorship and Entertainments Control Act, official text reproduced by Veritas Zimbabwe

In force since 1 December 1967. Binds private bodies.

What this law does

Where the Board of Censors has approved a film, film advertisement, or public entertainment subject to a condition that it not be exhibited or given to persons of a specified age or sex, no person of that specified age or sex may be present at the place where it is being exhibited or given, subject to a defence for a person present in the course of employment or outside the admitted area (s. 27(1)).

A person who contravenes this is liable to a fine not exceeding level four or imprisonment not exceeding three months, or both (s. 27(2)). Separately, where the Board has imposed such a condition, the person in charge of the place or premises must cause the relevant restriction to be prominently displayed, and no person may publish or exhibit an advertisement of the film or entertainment unless the restriction is published or exhibited with it (s. 28(1)).

The age at which admission is restricted is set by the Board's approval condition for each film, advertisement or entertainment rather than fixed by the Act itself at a single statutory number.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (320 words)

Zimbabwe has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Copyright and Neighbouring Rights Act [Chapter 26:05] (Act 11 of 2000, in force 10 September 2004) is the only enacted law reaching an aggregator's reproduction of news content.

Section 30(2) lets an article published in a newspaper or periodical, or in a broadcast, on a current economic, political, or religious topic be reproduced in the press or in a broadcast or cable programme without the author's authorisation, if the right of reproduction has not been expressly reserved and sufficient acknowledgement is given; this express-reservation proviso is the closest the Act comes to an author-side opt-out, though it predates the concept of a machine-readable reservation and is not framed as one.

Section 29 separately excuses fair dealing for the purposes of criticism, review, or reporting current events, subject to sufficient acknowledgement, except where the work is used to report current events by means of an audio-visual work, a sound recording, a broadcast, or a programme-carrying signal, and except that using a photograph to report current events is never fair dealing; section 31 excuses a quotation from a literary or musical work, including a quotation from an article in a journal that summarises the work, where the quotation is compatible with fair practice, does not exceed the extent justified by the purpose, and is sufficiently acknowledged.

The Act's neighbouring-rights provisions reach performers and broadcasting organisations, not print or online news publishers as such, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or reported case addresses whether a hyperlink is a communication to the public or whether framing or inline display changes the answer, and the Act predates the concept of a machine-readable text-and-data-mining opt-out; no reported Zimbabwe decision applies section 29 or 31 to a systematic news aggregator rather than a traditional newspaper or broadcaster.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.