What Is Cyber and Data Protection Act [Chapter 12:07], No. 5 of 2021?
Zimbabwe's Cyber and Data Protection Act [Chapter 12:07], No. 5 of 2021, was published and commenced on 11 March 2022. It designates the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) as the Data Protection Authority (section 5), with functions including regulating lawful processing, promoting and enforcing fair processing, investigating complaints by post or electronic means, and conducting inquiries at a data subject's request (section 6). Statutory Instrument 155 of 2024 added licensing of data controllers and Data Protection Officer appointment regulations. Section 14 gives a data subject the right to be informed of the use of personal information, access personal information held by a controller or processor, object to all or part of processing, correct false or misleading personal information, and delete false or misleading data. Sections 15–16 require notice of a right to object to direct marketing, free of charge, on both direct and indirect collection. Unlike some regional peers, Zimbabwe's express deletion right is framed around false or misleading data rather than a broader 'right to be forgotten.' This is a source-backed evidence profile. No general controller-response deadline or complaint-investigation timeline was located; an appeal from a POTRAZ decision goes to the Administrative Court. No Zimbabwe-specific data-broker registry or public-record suppression route was located.
At a glance
- Full name
- Cyber and Data Protection Act [Chapter 12:07], No. 5 of 2021
- Short code
- Zimbabwe Cyber and Data Protection Act
- Jurisdiction
- Zimbabwe
- Enacted
- 2021
- Last major update
- Published and commenced 11 March 2022; Statutory Instrument 155 of 2024 added licensing and Data Protection Officer regulations
- Regulator
- Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), designated Data Protection Authority
- Private right of action
- Limited
- Statutory citation
- Cyber and Data Protection Act [Chapter 12:07], No. 5 of 2021
Scope, who Zimbabwe Cyber and Data Protection Act covers
Protected data
Data subject rights
Be informed of the use of personal information (section 14)
Access personal information in the custody of a controller or processor (section 14)
Object to all or part of processing (section 14)
Correct false or misleading personal information (section 14)
Delete false or misleading data (section 14)
Object, free of charge, to processing for direct marketing, on notice at both direct and indirect collection (sections 15–16)
Notable features
POTRAZ — primarily a telecommunications regulator — also serves as Zimbabwe’s Data Protection Authority, an institutional combination distinct from a standalone data-protection commission. The Act’s section 14 deletion right is expressly limited to false or misleading data rather than a general erasure right.
Enforcement & penalties
Penalties: The reviewed official POTRAZ-hosted Act and SI 155 of 2024 for this research pass focused on rights, the regulator’s functions, and the licensing/DPO regime rather than a consolidated fine schedule; a penalty figure was not confirmed in this pass.
Private right of action: POTRAZ receives complaints by post, electronic means, or an equivalent method and may conduct inquiries or investigations at a data subject’s request; an appeal from a POTRAZ decision goes to the Administrative Court. No general data-subject complaint-investigation deadline or controller-response SLA was located.
Relevance to data brokers
No dedicated Zimbabwe data-broker registry, broker-specific opt-out route, or public-record suppression route was located. The bounded route inventory is a rights request to the relevant controller/processor, then a POTRAZ complaint if the processing is believed to contravene the Act; the sources do not establish that a request will result in removal or deletion.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Who is Zimbabwe’s data-protection regulator?+
The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), designated the Data Protection Authority under section 5 of the Cyber and Data Protection Act.
Can I get any inaccurate data about me deleted in Zimbabwe?+
Section 14 gives an express right to delete data that is false or misleading, which is narrower than a general right to erasure — do not assume it covers accurate data you simply want removed.
Official sources & citations
Other international privacy regimes
Zimbabwe Cyber and Data Protection Act sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
