Africa Zimbabwe social media surveillance

Zimbabwe's Data Licensing Drive Is Defensible in Principle, but an Unindependent Regulator With Document-Demand Powers Invites Misuse

POTRAZ began data controller inspections on 1 September 2026. Without an independent regulator, those powers could reach civil society records.

Zimbabwe's Data Licensing Regime People of Internet Research · Africa 50+ Licence threshold (individuals) Organisations processing data on 5… 7 years Maximum CEO prison term Penalty for processing data withou… 24 hrs Breach reporting window Breaches must be reported to POTRA… US$1,250 DPO certification cost Plus a US$30 application fee for e… peopleofinternet.com
Zimbabwe's Data Licensing Regime People of Internet Research · Africa 50+ Licence threshold (individuals) 7 years Maximum CEO prison term 24 hrs Breach reporting window US$1,250 DPO certification cost peopleofinternet.com

Key Takeaways

Zimbabwe's telecoms regulator POTRAZ began compliance inspections of data controllers on 1 September 2026. Under Regulatory Notice 2 of 2026, it is checking whether organisations hold the licences the Cyber and Data Protection Act requires. Reporting on the notice says a risk-based approach will start with sectors that hold large volumes of sensitive data: financial institutions, insurers, local authorities, health providers, schools, mining companies, religious bodies and government ministries. The Zimbabwean legal-information group Veritas has warned that the same powers could reach civil society membership lists.

The case for the regime

The strongest argument for enforcement is simple. A data protection law with no enforcement is a dead letter. Banks, insurers and hospitals hold intimate records, and breaches in poorly secured systems harm real people. Licensing under Statutory Instrument 155 of 2024 applied from September 2024, with a compliance deadline of 12 March 2025. Many organisations reportedly never registered (CITE). A regulator that never checks has no credibility. Breach reporting is also a sensible rule: reports say breaches must go to POTRAZ within 24 hours, and affected individuals must be told within 72 hours.

We accept all of that. The problem is design, not intent.

Where proportionality breaks down

The licensing threshold is low. Organisations that process the personal data of 50 or more individuals need a licence, which CITE notes could cover schools, churches, clinics and small retailers. Fees run from US$50 a year for the smallest databases up to US$2,500 for the largest. Each licensed body must also appoint a certified Data Protection Officer, and certification alone costs US$1,250 plus a US$30 application fee. CITE estimates that even the smallest licensed organisation could pay more than US$1,300 in its first year unless it hires an outside consultant. For a bank that is a rounding error. For a village church, a community clinic or a small advocacy group it is a serious barrier.

The penalties are also severe. CITE reports that processing personal data without a licence can bring a Level 11 fine, up to seven years' imprisonment for the CEO, or both. A criminal sanction of that weight for a paperwork failure by a small organisation is out of proportion. An administrative fine with a cure period would do the job. A Business Times report on POTRAZ's plans says administrative sanctions are still being pushed for but are not yet in place. That leaves criminal exposure as the regulator's main tool.

The independence problem

Data protection regulators are meant to be independent because they sit between the state and personal information, including the state's own. According to Veritas, POTRAZ is not independent: the President appoints its board and the Minister can issue it directives. Veritas also says the inspection and document-demand powers in sections 21(3) and 6 are broad enough to reach civil society membership lists. We could not verify the statutory text for ourselves, so we attribute these readings to Veritas. The gazetted Act is available on the Veritas site for readers who want to check.

If Veritas is right, the risk is concrete. A membership list reveals who belongs to an opposition-aligned union, a church network, or a rights organisation. Compelling that list under a data protection law turns a privacy statute into a tool for mapping associations. The risk is not that POTRAZ will do so on day one. It is that no structural safeguard prevents it, and the law's own tool for stopping it, an independent regulator, is missing.

The speech context

This matters because of how the same Act has been used before. Section 164C, added to the Criminal Law (Codification and Reform) Act by the data protection law, criminalises transmitting "false data messages intending to cause harm". The Committee to Protect Journalists reported that freelance sports journalist Hope Chizuzu was arrested and charged under it on 29 September 2022 (CPJ). In February 2026, Zimbo Live journalist Pellagia Mupurwa was charged with the same offence after interviewing Budiriro residents who accused a businessman of seizing a property (allAfrica). The Zimbabwe Union of Journalists said reputational disputes belong in civil courts and that the Act should be urgently reviewed.

None of this proves that licence inspections will be abused. But a state that has already used the Act against reporters is the wrong place to leave an unchecked power to demand records.

A comparison worth drawing

Surveillance of associations is a problem for democracies too. On 1 October 2026 a US federal judge in Manhattan refused to dismiss a suit by three unions challenging the State and Homeland Security departments' social media monitoring of visa and green card holders. The court said the threat of immigration consequences is enough to deter a person of ordinary firmness from exercising First Amendment rights (EFF). The lesson carries over: the chilling effect on association does not depend on the government ever acting on what it learns.

What proportionate enforcement would look like

Zimbabwe is right to enforce data protection. It should do so in a way that does not give a government with a record of prosecuting online speech an open-ended right to inspect who belongs to what.

Sources & Citations

  1. Cyber and Data Protection Act (Chapter 12:07, Act 5 of 2021), as gazetted, via Veritas
  2. CITE: POTRAZ data licence fees slammed as costly burden
  3. CPJ: Zimbabwean authorities charge journalist Hope Chizuzu under cybercrime law
  4. allAfrica: Press freedom under siege as journalist charged under cyber law
  5. EFF: Court rejects government effort to dismiss social media surveillance lawsuit