Africa Zimbabwe social media surveillance

Zimbabwe's Data Protection Law Gives Its Telecoms Regulator Vague, Unchecked Inspection Powers Over Civil Society

Veritas warns POTRAZ can demand any document and license any data controller under the Cyber and Data Protection Act, with no independent check.

Zimbabwe's Data Protection Act: Powers vs. Guardrail… People of Internet Research · Africa 9 Sectors in inspection sweep POTRAZ's compliance sweep covers 9… $50 Minimum data controller license Every organization storing persona… ~$1,250 DPO certification course cost Cost to certify a required data pr… 5 Years law in force before scrutiny The Act, Chapter 12:07, was passed… peopleofinternet.com
Zimbabwe's Data Protection Act: Powers… People of Internet Research · Africa 9 Sectors in inspection sweep $50 Minimum data controller licen… ~$1,250 DPO certification course cost 5 Years law in force before scr… peopleofinternet.com

Key Takeaways

Zimbabwe's Cyber and Data Protection Act [Chapter 12:07] (Act 5 of 2021) was sold as a conventional data-protection statute — the kind of law that lets citizens know who holds their data and gives them a way to complain when it's misused. Four years and multiple enforcement rounds later, the country's most respected legal-monitoring body says the law's actual text hands its designated regulator, POTRAZ, powers that look far less like consumer protection and far more like a surveillance mandate against civil society, with almost nothing on the statute books to stop it from being used that way.

What the Law Actually Says

Veritas Zimbabwe's Bill Watch 29-2026, published August 4, 2026, walks through the mechanics. Section 21(3) lets the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) — designated as the country's Data Protection Authority — inspect an organization's security measures whenever it "considers" that the organization's data processing entails "specific risks" to privacy rights. Section 6 goes further, empowering POTRAZ to "request the disclosure of any documents" in the course of an inquiry or investigation — a formulation broad enough, Veritas notes, to reach essentially any record an organization holds, electronic or paper, whether or not it has anything to do with personal data.

A companion bulletin, Bill Watch 27-2026 (July 28, 2026), confirms this is not hypothetical: POTRAZ began compliance inspections on September 1, working through nine sectors in sequence — financial institutions, insurers, local authorities, healthcare, mining, religious bodies, schools, government agencies, and, last on the list, NGOs. Under the 2024 Licensing Regulations, any organization that stores personal information digitally — a church membership roll, a human-rights group's beneficiary list, a small NGO's donor database — must obtain a data controller license (minimum US$50) and appoint and register a dedicated data protection officer, who must complete a certification course Veritas prices at roughly US$1,250.

The Case for the Law

Zimbabwe genuinely lacked a modern data-protection framework before 2021, and the gap was real: financial institutions and telecoms held growing troves of personal data with no statutory floor on consent, breach notification, or cross-border transfer. A regulator with investigative teeth — one that can walk into an organization and check whether it is actually protecting the data it holds — is standard practice under the EU's GDPR, Kenya's Data Protection Act, and most modern privacy regimes. POTRAZ itself has pushed back on the more inflammatory framing of its mandate: responding to viral claims of a standalone "Cyber Crimes Act," the regulator publicly clarified in January 2026 that Zimbabwe has no such separate law, that cybercrime is handled through existing Criminal Law Code provisions (sections 163–168), and that its framework tracks the UN Convention Against Cybercrime. On paper, licensing and inspection are the ordinary machinery of enforcement, not novel repression.

Where the Guardrails Are Missing

The problem Veritas identifies is not how the Act has been enforced so far — the bulletin is explicit that "we are not concerned about the way in which the Act is currently being administered, but rather about the lack of statutory guardrails to prevent undue restrictions being imposed in the future." That distinction matters. A power this broad doesn't need to be abused today to be dangerous; it only needs to sit on the books, available to a differently-motivated POTRAZ tomorrow.

And POTRAZ's independence is itself structurally thin: its board is appointed by the President, with no separate confirmation process or fixed-term insulation comparable to, say, a judicial appointment. A section 6 "disclosure of any documents" power, combined with a section 21(3) inspection trigger keyed to a subjective standard — POTRAZ "considers" a risk exists — gives a presidentially-appointed board effectively standing authority to walk into any licensed NGO, demand its records, and inspect its systems, with no requirement to show cause to an independent court first. For a human rights group whose core asset is a confidential list of the people it serves — torture survivors, LGBTQ+ Zimbabweans, opposition activists — that is not an abstract risk. It is the single scenario data-protection law is supposed to prevent, inverted: the state, not a criminal, becomes the actor with unchecked access to the list.

The Fix Is Narrower Than a Repeal

None of this requires scrapping data protection in Zimbabwe, and Veritas doesn't call for that. It calls for guardrails: a warrant or independent-authorization requirement before an inspection or document demand proceeds, a defined and reviewable standard for "specific risks" rather than a subjective one, and a licensing exemption or lighter-touch tier for small NGOs and clubs whose "personal data" is a membership spreadsheet, not a commercial dataset. Kenya's Data Protection Act, often cited as a regional model, requires its Data Commissioner to seek a court order before compelling production of records in contested cases — a check Zimbabwe's law simply omits. Proportionate data protection and civic-space protection aren't in tension; the current statute just hasn't been asked to hold both at once.

Key Takeaways

Sources & Citations

  1. Veritas Bill Watch 29-2026 (Aug 4, 2026)
  2. Veritas Bill Watch 27-2026 (Jul 28, 2026)
  3. Cyber Security and Data Protection Bill text, ICNL Digital Legal Library
  4. AllAfrica: POTRAZ Quashes Online Claims of New Cyber Crimes Law