Zimbabwe's Postal and Telecommunications Amendment Bill was scheduled to begin its Second Reading in the National Assembly on September 22, 2026, one of twelve bills moving through the chamber that week, according to Veritas Zimbabwe's parliamentary tracker Bill Watch 37-2026. Buried in a modernization package meant to update a telecoms law last substantially revised in the analogue era, Section 93L does something the current statute does not: it lets private telecommunications operators and their employees intercept and detain a customer's communications on mere suspicion, before any judge sees the request.
What the Bill Actually Changes
Under the Interception of Communications Act, 2007, warrant-based interception already routes through the executive branch rather than a court — a design civil society has criticized for two decades. Section 93L goes further still. As MISA Zimbabwe's analysis lays out, it authorizes carriers to act first and seek validation later, with "only retrospective authorisation from the Prosecutor-General and no requirement for a prior judicial warrant" (MISA Zimbabwe, July 2026). The same bill also folds telecommunications licensing, cybersecurity enforcement, and data-protection oversight into a single regulator — the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) — whose board and leadership the Minister appoints, and whose funding depends on ministerial sign-off for donor support.
The Case for Consolidation
Before dismissing the bill, it's worth taking the modernization argument seriously. Zimbabwe's Postal and Telecommunications Act Chapter 12:05 predates smartphones, cloud storage, and most of the cybercrime it now has to police. A regulator that has to escalate every cross-border data leak or SIM-swap fraud case to a separate cybersecurity agency, and a separate data-protection authority, genuinely loses time — and speed matters when a breach is live. Consolidating technical expertise under one roof, and letting carriers flag active harm (a phishing campaign moving in real time, a ransomware operator using local infrastructure) without waiting for a magistrate's calendar to clear, is not an unreasonable instinct. Fast-moving digital harms are a real regulatory problem, and slow, court-only processes have real costs too.
Where the Design Fails
But speed is not the same as removing the check entirely. Section 57 of Zimbabwe's Constitution guarantees the right to privacy, including of communications, and Section 86 permits limiting that right only where a restriction is "fair, reasonable, necessary and justifiable" — a standard built around prior, not retrospective, scrutiny. A warrant obtained before interception forces the requesting party to justify the intrusion to an independent arbiter while the citizen's rights are still intact. Authorization obtained after the fact reviews a decision that has already been made and already caused harm — the communications are already detained, already read, already potentially shared. The Prosecutor-General, moreover, is a member of the executive branch, not a judicial officer, which means the safeguard MISA Zimbabwe calls "vulnerable to abuse" is asking the government to check its own homework after the intrusion has occurred.
The stakes are sharpened by who gets swept in. Zimbabwe's press-freedom and civil-society record gives specific reason to worry that a low-threshold, after-the-fact mechanism will be used against journalists sourcing stories and activists organizing protests — precisely the communications that most need protection from a government with an interest in their content, not least because of it.
An Unaccountable Referee
The institutional design compounds the problem. Consolidating telecom licensing, cybersecurity enforcement, and data-protection oversight under POTRAZ isn't inherently wrong — plenty of well-functioning regulators hold multiple digital-economy mandates. What makes it risky here is that POTRAZ's leadership answers to a Minister who also gets to issue binding "policy directions" in the name of "national interest," a phrase broad enough to justify almost anything. A single regulator with interception-adjacent powers, cybersecurity enforcement authority, and access to the bulk data that mobile network operators and ISPs hold, operating under ministerial direction rather than an independently constituted board, is a structure that concentrates rather than checks power.
The Fix Is Narrow, Not Radical
None of this requires killing the bill's legitimate modernization goals. A workable version would keep the expanded technical mandate but restore a judicial warrant requirement before interception — not after — for anything beyond genuine, narrowly defined emergencies, and would insulate POTRAZ's board appointments and budget from single-minister control. Zimbabwe does not need to choose between an updated telecoms law and a citizen's ability to text a source without a carrier deciding, on suspicion alone, to open the message first and explain itself later.