Ivan Zhakata
Check Point Desk
Every time a person opens a bank account, registers a mobile number, sends money, applies for a service or interacts with a Government department, a digital trail is created — containing names, identity numbers, addresses, financial records, telephone numbers, transaction histories and, in some cases, biometric information.
The question increasingly confronting consumers is not whether their personal information is being collected but who can access it, why they can access it and how long they can keep it?
Zimbabwe’s Cyber and Data Protection Act provides a legal framework governing the collection, storage, processing and disclosure of personal information.
The law defines personal information broadly to include names, addresses, telephone numbers, identification numbers, financial and employment histories, health information and other information capable of identifying an individual.
The Postal and Telecommunications Regulatory Authority of Zimbabwe (Potraz) is the designated Data Protection Authority and is responsible for regulating the lawful processing of personal information. Potraz director-general Dr Gift Machengete is on record saying the law was intended to put citizens at the centre of the digital economy.
“The Cyber and Data Protection Act signalled Zimbabwe’s commitment to ensuring that the processing of personal data is lawful, secure and respectful of the rights of data subjects,” Dr Machengete said.
But evidence gathered by Potraz itself shows a significant gap between the law and public understanding.
A nationally representative Potraz survey conducted in December 2025 among Zimbabweans aged 18 and above across all 10 provinces, found that 77 percent have experienced misuse of their personal data at least once, while 22 percent said they did not know where to seek help when their data was violated.
Even more revealing, 80 percent said they did not understand what companies could do with their personal information, while 82 percent said they did not understand the laws governing its use.
For mobile-phone users, the information held by service providers can go far beyond a name and telephone number.
The Interception of Communications Act provides for the lawful interception and monitoring of communications and defines call-related information to include details identifying the origin, destination, duration and equipment involved in a communication, as well as, where applicable, the user’s location within the telecommunications system.
The law provides a framework under which authorised interception can take place, meaning telecommunications data can become accessible to State authorities under prescribed legal processes. At the same time, the Cyber and Data Protection Act requires data controllers to process information lawfully, fairly and transparently and only for specified and legitimate purposes.
This creates a delicate balance: telecom operators must protect subscribers’ information while also complying with lawful obligations imposed by the State.
Banks arguably hold some of the most sensitive information about an individual. A bank may have access to identification details, account balances, transaction histories, beneficiaries, remittance information, credit records, electronic-banking data and, in some circumstances, biometric information.
For example, BancABC’s current customer terms state that it may process identification, contact, financial and transactional, credit and risk, remittance, device and electronic-banking information, as well as CCTV and security-monitoring data.
The bank’s terms also provide for disclosure of personal information to regulatory authorities and courts, Potraz, credit-reference bureaux, correspondent banks and payment processors, service providers, and law-enforcement agencies where applicable. This demonstrates how a single customer’s information can move beyond the institution where it was originally supplied.
The Banking Act separately imposes secrecy obligations on banking institutions and certain officials, while allowing disclosure in specified circumstances, including where required by a court or another law. The Reserve Bank of Zimbabwe has also acknowledged that increasing use of artificial intelligence in financial institutions brings data-privacy and cybersecurity risks alongside potential benefits.
Government departments and agencies are also data controllers under Zimbabwe’s legal framework. The Cyber and Data Protection Act expressly includes public bodies within the definition of data controllers.
The law allows processing without consent in certain circumstances, including compliance with a legal obligation, protection of vital interests, public-interest tasks and the exercise of official authority.
This means that citizens’ data is not protected by consent alone. There are circumstances in which an institution can lawfully process or disclose information without obtaining fresh consent from the individual. The 2024 regulations governing data-controller licensing also cover organisations that process personal information and require notification to Potraz of certain processing activities, including intended transfers or sharing of personal information outside Zimbabwe and processing involving biometric or genetic data.
Potraz has moved to strengthen enforcement.
As of December 2025, Potraz said 880 data controllers had been licensed, while more than 1 000 Data Protection Officers had been trained. However, the authority acknowledged continuing gaps, including organisations that had not registered and entities without qualified Data Protection Officers.
Dr Machengete said the outstanding gaps remained a concern.
“These gaps undermine the effectiveness of the framework. That is why enforcement, guidance and training must move hand in hand,” he said.
Under the Act, individuals have the right to know how their personal information is being used, access information held about them, object to certain processing, and seek correction or deletion of false or misleading information.
Potraz has urged Data Protection Officers to act as contact points when citizens make formal requests concerning their personal information.
But the findings of its own survey suggest many citizens still do not know how to exercise those rights.
The Media Insitute of Southern Africa (MISA) Zimbabwe executive director Dr Tabani Moyo said the issue of protecting citizens’ data is key especially in this global economy.
He said global economy means most of our transactions are going digital with many government departments and organisations processing people’s personal information.
“As a country, we have the Cyber and Data Protection Act and SI 155 of 2024 which governs the collection and processing of the information of data subjects including cross border data transfers. Citizens should be aware of this legislation and their rights. The law allows them to ask why their data is being collected and how long its going to be retained.
“It calls on data controllers to appoint Data Protection Officers who are trained by the regulator to ensure data is collected and processed in ways that protect fundamental human rights like privacy and dignity. The issue with Zimbabwe is that we still have archaic laws which speak to back end surveillance and no judicial oversight,” said Dr Moyo.
He said there was need for alignment of archaic legislation in line with international best practices.
“There is need to raise awareness around the legal provisions of the Cyber and Data Protection Act. We commend the regulator for announcing compliance checks as this will ensure data controllers do not abuse people’s data,” he said.
Dr Moyo said where citizens have concerns, they must raise with the company they are dealing with, if not satisfied they have the legroom to petition the regulator – Potraz.
Legal practitioner and certified Data Protection Officer and board chairperson of the Privacy Practitioners Association of Zimbabwe Mr Innocent Chingarande said any customer of a licensable data controller who is a natural person is defined as data subject has the right among other rights, to access their personal information from any data controller who processes their personal information except where the law limits such right.
Mr Chingarande said there are other third parties who can legally have access to a customer’s personal information i.e regulatory authorities as provided in terms of their enabling statutes such as the Zimbabwe Revenue Authority (Zimra), National Social Security Authority (NSSA), national employment councils, ZRP and other third parties who share and process personal information with or on behalf of a licensable Data Controller in terms of a pata processing or sharing agreement.
“There are about three categories of third parties that a Data Controller can share customer information with, these are other Data Controllers or Processors in terms of a data sharing or processing agreement, regulatory authorities and law enforcement agencies,” said Mr Chingarande.
“Customers’ personal information can be shared with Government agencies where the respective agency’s enabling Act provides for such sharing and access. By way of an example, all Data Controllers are required to comply with tax legislations and tax authorities are empowered to have access to customer information in certain instances.
“Data Controllers are required to share their relevant employees’ details with the respective National Employment Council (NEC), including names grades and job titles. Designated Non-Financial Business and Professions such as Legal Practitioners bear obligations to prevent, detect, and report illicit financial flows.”
Mr Chingarande said this will ultimately involve sharing and access of personal information of the customers involved by the Financial Intelligence Unit.
He said law enforcement agencies such as ZRP, local councils and the Department of Immigration are authorised to process personal information for purposes of discharging their constitutional and statutory mandate which include arrest, investigation and court case preparations.
Mr Chingarande said the Act requires that Data Controllers must put in place technical and organizational measures in place to ensure that personal data is protected from breaches and other unauthorized processing.
“This varies on the sensitivity of the processing involved, a bank will not have the same measures as a retailer. Restricted access, strong passwords, training of employees are some of the measures that can be taken by Data Controllers to minimize and manage breaches.
“At a personal level, having a basic password and making sure you read fine print involving the use of your personal information when signing up online and on social media is a good starting point.”
He said every natural person has a constitutional right to privacy which is now codified in the Act.
Mr Chingarande said one can seek to enforce any of the above rights through a Data Protection Officer of an organisation that they think may have their personal information.
“If there is no cooperation or if unsatisfied, one may approach the Data Protection Authority for redress,” he said.
“The Data Protection Authority may make certain limited orders or may escalate the matter to criminal courts if the complaint is also criminal in nature. We are yet to see the amendments that were the subject of discussions in Nyanga last week with all stakeholders which may empower the Data Protection Authority to have the power to impose administrative fines and possibly compensation orders as part of redress.”
For ordinary Zimbabweans, the central issue is therefore, becoming one of visibility and accountability. A mobile operator may know where and when a subscriber communicates. A bank can see where money comes from and where it goes. Government departments may hold identity, tax, health, education or social-service records.
Individually, each piece of information may appear harmless. Combined, they can create an extraordinarily detailed picture of a person’s identity, movements, finances, relationships and activities. And that is why the question is no longer simply “Who has my information?”
It is “Who else can they give it to, under what authority, and can I find out?”



