Zimbabwe raises the bar on data protection

Samkeliso Ndlovu, Correspondent

ZIMBABWE’S mandatory data-protection compliance inspections, which commenced this month, mark an important transition in the country’s digital regulatory programme — from registration to active supervision.

The exercise is broad in scope, covering compliance with the country’s data-protection framework and the handling and processing of personal information. The initial focus is on higher-risk sectors: financial institutions, insurance, local authorities, healthcare and mining.

The inspections are the latest step in a regulatory framework that has been taking shape over the past four years. The Cyber and Data Protection Act (Chapter 12:07) established the legal foundation, followed by Statutory Instrument 155 of 2024, which introduced the licensing regime for data controllers and requirements for Data Protection Officers. Registration, sensitisation and capacity-building followed, laying the groundwork for the active supervision now being undertaken by Potraz as the national Data Protection Authority.

Responding to questions from the Sunday News recently, Deputy Minister of Information Communication Technology, Postal and Courier Services, Dingumuzi Phuti, said Zimbabwe’s data-protection architecture had “matured considerably” over the past four years, describing the commencement of mandatory compliance inspections as “the natural next step in that architecture.”

For organisations, that shift means the emphasis can no longer rest on registration alone. The question now is whether the systems, personnel and procedures behind the licence can withstand regulatory scrutiny.

Boards and senior management are increasingly expected to demonstrate that responsibility for personal information is understood and exercised across the entire operation.

Government’s approach, however, is not centred on enforcement for its own sake.

“Government’s message to corporate Zimbabwe is one of partnership, not just enforcement,” Deputy Minister Phuti said.

“We would rather see organisations come into compliance proactively than face the consequences of an inspection finding gaps.”
Potraz’s phased, risk-based approach reflects that intent. The broader objective, he added, is to build “a genuine culture of data stewardship, not a compliance checklist”, supported by staff training, incident-response preparedness and regular audits rather than treating data protection as a once-off registration exercise.

The timing matters given the pace at which Zimbabwe’s digital economy is expanding. Potraz’s latest first-quarter sector performance report shows active internet subscriptions rising from 13,25 million to 13,92 million.

Mobile data traffic increased from roughly 160 petabytes to 179 petabytes, while fixed internet traffic rose from about 479 petabytes to 621 petabytes. More people, businesses and institutions are online and considerably greater volumes of information are moving through the country’s communications infrastructure. This rapid expansion gives greater urgency to the regulatory push.

It also means the data-protection conversation cannot end with the current inspections. As the digital economy expands, the technologies through which information is collected, processed and analysed are changing with it.

Artificial intelligence, cloud computing and automated decision- making are increasingly becoming part of that environment, adding new dimensions to questions of accountability already at the heart of the existing framework.

This is where Government’s thinking begins to extend beyond the immediate compliance exercise.

Deputy Minister Phuti acknowledged that Zimbabwe’s existing framework was developed principally with conventional data processing in mind.

AI systems, cloud-hosted infrastructure and automated decision-making, he said, introduce issues that existing provisions address only in general terms, including algorithmic profiling, the use of personal information to train models, cross-border data flows and questions of accountability where processing spans multiple platforms and jurisdictions.

“We do not consider the current framework a finished product,” he said.
“It is a sound foundation, but it will need to evolve” through subsidiary regulations, sector-specific guidance from Potraz and closer alignment with continental and regional data-protection standards.

That evolution is a natural extension of the regulatory foundation already being enforced. As organisations adopt new technologies, the fundamental obligations around personal information remain, but the environment in which those obligations must be applied becomes more complex.

Deputy Minister Phuti said companies should “treat any AI tool, cloud service or automated system as a data-processing decision, not merely an IT procurement decision.”

Before adopting such systems, organisations should understand where their information is hosted and processed and satisfy themselves that cross-border transfers comply with the law. Using a cloud provider or an AI vendor, he stressed, “does not transfer legal responsibility for the data.”

The principle becomes increasingly important as organisations rely more heavily on third-party platforms for cloud storage, enterprise systems and automated services. Responsibility for personal information remains with the organisation entrusted with it, regardless of who processes it on its behalf.

Automated decision-making raises a related concern. Where AI systems make or materially influence decisions on creditworthiness, employment, insurance or similar matters, Government’s position is that organisations should be able to explain the basis of those decisions and provide a mechanism for human recourse.

This emerging regulatory conversation is also consistent with Government’s wider digital transformation agenda. Zimbabwe’s National Artificial Intelligence Strategy 2026–2030, launched by

President Mnangagwa earlier this year, places governance, ethics and regulation among the foundations for the country’s adoption of AI.

Data protection is also being considered alongside the wider cyber-security agenda, with Government advancing complementary work on the National Cybersecurity Strategy and the proposed

National Cybersecurity Authority alongside Potraz’s data-protection mandate.

As Deputy Minister Phuti put it: “Data protection and cyber-security are two sides of the same coin, a data controller cannot demonstrate accountability for personal information it cannot adequately secure.”

Taken together, the developments reveal a regulatory programme moving through distinct but connected stages. Zimbabwe first established the legal framework for data protection. Potraz then moved through registration, sensitisation and capacity-building.

Mandatory inspections now bring that framework into active supervision, even as Government looks ahead to the questions AI, cloud computing and automated systems will continue to raise.

The immediate task for corporate Zimbabwe is to comply with the data-protection obligations already in force and be able to demonstrate that compliance when required. The longer-term task is ensuring those protections remain effective as the technology used to process information grows more sophisticated.

As Deputy Minister Phuti put it, data protection “is no longer a discretionary good practice — it is now a legal obligation and increasingly a marker of institutional trustworthiness in a digital economy”.

Related Posts

The lake that took and the men who reached in: A Kariba tragedy etched in memory

Fatima Bulla-Musakwa, Features Writer A MONTH after the Mbuya Nehanda Ferry plunged into Lake Kariba’s black waters, the silence that followed has proved louder than the storm that sank it.…

Zimbabwe eyes bigger share of US$1 trillion COMESA market . . . Exports rebound as nation readies to host regional summit

Africa Moyo, Harare Bureau ZIMBABWE’S recovery in exports to the Common Market for Eastern and Southern Africa (COMESA) has highlighted the country’s scope for deeper penetration of a regional market…

Leave a Reply

Your email address will not be published. Required fields are marked *