Is written consent required for fingerprint or biometric attendance systems in Zimbabwe?
Short answer
Yes. Biometric data is sensitive data under sections 11 and 12 of the Cyber and Data Protection Act. You need written consent from each employee, or a basis in employment law, plus a notification to POTRAZ under SI 155 of 2024 that you process biometric data. Be ready to show why a less intrusive method was not enough.
What the law says
Section 11 provides that "no data controller shall process sensitive data unless the data subject has given consent in writing", with narrow exceptions including obligations under employment law. Section 12 specifically governs genetic, biometric and health data and repeats the written-consent rule with its own list of exceptions. Section 10 of SI 155 requires the controller to notify the Authority of biometric or genetic processing. Because employees cannot easily refuse their employer, POTRAZ's expectation, consistent with the Act's proportionality principle in section 7, is that biometrics are justified, minimised and secured, ideally after an impact assessment.
Example
A Harare security company installs fingerprint clocking for 300 guards to stop "buddy punching". It obtains signed consent forms explaining the purpose, the data kept (a template, not a fingerprint image), the retention period (deleted on leaving) and the right to withdraw; it offers a PIN alternative to the few who object; it notifies POTRAZ of the biometric processing; and its DPO records a short impact assessment. A neighbouring firm simply switches the machines on. The first firm can defend its system; the second is processing sensitive data unlawfully.
In practice
If cards or PINs would achieve the purpose, use them. If you need biometrics, do the impact assessment, take written consent, offer an alternative, store templates encrypted, delete on departure, and notify POTRAZ.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.