Your obligations

Can I buy or use a purchased customer list under Zimbabwe's data protection law?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Only if the people knew and agreed. When you receive personal information from a third party you must still inform the individuals, at the latest when you first use the data, who you are, why you have it and their rights, and SI 155 of 2024 requires you to notify POTRAZ about modifications to indirectly collected data. Buying or selling customer lists without the people's knowledge is unlawful for both sides.

What the law says

Section 16 of the Act imposes the information duties on a controller that obtains data other than directly from the data subject: identity, purposes, the categories of data, recipients and the existence of rights, to be given "at the time of recording or, if disclosure to a third party is envisaged, no later than the time of first disclosure". Section 10 requires a lawful ground for the new processing; the seller's consent from its customers does not automatically extend to you. Section 15 gives everyone the right to object to direct marketing free of charge. The cybercrime provisions on unlawful acquisition of data (section 163A of the amended Criminal Law Code) can apply to a person who obtains data without authority.

Example

A Harare car-insurance broker is offered a list of 20,000 new vehicle registrations "from a contact at a dealer group" and uses it for cold SMS. Recipients complain to POTRAZ; the broker cannot show any lawful ground, never informed the people under section 16, and cannot explain the source. A rival broker instead runs an opt-in campaign with the same dealers, where buyers tick a box to receive insurance offers and the dealer's privacy notice names the broker; it gets fewer leads but every one is lawful.

In practice

If you cannot honestly explain where a list came from and that the people agreed to this use, do not use it. Grow lists through opt-in at your own points of contact, honour opt-outs immediately, and record the source of every dataset in your processing record.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.