Your obligations

Do I need CCTV signs under Zimbabwe's data protection law?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes. CCTV footage of identifiable people is personal information under the Cyber and Data Protection Act, so you must tell people they are being recorded and by whom, have a clear purpose, limit who can view footage and keep it only for a short period. Visible signs at the entrance are how you meet the information duty.

What the law says

Sections 15 and 16 require the controller to inform data subjects of its identity and the purpose of processing at the time of collection; for CCTV that is a sign at the point where people enter the camera's view. Section 7 requires that data be adequate, relevant, not excessive and kept no longer than necessary, which rules out cameras in private areas and indefinite retention. Section 18 requires security, so footage must be access-controlled. Disclosing footage to third parties, or posting it on social media, is processing that needs its own lawful basis under section 10.

Example

A Harare shopping centre installs 40 cameras. Signs at every entrance read: "CCTV in operation for the safety and security of visitors and staff. Operated by [company]. Footage kept for 30 days. Data Protection Officer: [phone/email]." Footage is viewed only by two security supervisors, requests from the police are logged, and no cameras cover toilets or the staff changing room. When a tenant asks for footage of a shoplifter to post on Facebook, the DPO refuses and hands the clip to the police instead.

In practice

Add CCTV to your processing record (purpose, retention, who has access), put up signs with your name and DPO contact, keep footage for a short fixed period (30 days is common), and never publish footage to shame anyone; that is an unlawful disclosure and a defamation risk.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.