Do I need consent to process personal data under Zimbabwe's CDPA, including payroll?
Short answer
Not for everything. Consent is the main ground under section 10 of the Cyber and Data Protection Act, but the section also allows processing without consent to comply with a legal obligation, to protect vital interests, for public-interest tasks, where the data is evidence in proving an offence, and for your legitimate interests where they do not override the person's rights. Payroll rests on your legal duties and legitimate interests plus the agreement the employee gave when hired.
What the law says
Section 10 provides that personal information "may only be processed if the data subject or a competent person … consents to the processing", and then lists the exceptions: processing necessary for "compliance with an obligation to which the controller is subject by … a law", for "protecting the vital interests of the data subject", for "performing a task carried out in the public interest, or in the exercise of official authority", where the data is "material as evidence in proving an offence", or for "promoting the legitimate interests of the controller or a third party … except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject". Note that, unlike the EU GDPR, the Zimbabwean Act does not list "performance of a contract" as a separate ground; contractual processing is normally covered by the consent given on signing and by legitimate interests. Sensitive data (section 11) requires consent in writing.
Example
A Harare manufacturer runs payroll for 200 staff, deducting PAYE for ZIMRA and NSSA contributions: that is processing to comply with a legal obligation, plus the employment agreement. It keeps medical certificates for sick leave: health data, so the employee's written consent (usually built into the HR forms) or the employment-law exception in section 11 is needed. It wants to send staff a monthly newsletter with a partner supermarket's offers: that is marketing to a third party's benefit and needs opt-in consent with an easy opt-out.
In practice
In your processing record, write the legal ground next to each activity. Use consent where the person has a real choice (marketing, optional services, photos), the legal-obligation ground for tax and labour records, and legitimate interests for ordinary business operations, always checking that the person would not be surprised. Get sensitive data consent in writing.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.