Do I need written contracts with my accountant, payroll bureau and IT company under SI 155?
Short answer
Yes. Section 10 of SI 155 of 2024 requires a written data processing agreement between the data controller and every data processor, and section 18 of the Cyber and Data Protection Act requires the controller to bind processors by contract to appropriate security. Your accountant, payroll bureau, IT company, cloud provider, courier and marketing agency are all processors if they handle personal information for you.
What the law says
Section 18 requires the controller to choose a processor providing sufficient guarantees of technical and organisational security and to ensure, by contract, that the processor acts only on the controller's instructions. Section 10 of SI 155 lists among the controller's obligations maintaining a "written data processing agreement or contract" with processors and requiring "strict adherence" to the security measures. The processor's own failure does not relieve the controller: the controller notifies POTRAZ within 24 hours under section 19 even when the incident happened at the processor.
Example
A Mutare timber company outsources payroll to a bureau, IT support to a local firm with remote access to its server, and hosting to a South African cloud provider. None of the three contracts mentions personal information. After the CDPA review, each service agreement gets a two-page annex: the processor acts only on instructions, keeps data confidential, applies the company's security measures, tells the company immediately of any incident (so the company can meet its 24-hour deadline), does not subcontract or move data abroad without approval, helps with access requests, and returns or deletes data at the end. The cloud contract also records the section 28/29 basis for the transfer.
In practice
List your processors in the processor register, send each a standard annex, and chase signatures; a reputable vendor will have seen one before. A vendor who refuses to sign is telling you something about how they treat your customers' data.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.