Do I have to give a customer all the data I hold about them (data subject access request)?
Short answer
Yes. Section 14 of the Cyber and Data Protection Act gives every person the right to access their personal information, to have false or misleading data corrected or deleted, and to object to processing. Verify their identity, search all your systems, give them their data with the purposes and recipients, and do it promptly; the first copy should be free.
What the law says
Section 14 lists the data subject's rights: to "be informed of the use to which their personal information is to be put", to "access their personal information in custody of data controller or data processor", to "object to the processing of all or part of their personal information", to "correction of false or misleading personal information" and to "deletion of false or misleading data about them". Section 15 requires that the right to object to direct marketing be exercisable "by request and free of charge". The Act does not fix a number of days; the standard is prompt handling without undue delay, and POTRAZ's complaint function (section 6) is the remedy if you stall.
Example
A former employee of a Harare bank writes asking for "all the information you hold about me". The DPO verifies her identity, searches HR, payroll, the disciplinary file, email archives for her name and the access-control system, and within three weeks sends her a copy of her personal information with a covering letter explaining the purposes, the recipients (ZIMRA, NSSA, the medical aid, the pension fund) and the retention period. Third parties' details in the same documents are redacted. The request and response are logged. When she later complains to POTRAZ about a different matter, the log shows the bank handled her request properly.
In practice
Set a 30-day internal target, log every request (date received, identity verified, systems searched, date answered), redact other people's data, and never charge for the first copy. A clear log is what turns a complaint into a closed file.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.