The DPO role

Is the Data Protection Officer personally liable under Zimbabwe's CDPA?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Generally no. Liability under the Cyber and Data Protection Act and SI 155 sits with the data controller (the business and its responsible officers), not with the Data Protection Officer for performing their role. A DPO would only face personal action for offences they personally commit, such as unlawfully disclosing data.

What the law says

The duties in the Act are imposed on "the data controller" (sections 10 to 19, 24, 28), and section 33 penalises "a data controller who contravenes" them. SI 155's DPO provisions describe the DPO's functions (section 14) and make the controller liable for failing to appoint one. Section 33 also penalises anyone under the controller's authority who processes personal information otherwise than as instructed (fine up to level 7 or two years), which is the provision that could reach an individual, DPO or otherwise, who misuses data personally.

Example

The DPO of a retail chain in Harare advises in writing that customer ID copies should not be shared with an external debt collector without a processing agreement. Management goes ahead anyway; POTRAZ investigates after a complaint. The company faces the consequences; the DPO's written advice is evidence that she did her job. If, instead, the DPO herself had sold the customer list to a marketer, she would be personally exposed under section 33 and under the cybercrime provisions on unlawful data acquisition.

In practice

Reassure candidates with the law and with a written arrangement: DPO advice is recorded, management decisions are minuted, and the DPO has direct access to the board. That protects the DPO from blame and protects the company by showing governance.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.