Your obligations

Do I need POTRAZ approval to use Google Workspace, Microsoft 365 or a South African server?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

You must notify POTRAZ, not seek permission for each transfer. Storing personal information outside Zimbabwe is a trans-border transfer under sections 28 and 29 of the Cyber and Data Protection Act. You need a lawful basis for the transfer, a written processing agreement with the provider, and you must notify POTRAZ of your international transfers as part of your processing activities.

What the law says

Section 28 permits the transfer of personal information to a country that "ensures an adequate level of protection", assessed by reference to the nature of the data, the purpose and duration of processing, the recipient country's laws and the security measures in place. Section 29 permits transfers to countries without adequate protection where the data subject has consented, the transfer is necessary for the performance of a contract with the data subject or in the data subject's interest, is necessary on public-interest grounds or for legal claims, is necessary to protect vital interests, or is made from a public register. Section 10 of SI 155 requires the controller to notify POTRAZ of international data transfers.

Example

A Harare architecture firm uses Google Workspace for email and files (servers abroad), a South African payroll SaaS and a UK project-management tool. Its DPO records each in the processing record as an international transfer, identifies the basis (contractual necessity and the consent in staff and client engagement letters), obtains each vendor's data processing terms, notes their security certifications, and notifies POTRAZ of the transfers in the licence application. No further approval is sought or needed unless POTRAZ asks questions.

In practice

List every foreign-hosted system, record the section 28/29 basis and the vendor contract for each, tell staff and customers in your privacy notice that data is processed abroad, and include the transfers in your POTRAZ notification. Take extra care, and consider Zimbabwean or regional hosting, for sensitive data such as health or biometrics.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.