Your obligations

Do I need a privacy notice on my website and forms in Zimbabwe?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes. Sections 15 and 16 of the Cyber and Data Protection Act require you to tell people, when you collect their information, who you are, why you are collecting it, whether answering is compulsory, who you will share it with, and their rights to access and correct their data and to object. One plain-language page, plus a short line on paper forms and a notice at your counter, does the job.

What the law says

Section 15 applies where data is collected directly from the person and requires the controller to provide, at the latest at the time of collection, its identity and address, the purposes of processing, "the existence of the right to object, by request and free of charge" to processing for direct marketing, whether replying is compulsory and the consequences of not replying, the recipients or categories of recipients, and the existence of rights of access and rectification. Section 16 imposes equivalent duties where data is obtained from someone else. Section 33 attaches penalties to breaches of the controller's duties.

Example

A Harare gym's membership form asks for name, ID, phone, next of kin and medical conditions, and says nothing about why. After the CDPA review, the form carries a five-line notice: who the gym is; that the data is used to manage membership, safety and billing; that medical information is used only for safety and needs the member's signature; that data is shared with the payment provider and, in emergencies, medical services; that members can see and correct their data and opt out of marketing by messaging the DPO; and the DPO's phone number. The same text goes on the website and on a laminated sheet at reception.

In practice

Write it for your customers, not for lawyers: one page, plain English (and Shona or Ndebele where your customers prefer them), the DPO's contact details, and a line about how long you keep data. Put it wherever you collect information: forms, website, app sign-up, WhatsApp Business profile, counter.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.