Your obligations

Do I have to report every data breach to POTRAZ within 24 hours?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

To POTRAZ, yes. Section 19 of the Cyber and Data Protection Act requires the data controller to notify the Authority within 24 hours of any security breach affecting the data it processes, on Form DP3. To the affected individuals, notification is required within 72 hours only where the breach is likely to result in a high risk to their rights and freedoms.

What the law says

Section 19: "The data controller shall notify the Authority within twenty-four (24) hours of any security breach affecting data he or she processes." SI 155 prescribes Form DP3, requires the controller to answer POTRAZ's follow-up information requests within 14 days, and provides for POTRAZ to close its investigation within 21 days of notification. SI 155 and POTRAZ's 2025 Data Breach Notification Guidelines require notification of data subjects within 72 hours "where the detected breach is likely to result in a high risk of adversely affecting individuals' rights and freedoms". A "security breach" is any incident leading to loss, destruction, alteration, unauthorised disclosure of or access to personal information, whatever its cause.

Example

Three incidents at a Harare retailer in one year. (1) A courier misdelivers one customer's invoice to a neighbour: a breach, notified to POTRAZ within 24 hours; low risk, so no notice to the customer beyond an apology. (2) An encrypted laptop is stolen and the encryption key was not compromised: notified to POTRAZ; risk assessed as low; no individual notification. (3) The loyalty database with 15,000 names, phone numbers and ID numbers is exfiltrated by a hacker: notified to POTRAZ within 24 hours, and all 15,000 customers notified within 72 hours with advice on fraud and SIM-swap risks.

In practice

Do not spend the first 24 hours debating whether something "counts". Log it, contain it, notify POTRAZ with what you know, then assess the risk to individuals with the DPO and decide on the 72-hour notice. Keep the incident register even for incidents you conclude were not breaches; it shows you take the duty seriously.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.