Do frontline staff need data protection training under Zimbabwe's CDPA?
Short answer
Yes, briefly. Cashiers, receptionists, drivers, tellers and sales agents handle personal information every day, and most data breaches in Zimbabwe are their mistakes rather than hackers' attacks. A 60- to 90-minute awareness session once a year, with a signed attendance register, is the cheapest security measure you can buy and the first evidence a POTRAZ inspector accepts.
What the law says
Section 18 of the Act requires "appropriate technical and organisational measures", and section 33 penalises anyone acting under the controller's authority who processes personal information otherwise than as instructed (fine up to level 7 or two years). To instruct staff you must train them. Section 14 of SI 155 makes staff training a DPO function, and section 16 of SI 155 requires the controller to test the effectiveness of its measures, which for training means a short quiz or spot-check.
Example
At a bank branch in Gweru a teller reads a customer's balance aloud to a relative who claims to be "collecting for her"; at a clinic in Bulawayo a receptionist leaves the appointment book open on the counter with patients' conditions visible; at a Harare car dealership a salesman keeps 300 customers' ID photos on his personal phone. None of these needed a hacker. Each is a breach of section 18 and, in the first two cases, of the written-consent rule for sensitive data. Each is prevented by a one-hour session and a poster behind the counter.
In practice
Cover what personal information is, the five things staff must never do (share on personal WhatsApp, leave documents visible, photograph IDs on personal phones, give out information by phone without verification, write passwords down), how to recognise phishing, how to escalate a suspected breach to the DPO immediately (the 24-hour clock), and how to handle a customer's request to see or delete their data. Finish with a five-question quiz and a signed register.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.