Who must comply

Is keeping customer numbers on WhatsApp "processing personal data" under Zimbabwe's CDPA?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes. Saving a customer's number, sending a WhatsApp broadcast or keeping order history in a chat is "processing" personal information under Zimbabwe's Cyber and Data Protection Act. The law regulates what you do with people's information, not the tool you use to do it.

What the law says

"Processing" in section 3 of the Act covers any operation on personal information, including collection, recording, storage, use, disclosure and erasure. Section 15 requires you to inform people, when you collect their data, of your identity, the purpose and their right to object, "by request and free of charge", to processing for direct marketing. Section 18 requires appropriate security measures, and a lost or stolen phone holding customer data is a breach reportable to POTRAZ within 24 hours under section 19.

Example

A boutique in Bulawayo's city centre has three sales assistants, each using a personal phone to chat with customers and send photos of new stock to a broadcast list of 600 people. One assistant resigns and joins a competitor, taking the list with her. Another loses her phone in a kombi. The boutique has suffered two breaches, has no way of honouring an opt-out request, and cannot answer a customer who asks what data it holds on her.

In practice

Use a WhatsApp Business account on a company-owned number, keep the master customer list in your own system, tell customers in your profile and first message why you hold their number and how to opt out, and set a rule that customer data never sits on personal accounts. This is one of the most common findings small businesses will face in POTRAZ inspections.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.