StoneGuard › Penalties
Processing personal data without a POTRAZ data controller licence is an offence under section 3(3) of Statutory Instrument 155 of 2024, carrying a fine of up to level 11 or up to seven years imprisonment or both. Failing to appoint a Data Protection Officer carries up to level 7 or two years. The controller remains liable for fines incurred by its agents.
Last reviewed 2 September 2026.
Exposure under Zimbabwean data protection law comes from two places, and organisations tend to look at only one of them.
Statutory Instrument 155 of 2024 creates the licensing offences: not having a licence, not renewing it, lying on the application, not appointing an officer, and breaching the controller obligations in its section 10.
The Cyber and Data Protection Act [Chapter 12:07] creates the substantive data protection offences: mishandling sensitive information, failing the duties of a data controller, failing to secure the data, failing on accountability, and transferring personal information outside Zimbabwe unlawfully.
An organisation can hold a valid licence and still be committing offences under the Act. The licence is the entry ticket, not the compliance.
| Section | Conduct | Maximum penalty |
|---|---|---|
| 3(3) | Processing personal information without a data controller licence within the stipulated time frames | Level 11 or 7 years or both |
| 4(6) | Continuing to process data without a licence after the transition period in section 4(5) | Level 11 or 7 years or both |
| 5(3) | Failing without just cause to renew the licence by the date the previous one expires | Level 11 or 7 years or both |
| 7 | Submitting false information to the Authority in the process of applying for a licence | Level 11 or 7 years or both |
| 10(6) | Contravening the controller obligations in section 10, including the children’s data rules | Level 11 or 7 years or both |
| 11(4) | Providing DPO certification training without being accredited by the Authority | Level 11 or 7 years or both |
| 12(6) | Failing to appoint a Data Protection Officer | Level 7 or 2 years or both |
Section 33(2) of the Cyber and Data Protection Act [Chapter 12:07] is the provision that matters to controllers. It makes it an offence for a data controller, or their representative, agent or assignee, to contravene any of five named sections, with a maximum of a fine at level 11 or imprisonment of up to seven years or both.
| Section contravened | What it covers |
|---|---|
| Section 11 | Sensitive information, meaning the categories that carry stronger protection |
| Section 13 | The duties of a data controller |
| Section 18(4) | Taking the appropriate technical and organisational measures to protect data from negligent or unauthorised destruction, negligent loss, unauthorised alteration or access, and any other unauthorised processing |
| Section 24 | Accountability, meaning taking all necessary measures to comply and having internal mechanisms to demonstrate that compliance to data subjects and to the Authority |
| Section 28 | Transfer of personal information outside Zimbabwe |
Section 24 deserves a second look, because it is the one that turns an absence of paperwork into an offence. Accountability requires not only that you comply, but that you have the internal mechanisms in place to demonstrate compliance to the Authority. An organisation that is doing the right things but cannot evidence them is exposed under this section.
This is where a lot of published commentary quietly invents numbers, so it is worth being exact about what the law does and does not say.
The instruments express fines as a level on the standard scale rather than as an amount of money. The level is fixed in the law, but the value of each level is set by the standard scale and is revised from time to time, so the sensible thing is to confirm the current value rather than to rely on a figure quoted on a website. What is fixed, and what matters for planning, is the seriousness: these are criminal offences carrying prison terms, not administrative charges.
We are not going to put a dollar figure on a level here, because the instruments do not contain one and a figure copied from an out of date source is worse than no figure. If you need the current value of a level for a board paper, that is a question for your legal adviser against the standard scale as it stands on the day.
Fines and imprisonment are the headline, but section 33 of the Act carries three further consequences that tend to matter more to a working business.
Section 34 of the Act provides that any person aggrieved by a decision of the Authority may appeal to the Administrative Court, so there is a route of challenge, but it runs after the decision rather than instead of it.
Section 19 of the Cyber and Data Protection Act [Chapter 12:07] is one sentence long and it is the single hardest deadline in the whole regime. The data controller shall notify the Authority within twenty four hours of any security breach affecting data he or she processes.
Twenty four hours is not long enough to work out what your notification process is. The organisations that meet it are the ones that decided in advance who declares a breach, who drafts the notification, who signs it and where Form DP3 in the Fourth Schedule of SI 155 lives.
This is a large part of what an outsourced Data Protection Officer is actually for. A breach discovered at five on a Friday afternoon does not pause until Monday.
None of the above is a reason to panic, and it is not a reason to buy a policy template. The offences cluster around a small number of concrete things, and each of them is a document or an appointment.
Your compliance is run by a certified DPO who goes on record for your organisation, not by a template pack you are left to fill in yourself. A $90 consultation establishes where you actually stand against each of the sections above, and is credited in full toward your package when you proceed.
Processing personal information without a data controller licence is a criminal offence under section 3(3) of Statutory Instrument 155 of 2024, and continuing to process without one after the transition period is a further offence under section 4(6). Each carries a fine of up to level 11 or imprisonment of up to seven years or both. The register of licensed controllers is public under section 9, so the position is visible.
The maximum is a fine at level 11 on the standard scale, or imprisonment for up to seven years, or both. The regulation fixes the level rather than an amount of money, and the value of a level is set by the standard scale and revised from time to time.
The instruments do not state a monetary amount. They set the level, and the standard scale sets what a level is worth at any given time. Anyone quoting you a precise dollar figure for a level 11 fine is quoting a value that may already have changed, so confirm the current standard scale rather than relying on a published figure.
Yes. The licensing offences under SI 155 carry imprisonment of up to seven years, and section 33(2) of the Act carries the same maximum for a controller who contravenes sections 11, 13, 18(4), 24 or 28. Failing to appoint a Data Protection Officer carries up to two years under section 12(6).
Yes, under section 12(6) of SI 155 of 2024, carrying a fine of up to level 7 or imprisonment of up to two years or both. That is a lower maximum than the licensing offences, but an organisation with no officer usually also lacks the registers, procedures and training that the heavier offences are concerned with.
The controller carries it. Section 33(6) of the Act makes the controller or their representative liable for the payment of fines incurred by their agent or assignee, and section 10(4)(a) of SI 155 makes the controller accountable for a representative, agent, assignee, data processor, recipient or data protection officer who contravenes. Section 10(4)(f) separately requires a written agreement with every processor, which is how responsibilities get allocated between you in practice.
Twenty four hours. Section 19 of the Cyber and Data Protection Act [Chapter 12:07] requires the data controller to notify the Authority within twenty four hours of any security breach affecting data it processes. The notification form is Form DP3, in the Fourth Schedule of Statutory Instrument 155 of 2024.
Yes. Section 34 of the Act provides that any person aggrieved by a decision of the Authority may appeal to the Administrative Court.
A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.
Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.