StoneGuard › Penalties

Penalties under the Cyber and Data Protection Act and SI 155

Processing personal data without a POTRAZ data controller licence is an offence under section 3(3) of Statutory Instrument 155 of 2024, carrying a fine of up to level 11 or up to seven years imprisonment or both. Failing to appoint a Data Protection Officer carries up to level 7 or two years. The controller remains liable for fines incurred by its agents.

Last reviewed 2 September 2026.

Two instruments, two sets of offences

Exposure under Zimbabwean data protection law comes from two places, and organisations tend to look at only one of them.

Statutory Instrument 155 of 2024 creates the licensing offences: not having a licence, not renewing it, lying on the application, not appointing an officer, and breaching the controller obligations in its section 10.

The Cyber and Data Protection Act [Chapter 12:07] creates the substantive data protection offences: mishandling sensitive information, failing the duties of a data controller, failing to secure the data, failing on accountability, and transferring personal information outside Zimbabwe unlawfully.

An organisation can hold a valid licence and still be committing offences under the Act. The licence is the entry ticket, not the compliance.

Offences under SI 155 of 2024

Source: SI 155 of 2024, as published by POTRAZ.
SectionConductMaximum penalty
3(3)Processing personal information without a data controller licence within the stipulated time framesLevel 11 or 7 years or both
4(6)Continuing to process data without a licence after the transition period in section 4(5)Level 11 or 7 years or both
5(3)Failing without just cause to renew the licence by the date the previous one expiresLevel 11 or 7 years or both
7Submitting false information to the Authority in the process of applying for a licenceLevel 11 or 7 years or both
10(6)Contravening the controller obligations in section 10, including the children’s data rulesLevel 11 or 7 years or both
11(4)Providing DPO certification training without being accredited by the AuthorityLevel 11 or 7 years or both
12(6)Failing to appoint a Data Protection OfficerLevel 7 or 2 years or both

Offences under the Act (section 33)

Section 33(2) of the Cyber and Data Protection Act [Chapter 12:07] is the provision that matters to controllers. It makes it an offence for a data controller, or their representative, agent or assignee, to contravene any of five named sections, with a maximum of a fine at level 11 or imprisonment of up to seven years or both.

Source: sections 11, 13, 18(4), 24, 28 and 33(2) of the Cyber and Data Protection Act.
Section contravenedWhat it covers
Section 11Sensitive information, meaning the categories that carry stronger protection
Section 13The duties of a data controller
Section 18(4)Taking the appropriate technical and organisational measures to protect data from negligent or unauthorised destruction, negligent loss, unauthorised alteration or access, and any other unauthorised processing
Section 24Accountability, meaning taking all necessary measures to comply and having internal mechanisms to demonstrate that compliance to data subjects and to the Authority
Section 28Transfer of personal information outside Zimbabwe

Section 24 deserves a second look, because it is the one that turns an absence of paperwork into an offence. Accountability requires not only that you comply, but that you have the internal mechanisms in place to demonstrate compliance to the Authority. An organisation that is doing the right things but cannot evidence them is exposed under this section.

What a level 11 fine actually means

This is where a lot of published commentary quietly invents numbers, so it is worth being exact about what the law does and does not say.

The instruments express fines as a level on the standard scale rather than as an amount of money. The level is fixed in the law, but the value of each level is set by the standard scale and is revised from time to time, so the sensible thing is to confirm the current value rather than to rely on a figure quoted on a website. What is fixed, and what matters for planning, is the seriousness: these are criminal offences carrying prison terms, not administrative charges.

We are not going to put a dollar figure on a level here, because the instruments do not contain one and a figure copied from an out of date source is worse than no figure. If you need the current value of a level for a board paper, that is a question for your legal adviser against the standard scale as it stands on the day.

The consequences that are not fines

Fines and imprisonment are the headline, but section 33 of the Act carries three further consequences that tend to matter more to a working business.

Section 34 of the Act provides that any person aggrieved by a decision of the Authority may appeal to the Administrative Court, so there is a route of challenge, but it runs after the decision rather than instead of it.

The twenty four hour breach clock

Section 19 of the Cyber and Data Protection Act [Chapter 12:07] is one sentence long and it is the single hardest deadline in the whole regime. The data controller shall notify the Authority within twenty four hours of any security breach affecting data he or she processes.

Twenty four hours is not long enough to work out what your notification process is. The organisations that meet it are the ones that decided in advance who declares a breach, who drafts the notification, who signs it and where Form DP3 in the Fourth Schedule of SI 155 lives.

This is a large part of what an outsourced Data Protection Officer is actually for. A breach discovered at five on a Friday afternoon does not pause until Monday.

How exposure is actually reduced

None of the above is a reason to panic, and it is not a reason to buy a policy template. The offences cluster around a small number of concrete things, and each of them is a document or an appointment.

  1. Get licensed, in the right tier. Section 3(3) and 4(6) exposure ends when the licence is granted. Getting the tier right at the outset avoids the false information problem in section 7.
  2. Appoint and notify an officer. Section 12(6) exposure ends when a qualified, certified officer is appointed and notified on Form DP2, and the notification is kept current.
  3. Build the evidence, not just the practice. Section 24 of the Act asks you to demonstrate compliance. A record of processing activities, current policies, training registers and assessment reports are what demonstration looks like.
  4. Contract with your processors. Section 10(4)(f) requires a written agreement with every data processor. Most organisations have several and have papered none of them.
  5. Diarise the renewal. Section 5(2) wants the renewal at least three months before expiry, and section 5(3) makes missing it an offence.
  6. Rehearse the breach. Twenty four hours under section 19 is a process problem, not a legal one, and it is solved before the breach rather than during it.

Your compliance is run by a certified DPO who goes on record for your organisation, not by a template pack you are left to fill in yourself. A $90 consultation establishes where you actually stand against each of the sections above, and is credited in full toward your package when you proceed.

Frequently asked questions

What happens if you do not register with POTRAZ in Zimbabwe?

Processing personal information without a data controller licence is a criminal offence under section 3(3) of Statutory Instrument 155 of 2024, and continuing to process without one after the transition period is a further offence under section 4(6). Each carries a fine of up to level 11 or imprisonment of up to seven years or both. The register of licensed controllers is public under section 9, so the position is visible.

What is the fine for not having a data controller licence in Zimbabwe?

The maximum is a fine at level 11 on the standard scale, or imprisonment for up to seven years, or both. The regulation fixes the level rather than an amount of money, and the value of a level is set by the standard scale and revised from time to time.

How much is a level 11 fine in Zimbabwe?

The instruments do not state a monetary amount. They set the level, and the standard scale sets what a level is worth at any given time. Anyone quoting you a precise dollar figure for a level 11 fine is quoting a value that may already have changed, so confirm the current standard scale rather than relying on a published figure.

Can someone go to prison for a data protection offence in Zimbabwe?

Yes. The licensing offences under SI 155 carry imprisonment of up to seven years, and section 33(2) of the Act carries the same maximum for a controller who contravenes sections 11, 13, 18(4), 24 or 28. Failing to appoint a Data Protection Officer carries up to two years under section 12(6).

Is failing to appoint a Data Protection Officer an offence?

Yes, under section 12(6) of SI 155 of 2024, carrying a fine of up to level 7 or imprisonment of up to two years or both. That is a lower maximum than the licensing offences, but an organisation with no officer usually also lacks the registers, procedures and training that the heavier offences are concerned with.

If our IT provider causes a breach, are they liable or are we?

The controller carries it. Section 33(6) of the Act makes the controller or their representative liable for the payment of fines incurred by their agent or assignee, and section 10(4)(a) of SI 155 makes the controller accountable for a representative, agent, assignee, data processor, recipient or data protection officer who contravenes. Section 10(4)(f) separately requires a written agreement with every processor, which is how responsibilities get allocated between you in practice.

How long do we have to report a data breach in Zimbabwe?

Twenty four hours. Section 19 of the Cyber and Data Protection Act [Chapter 12:07] requires the data controller to notify the Authority within twenty four hours of any security breach affecting data it processes. The notification form is Form DP3, in the Fourth Schedule of Statutory Instrument 155 of 2024.

Can we appeal a decision of the Authority?

Yes. Section 34 of the Act provides that any person aggrieved by a decision of the Authority may appeal to the Administrative Court.

Get licensed and inspection ready

A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.

Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.