StoneGuard › Churches and ministries

Data protection for churches and ministries in Zimbabwe

A church or ministry in Zimbabwe is a data controller and must license with POTRAZ. A membership register reveals religious belief, which the Cyber and Data Protection Act [Chapter 12:07] treats as sensitive information, so a congregation carries the stronger obligations, needs a Data Protection Officer and must handle member data lawfully.

Last reviewed 2 September 2026.

Why a congregation is a data controller

Churches rarely think of themselves as data holders, but a congregation of any size is running several registers at once, usually across paper, spreadsheets and a handful of phones.

The legal position follows the same test as everyone else. The body that decides what to record about members, and what happens to it, is the controller. Where a denomination and a local assembly are separate legal entities, each licenses in its own registered name.

Membership itself is sensitive data

Section 11 of the Cyber and Data Protection Act [Chapter 12:07] deals with sensitive information, and religious belief sits inside that category. This has a consequence churches often miss: the sensitivity is not only in the counselling notes, it is in the membership list itself. The fact that a named person belongs to your congregation reveals their religious belief.

That is why a leaked membership spreadsheet is a more serious matter for a church than a leaked customer list is for a shop, and why access to the register should be narrower than most churches currently allow.

Contravening section 11 is one of the five sections named in section 33(2) of the Act, carrying a fine of up to level 11 or imprisonment of up to seven years or both.

Children’s ministry carries its own rules

Sunday school, youth ministry and any children’s programme brings section 10(5) of Statutory Instrument 155 of 2024 into play in full.

A church needs a Data Protection Officer

Because a church processes sensitive data as a matter of course, the officer requirement applies even at Tier 1. The appointment is notified to the Authority on Form DP2 under section 12, within ninety days, and changes to the officer’s details or their departure must be notified within fourteen days.

Section 13 requires the officer to hold a relevant qualification and to have completed a certification course approved by the Authority, and section 10(1) requires the church to fund continuing professional development to maintain that certification. Very few congregations have someone internally who meets that description and can be released for it, which is why an outsourced officer is the usual answer.

Failing to appoint an officer is an offence under section 12(6), carrying a fine of up to level 7 or imprisonment of up to two years or both.

Pastoral and counselling records

Counselling notes are the highest risk records a church holds and usually the least protected. They frequently contain health information, details of family breakdown, financial difficulty and matters disclosed in confidence, about people who did not expect a file to exist at all.

Confidentiality in a pastoral sense and confidentiality in a legal sense are not the same thing, and the law does not read a pastoral convention as a substitute for controls.

Which tier a church falls into

The count that sets your tier is data subjects, meaning people, not employees and not customers alone. It includes current and former staff, seasonal and casual workers, customers, enquirers who never bought, suppliers and their contact people, and anyone on a mailing list. Most organisations that assume they are small find they cross a tier boundary once the count is done properly, which is one of the things the consultation settles before anything is filed.

For a church the count includes members, regular attendees on the database, children in the children’s ministry, staff, and people whose records are still held after they left. Large assemblies and denominations with a central database will be well into Tier 2 or beyond.

Bands are the licence categories in section 6 of SI 155 of 2024. Fees are payable to POTRAZ at cost, ex VAT. POTRAZ adds VAT on its own invoice.
Licence tierData subjects (SI 155 s6)Licence fee (ex VAT)Application fee
Tier 1Minimum 50, maximum 1,000$50Not applicable
Tier 21,001 to 100,000$300$30
Tier 3100,001 to 500,000$500$30
Tier 4More than 500,000$2,500$30

Where churches most often come up short

How StoneGuard gets it done

POTRAZ fees are paid to POTRAZ at cost, ex VAT, and are separate from the StoneGuard service fee. You will always see two numbers, never one blended figure.

Frequently asked questions

Do churches in Zimbabwe need to register with POTRAZ?

Yes. A church determines the purposes and means of processing personal data about its members, which is the test in section 4(1) of Statutory Instrument 155 of 2024. Section 8 exempts only personal, family or household affairs, law enforcement, and journalistic, historical or archival purposes. There is no religious or charitable exemption from licensing.

Is a church’s membership list sensitive data?

Yes. Religious belief falls within the sensitive information category dealt with in section 11 of the Cyber and Data Protection Act [Chapter 12:07], and a membership register reveals the religious belief of everyone on it. That means the list itself carries the stronger obligations, not only the counselling files.

Does a church need a Data Protection Officer?

Yes. Because a church processes sensitive data as a matter of course, the officer requirement applies even at Tier 1. The appointment is notified to POTRAZ on Form DP2 under section 12 of Statutory Instrument 155 of 2024, and failing to appoint one is an offence under section 12(6) carrying a fine of up to level 7 or imprisonment of up to two years.

Which POTRAZ tier is a church?

It is set by the number of data subjects: members, regular attendees on the database, children in the children’s ministry, staff, and former members whose records are still held. Tier 1 covers 50 to 1,000 at $50 ex VAT with no application fee, and Tier 2 covers 1,001 to 100,000 at $300 ex VAT plus the $30 application fee.

Can we photograph or livestream our services?

With care and with consent, particularly where children are identifiable. Section 10(5) of SI 155 requires parental or guardian consent for processing children’s information and reasonable efforts to verify it. For adults, the practical approach is clear signage, a camera free area for those who prefer not to appear, and a recorded consent for anything that identifies an individual in promotional material.

Can we keep pastoral counselling notes?

Yes, but they should be proportionate, stored separately from the membership database, restricted to named individuals rather than an open pastoral group, held to a defined retention period, and known to the person they concern, who is entitled to request access to their own data.

We are a small assembly with under a hundred members. Does this still apply?

Size sets your tier and therefore your fee, not whether the duty applies. The tier categories in section 6 formally begin at 50 data subjects, and the duty to apply in sections 3 and 4 carries no size floor. Once members, children, staff and former members are counted, most assemblies are comfortably above 50.

Get licensed and inspection ready

A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.

Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.