
The Cyber and Data Protection Act : Implications for Journalists, Human-Rights Defenders, NGOs and Others (Part 1)
Summary
- Zimbabwe's Cyber and Data Protection Act, enacted in 2021, broadly defines data processing and applies to any organization holding electronic information.
- The Act designates POTRAZ as the data protection authority, granting it powers including mandatory licensing for digital personal information and inspection of security measures.
- Compliance with the Act is particularly onerous for organizations handling personal data, such as NGOs and civil society groups.
- Provisions within the Act and new computer crimes it introduced are seen to have a chilling effect on freedoms of expression and association, especially for journalists and human rights defenders.
- POTRAZ's board members are appointed by the President, raising questions about its independence despite statutory claims of autonomy.
Overview of the Act and its Broad Scope
The Act's broad definitions and the new computer crimes it introduced into the Criminal Law Code are seen as having a potentially “chilling effect” on these fundamental rights.
The Zimbabwe Cyber and Data Protection Act, enacted in 2021, established a framework intended to bolster cybersecurity and foster confidence in the use of information and communication technologies. Its primary aim, as outlined in Section 2, is to safeguard the security of data, which the legislation broadly defines as electronic information stored within computer systems and databases. This protection extends to all electronic data, with specific provisions for personal information pertaining to identifiable individuals. The Act also introduced amendments to the Criminal Law Code, creating new offenses designed to combat the misuse of computers and the data they contain.
While the Act’s objective of protecting vast amounts of sensitive personal information held digitally in Zimbabwe is commendable, its implementation has drawn criticism. The legislation, along with its accompanying regulations, is characterized by broad and often vague language, as noted in Bill Watch 40 of 2024, leading to concerns that it overreaches in its pursuit of cybersecurity. The scope of the Cyber and Data Protection Act Zimbabwe is exceptionally wide, applying under Section 4 to “the processing and storage of data wholly or partly by automated means.”
The definition of “processing” in Section 3 further expands this reach, encompassing “any operation or set of operations which are performed upon data, whether or not by automatic means, such as … holding the data.” This expansive definition means that any organization maintaining data on its computer system is considered to be “processing” that data, thereby obligating it to comply with the Act's provisions. For entities handling personal information, such as customer or member names and addresses, achieving Zimbabwe data privacy law compliance becomes a particularly onerous undertaking. These broad stipulations, coupled with new computer crimes, raise significant concerns about potential chilling effects on fundamental freedoms, particularly for journalists, human rights defenders, and non-governmental organizations.
The Role and Powers of POTRAZ
Central to the enforcement of the Cyber and Data Protection Act is the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), designated as the national data protection authority under Section 5. This designation grants POTRAZ significant powers, including the authority to “promote and enforce fair processing of data” and to generally oversee the Act's administration and enforcement. Among its more impactful capabilities, POTRAZ is empowered to mandate licensing for all entities that hold or process personal information digitally.
This mandatory licensing requirement is detailed in the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024, as referenced in Bill Watch 40 of 2024. Furthermore, Section 21(3) of the Act grants POTRAZ a concerning power: the ability to inspect an organization’s security measures if it determines that the processing of personal data “will entail specific risks” to the privacy rights of individuals involved. This provision has direct implications for Zimbabwe NGOs data processing risks, as it permits POTRAZ to examine sensitive personal data, such as membership lists maintained by civil society organizations.
While Section 6(2) of the Act asserts that POTRAZ operates free from external direction or control in its data protection functions, the composition of its board raises questions about true independence. All members of the POTRAZ board are appointed by the President following consultation with the responsible Minister, as stipulated in Section 6 of the Postal and Telecommunications Act. This appointment structure introduces a potential for influence, which could impact the impartial exercise of POTRAZ data protection authority powers, especially when dealing with organizations critical of the government.
Implications for Civil Society and Freedoms
The expansive reach and stringent requirements of the Zimbabwe Cyber and Data Protection Act carry profound implications for civil society, particularly regarding the freedoms of expression and association. The Act's broad definitions and the new computer crimes it introduced into the Criminal Law Code are seen as having a potentially “chilling effect” on these fundamental rights. This impact is especially acute for journalists, human rights defenders, and non-governmental organizations (NGOs), whose work often involves collecting, processing, and disseminating sensitive information.
Journalists, who are crucial in defending rights by exposing abuses, amplifying community voices, and holding power accountable, are identified as particularly vulnerable to these provisions. The requirement for mandatory licensing by POTRAZ, coupled with the authority's power to inspect data for “specific risks,” creates an environment where organizations might self-censor or limit their data collection activities to avoid scrutiny. The potential for inspection of sensitive records, such as NGO membership lists, under the guise of data protection, could undermine the privacy and security of individuals associated with these groups.
Ultimately, the Cyber and Data Protection Act implications extend beyond mere compliance burdens, posing a significant challenge to the operational capacity of civil society. The legislation's framework, despite its stated aim of enhancing cybersecurity, risks curtailing the ability of these vital actors to handle sensitive information necessary for their work, thereby potentially stifling dissent and oversight in Zimbabwe. Lawyers and compliance officers must therefore carefully advise clients on navigating these complex requirements and assessing the full scope of Zimbabwe data privacy law compliance.
Practical Implications
Lawyers and compliance officers must advise clients, particularly NGOs, journalists, and human rights defenders, on the broad scope and onerous compliance requirements of Zimbabwe's Cyber and Data Protection Act, including mandatory licensing by POTRAZ and potential inspection risks. They should assess client data processing activities for compliance exposure and the Act's chilling effect on freedoms of expression and association.
Source
How does this affect your business?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Wansom is AI and can make mistakes.