Statutory Instrument 156 of 2024 establishes specific protections for children's personal data online. Any organisation with an online presence that children can access must understand and comply with these obligations — regardless of whether children are your intended audience.
Children are recognised as a vulnerable category of data subject under Zimbabwe's data protection framework. They cannot be expected to fully understand what they are consenting to, what data is being collected about them, or how it might be used. The law compensates for this vulnerability by placing heightened obligations on organisations.
SI 156 of 2024 — issued under the CDPA — gives these protections specific regulatory force. Organisations that fail to comply face enforcement action not only under data protection law, but potentially under other child protection frameworks as well.
The risk is not hypothetical. Schools, health providers, sports clubs, churches, media organisations and retailers have all been caught out by obligations they did not know applied to them.
The regulation establishes several specific obligations for organisations processing children's personal data online.
Online services likely to be accessed by children must be designed with their best interests at mind. Default settings must be set to the most privacy-protective option.
Processing children's personal data for non-essential purposes requires parental or guardian consent. The consent mechanism must be genuine and verifiable — not just a tick-box.
Organisations must collect only the minimum personal data necessary from children. Collection that goes beyond what is strictly needed for the service is a specific breach of SI 156.
Privacy information provided to children must be in plain, age-appropriate language. Complex legal notices do not satisfy the transparency obligation when the audience includes children.
Processing that is detrimental to children's wellbeing — including certain forms of profiling, behavioural advertising and location tracking — is specifically restricted or prohibited.
Any processing of children's personal data that presents a high risk must be preceded by a Data Protection Impact Assessment. This is not optional — it is a specific obligation under the framework.
Expert guidance on building a CDPA-compliant data management environment.
Learn moreRequired impact assessments before deploying high-risk processing involving children.
Learn morePrivacy notices, consent mechanisms and documentation required by SI 156.
Learn moreDatahyve helps organisations across Zimbabwe understand and fulfil their obligations under SI 156 of 2024 — from initial assessment through to policy development, DPIA support and staff training.