SI 156 of 2024 Compliance

Children's Online Protection in Zimbabwe

Statutory Instrument 156 of 2024 establishes specific protections for children's personal data online. Any organisation with an online presence that children can access must understand and comply with these obligations — regardless of whether children are your intended audience.

Why This Matters

Children's data carries the highest obligations

Children are recognised as a vulnerable category of data subject under Zimbabwe's data protection framework. They cannot be expected to fully understand what they are consenting to, what data is being collected about them, or how it might be used. The law compensates for this vulnerability by placing heightened obligations on organisations.

SI 156 of 2024 — issued under the CDPA — gives these protections specific regulatory force. Organisations that fail to comply face enforcement action not only under data protection law, but potentially under other child protection frameworks as well.

The risk is not hypothetical. Schools, health providers, sports clubs, churches, media organisations and retailers have all been caught out by obligations they did not know applied to them.

Who is affected?

Schools and ECD centres with online portals or communication platforms
Higher education institutions enrolling students under 18
Health providers offering digital patient access
Sports clubs and associations with member registration systems
Churches and faith organisations with online communities
Media and entertainment platforms accessible by children
Retailers with e-commerce sites that children can access
Any organisation with a website that has a contact form, subscription, or login
SI 156 of 2024

What SI 156 of 2024 requires

The regulation establishes several specific obligations for organisations processing children's personal data online.

Age-appropriate design

Online services likely to be accessed by children must be designed with their best interests at mind. Default settings must be set to the most privacy-protective option.

Consent requirements

Processing children's personal data for non-essential purposes requires parental or guardian consent. The consent mechanism must be genuine and verifiable — not just a tick-box.

Data minimisation

Organisations must collect only the minimum personal data necessary from children. Collection that goes beyond what is strictly needed for the service is a specific breach of SI 156.

Transparent information

Privacy information provided to children must be in plain, age-appropriate language. Complex legal notices do not satisfy the transparency obligation when the audience includes children.

Prohibition on harmful processing

Processing that is detrimental to children's wellbeing — including certain forms of profiling, behavioural advertising and location tracking — is specifically restricted or prohibited.

DPIA requirement

Any processing of children's personal data that presents a high risk must be preceded by a Data Protection Impact Assessment. This is not optional — it is a specific obligation under the framework.

Frequently asked questions

Ready to assess your SI 156 obligations?

Datahyve helps organisations across Zimbabwe understand and fulfil their obligations under SI 156 of 2024 — from initial assessment through to policy development, DPIA support and staff training.