Subscriber databases, audience tracking, programmatic advertising and confidential source data all create obligations under the Cyber and Data Protection Act. The journalistic exemption exists, but it is narrow — and it does not cover subscriber management or advertising operations.
Why It Matters
Media organisations — broadcasters, newspapers, digital publishers and news agencies — operate at a unique intersection of data protection and press freedom. They collect personal data on subscribers, website visitors and in some cases the subjects of journalistic investigations.
The CDPA and AIPPA both apply to media companies, and their interaction requires careful navigation. Journalistic processing of personal data may be exempted from certain CDPA provisions, but this exemption has conditions and limits that most organisations have not mapped.
Advertising-funded digital media operations face particular challenges around audience data, programmatic advertising and cookie-based tracking — all of which involve personal data processing that must be disclosed and governed.
Zimbabwe Compliance Framework
Non-compliance carries financial penalties and reputational damage. Early action costs far less than remediation.
Compliance Requirements
Subscriber databases, newsletter lists and registered user data must be managed with appropriate privacy notices, verified consent mechanisms and security controls.
The CDPA includes limited exemptions for journalistic, literary and artistic purposes. Understanding the precise scope and limits of this exemption is essential to managing legal risk across editorial and commercial operations.
Data relating to confidential sources must be protected with technical and procedural measures that go beyond ordinary personal data security standards.
Digital publishers using programmatic advertising or third-party tracking must have a compliant cookie and tracking policy, and must ensure their data practices are accurately disclosed to audiences.
Data collected from freelancers, contributors and interviewees must be handled with the same governance standards as employee data, with defined access and retention controls.
Media organisations with large subscriber databases or significant online platforms are likely to meet POTRAZ registration thresholds under SI 155 of 2024.
Risk Exposure
Subscriber data shared with advertising partners without clear disclosure in the privacy policy
Interview subjects' personal information retained indefinitely in editorial archives without review
No documented process for handling subject access requests from individuals featured in articles
Freelancer and contributor payment data handled through personal rather than organisational accounts
Social media management accounts containing customer service data not covered by the organisation's data governance policies
Every one of these risks is addressable. Datahyve's compliance assessments identify which of these apply to your organisation and provide a clear, prioritised roadmap to resolve them.
Frequently Asked Questions
Take the Next Step
Start with a free consultation. We'll review your current posture and tell you exactly where you stand — no jargon, no obligation.