Learner records, health data, family circumstances and digital platforms all create compliance obligations under Zimbabwe's Cyber and Data Protection Act. Most schools have not yet assessed their exposure.
Why It Matters
Schools collect extensive personal information about learners — names, dates of birth, academic records, health conditions, family circumstances and sometimes biometric data for access control. Under the Cyber and Data Protection Act [Chapter 12:07], schools are data controllers and must ensure that this information is collected with a lawful basis, stored securely and not shared beyond what is necessary.
SI 156 of 2024 — the Children's Online Protection Regulations — creates specific obligations for schools whose online platforms or digital tools may be accessed by learners under 18. This adds a compliance layer that most schools are not yet aware of.
Regulatory scrutiny of educational institutions is increasing as Zimbabwe's data protection framework matures. An early compliance posture protects the school, its staff and the children in its care.
Zimbabwe Compliance Framework
Non-compliance carries financial penalties and reputational damage. Early action costs far less than remediation.
Compliance Requirements
Schools processing personal data at scale must register as data controllers with POTRAZ under SI 155 of 2024. The applicable tier depends on the volume and sensitivity of data processed.
Any digital platform, portal or communication tool used by learners under 18 must comply with SI 156 of 2024, including age verification and verifiable parental consent mechanisms.
Schools must provide clear, accessible information explaining what data is collected, why it is collected, who it is shared with and how long it is retained.
Employee records carry their own protection obligations. Access must be limited to those with a legitimate need, and records must be retained only as long as necessary.
Schools routinely share data with government agencies, examination bodies and third-party software providers. Each sharing arrangement must be assessed and governed by appropriate agreements.
Physical and digital records must be protected from unauthorised access. Lost or stolen devices containing learner data constitute a reportable data breach under the CDPA.
Risk Exposure
Sharing learner records with parents, guardians or third parties without verifying entitlement
Using WhatsApp or personal email to transmit sensitive learner information
No formal process for handling subject access requests from parents
Third-party school management systems with no data processing agreement in place
Retaining learner records indefinitely after they leave the school
Every one of these risks is addressable. Datahyve's compliance assessments identify which of these apply to your organisation and provide a clear, prioritised roadmap to resolve them.
Frequently Asked Questions
Take the Next Step
Start with a free consultation. We'll review your current posture and tell you exactly where you stand — no jargon, no obligation.