🏫 Data Protection for

Schools & ECD Centres

Learner records, health data, family circumstances and digital platforms all create compliance obligations under Zimbabwe's Cyber and Data Protection Act. Most schools have not yet assessed their exposure.

Why It Matters

Why Compliance Matters for Schools

Schools collect extensive personal information about learners — names, dates of birth, academic records, health conditions, family circumstances and sometimes biometric data for access control. Under the Cyber and Data Protection Act [Chapter 12:07], schools are data controllers and must ensure that this information is collected with a lawful basis, stored securely and not shared beyond what is necessary.

SI 156 of 2024 — the Children's Online Protection Regulations — creates specific obligations for schools whose online platforms or digital tools may be accessed by learners under 18. This adds a compliance layer that most schools are not yet aware of.

Regulatory scrutiny of educational institutions is increasing as Zimbabwe's data protection framework matures. An early compliance posture protects the school, its staff and the children in its care.

Zimbabwe Compliance Framework

  • CDPA [Chapter 12:07] — Zimbabwe's primary data protection legislation governing all personal data processing.
  • SI 155 of 2024 — Data Controller Registration Regulations establishing POTRAZ registration tiers.
  • SI 156 of 2024 — Children's Online Protection Regulations for digital services accessed by under-18s.

Non-compliance carries financial penalties and reputational damage. Early action costs far less than remediation.

Compliance Requirements

Key Compliance Obligations for Schools

📋

POTRAZ Registration

Schools processing personal data at scale must register as data controllers with POTRAZ under SI 155 of 2024. The applicable tier depends on the volume and sensitivity of data processed.

🔒

Children's Online Protection

Any digital platform, portal or communication tool used by learners under 18 must comply with SI 156 of 2024, including age verification and verifiable parental consent mechanisms.

👥

Privacy Notice for Parents and Learners

Schools must provide clear, accessible information explaining what data is collected, why it is collected, who it is shared with and how long it is retained.

📧

Staff and Teacher Data

Employee records carry their own protection obligations. Access must be limited to those with a legitimate need, and records must be retained only as long as necessary.

🗂️

Third-Party Data Sharing

Schools routinely share data with government agencies, examination bodies and third-party software providers. Each sharing arrangement must be assessed and governed by appropriate agreements.

⚠️

Secure Records Management

Physical and digital records must be protected from unauthorised access. Lost or stolen devices containing learner data constitute a reportable data breach under the CDPA.

Risk Exposure

Where Schools Most Often Fall Short

1

Sharing learner records with parents, guardians or third parties without verifying entitlement

2

Using WhatsApp or personal email to transmit sensitive learner information

3

No formal process for handling subject access requests from parents

4

Third-party school management systems with no data processing agreement in place

5

Retaining learner records indefinitely after they leave the school

Every one of these risks is addressable. Datahyve's compliance assessments identify which of these apply to your organisation and provide a clear, prioritised roadmap to resolve them.

Frequently Asked Questions

Common Questions

Take the Next Step

Ready to protect your schools & ecd centres data?

Start with a free consultation. We'll review your current posture and tell you exactly where you stand — no jargon, no obligation.