AI agents and Zimbabwe's Cyber and Data Protection Act
The Act does not mention agents, but it decides how much autonomy you can give one. Every obligation, mapped to a design decision in the orchestrator, the tools or the audit log.
The Cyber and Data Protection Act [Chapter 12:07] was written before “agent” meant software that books appointments. It still governs every agent that reads a phone number, a name or a transcript — which is every customer-facing agent. This article maps the obligations to design decisions. It is general information from the cited sources, not legal advice; the Act and SI 155 of 2024 are linked below so you can read the text.
The single most important fact
You are the data controller. Deploying an agent — built in-house, by a vendor, or on a platform — does not move responsibility for your customers’ personal data. The vendor may be a processor; the model provider is a processor; Meta is a processor for WhatsApp. The duties below are yours.
Obligations, mapped to design
| Obligation (source) | What it says | What it means for the agent |
|---|---|---|
| Licence (SI 155 of 2024) | Every data controller must be licensed by POTRAZ; the deadline for existing controllers was 12 March 2025; licences run 12 months and renewal is due three months before expiry. Processing without a licence after the deadline is an offence: fine up to level 11 (US$1,000) or up to seven years’ imprisonment, or both. | The licence is a project prerequisite. The application asks where data is stored — see data location below. |
| Data Protection Officer (SI 155) | Designate a DPO within 90 days, with expertise and certification requirements. | The DPO owns the agent’s data map: what it reads, writes, stores, and for how long. Name them in the runbook. |
| Breach notification (Act, regulations) | Report to POTRAZ within 24 hours of discovery; if the breach is likely to pose a high risk to individuals, notify them within 72 hours. | The trace store and audit log must let you answer “what did the agent read and send, to whom” within hours. Retention, access control and an incident runbook are agent features. |
| Automated decision-making | Decisions affecting individuals’ rights taken by automated processing require the data subject’s consent or legal authorisation. | The ceiling on autonomy. Booking and reminding are fine; credit holds, suspensions, hiring screens and claims outcomes keep a person on the decision — “act with confirmation” or “assist”, never “act”. |
| Children’s data | Parental consent is mandatory when processing children’s data. | School-fee, tutoring and paediatric agents verify the adult and obtain consent before storing anything about the child. |
| Data location | The licence application requires stating whether data is stored in Zimbabwe or another country. | Hosted models, WhatsApp and most CRMs are foreign processing. State it on the form; document the safeguards (encryption, contracts, retention). Do not pretend otherwise. |
| Accountability and security (Act) | Controllers must implement appropriate technical and organisational measures. | Least-privilege tools, confirmation gates, idempotent writes, audit logs, evaluation — the governance controls are also your accountability evidence. |
Three design decisions the Act settles for you
1. Autonomy level
The automated-decision rule is why the agent types on this site cluster at “act with confirmation”. An agent may gather, check, propose and remind. Where its output would be a decision with legal or similarly significant effect on a person, a human takes the decision and the log records who. This is not a limitation to work around; it is the design.
2. What the agent may remember
Long-term memory is a database of personal data. Every field the agent stores needs a purpose and a retention period, and the DPO needs the list. A booking agent stores name, number, appointment history; it does not store the free-text messages beyond the retention window, and it does not store anything clinical a patient volunteers — the transcript is redacted at the scope guardrail before storage where possible.
3. Where the trace lives
The trace is both your best debugging tool and a store of personal data. Keep it, because the 24-hour breach clock is unmeetable without it; protect it, because it is exactly what a breach would expose. Access by role, encryption at rest, a retention job that actually runs.
Foreign processing, honestly
Almost every Zimbabwean agent sends personal data abroad: to the model provider’s servers, to Meta for WhatsApp, to a CRM’s cloud. The Act’s licensing form asks about this directly. The practical answer is transparency and safeguards rather than avoidance: name the processors, hold contracts with them, minimise what is sent (the model does not need the patient’s full record to offer a slot), and prefer providers with documented retention and deletion terms. Self-hosting a model inside Zimbabwe is possible for organisations with a hard residency mandate and a budget for it; for most, it is not the proportionate control.
Where policy is heading
The National Artificial Intelligence Strategy 2026–2030, led by the Ministry of ICT, Postal and Courier Services, lists governance, ethics and regulatory framework among its six pillars and commits to human dignity, privacy, transparency, inclusivity, safety and accountability. None of that is yet a rule for a private agent deployment. Two expectations are cheap to meet now and likely to become requirements: tell people they are talking to an automated assistant and offer a person; and name a human owner accountable for what the agent does. Both are in the pre-launch checklist.
A compliance card for an agent project
- POTRAZ licence current; renewal date in the calendar.
- DPO named; agent data map signed off.
- Purpose and retention period for every stored field.
- Processors listed with contracts: model provider, Meta/BSP, CRM, hosting.
- Data-location statement on the licence matches reality.
- Autonomy level set below the automated-decision line for consequential outcomes.
- Consent flows for children’s data where relevant.
- Trace and audit log: access by role, encrypted, retention job tested.
- Breach runbook rehearsed against the 24 h / 72 h clocks.
- Disclosure text live: “You are chatting with an automated assistant; reply HUMAN to reach a person.”
Ten lines, none of which the model can do for you. That is the point: the Act regulates the organisation, and the agent inherits the organisation’s discipline — or its absence.
Sources
- SI 155 of 2024 — Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (Veritas PDF) — https://www.veritaszim.net/sites/veritas_d/files/SI%202024-155%20Cyber%20and%20Data%20Protection%20(Licensing%20of%20Data%20Controllers%20and%20Appointment%20of%20Data%20Protection%20Officers)%20Regulations,%202024.pdf
- Afriwise — Understanding SI 155 of 2024 (deadline, licence term, penalties) — https://www.afriwise.com/blog/understanding-si-155-of-2024-new-regulations-on-data-protection-licensing-and-data-protection-officers-in-zimbabwe
- DLA Piper Africa / Manokore Attorneys — A quick-start guide to Zimbabwe's data protection regulations — https://www.dlapiperafrica.com/en/zimbabwe/insights/2024/A-Quick-Start-Guide-to-Zimbabwes-Data-Protection-Regulations
- MISA Zimbabwe — Navigating the Data Protection Act requirements for data controllers — https://zimbabwe.misa.org/2025/03/14/navigating-the-data-protection-act-requirements-ensuring-compliance-for-zimbabwean-data-controllers/
- OECD.AI — Zimbabwe National Artificial Intelligence Strategy 2026–2030 — https://oecd.ai/en/dashboards/policy-initiatives/zimbabwe-national-artificial-intelligence-strategy-2026-2030
- Meta — WhatsApp Business Platform pricing and windows (foreign processing context) — https://developers.facebook.com/documentation/business-messaging/whatsapp/pricing
All sources accessed 2026-09-14 unless stated. Figures marked illustrative are worked examples, not measurements.