Briefing · Cross-sector

Data residency: where can a Zimbabwean enterprise legally run AI?

Section 28 of the Act, the Reserve Bank's cloud paragraphs and the size of the international link all point the same way. This briefing sets out the law, the facilities that exist, a decision path drawn as a diagram, and a worked classification of a bank's data classes into hosting patterns.

“Can we use the cloud?” is the question. The answer in Zimbabwe is “which data, to which country, under which basis, and with whom informed”, and it is shorter than it sounds because the Act, the regulations and the Reserve Bank each add one clause.

The law

Section 28(1) of the Data Protection Act (Act 5 of 2021, cited in its regulations as the Cyber and Data Protection Act [Chapter 12:07]) provides that a data controller may not transfer personal information about a data subject to a third party in a foreign country unless an adequate level of protection is ensured in the recipient’s country or organisation, and the data is transferred solely to allow tasks within the controller’s competence to be carried out. Section 28(2) says adequacy is assessed “in the light of all the circumstances”, with particular regard to the nature of the data, the purpose and duration of processing, the recipient country, its data protection law, and the professional rules and security measures complied with there. Section 28(3) lets the Authority lay down categories of processing for which transfer is not authorised.

Section 29 lists when a transfer to a country without adequate protection may still take place: unambiguous consent; necessity for a contract with the data subject or for pre-contractual measures at their request; necessity for a contract in the data subject’s interest with a third party; important public interest or legal claims; vital interests; and transfers from public registers.

SI 155 s.10(2)(c) requires a licensed data controller to notify the Authority of “any intention to transfer or share information of data subject outside Zimbabwe”. Sensitive data (s.11) and genetic, biometric and health data (s.12) need written consent to be processed at all, wherever the processing happens.

For banking institutions the Reserve Bank’s guideline adds: inform the Reserve Bank about outsourcing of critical functions to cloud service providers early in the decision process (5.12); assess jurisdictional risks, compliance obligations and data segregation under the shared responsibility model; ensure the agreement includes explicit provisions for compliance with data protection legislation covering storage, processing and transmission of personal data; and reference international standards to validate the provider’s security posture (5.13). Groups with foreign parents must run cross-border data flow risk assessments regularly (5.4(e)). Prior written approval is required before implementing a new technology platform (6.4).

The Act does not define which countries are adequate, and as at September 2026 we have not located a published adequacy list from the Authority. In practice that means each transfer needs its own s.28(2) assessment on the record, or a s.29 basis, and a notification.

The facilities

In-country: TelOne’s Mazowe Data Centre near Harare is marketed as a Tier III design with redundant power and cooling, and TelOne sells colocation and cloud services from it; Dandemutande operates data centres in Harare and Bulawayo and has announced a planned US$15 million carrier-neutral facility under the ITU Partner2Connect programme. Enterprises with a modern server room can host on their own premises.

Regional: AWS’s Africa (Cape Town) region, af-south-1, has three availability zones; Microsoft Azure has South Africa North (Johannesburg) and South Africa West (Cape Town); Google Cloud’s africa-south1 region in Johannesburg opened in 2024. All three are foreign countries for the purposes of s.28.

The link between them: Zimbabwe’s used incoming international internet bandwidth was 545,123 Mbps in Q3 2025 against 1,456,270 Mbps equipped, and used outgoing capacity was 202,485 Mbps. The link is shared by the whole economy; a hosted-model architecture makes every prompt depend on it. Power: ZESA reported 138 consecutive days without load shedding in May 2026 and a target of ending it by December 2026; regional cloud removes the power dependence for the service but not for the people using it.

The decision path

Hosting decision path for a Zimbabwean enterpriseStart by classifying the workload's data. If it contains sensitive, biometric, genetic or health data, obtain written consent and host in Zimbabwe. If it contains other personal data, host in Zimbabwe by default; a regional or global location requires an adequacy assessment or a section 29 basis, notification to the Authority, and for banks early notice to the Reserve Bank. If it is operational data needed on site, run it at the edge. If it is non-personal, choose the best quality within a foreign-currency budget, through the gateway. Classify the dataat ingestion, per workload Sensitive · biometric· genetic · health (s.11–12) Other personal datanames, accounts, IDs, locations Operational, needed on siteplant, cameras, branch systems Non-personalpublic, synthetic, redacted Written consent first; host in Zimbabweon-prem or colocation; notify biometric processing (SI 155 s.10(2)(d)) Zimbabwe by defaultRegional/global only with s.28(2) assessment or s.29 basis,SI 155 s.10(2)(c) notification; banks: RBZ 5.12 early notice Edge inference on sitesurvives link and grid failure; analysis later in-country Best quality within a forex budgethosted frontier models through the gateway; budget per identity One workload may contain several classes; the strictest class sets the hosting pattern unless the classes are separated at the gateway.
Figure 6. Hosting decision path. The strictest data class in a workload sets its hosting pattern; the gateway can separate classes so the rest of the workload is not dragged in-country unnecessarily.

A worked classification

Take a mid-sized bank’s AI programme and classify its workloads. The table is a worked example; the classes and consequences are real, the bank is not.

WorkloadData classes presentStrictest classHosting patternWhat must be on file
Internal knowledge assistant over policies and proceduresCommercial-confidential; staff names in documentsPersonal (low)In-country (colocation); could be regional with assessmentClassification note; RBZ 6.4 approval for the platform
Contact-centre assistant over customer recordsPersonal; possibly sensitive in complaintsPersonalIn-country onlyTier 4 licence; processing notification; access-control design
Claims or KYC document extractionPersonal; identity documents; possibly healthSensitive/healthIn-country only, written consents.11–12 consent records; DPIA
Marketing copy and non-customer researchPublicNon-personalHosted frontier model via gatewayBudget; redaction rule at the gateway
Transaction anomaly scoringPersonal financialPersonalIn-countryModel register entry; s.25 decision design
Disaster recovery for the in-country platformEverything above, encrypted at restPersonalRegional cloud only with a s.28(2) assessment, encryption with keys held in Zimbabwe, notification and RBZ early noticeAdequacy memo; key-management design; contract clauses (RBZ 5.13)

The result is the two-pattern architecture described on the model strategy page: an in-country platform for four of six workloads, a hosted model for one, and a carefully papered regional footprint for disaster recovery. Nothing in the table required a lawyer to invent a position; every row follows from a section and a paragraph already published.

What to write down

For every transfer you decide to make: the s.28(2) assessment (nature of data, purpose, duration, recipient country, its law, the security measures), the s.29 basis if adequacy cannot be shown, the SI 155 s.10(2)(c) notification, the processor contract under s.18(8), and, for banks, the correspondence with the Reserve Bank. Keep it with the model register entry so that the DPO, the CISO and the model owner are looking at the same file when the Authority asks.

Sources

  1. Data Protection Act, Act 5 of 2021 (Cyber and Data Protection Act [Chapter 12:07]) — s.11–12, s.18, s.28–29 — https://t3n9sm.c2.acecdn.net/wp-content/uploads/2024/11/Data-Protection-Act-5-of-2021.pdf
  2. Statutory Instrument 155 of 2024 — s.10(2)(c) — https://www.potraz.gov.zw/wp-content/uploads/2025/02/sI-155-of-2024-Cyber-and-Data-Protection-Normal_240913_1250178.pdf
  3. RBZ Cybersecurity and Resilience Guideline (August 2025) — paras 5.4, 5.12–5.13, 6.4 — https://www.rbz.co.zw/documents/Regulations_Acts/2025/Cybersecurity_and_Resilience_Guideline_-_August_2025.pdf
  4. Techzim (19 December 2025) — POTRAZ Q3 2025: international bandwidth — https://www.techzim.co.zw/2025/12/potraz-3rd-quarter-sector-performance-report-2025/
  5. Data Center Map — TelOne Mazowe Data Centre — https://www.datacentermap.com/zimbabwe/harare/mazowe-data-centre/
  6. TelOne — Data Centre and Cloud Services — https://www.telone.co.zw/products/details/data-centre-cloud-services
  7. DCD — Dandemutande plans US$15m data centre — https://www.datacenterdynamics.com/en/news/zimbabwean-it-provider-dandemutande-plans-15m-data-center/
  8. AWS — Africa (Cape Town) region now open — https://aws.amazon.com/blogs/aws/now-open-aws-africa-cape-town-region
  9. CIO — Azure South Africa North (Johannesburg) and West (Cape Town) — https://www.cio.com/article/193405/heres-how-amazons-south-africa-data-centres-will-impact-enterprises.html
  10. Northflank — Google Cloud africa-south1 (Johannesburg) — https://northflank.com/cloud/gcp/regions/africa-south1
  11. New Zimbabwe via allAfrica (11 May 2026) — ZESA load shedding statement — https://allafrica.com/stories/202605110146.html