“Can we use the cloud?” is the question. The answer in Zimbabwe is “which data, to which country, under which basis, and with whom informed”, and it is shorter than it sounds because the Act, the regulations and the Reserve Bank each add one clause.
The law
Section 28(1) of the Data Protection Act (Act 5 of 2021, cited in its regulations as the Cyber and Data Protection Act [Chapter 12:07]) provides that a data controller may not transfer personal information about a data subject to a third party in a foreign country unless an adequate level of protection is ensured in the recipient’s country or organisation, and the data is transferred solely to allow tasks within the controller’s competence to be carried out. Section 28(2) says adequacy is assessed “in the light of all the circumstances”, with particular regard to the nature of the data, the purpose and duration of processing, the recipient country, its data protection law, and the professional rules and security measures complied with there. Section 28(3) lets the Authority lay down categories of processing for which transfer is not authorised.
Section 29 lists when a transfer to a country without adequate protection may still take place: unambiguous consent; necessity for a contract with the data subject or for pre-contractual measures at their request; necessity for a contract in the data subject’s interest with a third party; important public interest or legal claims; vital interests; and transfers from public registers.
SI 155 s.10(2)(c) requires a licensed data controller to notify the Authority of “any intention to transfer or share information of data subject outside Zimbabwe”. Sensitive data (s.11) and genetic, biometric and health data (s.12) need written consent to be processed at all, wherever the processing happens.
For banking institutions the Reserve Bank’s guideline adds: inform the Reserve Bank about outsourcing of critical functions to cloud service providers early in the decision process (5.12); assess jurisdictional risks, compliance obligations and data segregation under the shared responsibility model; ensure the agreement includes explicit provisions for compliance with data protection legislation covering storage, processing and transmission of personal data; and reference international standards to validate the provider’s security posture (5.13). Groups with foreign parents must run cross-border data flow risk assessments regularly (5.4(e)). Prior written approval is required before implementing a new technology platform (6.4).
The Act does not define which countries are adequate, and as at September 2026 we have not located a published adequacy list from the Authority. In practice that means each transfer needs its own s.28(2) assessment on the record, or a s.29 basis, and a notification.
The facilities
In-country: TelOne’s Mazowe Data Centre near Harare is marketed as a Tier III design with redundant power and cooling, and TelOne sells colocation and cloud services from it; Dandemutande operates data centres in Harare and Bulawayo and has announced a planned US$15 million carrier-neutral facility under the ITU Partner2Connect programme. Enterprises with a modern server room can host on their own premises.
Regional: AWS’s Africa (Cape Town) region, af-south-1, has three availability zones; Microsoft Azure has South Africa North (Johannesburg) and South Africa West (Cape Town); Google Cloud’s africa-south1 region in Johannesburg opened in 2024. All three are foreign countries for the purposes of s.28.
The link between them: Zimbabwe’s used incoming international internet bandwidth was 545,123 Mbps in Q3 2025 against 1,456,270 Mbps equipped, and used outgoing capacity was 202,485 Mbps. The link is shared by the whole economy; a hosted-model architecture makes every prompt depend on it. Power: ZESA reported 138 consecutive days without load shedding in May 2026 and a target of ending it by December 2026; regional cloud removes the power dependence for the service but not for the people using it.
The decision path
A worked classification
Take a mid-sized bank’s AI programme and classify its workloads. The table is a worked example; the classes and consequences are real, the bank is not.
| Workload | Data classes present | Strictest class | Hosting pattern | What must be on file |
|---|---|---|---|---|
| Internal knowledge assistant over policies and procedures | Commercial-confidential; staff names in documents | Personal (low) | In-country (colocation); could be regional with assessment | Classification note; RBZ 6.4 approval for the platform |
| Contact-centre assistant over customer records | Personal; possibly sensitive in complaints | Personal | In-country only | Tier 4 licence; processing notification; access-control design |
| Claims or KYC document extraction | Personal; identity documents; possibly health | Sensitive/health | In-country only, written consent | s.11–12 consent records; DPIA |
| Marketing copy and non-customer research | Public | Non-personal | Hosted frontier model via gateway | Budget; redaction rule at the gateway |
| Transaction anomaly scoring | Personal financial | Personal | In-country | Model register entry; s.25 decision design |
| Disaster recovery for the in-country platform | Everything above, encrypted at rest | Personal | Regional cloud only with a s.28(2) assessment, encryption with keys held in Zimbabwe, notification and RBZ early notice | Adequacy memo; key-management design; contract clauses (RBZ 5.13) |
The result is the two-pattern architecture described on the model strategy page: an in-country platform for four of six workloads, a hosted model for one, and a carefully papered regional footprint for disaster recovery. Nothing in the table required a lawyer to invent a position; every row follows from a section and a paragraph already published.
What to write down
For every transfer you decide to make: the s.28(2) assessment (nature of data, purpose, duration, recipient country, its law, the security measures), the s.29 basis if adequacy cannot be shown, the SI 155 s.10(2)(c) notification, the processor contract under s.18(8), and, for banks, the correspondence with the Reserve Bank. Keep it with the model register entry so that the DPO, the CISO and the model owner are looking at the same file when the Authority asks.
Sources
- Data Protection Act, Act 5 of 2021 (Cyber and Data Protection Act [Chapter 12:07]) — s.11–12, s.18, s.28–29 — https://t3n9sm.c2.acecdn.net/wp-content/uploads/2024/11/Data-Protection-Act-5-of-2021.pdf
- Statutory Instrument 155 of 2024 — s.10(2)(c) — https://www.potraz.gov.zw/wp-content/uploads/2025/02/sI-155-of-2024-Cyber-and-Data-Protection-Normal_240913_1250178.pdf
- RBZ Cybersecurity and Resilience Guideline (August 2025) — paras 5.4, 5.12–5.13, 6.4 — https://www.rbz.co.zw/documents/Regulations_Acts/2025/Cybersecurity_and_Resilience_Guideline_-_August_2025.pdf
- Techzim (19 December 2025) — POTRAZ Q3 2025: international bandwidth — https://www.techzim.co.zw/2025/12/potraz-3rd-quarter-sector-performance-report-2025/
- Data Center Map — TelOne Mazowe Data Centre — https://www.datacentermap.com/zimbabwe/harare/mazowe-data-centre/
- TelOne — Data Centre and Cloud Services — https://www.telone.co.zw/products/details/data-centre-cloud-services
- DCD — Dandemutande plans US$15m data centre — https://www.datacenterdynamics.com/en/news/zimbabwean-it-provider-dandemutande-plans-15m-data-center/
- AWS — Africa (Cape Town) region now open — https://aws.amazon.com/blogs/aws/now-open-aws-africa-cape-town-region
- CIO — Azure South Africa North (Johannesburg) and West (Cape Town) — https://www.cio.com/article/193405/heres-how-amazons-south-africa-data-centres-will-impact-enterprises.html
- Northflank — Google Cloud africa-south1 (Johannesburg) — https://northflank.com/cloud/gcp/regions/africa-south1
- New Zimbabwe via allAfrica (11 May 2026) — ZESA load shedding statement — https://allafrica.com/stories/202605110146.html