Zimbabwe’s Cybersecurity Framework Now Requires Board-Level Accountability & New Executive KPIs

By Jonathan Mbiriyamveka

In a push to strengthen Zimbabwe’s cybersecurity and data privacy landscape, POTRAZ Director General Dr Gift Machengete has outlined new responsibilities for corporate boards and executives under the Cyber and Data Protection Act (CDPA).

The Act mandates that boards and executive teams integrate data protection into their strategies and decision-making processes, ensuring a company-wide commitment to data security.

“Data protection must be a top priority at the highest level of management. Leadership commitment is essential for sustainable compliance,” said Dr Machengete.

This means that boards and executives are now directly accountable for the organization’s data practices, with clear oversight structures required to ensure regulatory compliance.

To monitor this commitment, POTRAZ has introduced Key Performance Indicators (KPIs) for executives, including achieving zero data breaches and ensuring that all staff are trained in CDPA regulations annually.

Dr Machengete stressed that “you can’t manage what you can’t measure,” emphasizing the importance of quantitative tracking for compliance and risk management.

Failure to comply with these new requirements may expose organizations to reputational damage, regulatory audits, financial penalties, and potential disruptions to operations.

Non-compliant companies may face significant legal repercussions, with penalties including fines and imprisonment of up to seven years for executives who fail to uphold data security standards.

The new framework underlines POTRAZ’s commitment to making Zimbabwe a leader in data protection across Africa, with policies that support both consumer trust and business innovation.

About Author