SI 155 of 2024 and your AI vendor: who is the controller, who is the processor, and what goes in the contract
This is a buyer’s guide, not legal advice. Take the contract to a Zimbabwean lawyer; take this page with you.
Every AI service on this catalogue touches personal data: customers’ names and numbers, applicants’ CVs, staff on camera, buyers’ TINs on invoices. Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] and the 2024 licensing regulations put the responsibility for that data on the business that decides why and how it is processed — you — and not on the vendor who builds the tool. This guide sets out what that means when you sign.
Licensing in one page
Statutory Instrument 155 of 2024 — the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations — was gazetted in September 2024 and requires data controllers to be licensed by the Data Protection Authority, which is POTRAZ. The main points, as summarised by the law firms cited below:
- Who: any person or entity that determines the purpose and means of processing personal data — deciding what to collect, from whom, and what it is used for, including for commercial gain.
- Tiers: four, by number of data subjects, from a first tier starting at 50 data subjects to a top tier above 500,000. Licence fees are set per tier; commentaries put the range at US$50 to US$2,000.
- When: existing controllers had a six-month grace period ending 12 March 2025. Licences are valid twelve months and must be renewed at least three months before expiry.
- DPO: every controller must appoint a Data Protection Officer — an employee with qualifications or experience in data science, information security, law, audit or a relevant field, who completes certification approved by the Authority — and notify POTRAZ.
- Offence: processing without a licence after the deadline is an offence carrying a level-11 fine or imprisonment of up to seven years, or both. (Published commentaries differ on the dollar equivalent of a level-11 fine; treat the level, not a dollar figure, as the fact.)
- Location: the licence application asks whether data is stored in Zimbabwe or abroad. The regulations require you to declare it; they are not, in themselves, a data-localisation rule.
Controller and processor: the split that matters
You are the controller because you decided to collect customer numbers, screen applicants or record the gate. The vendor is your processor: it acts on your instructions and must be bound by contract to do only that. The vendor’s own suppliers — the messaging platform, the language-model API, the cloud — are sub-processors, almost always outside Zimbabwe. The regulations make you answer for the chain; the contract is the only tool you have to make the chain answerable to you.
Two exceptions to watch. If the vendor uses your data for its own purposes — to train its models, to build a product, to market — it has become a controller of that data and needs its own licence and your permission. And if you buy a subscription tool where the vendor decides the purposes, read its terms: you may both be controllers.
Nine clauses for the AI contract
| # | Clause | What “good” looks like |
|---|---|---|
| 1 | Roles | States that you are the controller, the vendor the processor, and lists sub-processors by name and country |
| 2 | Instructions and scope | Vendor processes only for the stated purpose; new uses need written consent |
| 3 | Training | Your data is not used to train or improve any model unless you opt in, in writing |
| 4 | Location | Where data is stored and processed; notice before any change of country or sub-processor |
| 5 | Security | Access control, encryption in transit and at rest, logging; who on the vendor’s side can see your data |
| 6 | Breach | Vendor notifies you within a fixed number of hours, with what happened and what to do |
| 7 | Data-subject requests | Vendor helps you delete, correct or export a person’s data end to end, including backups and sub-processors, within a fixed time |
| 8 | Retention and exit | What is kept after the contract, for how long, and a certified deletion at the end; full export in an open format before deletion |
| 9 | Audit | You (or your DPO) may inspect or receive evidence of compliance once a year and after any incident |
Two practical steps before go-live
Count your data subjects. Customers on WhatsApp, applicants this year, staff on CCTV, buyers with TINs on invoices. The count picks your tier and tells you whether an AI project will move you up one — recruitment automation is the usual culprit.
Name the DPO in the project. Your DPO should sign off the data section of any AI scope and receive the vendor’s monthly report. If you do not have a DPO yet, that is the first task, before the vendor.
Where this connects
The full vendor question bank has eight data-and-privacy questions that map to the clauses above. For large organisations, the governance framework at enterpriseai.co.zw goes further into policy, model inventory and audit trails; this guide is the buyer’s minimum.
- Veritas Zimbabwe — SI 155 of 2024, Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (full text)
- DLA Piper Africa (Manokore Attorneys) — Quick-start guide to Zimbabwe's data protection regulations
- Mawere Sibanda — Procedure for licensing of data controllers and appointment of DPOs under SI 155 of 2024
- MISA Zimbabwe — Navigating the Data Protection Act requirements for data controllers (14 Mar 2025)
- Afriwise — Understanding SI 155 of 2024