I recently arrived at Robert Gabriel Mugabe International Airport after a trip to Zambia. Like many other travellers, I went straight to the new self-service passport scanner. Within seconds, the system confirmed who I was.
It was an ordinary transaction, the kind we barely think about. We scan our passports, collect our luggage and leave. We rarely stop to wonder what happens behind the screen.
But this time, I did.
As I walked away, I found myself thinking about that scan: what exactly had the system just read about me, where had that information gone, and who ultimately controlled the infrastructure behind it?
Where did my data go?
What exactly did the system read from my e-passport? What information was retrieved or recorded in Zimbabwe’s immigration systems, where is it stored, who secures it, who can access it, and who built the infrastructure through which it travels? Most importantly, does the Government of Zimbabwe possess effective technological control over the digital systems that increasingly know who we are?
These may sound like technical questions for computer scientists and immigration officials. They are not: they are questions of sovereignty.
The passport is no longer just a passport
For generations, the passport was primarily a physical document establishing nationality and identity. The e-passport changes that relationship: an embedded contactless chip digitally stores identity information under International Civil Aviation Organisation standards, including biometric and cryptographic mechanisms used to authenticate the document. Zimbabwe introduced its e-passport programme in January 2022. The benefits are obvious: passports are harder to forge, verification is faster, and border processing more efficient. As someone who travels regularly, I appreciate that convenience.
But convenience creates another reality. The passport has quietly evolved from a booklet we carry in our pockets into an interface with a much larger digital identity infrastructure. And once identity becomes data, we must start asking who controls it.
There is an important distinction. When my Zimbabwean passport was scanned, that did not necessarily mean my entire biometric record was transmitted somewhere. The chip contains information that can be read and authenticated under international standards. But what sits behind the scanner? What database confirms identity, what record is created when someone enters or leaves Zimbabwe, where is it stored, and who administers the systems?
One scan seems insignificant. Millions become a database, and a database becomes an asset.
The same questions arise with Zimbabwe’s e-visa system. Applicants enter personal information, passport details and travel information online. The official platform says these details are confidential and stored in ‘high-security systems.’ Reassuring, yes, but where are those systems and backups, who operates the software, who has privileged administrator access, and who controls the encryption keys?
Who built Zimbabwe’s digital identity architecture?
Zimbabwe did not develop every component of its e-passport ecosystem on its own. In 2021, Cabinet announced implementation of the e-passport production project under a Build, Own, Operate and Transfer agreement with the Lithuanian company Garsu Pasaulis. Semlex, a Belgian biometric-identification company, separately lists Zimbabwe’s Ministry of Home Affairs among its government references for electronic and biometric passports, national identity cards, visas and civil records.
Foreign technological involvement is not unusual. Governments everywhere buy technology from companies based elsewhere, and Zimbabwe cannot manufacture every chip, server or line of code it needs. Nor does foreign involvement prove that anyone has a secret backdoor into Zimbabwe’s databases; such a claim requires evidence. But absence of evidence of unauthorised access is not the same as demonstrating sovereign control.
The important question is whether Zimbabwe possesses the technical capacity to independently verify that nobody who should not have access actually does. That is the sovereignty test.
A server in Harare is not enough
Zimbabwe has invested in government data-centre infrastructure, including the National Data Centre commissioned in Harare in 2021. But the centre itself illustrates the complexity of digital sovereignty. It was completed with assistance from the Chinese government and Chinese firms Inspur Group and Sino-Zimbabwe; at its commissioning, President Emmerson Mnangagwa publicly thanked China for its strategic support and technical expertise in e-government. The government has also signalled plans to upgrade it to Tier 4 standards, announced by ICT minister Tatenda Mavetera at the Computer Society of Zimbabwe Summit in 2025.
There is nothing inherently problematic about that cooperation, and Chinese involvement does not establish that China has access to data stored at the centre. But it sharpens the question this article is asking. What does sovereignty mean when the infrastructure is physically national, while some of the technology, expertise or technical dependencies that helped create it originate elsewhere? Localising data is important; it is not the same thing as possessing the knowledge and capacity to control the systems that hold it.
Those investments matter, but they do not answer where critical passport, e-visa, immigration, national identity and civil-registration databases and backups are hosted, which companies maintain their software and security architecture, or who possesses privileged access.
The public does not need sensitive technical configurations published. But independent institutions must know the answers. Parliament should exercise oversight, the Data Protection Authority should know, and cleared Zimbabwean cybersecurity experts should be capable of auditing critical systems. Sovereignty cannot depend entirely on assurances from those operating the technology.
We often talk about data sovereignty as if the decisive question were simply where the server sits. Geography matters, but it is only the beginning. A database can sit in Harare while depending on software, security updates, expertise or remote administrators located elsewhere. The server may be ours while the knowledge required to operate it belongs to somebody else. That is dependency, and dependency becomes vulnerability when a state cannot independently understand, audit, repair or replace a critical system.
The real test is simple: if the foreign technology provider disappeared tomorrow, could Zimbabwe keep the system running? If not, we need to distinguish between possessing data and possessing sovereignty over data.
This question of dependency also touches a wider debate about what economist Yanis Varoufakis calls technofeudalism: a system in which those who own and control cloud infrastructure, platforms and algorithmic systems acquire extraordinary power over those who depend on them. His thesis is contested, and Zimbabwe’s reliance on foreign technology should not simply be labelled technofeudalism. But the concept raises a useful question for African states: what happens when sovereignty remains formally national while some of the technological capabilities through which that sovereignty is exercised are controlled, maintained or understood elsewhere?
Europe is asking the same question
This is not uniquely a Zimbabwean anxiety. Germany’s Schleswig-Holstein has been moving its public administration from Microsoft Office towards LibreOffice and developing a Linux-based workplace, explicitly linking the migration to digital sovereignty and reduced technological dependency.
France confronted a more sensitive version in April 2026 when its Health Data Hubselected French provider Scaleway as it transitions away from Microsoft’s Azure cloud after concerns about sovereignty and foreign legal jurisdiction over health data. In June, the European Commission presented a Technological Sovereignty Package spanning semiconductors, cloud infrastructure, AI and open source, while its Cloud Sovereignty Framework assesses providers against criteria including strategic control, jurisdiction, data, technology and security.
These are wealthy states with sophisticated cybersecurity institutions and considerable bargaining power, yet they worry about technological dependency. If Europe is asking these questions about software and cloud infrastructure running its governments, why shouldn’t Zimbabwe ask them about passports, biometrics, immigration and civil-registration systems?
The lesson is not that African governments should stop using foreign technology. That would be neither realistic nor desirable. What matters is whether they retain capacity, control and choice. Dependence can hide in ordinary arrangements: a ministry using foreign cloud infrastructure or a contractor maintaining a database local officials cannot independently repair. Such arrangements may be legitimate, but the sovereignty question remains: who controls the digital machinery of the state?
African governments should be able to use American, Chinese, European, Indian or other technology without permanent dependence on the provider. A sovereign state should know where critical data resides, who has administrator access, who controls encryption keys, whether systems can be audited and migrated, and whether its own engineers can keep them functioning. Digital sovereignty is partly the ability to walk away.
But changing suppliers is not the same thing as becoming sovereign. Replacing an American platform with a Chinese one, or a Chinese system with a European one, does not create African sovereignty. The objective is to expand Africa’s capacity to choose through investment in cybersecurity, data centres, software engineering, open standards, research and indigenous AI, alongside regional standards and shared expertise through bodies such as SADC and the African Union.
The layers of sovereignty
So the question cannot stop at where data is stored. Legal control matters, but so do the infrastructure through which information moves, the software and encryption that govern it, the domestic expertise needed to operate or replace those systems, and increasingly the algorithms capable of turning vast datasets into classifications, predictions and knowledge.
These questions run into one another. Data moves through infrastructure and systems; algorithms can then turn it into knowledge. And knowledge, in the hands of states and powerful companies, is a form of power. That is why this discussion is much bigger than the passport.
Think again about the airport scan. One record of my return from Zambia tells you little; millions of travel records accumulated over years reveal patterns of movement. The same principle extends across identity, telecommunications, finance, health, civil-registration and tax systems: each serves a legitimate purpose, but together they describe a society in extraordinary detail.
AI and sophisticated algorithms can extract knowledge from such datasets at unprecedented scale. The strategic value of data increasingly lies not only in what one database contains, but in what can be learned when datasets are combined. Foreign-designed technology does not automatically mean foreign access, but governments must be able to identify, mitigate and independently audit the risks. Trust is not a cybersecurity architecture.
This is what I describe as geosociotechnopolitics: the interaction between geography, society, technology and political power. Zimbabwe’s passport system illustrates it well. It forces us to ask several questions at once: where the data sits; whose identities and movements it represents; who designed, maintains and understands the systems; who has authority to access, transfer or combine the information; and what dependence means when the actors involved possess vastly unequal technological and computational power.
Seen through this lens, the e-passport is no longer merely a travel document. It is part of the infrastructure through which the Zimbabwean citizen increasingly becomes digitally legible.
Zimbabwe has laws. But does it have the capacity?
Zimbabwe is not operating in a legal vacuum. The Cyber and Data Protection Actdesignates POTRAZ as the Data Protection Authority, regulates personal information and places conditions on transfers of personal information outside Zimbabwe.
But legislation cannot secure a database by itself. A country also needs engineers, cybersecurity specialists, secure infrastructure, encryption, independent auditing, incident-response capability and strong institutional oversight. Legal sovereignty without technological capacity risks becoming sovereignty on paper.
What Zimbabwe should do now
Zimbabwe does not need to disconnect from the world. It needs strategic digital autonomy: the ability to benefit from foreign technology while retaining effective control over critical national systems.
A practical starting point is to identify Zimbabwe’s critical sovereign data: passports and biometrics, national identity and civil registration, health, financial and tax information, telecommunications, electoral systems and national-security data.
Government should then conduct a sovereign-data and digital-infrastructure audit. For every critical system it should know where databases and backups are hosted, which companies and subcontractors are involved, who controls encryption keys and privileged access, whether remote administration is possible, what information crosses Zimbabwe’s borders, and whether access is independently logged and audited.
Government procurement also needs a sovereignty test. The EU experience shows that providers can be assessed against sovereignty criteria. African governments can develop frameworks suited to their own conditions, nationally and eventually through SADC or the African Union. Critical public technologies need not all be African-made, but they must remain under meaningful African control.
Procurement contracts should also require genuine technology transfer and a credible exit strategy. Zimbabwean engineers should not merely operate somebody else’s black box; they should understand the box. Open standards and open-source technologies should be considered where they improve transparency and independence, while vendor lock-in should be treated as a sovereignty risk.
Before signing a contract for critical national digital infrastructure, government should ask one deceptively simple question: if this company disappeared tomorrow, could Zimbabwe independently operate, secure, audit, repair and recover the system? If the answer is no, the problem is bigger than procurement. It is a sovereignty problem.
Who controls the digital Zimbabwean?
When I walked away from immigration at Robert Gabriel Mugabe International Airport, the passport scan had taken only seconds. But the questions stayed with me. We are rapidly digitising the state: passports, visas, borders, civil registries, health systems and financial services. Increasingly, the state encounters us as data. That changes the meaning of sovereignty.
Political independence gave African states authority over their territory and borders. Digital transformation introduces another frontier: who controls the digital representation of the people living within those borders?
There is also a distinctly Zimbabwean way of thinking about this question. In my doctoral work, I return to Nehanda as a symbol of self-determination and to the proposition that Zimbabwe’s story is not finished until Nehanda is in it. That idea takes on a new meaning in the digital age. Political independence was ultimately about the right of a people to determine their own affairs. Digital sovereignty carries that unfinished question into another domain: can a society meaningfully determine its own future if the technological systems through which its citizens are identified, governed and increasingly understood remain beyond its effective control?
If Nehanda represented the struggle for political self-determination, the digital age asks what self-determination means when identity, borders and state power increasingly run through code. The question is not whether Zimbabwe should reject foreign technology. It is whether technological modernisation expands our capacity for self-determination or quietly creates new forms of dependence. Seen this way, digital sovereignty is not technological nationalism. It is the digital expression of an older struggle for agency.
Zimbabwe should continue modernising its immigration systems and welcome e-passports, efficient e-gates and digital public services. But technological convenience should never require intellectual complacency.
The next time I place my passport on a scanner, I want to know that behind that simple transaction Zimbabwe possesses the people, institutions, laws, infrastructure and technological knowledge necessary to control it. The most important question is no longer simply whether the technology works, but who ultimately possesses the power behind it.
Where does the data go? Who stores it? Who secures it? Who can access it? Who understands the system? And who possesses the ultimate power to say no?
In the twenty-first century, controlling our borders is no longer enough.
We must also control the digital infrastructure through which those borders, and the people crossing them, are increasingly understood.







