Complete guide
Data protection compliance in Zimbabwe means registering with POTRAZ as a licensed Data Controller under SI 155 of 2024, appointing a Data Protection Officer, documenting what personal data you hold, publishing a privacy policy, training your staff under CDPG 1 of 2025 and keeping all of it current. Inspections begin on 1 September 2026.
Last updated 2026-08-28. Lioncap Ventures, Harare, Zimbabwe.
Compliance is often described as a licence, and the licence is the visible part, but it is only one of eight obligations. An organisation that holds the licence and nothing else fails an inspection. These are the obligations the Cyber and Data Protection Act places on a data controller in Zimbabwe:
It applies to any organisation in Zimbabwe that holds personal data, which in practice means almost all of them. If you employ people you hold payroll and personnel data. If you have customers you hold contact details. If you run CCTV you hold footage. All of that is personal data, and holding it makes you a data controller.
POTRAZ Regulatory Notice 2 of 2026 named nine sectors in the first wave of mandatory inspections:
Private companies outside those sectors are not exempt. The licensing obligation under SI 155 of 2024 applies to every data controller; the notice sets the inspection sequence, not the scope of the law.
The path is the same for a two person practice and for a bank. What changes is the depth of each step, not the sequence.
A gap analysis against the Act, a data map and an inventory of what you hold, where it lives and who touches it. This also settles whether you are a controller, a processor or both.
A record of processing activities, a privacy policy and consent wording, a breach response procedure, a data subject access request procedure, and an impact assessment where health, children’s or other sensitive data is involved.
A named officer, notified to POTRAZ on Form DP2. Appoint internally, or take an outsourced, dedicated or full time officer from Lioncap Ventures.
Mandatory under CDPG 1 of 2025 for everyone who handles personal data, with the attendance record kept as inspection evidence. Sessions run off hours so the working day is not disrupted.
Form DP1 with your certificate of incorporation, Form DP2 with your officer’s certificates, the tier fee, and your processing notification.
There are two numbers and we keep them separate on purpose. The first is what POTRAZ charges, which we pass through at cost with no markup. The second is the Lioncap Ventures service fee for the work.
The $30 application fee applies from Tier 2 upwards. A Tier 1 organisation does not pay it, and it is not charged again on an annual renewal.
Every POTRAZ figure above is exclusive of VAT, which POTRAZ adds on its own invoice at a rate we do not set. That is why we quote our service fee and the POTRAZ fees as two separate numbers and never give you a single all-in total. You pay POTRAZ exactly what POTRAZ bills us, with no markup.
On the service side, packages start at $250 for a small single site organisation and are fixed price, so the fee does not move once it is quoted. Every engagement begins with a $90 consultation, a one hour working session in which our data protection officers confirm your controller or processor status, map the records you hold, your sites and systems and the partners you share data with, and confirm your exact licence tier. The $90 is credited in full toward your compliance package when you proceed. Packages start at $250.
Compliance is ongoing, not a one off filing. After licensing there is a rhythm to it: a monthly officer function covering breaches and data subject requests, a quarterly sweep of your record of processing with any changes notified to POTRAZ, a six monthly internal review, and an annual audit, policy re approval, training refresher and licence renewal.
Organisations that treat licensing as a project and then stop are the ones that struggle at their second inspection, because the record of processing has drifted away from what they actually do. Keeping it current is less work than rebuilding it.
Paper records are inspected. Filing rooms, registers and archives have to be secured and access controlled, with a documented retention period, exactly as digital records do.
How personal data moves matters as much as where it rests. Sending personal details over ordinary email or a personal messaging account is among the most common findings, and overseas email or cloud storage can move personal data outside Zimbabwe, which is a cross border transfer that must be assessed and may need notification to POTRAZ.
The starting point is knowing your position rather than guessing at it. The $90 consultation is a one hour working session with our data protection officers that confirms your controller or processor status, maps your data footprint and fixes your licence tier, and it produces a written assessment and an accurate quotation. The $90 is credited in full toward your package when you proceed.
From there, most small organisations are documented and filed within one to two weeks. Larger organisations take longer because of the audit and multi site work, and the timeline is built backwards from the inspection date.
It means meeting the obligations of the Cyber and Data Protection Act (Chapter 12:07): registering with POTRAZ as a licensed Data Controller under SI 155 of 2024, appointing a Data Protection Officer, keeping a record of processing activities, publishing a privacy policy, holding breach and data subject request procedures, completing an impact assessment for high risk processing, securing paper records and training staff under CDPG 1 of 2025. Inspections begin on 1 September 2026.
Any organisation in Zimbabwe that holds personal data, which includes staff records, so in practice almost every trading organisation. Nine sectors were named in the first wave of inspections, but the licensing obligation itself applies to every data controller regardless of sector.
Two separate numbers. POTRAZ charges a licence fee by record volume, from $50 to $2,500, plus a $30 application fee from Tier 2 upwards; those figures are exclusive of VAT and we pass them through at cost. Lioncap Ventures charges a fixed service fee starting at $250, after a $90 consultation that is credited in full toward the package.
Most small organisations are documented and filed within one to two weeks of the consultation. Larger enterprises, groups and government ministries, departments and agencies take longer because of the audit and multi site rollout, and we build the timeline backwards from the inspection date.
A licensed data controller must appoint one under SI 155 of 2024. For a Tier 1 organisation holding up to 1,000 records, the appointment is required where sensitive data such as health, children’s or biometric data is processed. Lioncap Ventures can act as your officer on record, or we can prepare and file everything while your own appointed officer signs it off.
A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.
Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.