Complete guide

Data protection compliance in Zimbabwe: the complete guide

Data protection compliance in Zimbabwe means registering with POTRAZ as a licensed Data Controller under SI 155 of 2024, appointing a Data Protection Officer, documenting what personal data you hold, publishing a privacy policy, training your staff under CDPG 1 of 2025 and keeping all of it current. Inspections begin on 1 September 2026.

Last updated 2026-08-28. Lioncap Ventures, Harare, Zimbabwe.

Key facts

Law
Cyber and Data Protection Act (Chapter 12:07)
Licensing
Mandatory under SI 155 of 2024
Training
Mandatory under CDPG 1 of 2025
Inspections
Begin 1 September 2026, nine first wave sectors
POTRAZ licence fees
$50 to $2,500, at cost, exclusive of VAT
Lioncap packages
From $250

What compliance actually means

Compliance is often described as a licence, and the licence is the visible part, but it is only one of eight obligations. An organisation that holds the licence and nothing else fails an inspection. These are the obligations the Cyber and Data Protection Act places on a data controller in Zimbabwe:

Data Controller licence
Registering as a licensed Data Controller with POTRAZ is now mandatory under SI 155 of 2024. Operating without one is an offence.
Appoint a Data Protection Officer
Under SI 155 a licensed data controller must appoint a DPO to oversee compliance with the Act. Lioncap Ventures provides your required DPO on record, outsourced, dedicated or full-time.
Records of Processing (ROPA) + notification
You must document what personal data you hold, why, and for how long, and notify POTRAZ of your processing activities.
DPIA for high-risk processing
A Data Protection Impact Assessment is required where you process sensitive personal data at scale or in high-risk ways.
Privacy, breach & DSAR procedures
You need a published privacy policy plus written procedures for data breaches and data subject access requests.
Physical & paper records security
Inspectors check paper files too. Filing rooms, registers and archives must be secured and access controlled.
Mandatory staff training
Staff who handle personal data must be trained under CDPG 1 of 2025, the POTRAZ assessment guidelines. Inspectors ask for training records, and we run sessions off-hours so your working day is not disrupted.
Secure data in transit
Sending personal details over ordinary email or WhatsApp is one of the most common inspection findings. Sensitive data needs a secure channel, encrypted devices and documented safeguards.

Who it applies to

It applies to any organisation in Zimbabwe that holds personal data, which in practice means almost all of them. If you employ people you hold payroll and personnel data. If you have customers you hold contact details. If you run CCTV you hold footage. All of that is personal data, and holding it makes you a data controller.

POTRAZ Regulatory Notice 2 of 2026 named nine sectors in the first wave of mandatory inspections:

Private companies outside those sectors are not exempt. The licensing obligation under SI 155 of 2024 applies to every data controller; the notice sets the inspection sequence, not the scope of the law.

The five steps to compliant

The path is the same for a two person practice and for a bank. What changes is the depth of each step, not the sequence.

  1. Find out where you stand

    A gap analysis against the Act, a data map and an inventory of what you hold, where it lives and who touches it. This also settles whether you are a controller, a processor or both.

  2. Document what you do

    A record of processing activities, a privacy policy and consent wording, a breach response procedure, a data subject access request procedure, and an impact assessment where health, children’s or other sensitive data is involved.

  3. Appoint your Data Protection Officer

    A named officer, notified to POTRAZ on Form DP2. Appoint internally, or take an outsourced, dedicated or full time officer from Lioncap Ventures.

  4. Train your staff

    Mandatory under CDPG 1 of 2025 for everyone who handles personal data, with the attendance record kept as inspection evidence. Sessions run off hours so the working day is not disrupted.

  5. File with POTRAZ

    Form DP1 with your certificate of incorporation, Form DP2 with your officer’s certificates, the tier fee, and your processing notification.

What compliance costs

There are two numbers and we keep them separate on purpose. The first is what POTRAZ charges, which we pass through at cost with no markup. The second is the Lioncap Ventures service fee for the work.

Tier 1, up to 1,000 records
$50 licence fee
Tier 2, 1,001 – 100,000 records
$300 licence fee
Tier 3, 100,001 – 500,000 records
$500 licence fee
Tier 4, over 500,000 records
$2,500 licence fee

The $30 application fee applies from Tier 2 upwards. A Tier 1 organisation does not pay it, and it is not charged again on an annual renewal.

Every POTRAZ figure above is exclusive of VAT, which POTRAZ adds on its own invoice at a rate we do not set. That is why we quote our service fee and the POTRAZ fees as two separate numbers and never give you a single all-in total. You pay POTRAZ exactly what POTRAZ bills us, with no markup.

On the service side, packages start at $250 for a small single site organisation and are fixed price, so the fee does not move once it is quoted. Every engagement begins with a $90 consultation, a one hour working session in which our data protection officers confirm your controller or processor status, map the records you hold, your sites and systems and the partners you share data with, and confirm your exact licence tier. The $90 is credited in full toward your compliance package when you proceed. Packages start at $250.

The compliance year

Compliance is ongoing, not a one off filing. After licensing there is a rhythm to it: a monthly officer function covering breaches and data subject requests, a quarterly sweep of your record of processing with any changes notified to POTRAZ, a six monthly internal review, and an annual audit, policy re approval, training refresher and licence renewal.

Organisations that treat licensing as a project and then stop are the ones that struggle at their second inspection, because the record of processing has drifted away from what they actually do. Keeping it current is less work than rebuilding it.

Digital and paper, both in scope

Paper records are inspected. Filing rooms, registers and archives have to be secured and access controlled, with a documented retention period, exactly as digital records do.

How personal data moves matters as much as where it rests. Sending personal details over ordinary email or a personal messaging account is among the most common findings, and overseas email or cloud storage can move personal data outside Zimbabwe, which is a cross border transfer that must be assessed and may need notification to POTRAZ.

Where to start

The starting point is knowing your position rather than guessing at it. The $90 consultation is a one hour working session with our data protection officers that confirms your controller or processor status, maps your data footprint and fixes your licence tier, and it produces a written assessment and an accurate quotation. The $90 is credited in full toward your package when you proceed.

From there, most small organisations are documented and filed within one to two weeks. Larger organisations take longer because of the audit and multi site work, and the timeline is built backwards from the inspection date.

Frequently asked questions

What is data protection compliance in Zimbabwe?

It means meeting the obligations of the Cyber and Data Protection Act (Chapter 12:07): registering with POTRAZ as a licensed Data Controller under SI 155 of 2024, appointing a Data Protection Officer, keeping a record of processing activities, publishing a privacy policy, holding breach and data subject request procedures, completing an impact assessment for high risk processing, securing paper records and training staff under CDPG 1 of 2025. Inspections begin on 1 September 2026.

Who needs to comply?

Any organisation in Zimbabwe that holds personal data, which includes staff records, so in practice almost every trading organisation. Nine sectors were named in the first wave of inspections, but the licensing obligation itself applies to every data controller regardless of sector.

How much does it cost to become compliant?

Two separate numbers. POTRAZ charges a licence fee by record volume, from $50 to $2,500, plus a $30 application fee from Tier 2 upwards; those figures are exclusive of VAT and we pass them through at cost. Lioncap Ventures charges a fixed service fee starting at $250, after a $90 consultation that is credited in full toward the package.

How long does it take to become compliant?

Most small organisations are documented and filed within one to two weeks of the consultation. Larger enterprises, groups and government ministries, departments and agencies take longer because of the audit and multi site rollout, and we build the timeline backwards from the inspection date.

Do we need a Data Protection Officer?

A licensed data controller must appoint one under SI 155 of 2024. For a Tier 1 organisation holding up to 1,000 records, the appointment is required where sensitive data such as health, children’s or biometric data is processed. Lioncap Ventures can act as your officer on record, or we can prepare and file everything while your own appointed officer signs it off.

Get inspection-ready

A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.

Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.