For practices
An accounting or audit practice in Zimbabwe is a data controller for its own staff and client records, and usually a data processor as well for the payroll and bookkeeping it runs on client instructions. Both positions carry obligations under Statutory Instrument 155 of 2024, and the written agreements in section 10(4)(f) are the ones practices most often lack.
Last updated 2026-09-02. Lioncap Ventures, Harare, Zimbabwe.
This is the point that makes a practice different from an ordinary business, and it is worth getting right before anything is filed, because the two positions carry different obligations.
You are a data controller where you determine the purposes and means of the processing yourself. That covers your own staff records, your partner and employee files, your client relationship data, your billing and your marketing list. It also covers statutory audit work, where the scope and the methods are determined by your professional obligations rather than by the client’s instructions.
You are a data processor where you handle personal data on a client’s instructions and for the client’s purposes. Running a client’s payroll, keeping their books or filing their returns is processing on their behalf: they decide what the data is for, and you execute.
Most practices are running both at once, often for the same client. The classification is settled engagement by engagement at the consultation, because filing under the wrong status means filing twice, and because it changes what your engagement letters need to say.
The volume surprises people, because a practice holds data about its clients’ people as well as its own, and the client side is usually far larger.
Payroll deductions for medical aid, and disciplinary or garnishee detail, take a practice into health and other sensitive information without any deliberate decision to hold it.
Section 10(4)(f) of SI 155 requires a data controller to enter into a written data processing agreement, contract or legal instrument with each data processor, ensuring the processor maintains the necessary security measures. For a practice this cuts both ways, and both directions are commonly missing.
Section 10(4)(a) then makes the controller accountable for a representative, agent, assignee, processor, recipient or data protection officer who contravenes, and section 33(6) of the Act makes a controller liable for fines incurred by its agent or assignee. Subcontracting the work does not subcontract the exposure.
Practices tend to feel covered here, because confidentiality has been a professional obligation for as long as the profession has existed, and because it is taken seriously. But the two regimes ask different questions and one does not satisfy the other.
Confidentiality asks whether you disclosed information you should not have. Data protection asks a wider set of questions: whether you should be holding the data at all, whether the person knows you hold it, whether they can ask for a copy, how long you keep it, where in the world it sits, what happens when it leaks, and whether you can demonstrate all of that to a regulator under section 24 of the Act.
A practice with an excellent confidentiality culture and no record of processing activities, no licence and no appointed officer is still exposed. The culture helps enormously with the substance, and does nothing for the demonstration duty.
Most practices have moved to cloud accounting, cloud practice management and cloud document storage, and most of those platforms are hosted outside Zimbabwe. That is a transfer of personal information outside Zimbabwe, and a continuing one rather than a single event.
Section 10(2)(c) of Statutory Instrument 155 of 2024 requires notification of any intention to transfer or share data subject information outside Zimbabwe, so the notifiable event happens before the platform goes live rather than after. Section 28 of the Act governs the transfer itself and section 29 deals with transfers to a country that does not assure an adequate level of protection. Contravening section 28 is one of the five sections named in section 33(2).
None of this means the platforms cannot be used. It means the intention is notified, the arrangement is papered, and clients are told in your engagement terms where their data goes.
Tier is set by the number of data subjects whose information you process, and for a practice that count is dominated by other organisations’ people rather than your own. A practice with thirty staff can easily be processing for tens of thousands of individuals once client payrolls and ledgers are counted.
The $30 application fee applies from Tier 2 upwards. A Tier 1 organisation does not pay it, and it is not charged again on an annual renewal. Every POTRAZ figure above is exclusive of VAT, which POTRAZ adds on its own invoice at a rate we do not set. That is why we quote our service fee and the POTRAZ fees as two separate numbers and never give you a single all-in total. You pay POTRAZ exactly what POTRAZ bills us, with no markup.
The gaps in a practice are rarely about carelessness. They are about a set of obligations that sit slightly outside the professional standards the firm is used to being measured against.
A practice that closes those seven is in a materially defensible position, and none of them requires new systems.
Usually both. You are a controller for your own staff records, client relationship data, billing and marketing, and for statutory audit work where your professional obligations determine the scope and methods. You are a processor where you run payroll or keep books on a client’s instructions and for the client’s purposes. The split is settled engagement by engagement, because it changes what your engagement letters need to say.
Yes. A practice determines the purposes and means of processing personal data about its own people and its clients, which is the test in section 4(1) of Statutory Instrument 155 of 2024. Section 8 exempts only personal, family or household affairs, law enforcement, and journalistic, historical or archival purposes. There is no professional practice exemption.
No. Confidentiality asks whether you improperly disclosed information. Data protection asks whether you should hold the data, whether the person knows, whether they can obtain a copy, how long you keep it, where it is stored, what happens on a breach, and whether you can demonstrate all of it to the regulator under section 24 of the Act. A strong confidentiality culture helps with the substance and does nothing for the demonstration duty.
Where you process on a client’s instructions, section 10(4)(f) of Statutory Instrument 155 of 2024 requires a written data processing agreement between the client as controller and you as processor. Practically, that is best handled inside the engagement letter, alongside the controller and processor split, retention periods and what happens to the data when the engagement ends. You also need agreements running the other way, with your own subcontractors and software vendors.
It is manageable, but it is a transfer of personal information outside Zimbabwe and it needs handling rather than ignoring. Section 10(2)(c) requires you to notify the intention to transfer or share data outside Zimbabwe, section 28 of the Act governs the transfer, and section 29 addresses countries that do not assure an adequate level of protection. The practical steps are notifying properly, papering the arrangement, and telling clients in your engagement terms where their data goes.
It is set by the number of data subjects you process for, which for a practice is dominated by client payrolls and ledgers rather than by your own headcount. A practice with thirty staff can be processing for tens of thousands of people. Tier 1 covers up to 1,000 records and Tier 2 runs to 100,000, so most established practices sit at Tier 2 or above once the count is done properly.
A licensed controller appoints one under section 12(1) of SI 155. Payroll work takes most practices into sensitive data through medical aid deductions and disciplinary or garnishee detail, which reaches the requirement even at Tier 1. The appointment is notified on Form DP2 and failing to appoint is an offence under section 12(6).
A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.
Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.