DPO outsourcing

Outsourcing the Data Protection Officer role in Zimbabwe

Statutory Instrument 155 of 2024 requires a licensed data controller to appoint a Data Protection Officer and notify POTRAZ on Form DP2. It sets qualifications and requires an approved certification, but it does not require the officer to be your employee. Lioncap Ventures provides the officer on record and performs the statutory functions.

Last updated 2026-09-02. Lioncap Ventures, Harare, Zimbabwe.

Key facts

The duty
Section 12(1) of SI 155 of 2024: appoint an officer and notify the Authority in writing
The form
Form DP2, Third Schedule
Appointment window
Ninety days, under section 12(5)
Qualifications
Section 13(1): data science, data analytics, information security systems, information systems audit, law, audit or other relevant qualification
Certification
Section 13(2): a certification course approved by the Authority
Penalty for not appointing
Section 12(6): a fine up to level 7 or imprisonment up to two years or both

Can the role be outsourced

Yes, and for most organisations it is the sensible answer. What the regulations require is that a Data Protection Officer is appointed, that the appointment is notified to the Authority in writing on Form DP2, and that the person holding the role meets the qualification and certification requirements in section 13. They regulate the officer, the notification and the functions performed. They do not require that the officer sits on your payroll.

What outsourcing does not do is move the liability. Section 10(4)(a) of SI 155 makes the controller accountable for a representative, agent, assignee, data processor, recipient or data protection officer who contravenes the regulations or the Act, and section 33(6) of the Act makes the controller liable for the payment of fines incurred by its agent or assignee. You are buying the capability and the capacity, not an escape route, and any provider who suggests otherwise is selling something they cannot deliver.

Who is actually eligible

Section 13(1) sets out what the officer must bring. It is a broader list than people expect, and it is not limited to lawyers.

Section 13(2) then adds the requirement that trips up internal appointments: every officer must undergo a certification course approved by the Authority. Section 11(2) provides for the Authority to deliver that certification training in conjunction with an institution of higher learning or accredited institutions, and section 11(3) makes it an offence for anyone to provide certification training for these purposes without being accredited by the Authority. If you are appointing internally, check that the training your candidate took was delivered by an accredited provider, because a certificate from an unaccredited trainer does not put you where you need to be.

What the officer is required to do

Section 14 lists the functions, and it is worth reading as a job description rather than as a formality. This is the work, and it is continuous rather than annual.

Section 10(1) adds a duty on you rather than on the officer: the controller must provide continuous professional development training to the officer, so that the certification is maintained. That is a recurring cost of an internal appointment which organisations rarely price in when they compare the options.

Outsourcing compared with appointing internally

Both are legitimate. The question is which one your organisation can actually sustain, and the honest comparison is about capacity and continuity rather than about cost alone.

Certification
An internal appointee has to complete an approved certification course before they are eligible, and you carry the cost and the time. An outsourced officer arrives certified.
Continuing development
Section 10(1) requires you to fund continuous professional development for your officer. With an outsourced officer that sits with the provider.
Continuity
If an internal officer resigns, section 12(4) gives you fourteen days to notify the Authority and section 12(5) gives you ninety days to appoint a replacement, who then needs certifying. An outsourced arrangement absorbs that.
Availability
The twenty four hour breach clock in section 19 of the Act runs at weekends and over holidays. A single internal appointee is a single point of failure; a provider carries cover.
Independence
Section 14 requires the officer to monitor compliance and conduct internal compliance audits. Where the obvious internal candidate is the person who also runs the systems being audited, they are being asked to audit their own work, which is uncomfortable at best.
Business knowledge
This is the one point where an internal officer starts ahead. Section 13(1) requires an understanding of your operations and processing activities, and an outsourced officer builds that during onboarding rather than arriving with it.

The pattern that works for larger organisations is often a hybrid: an outsourced officer on record carrying the statutory functions and the regulator relationship, with an internal compliance contact who knows the business and coordinates internally.

What our outsourced officer actually does through the year

The retainer is described by duties and by service limits rather than by a list of hours. Every tier carries the same duties; the tier sets the limits, scaled to the size of the organisation. If another organisation pays less, it is because it is smaller, not because it is less covered.

Some things sit outside the retainer at every tier and are quoted separately when they arise: an impact assessment for a brand new system you bring in, a material change assessment, forensic investigation beyond the on-call response, and the POTRAZ licence fee itself, which is passed through at cost. The service limits by tier, covering data subject request volumes, breach response times, register sweeps, reporting cadence, training and audit depth, are set out on the compliance page and confirmed in your service level agreement.

Does your organisation actually need one

A licensed data controller appoints an officer under section 12(1). For a Tier 1 organisation holding up to 1,000 records, the appointment is required where sensitive data is processed, which in practice means health information, data about children, biometric data or data revealing religious belief.

That carve-out is narrower than it first appears. A school holds health information about learners and data about children. A church membership register reveals religious belief. A clinic holds patient records. A business running fingerprint clocking processes biometric data. Each of those reaches the trigger even at the smallest tier, which is why the question is settled at the consultation rather than assumed.

Where you have already appointed your own officer, no Lioncap retainer applies. We prepare and file everything else, and your officer signs it off. Every engagement begins with a $90 consultation, a one hour working session in which our data protection officers confirm your controller or processor status, map the records you hold, your sites and systems and the partners you share data with, and confirm your exact licence tier. The $90 is credited in full toward your compliance package when you proceed. Packages start at $250.

Frequently asked questions

Can a Data Protection Officer be outsourced in Zimbabwe?

Yes. Statutory Instrument 155 of 2024 requires that an officer is appointed and notified to the Authority on Form DP2, and that the officer meets the qualification requirements in section 13(1) and holds a certification approved by the Authority under section 13(2). It regulates the officer and the functions, not the employment relationship. Liability stays with the controller either way, under section 10(4)(a) of SI 155 and section 33(6) of the Act.

Who can be a Data Protection Officer?

Section 13(1) requires skill, qualifications or experience in data science, data analytics, information security systems, information systems audit, law, audit or any other relevant qualification, together with knowledge of national data protection laws and practices and an understanding of the controller’s business operations and processing activities. Section 13(2) additionally requires a certification course approved by the Authority.

Does a small business need a Data Protection Officer?

A licensed controller appoints one under section 12(1). At Tier 1, up to 1,000 records, the requirement applies where sensitive data is processed, such as health information, children’s data, biometric data or data revealing religious belief. Many small organisations reach that trigger without realising it, so it is confirmed at the consultation rather than assumed either way.

What happens if we do not appoint one?

Failing to appoint a Data Protection Officer is an offence under section 12(6) of SI 155 of 2024, carrying a fine of up to level 7 or imprisonment of up to two years or both. That is a lower maximum than the licensing offences, but an organisation with no officer generally also lacks the registers, procedures and training that the heavier offences are concerned with.

How much does an outsourced DPO cost in Zimbabwe?

The retainer is priced by the size of your organisation, and for a dedicated named officer by industry group as well. Rather than quote a figure that may not fit your situation, the calculator on our compliance page works it out from your sector, record volume and the type of officer you need. It starts when the licence is granted, and it is quoted separately from the POTRAZ fees, which are passed through at cost.

Can our IT manager or company secretary be the officer?

They can, if they meet section 13(1) and hold a certification approved by the Authority under section 13(2), and you should check that whoever trained them was accredited, because section 11(3) makes unaccredited certification training an offence. The practical difficulty is section 14, which requires the officer to monitor compliance and conduct internal compliance audits. Where the candidate also runs the systems under audit, they are auditing their own work.

What if our officer resigns?

Section 12(4) requires you to notify the Authority in writing within fourteen days of the termination of the contract, and section 12(5) gives you ninety days from that termination to appoint a replacement, who must themselves be certified and notified on a fresh Form DP2.

Get inspection-ready

A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.

Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.