The forms

POTRAZ Forms DP1, DP2 and DP3, and how to complete them

Statutory Instrument 155 of 2024 runs on three forms. Form DP1, in the First Schedule, is the Data Controller licence application and renewal. Form DP2, in the Third Schedule, notifies POTRAZ of your Data Protection Officer. Form DP3, in the Fourth Schedule, is the security breach notification. Lioncap Ventures prepares and files them for you.

Last updated 2026-09-02. Lioncap Ventures, Harare, Zimbabwe.

Key facts

Form DP1
Data Controller licence application and renewal, First Schedule to SI 155 of 2024
Form DP2
Data Protection Officer designation and appointment notification, Third Schedule
Form DP3
Security breach notification, Fourth Schedule
Where the forms come from
POTRAZ, at potraz.gov.zw
POTRAZ response time
Fourteen days from receipt of the application, under section 4(3)
Renewal deadline
At least three months before the licence expires, under section 5(2)

Three forms, three different jobs

Statutory Instrument 155 of 2024 carries four schedules. One of them sets the fees, and the other three are forms you will actually complete. They are not alternatives to one another and they are not filed at the same moment, which is the first thing to get straight.

DP1 gets you licensed. DP2 tells the regulator who inside your organisation is accountable. DP3 is the one you hope never to send, and the one you most need drafted in advance.

Form DP1, First Schedule
The application for a Data Controller licence. The same form is used again at renewal, so it is filed at least once a year for the life of the organisation.
Form DP2, Third Schedule
The Data Protection Officer designation and appointment notification. Filed when the officer is appointed, and again whenever the officer or their contact details change.
Form DP3, Fourth Schedule
The security breach notification. Section 19 of the Act gives you twenty four hours from a security breach to notify the Authority, so this one is prepared before you need it.

All three are obtained from POTRAZ. We prepare them from the information gathered at the consultation, you review and sign, and we file the bundle and handle the correspondence that follows.

Completing Form DP1

Section 4(2) requires a written application in Form DP1, submitted to the Authority together with the fee specified in the Second Schedule. The form itself is not difficult. What causes trouble is that several of the fields have consequences, and organisations fill them in casually.

  1. The registered name, exactly as registered

    POTRAZ licenses a legal entity, not a brand. The name on the DP1 must match the certificate of incorporation, trust deed or constitution character for character. A trading name, an abbreviation or a group name that differs from the registered entity is the single most common reason a filing has to be redone. Where a group runs several registered entities, each one applies separately in its own name.

  2. Controller or processor

    You are a controller if you determine the purposes and means of the processing, which is the test in section 4(1). You are a processor if you handle personal data on another organisation’s instructions. Many organisations are both at once, a controller for their own staff and customer data and a processor for work performed for clients. Getting this wrong means filing twice, so it is settled at the consultation before anything goes in.

  3. The number of data subjects

    This field sets your tier and therefore your fee, and it is a count of people rather than of files or documents. One customer with ten years of history is one data subject. The count includes current and former staff, seasonal and casual workers, customers, enquirers who never bought, suppliers and their contact people, and anyone on a mailing list. Under-counting here is not a saving, because section 7 makes submitting false information to the Authority an offence carrying up to level 11 or seven years.

  4. Sites and staff who handle personal data

    Branches, clinics, depots and any site where records are held or accessed, together with the number of staff who touch personal data. These feed the risk picture the regulator forms of you, and they should match what your record of processing activities says.

  5. Entity particulars and contact person

    Registered and physical address, contact person, email and telephone number. Use an address and a mailbox that will still be monitored in a year, because this is where correspondence and renewal reminders go.

  6. Proof of payment, from Tier 2 upwards

    The $30 application fee is paid before the application goes in, and proof of payment is attached to the DP1. Tier 1 does not attract the application fee, so a Tier 1 applicant attaches nothing here.

Section 4(3) then gives the Authority fourteen days to do one of three things: request further information or supporting documents, issue the licence, or reject the application and give reasons. A request for further information is common, and an application that is complete and internally consistent the first time is the only real way to shorten the process. Section 4(4) also allows the Authority to issue a licence with conditions attached, and section 5(1) makes the twelve month validity subject to compliance with those conditions, so read them when the licence arrives rather than filing it away.

Completing Form DP2

Section 12(1) requires a data controller to appoint a Data Protection Officer and to notify the Authority in writing, and section 12(2) requires that notice to be in Form DP2. Section 12(5) sets ninety days from promulgation, or from the termination of a previous officer’s contract, as the window in which the appointment is made.

DP2 is where the regulator learns that a named, qualified human being is accountable for compliance in your organisation, so the attachments matter more than the form.

The officer’s identity
Full name and a copy of the national identity document.
Qualifications
Educational and professional certificates, or the data protection officer certificate. Section 13(1) lists data science, data analytics, information security systems, information systems audit, law, audit or any other relevant qualification, together with knowledge of national data protection laws and practices and an understanding of your business operations and processing activities.
Certification
Section 13(2) requires every officer to have undergone a certification course approved by the Authority. Section 11(3) makes it an offence to provide that certification training without being accredited by the Authority, so check that whoever trained your officer was accredited.
Contact details
The officer’s telephone number, email address and physical address. Section 12(3) requires any change to these to be notified to the Authority within fourteen days.

Two obligations attach to DP2 after it is filed and are routinely missed. Section 12(4) requires you to notify the Authority in writing within fourteen days if the officer is dismissed or resigns, and section 12(5) then restarts the ninety day clock for appointing a replacement. Section 10(1) separately requires the controller to provide continuous professional development training to the officer, so that the certification stays current. Failing to appoint an officer at all is an offence under section 12(6), carrying a fine of up to level 7 or imprisonment of up to two years or both.

Form DP3, and the twenty four hour clock

Section 19 of the Cyber and Data Protection Act (Chapter 12:07) is a single sentence and it is the hardest deadline in the whole regime. The data controller shall notify the Authority within twenty four hours of any security breach affecting data it processes.

Twenty four hours is not enough time to work out what your process is. Organisations that meet it are the ones that decided in advance who is entitled to declare a breach, who drafts the notification, who signs it off, and where the blank DP3 is kept. Organisations that miss it are almost always the ones who spent the first day deciding whether it counted as a breach at all.

This is a large part of what an outsourced Data Protection Officer is actually for. A breach discovered late on a Friday does not wait for Monday, and the notification is a regulatory document rather than an email.

The documents to have ready before you start

Filings stall on missing attachments far more often than on the forms themselves. We ask for the complete set up front, every client, because a late document request is what turns a two week filing into a two month one.

The complete set goes in as one bundle. A submission that is disapproved has to be resubmitted as a complete new set, clearly marked as a resubmission, which is the other reason it pays to get the attachments right the first time.

Where these filings actually go wrong

After preparing these forms for a range of organisations, the same handful of problems account for most of the delay.

Every engagement begins with a $90 consultation, a one hour working session in which our data protection officers confirm your controller or processor status, map the records you hold, your sites and systems and the partners you share data with, and confirm your exact licence tier. The $90 is credited in full toward your compliance package when you proceed. Packages start at $250.

Frequently asked questions

What is Form DP1?

Form DP1 is the POTRAZ Data Controller licence application, set out in the First Schedule to Statutory Instrument 155 of 2024. Section 4(2) requires a written application in that form, submitted with the fee specified in the Second Schedule. The same form is used again for the annual renewal.

What is Form DP2?

Form DP2 is the Data Protection Officer designation and appointment notification, in the Third Schedule to Statutory Instrument 155 of 2024. Section 12(1) requires you to appoint an officer and notify the Authority in writing, and section 12(2) requires that notice to be in Form DP2. It is filed with the officer’s identity document and their qualification or certification documents.

What is Form DP3?

Form DP3 is the security breach notification, in the Fourth Schedule to Statutory Instrument 155 of 2024. Section 19 of the Cyber and Data Protection Act (Chapter 12:07) requires a data controller to notify the Authority within twenty four hours of any security breach affecting the data it processes.

Where do I get the POTRAZ forms?

The forms are obtained from POTRAZ at potraz.gov.zw, and they are reproduced as schedules to SI 155 of 2024. Lioncap Ventures prepares them from the information gathered at the consultation, so in practice you review and sign rather than complete them yourself.

How long does POTRAZ take to respond to a DP1?

Section 4(3) gives the Authority fourteen days from receiving the application to request further information or supporting documents, issue the licence, or reject the application with reasons. A request for further information is common, so a complete and internally consistent first submission is what actually shortens the process.

Do I file a new DP1 every year?

Yes. Section 5(1) makes the licence valid for twelve months, and section 5(2) requires a renewal application on the same Form DP1, with the fee, at least three months before the licence expires. Failing without just cause to renew by the expiry date is an offence under section 5(3).

What happens if our Data Protection Officer leaves?

Section 12(4) requires you to notify the Authority in writing within fourteen days of the termination of the officer’s contract, and section 12(5) gives you ninety days from that termination to appoint a replacement, notified on a fresh Form DP2.

Get inspection-ready

A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.

Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.