The forms
Statutory Instrument 155 of 2024 runs on three forms. Form DP1, in the First Schedule, is the Data Controller licence application and renewal. Form DP2, in the Third Schedule, notifies POTRAZ of your Data Protection Officer. Form DP3, in the Fourth Schedule, is the security breach notification. Lioncap Ventures prepares and files them for you.
Last updated 2026-09-02. Lioncap Ventures, Harare, Zimbabwe.
Statutory Instrument 155 of 2024 carries four schedules. One of them sets the fees, and the other three are forms you will actually complete. They are not alternatives to one another and they are not filed at the same moment, which is the first thing to get straight.
DP1 gets you licensed. DP2 tells the regulator who inside your organisation is accountable. DP3 is the one you hope never to send, and the one you most need drafted in advance.
All three are obtained from POTRAZ. We prepare them from the information gathered at the consultation, you review and sign, and we file the bundle and handle the correspondence that follows.
Section 4(2) requires a written application in Form DP1, submitted to the Authority together with the fee specified in the Second Schedule. The form itself is not difficult. What causes trouble is that several of the fields have consequences, and organisations fill them in casually.
POTRAZ licenses a legal entity, not a brand. The name on the DP1 must match the certificate of incorporation, trust deed or constitution character for character. A trading name, an abbreviation or a group name that differs from the registered entity is the single most common reason a filing has to be redone. Where a group runs several registered entities, each one applies separately in its own name.
You are a controller if you determine the purposes and means of the processing, which is the test in section 4(1). You are a processor if you handle personal data on another organisation’s instructions. Many organisations are both at once, a controller for their own staff and customer data and a processor for work performed for clients. Getting this wrong means filing twice, so it is settled at the consultation before anything goes in.
This field sets your tier and therefore your fee, and it is a count of people rather than of files or documents. One customer with ten years of history is one data subject. The count includes current and former staff, seasonal and casual workers, customers, enquirers who never bought, suppliers and their contact people, and anyone on a mailing list. Under-counting here is not a saving, because section 7 makes submitting false information to the Authority an offence carrying up to level 11 or seven years.
Branches, clinics, depots and any site where records are held or accessed, together with the number of staff who touch personal data. These feed the risk picture the regulator forms of you, and they should match what your record of processing activities says.
Registered and physical address, contact person, email and telephone number. Use an address and a mailbox that will still be monitored in a year, because this is where correspondence and renewal reminders go.
The $30 application fee is paid before the application goes in, and proof of payment is attached to the DP1. Tier 1 does not attract the application fee, so a Tier 1 applicant attaches nothing here.
Section 4(3) then gives the Authority fourteen days to do one of three things: request further information or supporting documents, issue the licence, or reject the application and give reasons. A request for further information is common, and an application that is complete and internally consistent the first time is the only real way to shorten the process. Section 4(4) also allows the Authority to issue a licence with conditions attached, and section 5(1) makes the twelve month validity subject to compliance with those conditions, so read them when the licence arrives rather than filing it away.
Section 12(1) requires a data controller to appoint a Data Protection Officer and to notify the Authority in writing, and section 12(2) requires that notice to be in Form DP2. Section 12(5) sets ninety days from promulgation, or from the termination of a previous officer’s contract, as the window in which the appointment is made.
DP2 is where the regulator learns that a named, qualified human being is accountable for compliance in your organisation, so the attachments matter more than the form.
Two obligations attach to DP2 after it is filed and are routinely missed. Section 12(4) requires you to notify the Authority in writing within fourteen days if the officer is dismissed or resigns, and section 12(5) then restarts the ninety day clock for appointing a replacement. Section 10(1) separately requires the controller to provide continuous professional development training to the officer, so that the certification stays current. Failing to appoint an officer at all is an offence under section 12(6), carrying a fine of up to level 7 or imprisonment of up to two years or both.
Section 19 of the Cyber and Data Protection Act (Chapter 12:07) is a single sentence and it is the hardest deadline in the whole regime. The data controller shall notify the Authority within twenty four hours of any security breach affecting data it processes.
Twenty four hours is not enough time to work out what your process is. Organisations that meet it are the ones that decided in advance who is entitled to declare a breach, who drafts the notification, who signs it off, and where the blank DP3 is kept. Organisations that miss it are almost always the ones who spent the first day deciding whether it counted as a breach at all.
This is a large part of what an outsourced Data Protection Officer is actually for. A breach discovered late on a Friday does not wait for Monday, and the notification is a regulatory document rather than an email.
Filings stall on missing attachments far more often than on the forms themselves. We ask for the complete set up front, every client, because a late document request is what turns a two week filing into a two month one.
The complete set goes in as one bundle. A submission that is disapproved has to be resubmitted as a complete new set, clearly marked as a resubmission, which is the other reason it pays to get the attachments right the first time.
After preparing these forms for a range of organisations, the same handful of problems account for most of the delay.
Every engagement begins with a $90 consultation, a one hour working session in which our data protection officers confirm your controller or processor status, map the records you hold, your sites and systems and the partners you share data with, and confirm your exact licence tier. The $90 is credited in full toward your compliance package when you proceed. Packages start at $250.
Form DP1 is the POTRAZ Data Controller licence application, set out in the First Schedule to Statutory Instrument 155 of 2024. Section 4(2) requires a written application in that form, submitted with the fee specified in the Second Schedule. The same form is used again for the annual renewal.
Form DP2 is the Data Protection Officer designation and appointment notification, in the Third Schedule to Statutory Instrument 155 of 2024. Section 12(1) requires you to appoint an officer and notify the Authority in writing, and section 12(2) requires that notice to be in Form DP2. It is filed with the officer’s identity document and their qualification or certification documents.
Form DP3 is the security breach notification, in the Fourth Schedule to Statutory Instrument 155 of 2024. Section 19 of the Cyber and Data Protection Act (Chapter 12:07) requires a data controller to notify the Authority within twenty four hours of any security breach affecting the data it processes.
The forms are obtained from POTRAZ at potraz.gov.zw, and they are reproduced as schedules to SI 155 of 2024. Lioncap Ventures prepares them from the information gathered at the consultation, so in practice you review and sign rather than complete them yourself.
Section 4(3) gives the Authority fourteen days from receiving the application to request further information or supporting documents, issue the licence, or reject the application with reasons. A request for further information is common, so a complete and internally consistent first submission is what actually shortens the process.
Yes. Section 5(1) makes the licence valid for twelve months, and section 5(2) requires a renewal application on the same Form DP1, with the fee, at least three months before the licence expires. Failing without just cause to renew by the expiry date is an offence under section 5(3).
Section 12(4) requires you to notify the Authority in writing within fourteen days of the termination of the officer’s contract, and section 12(5) gives you ninety days from that termination to appoint a replacement, notified on a fresh Form DP2.
A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.
Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.