Inspection preparation

How to prepare for a POTRAZ inspection

Preparing for a POTRAZ inspection means being able to evidence each obligation, not merely to assert it. Section 24 of the Cyber and Data Protection Act (Chapter 12:07) requires a controller to have internal mechanisms for demonstrating compliance to the Authority. In practice that is a licence, a notified officer, current registers, working procedures and training records, assembled before the visit.

Last updated 2026-09-02. Lioncap Ventures, Harare, Zimbabwe.

Key facts

Inspections began
1 September 2026
The governing duty
Section 24 of the Act: take all necessary measures to comply, and have internal mechanisms to demonstrate that compliance to data subjects and the Authority
Licence validity
Twelve months, under section 5(1) of SI 155 of 2024
Breach notification
Within twenty four hours, under section 19 of the Act
Register of controllers
Public and inspectable, under section 9 of SI 155 of 2024
Preparation lead time
Four to six weeks for a small organisation starting from nothing

The standard is demonstration, not good intentions

Section 24 of the Cyber and Data Protection Act (Chapter 12:07) is the provision that shapes everything about how you prepare. It requires the data controller to take all necessary measures to comply with the principles and obligations in the Act, and separately to have the necessary internal mechanisms in place for demonstrating that compliance to both data subjects and the Authority.

Those are two different duties, and the second is the one organisations fail. A business can be handling personal data carefully and still be exposed, because careful handling that leaves no evidence is indistinguishable, from the outside, from no handling at all. Contravening section 24 is one of the five sections named in section 33(2), which carries a fine of up to level 11 or imprisonment of up to seven years or both.

Preparation, then, is not about tidying up before a visit. It is about producing the artefacts that make your compliance legible to somebody who has never met you.

One point worth being exact about, because a good deal of published commentary is not. The instruments express fines as a level on the standard scale rather than as an amount of money. The level is fixed in the law, but what a level is worth is set by the standard scale and revised from time to time. We therefore do not quote a dollar figure for a fine, and you should treat any website that does with caution. What is fixed, and what matters when you are weighing this up, is that these are criminal offences carrying prison terms rather than administrative charges.

The evidence file, obligation by obligation

The most useful thing you can build is a single file, physical or digital, in which every statutory obligation has a corresponding document behind it. Assemble it against the sections rather than against a generic checklist, because the sections are what you can actually be measured on.

A current Data Controller licence
Section 4 of SI 155. In the exact registered name of the entity, in date, with any conditions attached under section 4(4) noted and complied with.
The Data Protection Officer appointment
Sections 12 and 13. The filed Form DP2, the officer’s qualifications and approved certification, and evidence of the continuing professional development that section 10(1) requires you to provide.
A record of processing activities
Section 10(2)(a) requires notification of all processing activities performed on personal information. The register should match what the business actually does, including the systems nobody thinks of as systems.
Cross-border notifications
Section 10(2)(c) requires notification of any intention to transfer or share data subject information outside Zimbabwe. Cloud platforms hosted abroad and group access from a regional office both count.
Biometric and genetic processing notifications
Section 10(2)(d) singles these out. Fingerprint clocking and access control systems are the usual trigger, and they are usually undocumented.
Written agreements with every processor
Section 10(4)(f) requires a written data processing agreement, contract or legal instrument with each processor. Most organisations use several processors and have papered none of them.
Security measures
Section 18(4) of the Act requires appropriate technical and organisational measures against negligent or unauthorised destruction, negligent loss, unauthorised alteration or access, and any other unauthorised processing. Access control lists, encryption, backups and the decisions behind them.
The breach procedure
Section 19 of the Act and Form DP3. A written procedure, a named decision maker, and a prepared draft notification.
Data subject request procedure
Section 10(4)(d) requires measures to facilitate the exercise of data subject rights, and section 14 makes the officer the contact point for data subjects. A logged, timed process, with the log.
Impact assessments
Section 10(5)(d) requires regular data protection impact assessments where children’s data is processed. Elsewhere they are the natural evidence for higher risk processing.
Training records
Staff data protection training is mandatory for licensed controllers under CDPG 1 of 2025. Keep the attendance record, the date and the material, not just the assertion that training happened.

Build the file so that each row above can be answered by pointing at a document rather than by explaining. An inspection where every question is answered with a narrative is an inspection that produces findings.

Walk the building before anyone else does

Documents are only half of it. The other half is whether what the documents describe is what an inspector would see if they walked through your premises, and this is where the awkward findings come from.

Each of these maps back to section 18(4) of the Act, the duty to take appropriate technical and organisational measures. They are also, in our experience, the cheapest gaps to close and the most visible ones to leave open.

Make the documents agree with each other

A quieter failure mode, and one that is harder to talk your way out of, is a set of documents that individually look fine but contradict one another. An inspector reading across your file will notice before you do.

A realistic preparation timeline

Inspections began on 1 September 2026, so this is no longer forward planning. For an organisation starting from nothing, four to six weeks is a realistic run at it, and the order matters because each step depends on the one before.

  1. Week one: establish the position

    A gap analysis against the Act and SI 155, and the data subject count that settles your tier. This is what the consultation produces, and everything downstream depends on it being right rather than optimistic.

  2. Week one to two: license and appoint

    Form DP1 filed with the correct tier and attachments, the officer identified and Form DP2 prepared. Section 4(3) gives the Authority fourteen days to respond, so this starts early.

  3. Week two to four: build the registers and procedures

    Record of processing activities, privacy notice and consent wording, breach procedure, data subject request procedure, and the impact assessment where health, children’s or biometric data is involved.

  4. Week three to four: paper the third parties

    Written data processing agreements with every processor, under section 10(4)(f), and the cross-border notifications under section 10(2)(c). This step takes longest because it depends on other organisations responding.

  5. Week four to five: train, and record it

    Staff training, mandatory under CDPG 1 of 2025, with the attendance record kept as evidence rather than as an afterthought.

  6. Week five to six: remediate and rehearse

    Close the physical and access findings from the walkthrough, then run the breach procedure as a dry exercise against the twenty four hour clock in section 19. A procedure that has never been tested is a document, not a capability.

Where an inspection is already scheduled and the file is thin, the order changes: licence and officer first, because their absence is the most immediately actionable, then the registers, then everything else.

What to have settled before the day

Decide these things in advance rather than in the moment, and write the answers down where the person on reception can find them.

Where a gap is found, having a dated remediation plan already in existence is materially better than being told about the gap for the first time. That, again, is section 24: internal mechanisms for demonstrating compliance.

Frequently asked questions

What does a POTRAZ inspector ask to see?

An inspection tests the obligations the law actually imposes, so the file to have ready is a current Data Controller licence, the filed Form DP2 and the officer’s qualifications, a record of processing activities, notifications of cross-border and biometric processing, written agreements with your processors, evidence of the security measures required by section 18(4) of the Cyber and Data Protection Act (Chapter 12:07), a breach procedure, a data subject request procedure, impact assessments and staff training records.

How long does it take to prepare for a POTRAZ inspection?

For a small organisation starting from nothing, four to six weeks is realistic, because the steps depend on each other and because papering third party processors takes as long as those third parties take to respond. An organisation that is already licensed and simply needs its registers brought current can be ready considerably faster.

What is the most common gap organisations discover?

Written agreements with data processors. Section 10(4)(f) of SI 155 requires a written data processing agreement with each processor, and most organisations use several, the payroll bureau, the IT provider, the cloud platform, the archiving company, on nothing more than an invoice. The second most common is a record of processing activities that no longer matches the systems the business actually runs.

Do we need to be licensed before an inspection?

Yes, and being unlicensed is not a gap that can be closed on the day. Processing without a licence is an offence under section 3(3) of Statutory Instrument 155 of 2024, and the register of licensed controllers is public under section 9, so your status is visible before anyone visits.

Does our Data Protection Officer have to attend the inspection?

The officer is your contact point with the Authority under section 14 of SI 155, which includes working with the Authority in relation to the performance of its functions, so their attendance is the natural arrangement. Attending an inspection is one of the duties covered under our outsourced DPO retainer.

What happens if the inspection finds something?

Being able to show a dated remediation plan is materially better than being told about a gap for the first time, which is what the demonstration duty in section 24 is really about. Section 34 of the Act separately provides that any person aggrieved by a decision of the Authority may appeal to the Administrative Court.

Get inspection-ready

A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.

Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.