Inspection preparation
Preparing for a POTRAZ inspection means being able to evidence each obligation, not merely to assert it. Section 24 of the Cyber and Data Protection Act (Chapter 12:07) requires a controller to have internal mechanisms for demonstrating compliance to the Authority. In practice that is a licence, a notified officer, current registers, working procedures and training records, assembled before the visit.
Last updated 2026-09-02. Lioncap Ventures, Harare, Zimbabwe.
Section 24 of the Cyber and Data Protection Act (Chapter 12:07) is the provision that shapes everything about how you prepare. It requires the data controller to take all necessary measures to comply with the principles and obligations in the Act, and separately to have the necessary internal mechanisms in place for demonstrating that compliance to both data subjects and the Authority.
Those are two different duties, and the second is the one organisations fail. A business can be handling personal data carefully and still be exposed, because careful handling that leaves no evidence is indistinguishable, from the outside, from no handling at all. Contravening section 24 is one of the five sections named in section 33(2), which carries a fine of up to level 11 or imprisonment of up to seven years or both.
Preparation, then, is not about tidying up before a visit. It is about producing the artefacts that make your compliance legible to somebody who has never met you.
One point worth being exact about, because a good deal of published commentary is not. The instruments express fines as a level on the standard scale rather than as an amount of money. The level is fixed in the law, but what a level is worth is set by the standard scale and revised from time to time. We therefore do not quote a dollar figure for a fine, and you should treat any website that does with caution. What is fixed, and what matters when you are weighing this up, is that these are criminal offences carrying prison terms rather than administrative charges.
The most useful thing you can build is a single file, physical or digital, in which every statutory obligation has a corresponding document behind it. Assemble it against the sections rather than against a generic checklist, because the sections are what you can actually be measured on.
Build the file so that each row above can be answered by pointing at a document rather than by explaining. An inspection where every question is answered with a narrative is an inspection that produces findings.
Documents are only half of it. The other half is whether what the documents describe is what an inspector would see if they walked through your premises, and this is where the awkward findings come from.
Each of these maps back to section 18(4) of the Act, the duty to take appropriate technical and organisational measures. They are also, in our experience, the cheapest gaps to close and the most visible ones to leave open.
A quieter failure mode, and one that is harder to talk your way out of, is a set of documents that individually look fine but contradict one another. An inspector reading across your file will notice before you do.
Inspections began on 1 September 2026, so this is no longer forward planning. For an organisation starting from nothing, four to six weeks is a realistic run at it, and the order matters because each step depends on the one before.
A gap analysis against the Act and SI 155, and the data subject count that settles your tier. This is what the consultation produces, and everything downstream depends on it being right rather than optimistic.
Form DP1 filed with the correct tier and attachments, the officer identified and Form DP2 prepared. Section 4(3) gives the Authority fourteen days to respond, so this starts early.
Record of processing activities, privacy notice and consent wording, breach procedure, data subject request procedure, and the impact assessment where health, children’s or biometric data is involved.
Written data processing agreements with every processor, under section 10(4)(f), and the cross-border notifications under section 10(2)(c). This step takes longest because it depends on other organisations responding.
Staff training, mandatory under CDPG 1 of 2025, with the attendance record kept as evidence rather than as an afterthought.
Close the physical and access findings from the walkthrough, then run the breach procedure as a dry exercise against the twenty four hour clock in section 19. A procedure that has never been tested is a document, not a capability.
Where an inspection is already scheduled and the file is thin, the order changes: licence and officer first, because their absence is the most immediately actionable, then the registers, then everything else.
Decide these things in advance rather than in the moment, and write the answers down where the person on reception can find them.
Where a gap is found, having a dated remediation plan already in existence is materially better than being told about the gap for the first time. That, again, is section 24: internal mechanisms for demonstrating compliance.
An inspection tests the obligations the law actually imposes, so the file to have ready is a current Data Controller licence, the filed Form DP2 and the officer’s qualifications, a record of processing activities, notifications of cross-border and biometric processing, written agreements with your processors, evidence of the security measures required by section 18(4) of the Cyber and Data Protection Act (Chapter 12:07), a breach procedure, a data subject request procedure, impact assessments and staff training records.
For a small organisation starting from nothing, four to six weeks is realistic, because the steps depend on each other and because papering third party processors takes as long as those third parties take to respond. An organisation that is already licensed and simply needs its registers brought current can be ready considerably faster.
Written agreements with data processors. Section 10(4)(f) of SI 155 requires a written data processing agreement with each processor, and most organisations use several, the payroll bureau, the IT provider, the cloud platform, the archiving company, on nothing more than an invoice. The second most common is a record of processing activities that no longer matches the systems the business actually runs.
Yes, and being unlicensed is not a gap that can be closed on the day. Processing without a licence is an offence under section 3(3) of Statutory Instrument 155 of 2024, and the register of licensed controllers is public under section 9, so your status is visible before anyone visits.
The officer is your contact point with the Authority under section 14 of SI 155, which includes working with the Authority in relation to the performance of its functions, so their attendance is the natural arrangement. Attending an inspection is one of the duties covered under our outsourced DPO retainer.
Being able to show a dated remediation plan is materially better than being told about a gap for the first time, which is what the demonstration duty in section 24 is really about. Section 34 of the Act separately provides that any person aggrieved by a decision of the Authority may appeal to the Administrative Court.
A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.
Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.