Inspections
POTRAZ inspections under the Cyber and Data Protection Act begin on 1 September 2026, and Regulatory Notice 2 of 2026 names nine first wave sectors. An inspector asks for your Data Controller licence, your record of processing, your privacy policy, your breach and data subject request procedures, your staff training records and evidence that paper files are secure.
Last updated 2026-08-28. Lioncap Ventures, Harare, Zimbabwe.
POTRAZ Regulatory Notice 2 of 2026 named nine sectors in the first wave of mandatory inspections. If your organisation falls into one of these, you should assume you are in scope from the start rather than at some later date:
Being outside the first wave is a matter of sequencing, not exemption. The licensing obligation under SI 155 of 2024 applies to every data controller in Zimbabwe regardless of sector, and operating without a licence is already an offence.
An inspection is a documentary exercise before it is anything else. The inspector is establishing whether the organisation can evidence what it claims. These are the items to have ready:
Across the assessments we run, the same gaps recur. None of them are exotic, and all of them are fixable before an inspection rather than after one.
Expect a documentary review, questions to the people who actually handle personal data, and a walk through of where records are physically kept. Inspectors talk to staff, not only to management, which is why training matters beyond the certificate: an employee who cannot say what to do when a customer asks for their data is itself a finding.
Having your Data Protection Officer present changes the character of the visit. The officer answers for the compliance file, produces the documents and takes any follow up items away as actions. Attending an inspection with you is part of what the officer role covers.
If you are starting from nothing, the order matters. Get the licence application in, because being unlicensed is the finding that stands on its own. Then close the training gap, because it is the only item that cannot be produced on demand. Then document: the record of processing, the privacy policy, the breach and data subject request procedures. Then remediate the technical items: encryption, the secure sharing channel, CCTV signage and retention.
Practically, a small organisation can be documented and filed within one to two weeks. Every engagement begins with a $90 consultation, a one hour working session in which our data protection officers confirm your controller or processor status, map the records you hold, your sites and systems and the partners you share data with, and confirm your exact licence tier. The $90 is credited in full toward your compliance package when you proceed. Packages start at $250.
Once inspections begin, being unlicensed or undocumented exposes you to enforcement action and penalties under the Act. That is the reason to act now rather than to wait and see how the first wave goes.
If you have already missed a step, we fast track the essentials first: the licence application, the training, and the documents an inspector asks for on the day. The remaining remediation follows on a plan you can show, which is a materially better position than having nothing at all.
POTRAZ inspections under the Cyber and Data Protection Act begin on 1 September 2026, under Regulatory Notice 2 of 2026, which names nine first wave sectors.
The nine named first wave sectors are Financial institutions, Insurance companies, Local authorities, Healthcare providers, Mining enterprises, Religious organisations, Schools & tertiary institutions, Government ministries & agencies (MDAs), NGOs & Private Voluntary Organisations. Organisations outside these sectors are not exempt from licensing; they are simply later in the sequence.
Your Data Controller licence, the identity of your appointed Data Protection Officer, your record of processing activities, your privacy policy and consent wording, your data protection impact assessment where it applies, your breach and data subject access request procedures, your staff training records, evidence that paper records are secure, and your third party data processing and sharing agreements.
Yes. Filing rooms, registers and archives are in scope and are inspected. Every Lioncap package includes a physical records security checklist so paper files meet the same standard as digital ones.
Once inspections begin, being unlicensed or undocumented exposes you to enforcement action and penalties under the Act. The safest path is to get licensed and inspection ready now. If you have already missed a step, we can fast track the essentials first.
A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.
Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.