Inspections

POTRAZ inspections: what to expect from 1 September 2026

POTRAZ inspections under the Cyber and Data Protection Act begin on 1 September 2026, and Regulatory Notice 2 of 2026 names nine first wave sectors. An inspector asks for your Data Controller licence, your record of processing, your privacy policy, your breach and data subject request procedures, your staff training records and evidence that paper files are secure.

Last updated 2026-08-28. Lioncap Ventures, Harare, Zimbabwe.

Key facts

Inspections begin
1 September 2026
Authority
POTRAZ Regulatory Notice 2 of 2026, under the Cyber and Data Protection Act
First wave
Nine named sectors
Scope
Digital and paper records, policies, procedures, training records
Most common gap
Missing staff training records under CDPG 1 of 2025

Who is inspected first

POTRAZ Regulatory Notice 2 of 2026 named nine sectors in the first wave of mandatory inspections. If your organisation falls into one of these, you should assume you are in scope from the start rather than at some later date:

Being outside the first wave is a matter of sequencing, not exemption. The licensing obligation under SI 155 of 2024 applies to every data controller in Zimbabwe regardless of sector, and operating without a licence is already an offence.

What an inspector asks to see

An inspection is a documentary exercise before it is anything else. The inspector is establishing whether the organisation can evidence what it claims. These are the items to have ready:

Your Data Controller licence
Proof that you are registered with POTRAZ, and that the registration is current.
Your Data Protection Officer
Who the appointed officer is, and confirmation that they were notified to POTRAZ.
Record of processing activities
What personal data you hold, why you hold it, where it is stored and for how long you keep it.
Privacy policy and consent wording
A published policy, and the wording you actually use when you collect data.
Data protection impact assessment
Required where you process sensitive personal data at scale or in a high risk way, including health and children’s data.
Breach response procedure
A written procedure, and evidence that your people know it exists.
Data subject access request procedure
How a person asks what you hold about them, and how you respond within the time allowed.
Staff training records
Evidence that staff who handle personal data have been trained under CDPG 1 of 2025.
Physical records security
How filing rooms, registers and archives are secured and access controlled.
Third party agreements
Data processing agreements and data sharing agreements with the parties you share data with.

The findings that come up most often

Across the assessments we run, the same gaps recur. None of them are exotic, and all of them are fixable before an inspection rather than after one.

Personal details sent over ordinary email or messaging
One of the most common findings. Sending personal details over an unsecured channel risks interception and breaches the rules on transmitting sensitive data. The fix is a secure sharing channel and a documented procedure.
No staff training record
Training is mandatory under CDPG 1 of 2025 and the record is the evidence. It cannot be produced retrospectively, which makes it the gap worth closing first.
Unencrypted laptops and desktops
If a machine is lost or stolen, unencrypted files are exposed. Full disk encryption is a same day fix on most modern machines.
Unassessed cross border transfers
Overseas email, cloud storage, an overseas supplier or a head office abroad all move personal data outside Zimbabwe. Each flow has to be assessed and may need notification to POTRAZ.
CCTV without signage or a retention rule
CCTV footage is personal data. Signage, a documented purpose and a retention period are required.
Paper files left out of scope
Filing rooms, registers and archives are inspected. Paper has to meet the same standard as digital.

How an inspection runs

Expect a documentary review, questions to the people who actually handle personal data, and a walk through of where records are physically kept. Inspectors talk to staff, not only to management, which is why training matters beyond the certificate: an employee who cannot say what to do when a customer asks for their data is itself a finding.

Having your Data Protection Officer present changes the character of the visit. The officer answers for the compliance file, produces the documents and takes any follow up items away as actions. Attending an inspection with you is part of what the officer role covers.

How to prepare in the time you have

If you are starting from nothing, the order matters. Get the licence application in, because being unlicensed is the finding that stands on its own. Then close the training gap, because it is the only item that cannot be produced on demand. Then document: the record of processing, the privacy policy, the breach and data subject request procedures. Then remediate the technical items: encryption, the secure sharing channel, CCTV signage and retention.

Practically, a small organisation can be documented and filed within one to two weeks. Every engagement begins with a $90 consultation, a one hour working session in which our data protection officers confirm your controller or processor status, map the records you hold, your sites and systems and the partners you share data with, and confirm your exact licence tier. The $90 is credited in full toward your compliance package when you proceed. Packages start at $250.

If you are not licensed yet

Once inspections begin, being unlicensed or undocumented exposes you to enforcement action and penalties under the Act. That is the reason to act now rather than to wait and see how the first wave goes.

If you have already missed a step, we fast track the essentials first: the licence application, the training, and the documents an inspector asks for on the day. The remaining remediation follows on a plan you can show, which is a materially better position than having nothing at all.

Frequently asked questions

When do POTRAZ inspections start?

POTRAZ inspections under the Cyber and Data Protection Act begin on 1 September 2026, under Regulatory Notice 2 of 2026, which names nine first wave sectors.

Which sectors are inspected first?

The nine named first wave sectors are Financial institutions, Insurance companies, Local authorities, Healthcare providers, Mining enterprises, Religious organisations, Schools & tertiary institutions, Government ministries & agencies (MDAs), NGOs & Private Voluntary Organisations. Organisations outside these sectors are not exempt from licensing; they are simply later in the sequence.

What documents will an inspector ask for?

Your Data Controller licence, the identity of your appointed Data Protection Officer, your record of processing activities, your privacy policy and consent wording, your data protection impact assessment where it applies, your breach and data subject access request procedures, your staff training records, evidence that paper records are secure, and your third party data processing and sharing agreements.

Do inspectors look at paper records?

Yes. Filing rooms, registers and archives are in scope and are inspected. Every Lioncap package includes a physical records security checklist so paper files meet the same standard as digital ones.

What if we miss 1 September 2026?

Once inspections begin, being unlicensed or undocumented exposes you to enforcement action and penalties under the Act. The safest path is to get licensed and inspection ready now. If you have already missed a step, we can fast track the essentials first.

Get inspection-ready

A $90 consultation begins any engagement and is credited toward your package if you proceed. Existing Lioncap Ventures clients save 10% on the service fee.

Contact Lioncap Ventures: email [email protected] or WhatsApp +263772724514.