External DPO
in Zimbabwe

Since SI 155 of 2024, holding data on 50 people or more means a licence and a Data Protection Officer of your own. We hold that role: a certified officer, filed with POTRAZ as your point of contact, who brings you into line with the Cyber and Data Protection Act and keeps you there.

Breach Desk
A laptop holding our client database was stolen last night. What do we do?
This is a reportable breach. Your Form DP3 notification to POTRAZ is drafted and due within 24 hours. Because the file was unencrypted, the 4,200 clients concerned must be told within 72 hours. Start containment now: revoke the device certificate and force a password reset.
Licensing
We hold records on roughly 3,000 customers. Which licence do we need?
That places you in Tier 2, plus a $30 application fee on Form DP1.
Tier 1 50 to 1,000 data subjects
$50
Tier 3 100,001 to 500,000 subjects
$500
Compliance
218 Days to renewal
34 Activities logged
3 Open requests
0 Open breaches
Requests handled per month
Calendar
File Form DP2 for DPO 09:00
Update processing register 11:00
Impact assessment, HR system 14:00
Privacy training, sales team 16:00
Data Subject Requests
4 Open
1 Due soon
62 Closed
Access request 2 days left
Erasure request 9 days left
Correction request 21 days left
Readiness
Human Resources 12 activities
88%
Finance 8 activities
61%
Marketing 6 activities
24%
Operations 9 activities
74%
Updated continuously
Your obligations

What the Cyber and Data Protection Act asks of you

Data controller licence

POTRAZ registration

Hold personal data on 50 people or more and you need a data controller licence from POTRAZ. It lasts 12 months, renewal has to be applied for 3 months before it lapses, and the fee depends on how many people you hold records about. Processing without a valid licence is a criminal offence.

We establish which tier you fall into, prepare and file Form DP1, deal with the Authority's questions, and hold the renewal calendar so your licence never quietly expires.

A certified Data Protection Officer

DPO appointment

Every controller has to designate a Data Protection Officer and notify the Authority on Form DP2. That person needs real grounding in law, audit, data science or information security, has to complete approved certification, and keeps it current through continuing professional development.

We take the role under a written mandate and act as your registered point of contact, or we stand behind the colleague you appoint internally and carry the technical weight for them.

Records, requests and breach notification

Proof, and fast

The licence is only the beginning. You need a written record of every processing activity, a lawful basis attached to each one, an answer for anyone who asks to see or correct their file, and a notification to the Authority within 24 hours of learning that something has gone wrong. The Act makes the absence of documentation an offence in its own right.

We build the register with your department heads, attach a defensible basis to every purpose, run the requests from start to finish, and keep the incident procedure rehearsed so the 24 hour clock is never a surprise.

How we work

Four stages, from first inventory to standing mandate

What we offer

Data protection services for controllers in Zimbabwe

DPO as a Service

Ongoing Mandate

A certified officer on retainer, named to the Authority as your point of contact, for a fraction of what the role costs as a full-time hire. The certification, the continuing development and the technical depth are ours to carry. Your side of the arrangement is one internal liaison who knows the business and can open doors for us.

Named officer filed on Form DP2
Requests from individuals handled end to end
Breach line open around the clock
ROPA kept current as your systems change
Annual internal audit programme
Quarterly report your board can read

Licensing Support

Registration and Renewal

Everything between your first application and the licence on the wall, then the cycle that keeps it there. We establish which tier you fall into and write down the counting method behind it, because Form DP1 is signed under oath and has to be defensible a year later. All correspondence with the Authority comes through us.

Tier assessment and documented counting method
Form DP1 built as a reusable master file
Form DP2 and the 14-day change notices
Notification of processing activities
Renewal filed at the 9-month mark
Licence conditions tracked and evidenced

Compliance Tools

Software and Templates

Compliance that lives in a shared folder decays within months. We deploy web tools, built and hosted by our own development team, that hold the register, the consents, the requests and the deadlines in one place, with the statutory clocks running automatically rather than in somebody's head.

ROPA covering the 13 statutory headings
DSAR tracker with identity checks built in
Incident log with 24, 72 and 21 day timers
Consent and withdrawal trail
Processor register with assessment scores
Compliance dashboard by department

Consulting

Advisory and Audit

Specific questions answered by people who have read the instrument rather than a summary of it. Engagements run from a half-day workshop on one biometric project to a full programme leading up to an inspection, and you keep every document we produce.

Gap assessment and diagnostic note
DPIA for biometrics, monitoring and new systems
Transfer adequacy analysis for cloud hosting
Processor clauses for supplier contracts
Inspection file and audit readiness
Sector code of conduct watch

Training

Awareness for Your Teams

Most breaches start with someone who did not know better. Sessions are built around your own systems and the situations your staff actually meet, in English, chiShona or isiNdebele, and they leave behind one-page memos that people keep rather than a slide deck nobody opens twice.

Awareness sessions for staff
Briefings for management and boards
Induction pack for new joiners
Tabletop exercises on realistic incidents
Memos for lost devices, leaks and AI tools
Attendance records that stand as evidence

Foreign Controllers

Cross-Border Processing

If your company sits in Johannesburg, London or Paris but processes the data of people in Zimbabwe, the obligations still reach you. We give you a presence in Harare and translate between the framework you already run and the one that applies here, which is not the same framework however close it looks.

Local point of contact in Harare
Licensing for foreign-owned entities
Mapping against your GDPR programme
Written adequacy analysis for each transfer
Intra-group transfer arrangements
Group whistleblowing lines and their approvals

The toolkit we bring with us

Registers and records
ROPA covering the 13 headings of section 22
Breach register, including incidents you did not notify
DSAR log, timestamped from the day of receipt
Processor inventory with written assessments
Consent and withdrawal trail
Independence and conflicts of interest register
Training attendance and audit programme
Policies and notices
Privacy notices for customers and for staff
Retention schedule tied to statutory periods
IT and data use charter
Workplace monitoring and messaging policies
Data processing agreements for your suppliers
Joint controllership and intra-group agreements
Versions in English, chiShona and isiNdebele
Procedures and playbooks
Breach response with a pre-filled Form DP3
Incident qualification matrix and risk scoring grid
Handling, refusing and redacting requests
Crisis holding statements, written before the crisis
One-page memos for staff on the situations that recur
What to do if inspectors arrive
Annual compliance calendar with every deadline
Questions we are asked

Questions about POTRAZ licensing and the DPO role

Something else on your mind? Put your question to our assistant and get an answer on the Act, SI 155 of 2024 and what applies to your own situation.

What do we actually get when we appoint you?

A certified officer whose name goes on the filing as your point of contact, and all the work that sits behind that name: the register of processing activities built and kept current, the notices and policies written, your supplier contracts fixed, requests from individuals answered inside the deadlines, incidents notified on time, an annual internal audit, and a short quarterly report your board can act on.

What you do not get is a folder of templates and a wish of good luck.

Do we still need someone internally?

One person, and not a specialist. We ask for an internal liaison who knows how the business really works and can open doors for us, usually someone in operations, finance or human resources.

The demanding part is the discovery, and it is front-loaded: an hour or two with each department head, once. After that we write and you review. Most clients then spend under half a day a month on data protection, and they spend it reading rather than drafting.

The certification, the filings and the technical exposure stay with us. That is the point of the arrangement.

How quickly can you start?

The mandate can be signed and the appointment filed within days of a first conversation, which matters if you are already past a deadline. The assessment that establishes what you hold runs 2 to 3 weeks alongside it.

Building the framework behind it, the register, the notices, the supplier contracts and the training, takes 2 to 3 months. You are covered on the appointment from the moment the filing goes in.

Who deals with the Authority?

We do. The application, the questions that come back, the annual renewal, the notifications when you start something new, the routine correspondence, and the file an inspector asks to see.

Where a point of interpretation is genuinely unclear, we can ask the Authority for a formal view rather than guess, which puts your position on the record instead of leaving it to be argued about later.

And if you are calling because something has already slipped, a letter nobody answered, a request sitting untouched for 2 months, a licence that was never applied for, there is almost always a route back that is better than silence.

A laptop has just been stolen. What happens?

You call the line. In the first hours we work out with you whether this is notifiable, then draft the notification so that it is filed within 24 hours of the moment you became aware. Where the risk to the people concerned is high, they have to hear from you within 72 hours, and we write that message too.

After that we run the calendar behind the incident: the Authority's questions answered within 14 days, the closing report delivered at 21 days, the entry made in the breach register whether or not the incident was notified.

Your team spends the night containing the damage rather than drafting forms.

What does it cost, and what if we stop?

The retainer follows your licence tier and the number of processing activities we have to keep alive, so a 30-person business does not pay what a bank pays. Work outside the mandate, a large impact assessment or a full inspection preparation, is quoted before it starts.

The initial assessment is priced separately and stands on its own. If you decide to go no further, you keep the report and the licence application it feeds.

And if you leave later, you keep everything: the register, the policies, the notices, the logs and the audit files, in editable form and in your own systems. We notify the change of officer within the statutory window and hand over to whoever comes next. Nothing we build is locked to us.

Knowledge base

Everything you need to know about the Act, SI 155 of 2024 and the DPO

Whether you need a POTRAZ licence, which tier you fall into, what a fine actually costs, who can be your Data Protection Officer, what happens in the 24 hours after a laptop goes missing. Every answer cites the section it comes from and works through a realistic Zimbabwean example. Free, and nothing to fill in.

Open the knowledge base 100 questions · Zimbabwe only · reviewed 9 September 2026

Find out where you stand

A short conversation is usually enough to tell whether you need a licence, which tier you fall into, and how much work sits between you and compliance. No commitment, and you keep whatever we work out together.