Knowledge base

POTRAZ, DPO and CDPA: 100 questions answered for Zimbabwean organisations

Everything a data controller in Zimbabwe asks about the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ's 2025 Implementation Guidelines. Each answer gives you the position, the section it comes from, a realistic Zimbabwean example and what to do next. Search it, or work through a category.

Zimbabwe only · CDPA, SI 155 of 2024, Implementation Guidelines 2025 Reviewed 9 September 2026

Explore by category

Eight categories covering scope, licensing, the Data Protection Officer, training, tooling, penalties, day-to-day obligations, and what the whole exercise costs.

15 questions

Does the CDPA apply to me?

Whether the Cyber and Data Protection Act reaches small businesses, sole traders, NGOs, churches, schools, B2B companies, paper files, WhatsApp lists and foreign sellers, and whether you are a data controller or a data processor.

Open this category
15 questions

POTRAZ licence and fees

Tiers and fees under SI 155 of 2024, Form DP1, what documents you need, renewals, tier upgrades mid-year, group companies, late registration and whether POTRAZ can refuse or revoke a licence.

Open this category
20 questions

Data Protection Officer

Whether a Data Protection Officer is mandatory, whether you can appoint yourself, certification and exams, shared and outsourced DPOs, the 90-day replacement rule, personal liability of the DPO and of directors.

Open this category
8 questions

DPO and staff training

Whether data protection training is legally required, what frontline staff need, the cost and duration of DPO certification, which institutions POTRAZ approves, online delivery, and how to evidence training to an inspector.

Open this category
7 questions

Compliance software

Whether compliance software is required by law, what it should actually do for a Zimbabwean controller, where the data may be hosted, automated breach reporting, and whether Excel and WhatsApp are good enough.

Open this category
15 questions

Penalties and inspections

Fines in US dollars, prison terms, what POTRAZ checks during an inspection, how likely an inspection is, complaints from customers and ex-employees, director liability, civil claims and late registration.

Open this category
15 questions

Day-to-day obligations

Privacy notices, lawful grounds and consent, processor contracts, the 24-hour breach notification, subject access requests, erasure against tax retention, biometrics, CCTV signage, children's data, DPIAs and foreign hosting.

Open this category
5 questions

Cost and timeline

Total first-year cost for a small business, whether you need a lawyer, how long compliance takes from zero, what to do this week, and the minimum checklist.

Open this category

POTRAZ, DPO and CDPA key numbers

The figures and deadlines people look up most often, with the provision each one comes from.

QuestionAnswerSource
Who regulates data protection in Zimbabwe?POTRAZ (Data Protection Authority)Act s.5
Who is exempt from the POTRAZ licence?Personal/household use; journalistic, historical, archival (still register); law enforcementSI 155 s.8
Lowest POTRAZ licence tier50 data subjectsSI 155 First Schedule
POTRAZ licence feesT1 (50–1,000) USD 50; T2 (1,001–100,000) USD 300; T3 (100,001–500,000) USD 500; T4 (>500,000) USD 2,500; T2–T4 application fee USD 30SI 155 Second Schedule
Licence validity / renewal12 months; renew at least 3 months before expiry (Form DP1)SI 155
POTRAZ decision on application14 daysSI 155
Deadlines for existing controllers12 March 2025 (licence); 12 December 2024 (DPO)SI 155
Is a DPO mandatory?Yes, for every data controller; Form DP2; changes within 14 days; replacement within 90 daysSI 155 ss.11–14
DPO certification feeUSD 1,250 (citizens) / USD 1,450 (international)SI 155 Second Schedule
Data breach to POTRAZWithin 24 hours (Form DP3)Act s.19; SI 155
Data breach to individualsWithin 72 hours if high riskSI 155; POTRAZ Breach Guidelines 2025
Reply to POTRAZ breach queries14 days; POTRAZ aims to close within 21 daysSI 155
ChildrenUnder 18; parental/guardian consent; DPIAs; no ad profilingAct ss.3, 26; SI 155 s.10
Sensitive data (health, biometrics, beliefs, criminal record…)Written consent or narrow exceptionAct ss.11–12
Lawful grounds (non-sensitive data)Consent; legal obligation; vital interests; public task; evidence of an offence; legitimate interestsAct s.10
Penalty: no licence / core breachesFine up to level 11 (USD 1,000) or up to 7 years, or bothAct s.33; SI 155
Penalty: no DPOFine up to level 7 (USD 400) or up to 2 years, or bothSI 155
Appeals against POTRAZAdministrative CourtAct s.34
POTRAZ inspectionsFrom 1 September 2026, risk-based, nine priority sectorsPOTRAZ notice, July 2026

Fine amounts follow the Standard Scale of Fines Notice (SI 14A of 2023) and are updated by Government from time to time.

All 100 questions

Every question has its own page with the position, the section of the Act or of SI 155 it comes from, a realistic Zimbabwean example and what to do about it.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.