The DPO role

Can my accountant, lawyer or IT provider act as my Data Protection Officer?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes. An accountant, lawyer or IT provider can be your Data Protection Officer in Zimbabwe if they hold the POTRAZ-approved DPO certification, understand your operations and are formally appointed and named on Form DP2. SI 155 of 2024 expressly lists law, audit and information security among relevant DPO backgrounds.

What the law says

Section 13 of SI 155 requires the DPO to have "skill, qualifications, or experience in" data science, data analytics, information security, audit, law "or any other relevant qualification", together with knowledge of national data protection law and an understanding of the controller's processing operations. Nothing restricts the DPO to employees. POTRAZ's DPO Guidelines recognise engagement under a service contract and emphasise the avoidance of conflicts of interest: the DPO should not be the person who determines the purposes and means of the processing they monitor.

Example

A law firm in Harare offers DPO services to twelve SME clients through one certified associate; each client signs a service agreement and files a Form DP2 naming her. A Bulawayo IT company also offers DPO services to the businesses whose servers it manages. That works, but with a caveat: for those clients the IT company designs the security it would also be auditing as DPO. A sensible arrangement has a director at each client sign off on the DPO's audit findings and keeps the DPO role in a separate contract from the IT support contract.

In practice

Put the engagement in writing: the section 14 functions, time commitment, access to management and records, confidentiality, breach response availability (the 24-hour clock does not wait for office hours), and fees. Attach the DPO's POTRAZ certificate to the Form DP2 you file.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.