Knowledge base · 5 questions

Total cost and timeline of CDPA compliance in Zimbabwe

Five questions that put a number and a date on the whole exercise. Total first-year cost for a small business, whether you need a lawyer, how long compliance takes from zero, what to do this week, and the minimum checklist.

Zimbabwe only · CDPA, SI 155 of 2024, Implementation Guidelines 2025 Reviewed 9 September 2026

Compliance is cheaper than most owners expect and slower than most expect. The licence itself starts at USD 50 a year. The first-year cost is dominated by the DPO certification and by the time it takes to find out what personal data you actually hold, which is the step nobody can skip.

What is the total cost of POTRAZ data protection compliance for a small business?

For a Tier 1 business with an internal Data Protection Officer, roughly USD 1,300 to USD 2,000 in the first year: the POTRAZ licence (USD 50), the DPO certification (USD 1,250), a staff awareness session and basic security you should have anyway. In later years the licence (USD 50), CPD for the DPO and any software subscription.

The mandatory costs are fixed in SI 155's Second Schedule: the tier licence fee (USD 50 for Tier 1, USD 300 plus USD 30 for Tier 2) and the DPO certification (USD 1,250 for citizens). Section 10 of SI 155 adds an annual CPD expectation for the DPO. The other costs are how you meet the general duties: section 18 security (password manager,…

Read the full answer, with the law and an example

Do I need a lawyer for POTRAZ data protection compliance, or can I do it myself?

Most SMEs can do the core work themselves: count data subjects, complete Forms DP1 and DP2, write a one-page processing record and privacy notice, sign processor annexes and set up security basics. A lawyer is worth engaging for specific problems: complex group structures, cross-border transfers of sensitive data, a POTRAZ complaint or inspection finding, an appeal, or a serious breach.

Nothing in the Act or SI 155 requires legal representation for licensing or DPO appointment; the forms are designed to be completed by the controller, and the DPO certification course exists precisely to give a non-lawyer the knowledge to run compliance. Section 13 of SI 155 lists law as one of several acceptable DPO backgrounds, alongsid…

Read the full answer, with the law and an example

How long does it take to become CDPA-compliant in Zimbabwe from zero?

Most small businesses can be inspection-ready in six to eight weeks. POTRAZ licence and Data Protection Officer notification take two to four weeks (POTRAZ decides on the licence within 14 days); DPO certification about two weeks of course plus the examination; basic documents a week of focused DPO work; security basics a few days with your IT provider.

SI 155 gives POTRAZ 14 days to approve or reject a licence application. The certification course length is set by the approved provider (about two weeks at the first accredited institution). The documents map to sections 15 and 16 of the Act (privacy notice), section 10 of SI 155 (processing record, processor agreements), section 18 and S…

Read the full answer, with the law and an example

What should I do this week if my business has done nothing about POTRAZ compliance?

Five actions. (1) Count how many people's data you hold and note your POTRAZ tier. (2) Choose your Data Protection Officer and book the POTRAZ-approved certification, or engage an external certified DPO. (3) Download Forms DP1 and DP2, complete them, pay the tier fee and file. (4) Tell staff in writing that customer and employee data stays on company-controlled systems and that any suspected breach goes to the DPO immediately. (5) Diarise the licence renewal and the DPO's CPD.

Actions 1 to 3 satisfy SI 155's licensing and DPO requirements (First Schedule tiers, Forms DP1 and DP2, certification). Action 4 is the first organisational measure under section 18 of the Act and gives you a fighting chance of meeting the 24-hour breach deadline in section 19. Action 5 addresses SI 155's three-month renewal rule and the…

Read the full answer, with the law and an example

What is the minimum CDPA compliance checklist for a Zimbabwean business?

Eight items: (1) a POTRAZ data controller licence in the right tier; (2) a certified Data Protection Officer notified on Form DP2; (3) a one-page record of processing activities; (4) a plain-language privacy notice; (5) written processing agreements with your processors; (6) security basics; (7) a one-page breach plan with the 24-hour and 72-hour deadlines and a pre-filled Form DP3; (8) an annual staff awareness session and CPD for the DPO.

Each item answers a specific provision. Licence: SI 155 (Tier 1 USD 50; Tier 2 USD 300 plus USD 30). DPO: SI 155 sections 11 to 14 and the certification requirement (USD 1,250). Processing record: SI 155 section 10 and section 24 of the Act. Privacy notice: sections 15 and 16 of the Act. Processor agreements: section 18 of the Act and SI …

Read the full answer, with the law and an example

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.