What are the duties of a Data Protection Officer under SI 155 of 2024?
Short answer
Section 14 of SI 155 of 2024 gives the Data Protection Officer nine functions: monitor compliance with the Cyber and Data Protection Act; oversee internal processing activities; raise awareness and train staff; conduct audits; handle requests from POTRAZ and from data subjects; advise management on its obligations; advise on data protection impact assessments; cooperate with POTRAZ; and act as the contact point for data subjects.
What the law says
Section 14 of SI 155 lists the functions in those terms. Section 20 of the Act, which created the role, describes the DPO's purpose as ensuring compliance with the Act, handling data subject requests and working with the Authority on the controller's obligations. POTRAZ's DPO Guidelines add that the DPO should report to the highest management level, be involved in all data protection matters "properly and in a timely manner", and be given the resources needed to do the job.
Example
The DPO of a Tier 2 retail chain in Harare has a simple monthly rhythm. Week one: review the request log (two access requests, one marketing opt-out, all closed) and the incident register (one misdirected email, contained, not notifiable). Week two: spot-check one branch's handling of customer ID copies. Week three: 45-minute awareness session for new staff. Week four: one-page note to the managing director on open risks (the loyalty app vendor has not yet signed the processing agreement) and on the renewal date. Once a year she runs a fuller audit before the licence renewal is filed.
In practice
Turn section 14 into a calendar. The duties look daunting as a list but are manageable as a routine, and the routine is precisely what a POTRAZ inspector will ask to see: logs, training records, audit notes, management reports.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.