Licence and cost

Can a group of companies share one POTRAZ data controller licence?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

No. Each legal entity that decides why and how it processes personal information is its own data controller and needs its own POTRAZ licence under SI 155 of 2024. A group can, however, share a single certified Data Protection Officer.

What the law says

The Act attaches the duties of a data controller to the "natural person or legal person" that determines the purposes and means of processing (section 3). A subsidiary is a separate legal person, with its own employees, customers and contracts, so it is a separate controller. SI 155 licenses "data controllers", not groups. By contrast, nothing in SI 155 prevents one certified person acting as DPO for several controllers, and POTRAZ's DPO Guidelines accept this as long as the person can genuinely perform the role for each.

Example

A Harare group owns a retail chain (Tier 2), a property company (Tier 1) and a small insurance broker (Tier 1). It needs three licences: USD 330 plus USD 50 plus USD 50 in year one. It appoints its group compliance manager, once certified (USD 1,250), as DPO for all three companies, filing three Forms DP2 naming the same person and making sure she has time for all three audits and breach plans.

In practice

License each entity, keep a group compliance calendar with all three renewal dates, and use one DPO, one set of policies and one software instance to keep the cost of three licences close to the cost of one.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.