The DPO role

Is a Data Protection Officer (DPO) mandatory in Zimbabwe?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes. A Data Protection Officer (DPO) is mandatory for every data controller in Zimbabwe. SI 155 of 2024 requires each data controller to appoint a DPO and notify POTRAZ in writing on Form DP2, with no exemption based on size, sector or turnover. Failing to appoint one is a criminal offence.

What the law says

Section 20 of the Act introduced the Data Protection Officer and empowered the Authority to issue guidelines on the role. SI 155 made the appointment compulsory: every data controller "shall appoint a data protection officer" and "notify the Authority in writing" using Form DP2, initially "within 90 days from the date of promulgation" (by 12 December 2024). Sections 13 and 14 of SI 155 set the qualifications and functions, and a controller that fails to appoint a DPO is "liable to a fine not exceeding level 7 or to imprisonment not exceeding two years", or both. POTRAZ's 2025 Implementation Guidelines on the Appointment, Roles, Responsibilities, Training and Certification of DPOs add practical detail.

Example

A boarding school in Nyanga with 450 pupils and 60 staff argues that "schools don't need compliance officers". It is a data controller processing children's data, health data (medical forms) and religious data (denominational records), and under SI 155 it must have a DPO like any bank. Its bursar completes the POTRAZ-approved certification, is appointed by letter from the board, and is notified on Form DP2. The school is now one of the compliant institutions in POTRAZ's education priority sector rather than one of the many that are not.

In practice

Choose the person this week (see Q50), sign an appointment letter, book the POTRAZ-approved certification, and file Form DP2. A POTRAZ inspector's first two questions are "Where is your licence?" and "Who is your DPO?".

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.