The DPO role

Can a junior employee be the Data Protection Officer to save money?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Legally the Data Protection Officer needs relevant skills or experience, knowledge of Zimbabwean data protection law, understanding of your business and POTRAZ certification; practically, the DPO must have enough standing to tell a director "we cannot do that" and be heard. A junior clerk rarely meets either test, and the certification fee is the same whoever you send.

What the law says

Section 13 of SI 155 requires "skill, qualifications, or experience in data science, data analytics, information security, audit, law or any other relevant qualification", plus knowledge of national data protection law and of the controller's operations. POTRAZ's DPO Guidelines expect the DPO to report to the highest management level and to perform the section 14 functions independently. A person with no authority over colleagues cannot conduct audits, enforce training or challenge a marketing decision.

Example

A wholesaler in Bulawayo names a 22-year-old filing clerk as DPO because "she has time". She passes the course but cannot get the sales director to stop buying customer lists from a broker, and she is not invited to management meetings. When POTRAZ investigates a complaint about unsolicited SMS, the company's defence that "our DPO was handling it" collapses on the first question about what management did with her advice. A competitor appointed its internal auditor, who reports to the board quarterly; the difference shows immediately.

In practice

Appoint someone with standing (finance, audit, compliance, HR or IT lead, or an experienced external DPO), give them a reporting line to the owner or board, and minute their reports. Junior staff can support the DPO with logs and training administration; they should not carry the role.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.