What is the minimum CDPA compliance checklist for a Zimbabwean business?
Short answer
Eight items: (1) a POTRAZ data controller licence in the right tier; (2) a certified Data Protection Officer notified on Form DP2; (3) a one-page record of processing activities; (4) a plain-language privacy notice; (5) written processing agreements with your processors; (6) security basics; (7) a one-page breach plan with the 24-hour and 72-hour deadlines and a pre-filled Form DP3; (8) an annual staff awareness session and CPD for the DPO.
What the law says
Each item answers a specific provision. Licence: SI 155 (Tier 1 USD 50; Tier 2 USD 300 plus USD 30). DPO: SI 155 sections 11 to 14 and the certification requirement (USD 1,250). Processing record: SI 155 section 10 and section 24 of the Act. Privacy notice: sections 15 and 16 of the Act. Processor agreements: section 18 of the Act and SI 155 section 10. Security basics (passwords, two-factor authentication, backups, encryption, need-to-know access): section 18 of the Act and SI 155 section 16. Breach plan: section 19 (24 hours to POTRAZ) and the 72-hour rule for high-risk breaches. Training: SI 155 sections 10 (CPD) and 14 (staff training), and section 16 (policies and testing).
Example
A Tier 1 dental practice in Harare with 9 staff and 900 patients keeps the eight items in a single binder and in its compliance software: licence certificate and renewal date; the practice manager's DPO appointment letter and POTRAZ certificate; a one-page processing record (patients, staff, suppliers, the practice-management software vendor in South Africa, CCTV in reception); a patient privacy notice and written consent form for health data; signed annexes with the software vendor and the accountant; encrypted laptops, a password manager, daily backups and role-based access; a breach plan with the IT contractor's number and a pre-filled Form DP3; and last year's staff session register plus the DPO's CPD certificate. An inspector's ninety minutes are spent confirming that the binder reflects reality.
In practice
Business Science Institute provides the training for items 2 and 8 and the software that holds items 3 to 7 and reminds you of every deadline. Together the eight items protect you from the two criminal offences POTRAZ inspectors look for first (no licence: up to seven years; no DPO: up to two years) and from the far more common everyday risk: a complaint or a stolen laptop you cannot answer.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.