Is there a turnover threshold for POTRAZ data protection registration in Zimbabwe?
Short answer
No. There is no turnover or revenue threshold for POTRAZ data protection registration. SI 155 of 2024 sets the licence tiers by the number of people whose personal information you hold, not by turnover, staff count or company type.
What the law says
The First Schedule to SI 155 defines the four tiers purely by data subjects: Tier 1 (50 to 1,000), Tier 2 (1,001 to 100,000), Tier 3 (100,001 to 500,000) and Tier 4 (more than 500,000). The Second Schedule attaches the fees (USD 50, 300, 500 and 2,500). Nothing in the Act or the Regulations refers to revenue, and nothing exempts start-ups or micro-enterprises.
Example
A one-woman digital marketing consultancy in Harare has a newsletter list of 5,200 subscribers gathered over three years of webinars: she is Tier 2 (USD 300 a year plus USD 30 application) despite a modest income. A mining contractor in Zvishavane turning over millions of dollars, with 40 employees and no customer database, is below Tier 1 on data subjects (though it will need a licence for its 40 staff files once applicants and former staff are counted, which usually pushes it past 50).
In practice
Count people, not dollars. If your data subject count is much higher than your turnover would suggest (typical for newsletters, apps and loyalty programmes), consider pruning inactive contacts before you apply; lawful deletion of data you no longer need is good practice under the Act's storage-limitation principle and may keep you in a lower tier.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.