Licence and cost

Do I have to register CCTV, my website or my mobile app separately with POTRAZ?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

No separate POTRAZ licences are needed for CCTV, a website or a mobile app, but each is a processing activity you must describe in your licence application and notify to POTRAZ if it materially changes. SI 155 of 2024 also requires specific notification when you process biometric or genetic data and when you transfer personal data internationally.

What the law says

Section 10 of SI 155 requires the data controller to notify the Authority of "all processing activities", of modifications to indirectly collected data, of international data transfers and of biometric or genetic processing. The Act itself (section 12) restricts the processing of genetic and biometric data to cases of written consent or a listed exception. One licence covers the controller; the notifications keep POTRAZ informed of what the controller does.

Example

A fuel station chain in Harare has CCTV at 12 forecourts, a loyalty app with 25,000 users hosted on a server in Johannesburg, and a new fingerprint clock-in system for 180 staff. It needs one Tier 2 licence. Its Form DP1 must describe all three activities; the fingerprint system must be notified as biometric processing (with written staff consent under section 12); and the Johannesburg hosting must be notified as an international transfer with the lawful basis under sections 28 and 29.

In practice

List every system that touches personal information in your record of processing activities, mark the ones involving biometrics, children or foreign hosting, and make sure each is reflected in your licence application. When you add a new system, have the DPO update the record and, where required, notify POTRAZ.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.