External DPO
in Zimbabwe
Since SI 155 of 2024, holding data on 50 people or more means a licence and a Data Protection Officer of your own. We hold that role: a certified officer, filed with POTRAZ as your point of contact, who brings you into line with the Cyber and Data Protection Act and keeps you there.
What the Cyber and Data Protection Act asks of you
Data controller licence
POTRAZ registrationHold personal data on 50 people or more and you need a data controller licence from POTRAZ. It lasts 12 months, renewal has to be applied for 3 months before it lapses, and the fee depends on how many people you hold records about. Processing without a valid licence is a criminal offence.
We establish which tier you fall into, prepare and file Form DP1, deal with the Authority's questions, and hold the renewal calendar so your licence never quietly expires.
A certified Data Protection Officer
DPO appointmentEvery controller has to designate a Data Protection Officer and notify the Authority on Form DP2. That person needs real grounding in law, audit, data science or information security, has to complete approved certification, and keeps it current through continuing professional development.
We take the role under a written mandate and act as your registered point of contact, or we stand behind the colleague you appoint internally and carry the technical weight for them.
Records, requests and breach notification
Proof, and fastThe licence is only the beginning. You need a written record of every processing activity, a lawful basis attached to each one, an answer for anyone who asks to see or correct their file, and a notification to the Authority within 24 hours of learning that something has gone wrong. The Act makes the absence of documentation an offence in its own right.
We build the register with your department heads, attach a defensible basis to every purpose, run the requests from start to finish, and keep the incident procedure rehearsed so the 24 hour clock is never a surprise.
Four stages, from first inventory to standing mandate
Data protection services for controllers in Zimbabwe
DPO as a Service
Ongoing MandateA certified officer on retainer, named to the Authority as your point of contact, for a fraction of what the role costs as a full-time hire. The certification, the continuing development and the technical depth are ours to carry. Your side of the arrangement is one internal liaison who knows the business and can open doors for us.
Licensing Support
Registration and RenewalEverything between your first application and the licence on the wall, then the cycle that keeps it there. We establish which tier you fall into and write down the counting method behind it, because Form DP1 is signed under oath and has to be defensible a year later. All correspondence with the Authority comes through us.
Compliance Tools
Software and TemplatesCompliance that lives in a shared folder decays within months. We deploy web tools, built and hosted by our own development team, that hold the register, the consents, the requests and the deadlines in one place, with the statutory clocks running automatically rather than in somebody's head.
Consulting
Advisory and AuditSpecific questions answered by people who have read the instrument rather than a summary of it. Engagements run from a half-day workshop on one biometric project to a full programme leading up to an inspection, and you keep every document we produce.
Training
Awareness for Your TeamsMost breaches start with someone who did not know better. Sessions are built around your own systems and the situations your staff actually meet, in English, chiShona or isiNdebele, and they leave behind one-page memos that people keep rather than a slide deck nobody opens twice.
Foreign Controllers
Cross-Border ProcessingIf your company sits in Johannesburg, London or Paris but processes the data of people in Zimbabwe, the obligations still reach you. We give you a presence in Harare and translate between the framework you already run and the one that applies here, which is not the same framework however close it looks.
The toolkit we bring with us
Questions about POTRAZ licensing and the DPO role
Something else on your mind? Put your question to our assistant and get an answer on the Act, SI 155 of 2024 and what applies to your own situation.
What do we actually get when we appoint you?
A certified officer whose name goes on the filing as your point of contact, and all the work that sits behind that name: the register of processing activities built and kept current, the notices and policies written, your supplier contracts fixed, requests from individuals answered inside the deadlines, incidents notified on time, an annual internal audit, and a short quarterly report your board can act on.
What you do not get is a folder of templates and a wish of good luck.
Do we still need someone internally?
One person, and not a specialist. We ask for an internal liaison who knows how the business really works and can open doors for us, usually someone in operations, finance or human resources.
The demanding part is the discovery, and it is front-loaded: an hour or two with each department head, once. After that we write and you review. Most clients then spend under half a day a month on data protection, and they spend it reading rather than drafting.
The certification, the filings and the technical exposure stay with us. That is the point of the arrangement.
How quickly can you start?
The mandate can be signed and the appointment filed within days of a first conversation, which matters if you are already past a deadline. The assessment that establishes what you hold runs 2 to 3 weeks alongside it.
Building the framework behind it, the register, the notices, the supplier contracts and the training, takes 2 to 3 months. You are covered on the appointment from the moment the filing goes in.
Who deals with the Authority?
We do. The application, the questions that come back, the annual renewal, the notifications when you start something new, the routine correspondence, and the file an inspector asks to see.
Where a point of interpretation is genuinely unclear, we can ask the Authority for a formal view rather than guess, which puts your position on the record instead of leaving it to be argued about later.
And if you are calling because something has already slipped, a letter nobody answered, a request sitting untouched for 2 months, a licence that was never applied for, there is almost always a route back that is better than silence.
A laptop has just been stolen. What happens?
You call the line. In the first hours we work out with you whether this is notifiable, then draft the notification so that it is filed within 24 hours of the moment you became aware. Where the risk to the people concerned is high, they have to hear from you within 72 hours, and we write that message too.
After that we run the calendar behind the incident: the Authority's questions answered within 14 days, the closing report delivered at 21 days, the entry made in the breach register whether or not the incident was notified.
Your team spends the night containing the damage rather than drafting forms.
What does it cost, and what if we stop?
The retainer follows your licence tier and the number of processing activities we have to keep alive, so a 30-person business does not pay what a bank pays. Work outside the mandate, a large impact assessment or a full inspection preparation, is quoted before it starts.
The initial assessment is priced separately and stands on its own. If you decide to go no further, you keep the report and the licence application it feeds.
And if you leave later, you keep everything: the register, the policies, the notices, the logs and the audit files, in editable form and in your own systems. We notify the change of officer within the statutory window and hand over to whoever comes next. Nothing we build is locked to us.
Everything you need to know about the Act, SI 155 of 2024 and the DPO
Whether you need a POTRAZ licence, which tier you fall into, what a fine actually costs, who can be your Data Protection Officer, what happens in the 24 hours after a laptop goes missing. Every answer cites the section it comes from and works through a realistic Zimbabwean example. Free, and nothing to fill in.
Find out where you stand
A short conversation is usually enough to tell whether you need a licence, which tier you fall into, and how much work sits between you and compliance. No commitment, and you keep whatever we work out together.