The DPO role

Can a business owner be their own Data Protection Officer in Zimbabwe?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes, but only if you complete the POTRAZ-approved DPO certification and can actually perform the Data Protection Officer functions. Naming yourself without certification is not a valid appointment under SI 155 of 2024, and in a business with a management team the conflict of interest usually makes someone else the better choice.

What the law says

SI 155 requires every DPO to "undergo a certification course approved by the Authority" and to have the skills listed in section 13. Section 14 makes the DPO responsible for monitoring the controller's compliance and conducting audits. POTRAZ's DPO Guidelines stress independence: the DPO should be able to perform the functions without instruction on how to carry them out and without being penalised for doing so, and should report to the highest management level. An owner who also decides every processing purpose is monitoring themselves, which the Guidelines discourage where an alternative exists.

Example

A sole proprietor running a Tier 1 hardware shop in Chinhoyi with six staff completes the certification and appoints herself DPO. That is acceptable: there is no other management layer, and she genuinely does the tasks. By contrast, the managing director of a 120-employee transport company in Harare who names himself DPO "to keep control" is the person who decided to install GPS trackers and cameras in every cab; he cannot credibly audit that decision, and an inspector will ask why the HR or compliance manager was not appointed.

In practice

If you are the only manager, certify yourself and keep good written records so that your DPO decisions are visible. If you have a management team, appoint someone who does not set the processing purposes, give them direct access to you, and let them challenge you. Record their advice and your decisions.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.