Compliance tools

What should CDPA compliance software do for a Zimbabwean business?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Eight things: hold your record of processing activities; log data-subject requests; run an incident and breach register with the 24-hour (POTRAZ) and 72-hour (individuals) timers and a Form DP3 template; keep consent and privacy-notice records; track processors and their contracts; show a licence and DPO dashboard with renewal and 14-day notification reminders; store training records; and produce audit reports for POTRAZ.

What the law says

Each module maps to a legal duty: the processing record to section 10 of SI 155 (notify all processing activities); the request log to section 14 of the Act (access, correction, deletion, objection); the breach register to section 19 (24 hours) and the SI 155 / Guidelines 72-hour rule for high-risk breaches; consent records to sections 10 and 11 (consent, written consent for sensitive data); the processor register to section 18 and SI 155 section 10 (written processing agreements); the licence and DPO dashboard to SI 155's 12-month validity, three-month renewal and 14-day change rules; training records to section 16 of SI 155; and audit reports to section 24 (accountability).

Example

The DPO of a Tier 2 logistics company in Harare logs a stolen driver's tablet at 09:40. The software opens an incident, starts the 24-hour timer, asks the ten questions POTRAZ needs, flags that the tablet held 1,200 consignees' names, numbers and addresses, suggests that the risk to individuals is moderate rather than high, and produces a completed Form DP3 for review. By 15:00 the DPO has submitted it and recorded POTRAZ's reference. The same evening the dashboard reminds her that the licence renewal is due in six weeks.

In practice

Judge any tool, ours included, against those eight duties and against Zimbabwean forms and deadlines specifically. A tool built for the EU GDPR will speak of 72 hours to the regulator and supervisory authorities; in Zimbabwe the regulator's deadline is 24 hours and the regulator is POTRAZ.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.