Data Protection Officer in Zimbabwe: is a DPO mandatory, who can be one, what does it cost?
Twenty questions on the DPO. Whether a Data Protection Officer is mandatory, whether you can appoint yourself, certification and exams, shared and outsourced DPOs, the 90-day replacement rule, personal liability of the DPO and of directors.
SI 155 of 2024 requires every data controller to appoint a Data Protection Officer and to file that appointment with POTRAZ on Form DP2. The obligation does not scale with size: a 60-person business needs an appointed, certified officer just as a bank does. What does scale is how you meet it, and a shared or outsourced DPO is the normal route for smaller organisations.
Is a Data Protection Officer (DPO) mandatory in Zimbabwe?
Yes. A Data Protection Officer (DPO) is mandatory for every data controller in Zimbabwe. SI 155 of 2024 requires each data controller to appoint a DPO and notify POTRAZ in writing on Form DP2, with no exemption based on size, sector or turnover. Failing to appoint one is a criminal offence.
Section 20 of the Act introduced the Data Protection Officer and empowered the Authority to issue guidelines on the role. SI 155 made the appointment compulsory: every data controller "shall appoint a data protection officer" and "notify the Authority in writing" using Form DP2, initially "within 90 days from the date of promulgation" (by…
Does appointing a DPO in Zimbabwe mean hiring a full-time employee?
No. Appointing a Data Protection Officer in Zimbabwe does not require a full-time hire. SI 155 of 2024 requires you to appoint a DPO with the right skills, certification and authority; it does not require a dedicated post. Most SMEs assign the role to an existing manager or contract an external DPO.
SI 155 section 13 describes the DPO by "skill, qualifications, or experience", not by employment status or hours. Section 14 lists functions (monitoring, training, audits, handling requests, liaising with POTRAZ) that scale with the size and risk of the organisation. POTRAZ's DPO Guidelines recognise that the DPO may be a staff member or …
How much does a Data Protection Officer cost in Zimbabwe?
A Data Protection Officer in Zimbabwe costs from the USD 1,250 POTRAZ-approved certification fee upwards, depending on the model. An internal DPO costs the certification plus part of an existing salary; an external DPO costs a retainer; a shared DPO splits either cost across several organisations.
The Second Schedule to SI 155 fixes the DPO training and certification fee at USD 1,250 per person for Zimbabwean citizens and USD 1,450 for international candidates. Section 10 of SI 155 also obliges the controller to provide "continuous professional development training to the data protection officer", so there is a recurring cost. The …
Can a business owner be their own Data Protection Officer in Zimbabwe?
Yes, but only if you complete the POTRAZ-approved DPO certification and can actually perform the Data Protection Officer functions. Naming yourself without certification is not a valid appointment under SI 155 of 2024, and in a business with a management team the conflict of interest usually makes someone else the better choice.
SI 155 requires every DPO to "undergo a certification course approved by the Authority" and to have the skills listed in section 13. Section 14 makes the DPO responsible for monitoring the controller's compliance and conducting audits. POTRAZ's DPO Guidelines stress independence: the DPO should be able to perform the functions without ins…
Can my accountant, lawyer or IT provider act as my Data Protection Officer?
Yes. An accountant, lawyer or IT provider can be your Data Protection Officer in Zimbabwe if they hold the POTRAZ-approved DPO certification, understand your operations and are formally appointed and named on Form DP2. SI 155 of 2024 expressly lists law, audit and information security among relevant DPO backgrounds.
Section 13 of SI 155 requires the DPO to have "skill, qualifications, or experience in" data science, data analytics, information security, audit, law "or any other relevant qualification", together with knowledge of national data protection law and an understanding of the controller's processing operations. Nothing restricts the DPO to e…
Does a DPO in Zimbabwe have to pass an exam?
Yes. SI 155 of 2024 requires every Data Protection Officer to undergo a certification course approved by POTRAZ, and the approved course ends in a formal examination. Until the candidate passes, they are not certified and your DPO appointment is incomplete.
SI 155 provides that "every data protection officer shall be required to undergo a certification course approved by the Authority", and the Second Schedule fixes the training and certification fee (USD 1,250 for citizens, USD 1,450 international). POTRAZ's 2025 DPO Guidelines describe the training and certification framework; the first ac…
My Data Protection Officer resigned. How long do I have to appoint a new DPO?
Two clocks start when your Data Protection Officer leaves. Under SI 155 of 2024 you must notify POTRAZ within 14 days that the appointment has ended, and you must appoint a certified replacement DPO and file a new Form DP2 within 90 days.
SI 155 requires the controller to notify the Authority of the dismissal or resignation of a DPO "within 14 days of termination" and to notify any change in the DPO's details within 14 days. The 90-day period that applied to the initial appointment is applied to replacements as well. During the gap, all the controller's obligations continu…
Is the Data Protection Officer personally liable under Zimbabwe's CDPA?
Generally no. Liability under the Cyber and Data Protection Act and SI 155 sits with the data controller (the business and its responsible officers), not with the Data Protection Officer for performing their role. A DPO would only face personal action for offences they personally commit, such as unlawfully disclosing data.
The duties in the Act are imposed on "the data controller" (sections 10 to 19, 24, 28), and section 33 penalises "a data controller who contravenes" them. SI 155's DPO provisions describe the DPO's functions (section 14) and make the controller liable for failing to appoint one. Section 33 also penalises anyone under the controller's …
Does a DPO in Zimbabwe have to be a Zimbabwean citizen or resident?
No. Zimbabwean citizenship is not required for a Data Protection Officer. What SI 155 of 2024 requires is knowledge of Zimbabwe's data protection law, the POTRAZ-approved certification (USD 1,450 for international candidates versus USD 1,250 for citizens) and the ability to perform the role, including being reachable by POTRAZ and by your data subjects.
Section 13 of SI 155 requires "knowledge of national data protection laws and practices" and an understanding of the controller's operations, and the certification requirement applies to every DPO. The Second Schedule's separate "international" fee shows that non-citizens are expected to take the course. Nothing in the Act or SI 155 recog…
Can several companies share one Data Protection Officer in Zimbabwe?
Yes. Several companies can share one Data Protection Officer in Zimbabwe. Nothing in SI 155 of 2024 prevents one certified person acting as DPO for several data controllers, and POTRAZ's 2025 DPO Guidelines accept shared and outsourced arrangements provided the person can genuinely perform the role for each organisation.
SI 155 requires each controller to appoint "a data protection officer" and notify the Authority; it does not say the person must be exclusive to one controller. The Guidelines focus on capability and independence: the DPO must have the time, access and authority to carry out the section 14 functions for each controller, and each controlle…
What are the duties of a Data Protection Officer under SI 155 of 2024?
Section 14 of SI 155 of 2024 gives the Data Protection Officer nine functions: monitor compliance with the Cyber and Data Protection Act; oversee internal processing activities; raise awareness and train staff; conduct audits; handle requests from POTRAZ and from data subjects; advise management on its obligations; advise on data protection impact assessments; cooperate with POTRAZ; and act as the contact point for data subjects.
Section 14 of SI 155 lists the functions in those terms. Section 20 of the Act, which created the role, describes the DPO's purpose as ensuring compliance with the Act, handling data subject requests and working with the Authority on the controller's obligations. POTRAZ's DPO Guidelines add that the DPO should report to the highest manage…
Can I appoint a DPO now and complete the POTRAZ certification later?
Appoint now and book the POTRAZ-approved certification immediately. SI 155 of 2024 requires the Data Protection Officer to undergo the approved certification course; until they have done so, POTRAZ may treat your DPO appointment as incomplete, but a filed Form DP2 with a course booking is far better than nothing.
SI 155 imposes two separate duties: to appoint and notify a DPO (Form DP2) and to ensure the DPO undergoes the approved certification. The Regulations do not state a period within which certification must follow appointment, but the original 90-day appointment deadline and the 12 December 2024 target date for certification announced at th…
Is annual DPO training (CPD) required in Zimbabwe?
Yes. Section 10 of SI 155 of 2024 obliges the data controller to provide its Data Protection Officer with continuous professional development (CPD). The initial POTRAZ certification is a one-off, but the law expects the DPO's knowledge to be kept current, and inspectors can ask for evidence.
Among the obligations of a data controller in section 10 of SI 155 is to provide "continuous professional development training to the data protection officer". The Regulations do not prescribe a number of hours; the standard is that the DPO remains competent as POTRAZ issues new guidelines (the 2025 DPO and breach notification guidelines …
Do I have to notify POTRAZ when my DPO's contact details change?
Yes, within 14 days. SI 155 of 2024 requires any change in the Data Protection Officer's details, and any termination of the appointment, to be notified to POTRAZ within 14 days. It is a two-minute task with a real purpose: POTRAZ and your data subjects must always be able to reach the right person.
SI 155 provides that the controller shall notify the Authority of any changes to the DPO's particulars "within a period of 14 days", and of a DPO's dismissal or resignation "within 14 days of termination". Section 14 makes the DPO the contact point for data subjects, and sections 15 and 16 of the Act require your privacy notice to identif…
Which businesses in Zimbabwe do not need a Data Protection Officer?
Only organisations that are not data controllers at all: purely personal or household use, and the section 8 SI 155 categories (journalistic, historical and archival processing, with law enforcement handled separately). Every trading business, NGO, church, school and clinic that holds personal information is a data controller and must appoint a Data Protection Officer.
SI 155 attaches the DPO duty to "every data controller". The only processing outside the controller regime is the section 8 exempt processing, and even journalists and law-enforcement bodies must register with POTRAZ and follow the principles. There is no threshold of staff, turnover or records below which the DPO requirement falls away. …
What is the penalty for not appointing a Data Protection Officer in Zimbabwe?
Failing to appoint a Data Protection Officer is a criminal offence under SI 155 of 2024, punishable by a fine of up to level 7 (currently USD 400 on Zimbabwe's standard scale) or imprisonment of up to two years, or both. The practical exposure is larger than the fine.
SI 155 provides that a data controller who fails to appoint a DPO as required "shall be liable to a fine not exceeding level 7 or to imprisonment not exceeding two years or to both". Level 7 on the Standard Scale of Fines (SI 14A of 2023) is USD 400, payable in local currency at the interbank rate. In addition, a licence application witho…
Can a junior employee be the Data Protection Officer to save money?
Legally the Data Protection Officer needs relevant skills or experience, knowledge of Zimbabwean data protection law, understanding of your business and POTRAZ certification; practically, the DPO must have enough standing to tell a director "we cannot do that" and be heard. A junior clerk rarely meets either test, and the certification fee is the same whoever you send.
Section 13 of SI 155 requires "skill, qualifications, or experience in data science, data analytics, information security, audit, law or any other relevant qualification", plus knowledge of national data protection law and of the controller's operations. POTRAZ's DPO Guidelines expect the DPO to report to the highest management level and …
Does the Data Protection Officer have to be independent from management?
The Data Protection Officer should be able to do the job without being penalised for giving unwelcome advice and should report directly to top management. That does not put the DPO above the board: you receive the advice, decide, record the decision and remain responsible to POTRAZ.
Section 14 of SI 155 makes the DPO responsible for monitoring the controller's compliance and conducting audits, functions that only make sense if the DPO can reach conclusions management may not like. POTRAZ's 2025 DPO Guidelines require that the DPO reports to the highest level of management, is not dismissed or penalised for performing…
Are company directors personally liable if there is no POTRAZ licence or DPO?
Potentially, yes. Offences under the Cyber and Data Protection Act and SI 155 of 2024 are criminal offences that can be prosecuted against the data controller and, depending on the facts, against the officers who caused or permitted the contravention. Coverage of POTRAZ's 2026 enforcement drive explicitly warns of fines or prison terms for responsible executives.
Section 33 of the Act imposes penalties including imprisonment ("not exceeding seven years" for the core breaches; "not exceeding two years" under SI 155 for failing to appoint a DPO). Imprisonment can only be served by a natural person, so where the controller is a company these provisions are applied through the ordinary principles of Z…
What is the fastest way to appoint a compliant Data Protection Officer in Zimbabwe?
Four weeks. Week 1: choose the person and sign an appointment letter; book the POTRAZ-approved certification or confirm an external DPO's certificate. Week 2: file Form DP2 with POTRAZ (with Form DP1 if you are not yet licensed). Weeks 2 to 4: the DPO builds the one-page data inventory and the breach plan.
SI 155 requires the appointment and written notification to POTRAZ on Form DP2, the section 13 qualifications, the approved certification, and thereafter CPD. Section 14 functions begin on appointment, so the first tasks are those that protect the controller immediately: the record of processing activities (which section 10 of SI 155 requ…
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.