Is annual DPO training (CPD) required in Zimbabwe?
Short answer
Yes. Section 10 of SI 155 of 2024 obliges the data controller to provide its Data Protection Officer with continuous professional development (CPD). The initial POTRAZ certification is a one-off, but the law expects the DPO's knowledge to be kept current, and inspectors can ask for evidence.
What the law says
Among the obligations of a data controller in section 10 of SI 155 is to provide "continuous professional development training to the data protection officer". The Regulations do not prescribe a number of hours; the standard is that the DPO remains competent as POTRAZ issues new guidelines (the 2025 DPO and breach notification guidelines are examples) and as the controller's processing changes.
Example
A medical aid society in Harare certifies its compliance officer in 2025. In 2026 POTRAZ publishes the breach notification guidelines and begins inspections. The society sends the DPO to a one-day update course on the new guidelines and to a half-day session on health data security, and files both certificates. During the September 2026 inspection the inspector notes that the DPO's knowledge is current, which is exactly what section 10 envisages.
In practice
Budget one or two days of CPD a year per DPO, choose sessions that follow POTRAZ's own publications, and keep the certificates in the compliance file. Business Science Institute's annual update sessions are designed to double as the CPD evidence you need.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.