The DPO role

What is the fastest way to appoint a compliant Data Protection Officer in Zimbabwe?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Four weeks. Week 1: choose the person and sign an appointment letter; book the POTRAZ-approved certification or confirm an external DPO's certificate. Week 2: file Form DP2 with POTRAZ (with Form DP1 if you are not yet licensed). Weeks 2 to 4: the DPO builds the one-page data inventory and the breach plan.

What the law says

SI 155 requires the appointment and written notification to POTRAZ on Form DP2, the section 13 qualifications, the approved certification, and thereafter CPD. Section 14 functions begin on appointment, so the first tasks are those that protect the controller immediately: the record of processing activities (which section 10 of SI 155 requires you to be able to notify) and the breach plan (section 19 of the Act, 24 hours).

Example

A Tier 1 furniture manufacturer in Mutare runs the plan. Week 1: the finance manager is appointed by a one-page letter listing the section 14 functions and a reporting line to the managing director; she is enrolled on the next certification course. Week 2: Form DP2 is filed with the enrolment receipt, alongside Form DP1 and the USD 50 fee. Week 3: she completes the data inventory (staff, customers, suppliers, CCTV, WhatsApp Business) and drafts the privacy notice. Week 4: the breach plan is agreed, with the IT contractor's number and a pre-filled Form DP3. By the time the inspector calls, the company has the two things asked for first and the evidence behind them.

In practice

Business Science Institute's DPO training package includes the appointment-letter template, the data inventory template and the breach plan template, so the four weeks are mostly filling in your own details rather than starting from a blank page.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.