Who must comply

Is POTRAZ data protection compliance really necessary or just another tax?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

It is necessary, and it is not primarily a revenue measure. POTRAZ licence fees run from USD 50 to USD 2,500 a year depending on tier; the real weight of the Cyber and Data Protection Act is that it gives your customers and staff enforceable rights and gives POTRAZ the power to inspect and prosecute.

What the law says

Section 33 of the Act makes contraventions of the core duties (sensitive data, section 11; controller duties, section 13; security, section 18; accountability, section 24; cross-border transfers, section 28) offences punishable by "a fine not exceeding level 11 or imprisonment for a period not exceeding seven years or both". SI 155 adds offences for processing without a licence (same penalty) and for failing to appoint a DPO (level 7 or two years). Section 14 gives every person rights of access, correction, deletion and objection, and section 6 gives POTRAZ the function of investigating complaints. The fees in the Second Schedule are a small part of the picture.

Example

A hardware chain with four branches in Harare and Bulawayo weighs USD 330 a year (Tier 2) against "doing nothing". A year later a former branch manager, dismissed for theft, reports the chain to POTRAZ for holding 30,000 customer records without a licence and for sharing customer numbers with a private debt collector without any contract. The licence fee it saved is now the least of its problems.

In practice

Look at compliance as risk management rather than tax. The paperwork is a few days of work, the fee is lower than most municipal licences, and the alternative is a criminal exposure that your bank, insurer and larger customers are already asking about.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.