Cost and timeline

Do I need a lawyer for POTRAZ data protection compliance, or can I do it myself?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Most SMEs can do the core work themselves: count data subjects, complete Forms DP1 and DP2, write a one-page processing record and privacy notice, sign processor annexes and set up security basics. A lawyer is worth engaging for specific problems: complex group structures, cross-border transfers of sensitive data, a POTRAZ complaint or inspection finding, an appeal, or a serious breach.

What the law says

Nothing in the Act or SI 155 requires legal representation for licensing or DPO appointment; the forms are designed to be completed by the controller, and the DPO certification course exists precisely to give a non-lawyer the knowledge to run compliance. Section 13 of SI 155 lists law as one of several acceptable DPO backgrounds, alongside audit, information security and data science. Section 34 appeals to the Administrative Court, by contrast, are formal proceedings where legal advice is prudent.

Example

A Harare printing company with 40 staff completes its licence and DPO appointment in three weeks without a lawyer, using our templates and the DPO's course materials. It calls a lawyer twice in the following year: once to review the processing agreement a bank customer insists on (which contained an indemnity far broader than the Act requires), and once when a former employee's complaint to POTRAZ turns into a formal investigation. Both were the right moments.

In practice

Do the routine yourself, or with the DPO's training and our director briefing; bring in a lawyer when the stakes rise or the other side has one. Keep your compliance file in good order so that, when a lawyer is needed, the first hour is spent on the problem rather than on reconstructing what you did.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.