Who must comply

Do NGOs, churches and schools need a POTRAZ data controller licence in Zimbabwe?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Yes. NGOs, churches, schools and sports clubs in Zimbabwe need a POTRAZ data controller licence and a Data Protection Officer. SI 155 of 2024 contains no exemption for non-profit organisations, and POTRAZ's 2026 inspection programme names them as priority sectors.

What the law says

The Act defines the data controller by what it does (determining purposes and means), not by whether it makes a profit. Section 11 treats information revealing religious beliefs as sensitive data, so a church membership register is sensitive by definition and needs written consent. Section 3 defines a child as anyone under 18, and SI 155 requires parental consent and regular impact assessments where children's data is processed, which covers every school and youth club. POTRAZ's July 2026 inspection notice lists religious organisations, educational institutions, professional bodies and NGOs / private voluntary organisations among the nine priority categories.

Example

A church in Highfield, Harare, keeps a register of 800 members with ID numbers, addresses, tithe records and prayer requests that mention illnesses. A community NGO in Masvingo holds beneficiary lists for 2,000 households, including HIV status for a health programme. Both hold large volumes of sensitive data on many people. Both are data controllers (Tier 1 and Tier 2 respectively) and both are squarely inside POTRAZ's stated inspection priorities.

In practice

Appoint a DPO (a trustee, administrator or shared external DPO), apply for the licence, obtain written consent for membership and health data, restrict access to registers, and adopt a retention rule for former members and beneficiaries. Donors and international partners increasingly ask for this anyway.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.