Is POTRAZ extending the data protection licence deadline or offering an amnesty?
Short answer
Do not plan on one. The SI 155 transition period ended on 12 March 2025, POTRAZ declined to extend it, and mandatory inspections began on 1 September 2026. POTRAZ's public position is that the awareness phase is over and the enforcement phase has begun; any change would be announced by POTRAZ itself.
What the law says
SI 155 gave existing controllers six months from 13 September 2024 to apply for a licence and 90 days to appoint a DPO. Those periods are fixed in the Regulations and could only be extended by a further statutory instrument, which has not been issued. The Second Schedule contains no amnesty or late-registration mechanism; late applicants simply pay the ordinary fee. POTRAZ's July 2026 inspection notice confirmed that it was moving to enforcement rather than extending deadlines.
Example
An association of Harare private schools writes to POTRAZ in 2026 asking for a sector extension because "schools are only now becoming aware". POTRAZ's answer is to offer a briefing and to remind the association that education is a priority inspection sector from September 2026. The schools that treat the reply as a starting gun are licensed with certified DPOs within two months; those still waiting for an extension are the ones inspectors meet first.
In practice
Assume the deadlines have passed and act accordingly. If POTRAZ ever announces a formal amnesty, being already compliant costs you nothing; if it does not, having waited could cost you a great deal.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.