Who must comply

When did the POTRAZ licence and DPO requirements start in Zimbabwe, and are they enforced?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

The Cyber and Data Protection Act has been in force since December 2021, the POTRAZ licence and Data Protection Officer obligations came in with SI 155 on 13 September 2024, and POTRAZ started mandatory, risk-based inspections on 1 September 2026. The grace periods have expired.

What the law says

SI 155 provides that "persons that are controlling data by the date of promulgation of these regulations shall submit their applications for a data controller licence within 6 months from the date of promulgation", which gave existing controllers until 12 March 2025. DPOs had to be appointed "within 90 days from the date of promulgation", that is by 12 December 2024. Continuing to process personal data without a licence after the transition period is an offence under the Regulations. In July 2026 POTRAZ announced that from 1 September 2026 it would carry out inspections to verify licensing, DPO appointment and data governance, prioritising nine sectors.

Example

A microfinance institution in Chitungwiza with 20,000 borrowers ignored the March 2025 deadline, reasoning that "nobody is checking". In September 2026 it receives a POTRAZ inspection letter because financial institutions are the first priority sector. It is now processing without a licence (an offence carrying up to seven years) and has no DPO (up to two years), and it must explain eighteen months of inaction to the inspector.

In practice

If you have not yet applied, do so this week; voluntary late compliance is treated very differently from non-compliance discovered in an inspection. Keep dated evidence of every step you take from now on.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.