Is a business with fewer than 50 data subjects exempt from the POTRAZ licence in Zimbabwe?
Short answer
Partly. The POTRAZ licence tiers in SI 155 of 2024 start at 50 data subjects, so a business holding data on fewer than 50 people does not fall into any fee tier and is not, on the face of the Regulations, required to hold a data controller licence. It is not, however, exempt from the Cyber and Data Protection Act itself.
What the law says
The First Schedule to SI 155 defines Tier 1 as "a minimum of 50 or a maximum of 1000 data subjects". No tier covers 1 to 49, and no fee is listed for that range. But the Act's obligations (lawful processing under section 10, written consent for sensitive data under section 11, security under section 18, breach notification under section 19, data subject rights under section 14) apply to every data controller regardless of size, and the offences in section 33 do not depend on a licence tier. POTRAZ has not published a formal "under-50" exemption; the position simply follows from the tier definitions.
Example
A start-up in Harare's Avondale suburb has three founders, four staff, a dozen suppliers' contacts and 25 pilot customers: 44 people. It is not yet in a tier. Six weeks later it launches its app publicly and signs up 300 users; it is now Tier 1 and should apply immediately. If in the meantime it had leaked those 25 pilot customers' details, section 19 (24-hour breach notification) and section 18 (security) would have applied to it in full.
In practice
Treat "under 50" as a short transitional stage, not a business model. Document your count with a date, keep the Act's basics in place from day one, and file Form DP1 (and appoint a DPO) the day you reach 50. If you want certainty for your own case, ask POTRAZ's Data Protection Authority unit in writing and keep the reply.
General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.