Knowledge base · 15 questions

POTRAZ penalties, fines and inspections: what happens if I don't comply?

Fifteen questions on enforcement. Fines in US dollars, prison terms, what POTRAZ checks during an inspection, how likely an inspection is, complaints from customers and ex-employees, director liability, civil claims and late registration.

Zimbabwe only · CDPA, SI 155 of 2024, Implementation Guidelines 2025 Reviewed 9 September 2026

The Cyber and Data Protection Act is criminal legislation. Operating without a licence attracts a fine up to level 11 or up to seven years' imprisonment, or both; failing to appoint a DPO attracts a level 7 fine or up to two years. POTRAZ began a risk-based inspection programme in September 2026 across nine priority sectors, and a single complaint from a customer or a former employee is enough to start a file.

What happens if I ignore the Cyber and Data Protection Act in Zimbabwe?

Until September 2026, in many cases nothing, which is why so many businesses did. That has changed. POTRAZ began mandatory, risk-based inspections on 1 September 2026; being found without a licence is an offence carrying up to seven years' imprisonment, without a DPO up to two years, and POTRAZ can order you to stop processing. Any customer or employee can complain at any time.

SI 155 makes processing without a licence after the transition period an offence with "a fine not exceeding level 11 or imprisonment for a period not exceeding seven years or both", and failing to appoint a DPO an offence at level 7 or two years. Section 33 of the Act applies the level 11 / seven-year penalty to breaches of the core dutie…

Read the full answer, with the law and an example

What are the data protection fines in Zimbabwe in US dollars?

Zimbabwe's Cyber and Data Protection Act uses the Standard Scale of Fines: level 7 is USD 400, level 11 is USD 1,000 and level 14 (used for cybercrimes such as hacking) is USD 5,000, payable in local currency at the interbank rate. The dollar amounts are small; the same offences carry imprisonment of up to two, seven or ten years and more.

The Criminal Law (Codification and Reform) (Standard Scale of Fines) Notice, SI 14A of 2023, sets level 1 at USD 5 rising to level 14 at USD 5,000, with level 7 at USD 400 and level 11 at USD 1,000; the notice states that fines are "expressed in United States dollars but payable in the equivalent Zimbabwean dollars at the prevailing inter…

Read the full answer, with the law and an example

Can you go to prison for not registering with POTRAZ as a data controller?

The law allows it. Processing personal information without a POTRAZ data controller licence carries imprisonment of up to seven years under SI 155 of 2024, and failing to appoint a Data Protection Officer up to two years, in each case "or both" with the fine. Whether a court imposes prison on a first, minor, cooperative offender is a matter of judicial discretion, but directors should not plan around leniency.

SI 155 provides that a person who continues to process personal data without a licence after the transition period is liable to "a fine not exceeding level 11 or to imprisonment for a period not exceeding seven years or to both". Section 33 of the Act uses the same formula for the core substantive breaches. These are the same penalty leve…

Read the full answer, with the law and an example

How likely is a POTRAZ inspection for a small business in Zimbabwe?

More likely than a year ago. POTRAZ's inspection programme, running since 1 September 2026, is risk-based and starts with nine priority sectors, but three other routes reach small businesses every day: a customer or employee complaint to POTRAZ, a data breach you must report within 24 hours, and a bank or large client asking for your data controller licence number.

Section 6 of the Act gives POTRAZ the functions of ensuring lawful processing and investigating complaints, and SI 155 gives it the licensing powers that inspections enforce. POTRAZ's July 2026 announcement listed the priority categories: financial institutions, insurers, local authorities, healthcare providers, mining enterprises, religi…

Read the full answer, with the law and an example

Can a customer or former employee report my business to POTRAZ?

Yes. Investigating complaints is one of POTRAZ's core functions under section 6 of the Cyber and Data Protection Act, and any person can lodge one. Former employees know exactly what data you hold and how it is handled, and dismissal disputes are a classic trigger.

Section 6 lists among the Authority's functions investigating complaints and ensuring that data controllers process personal information lawfully. Section 14 gives every data subject rights whose denial is a natural ground of complaint. SI 155 requires controllers to respond to POTRAZ information requests on breaches within 14 days, and t…

Read the full answer, with the law and an example

What does POTRAZ check during a data protection inspection?

Based on POTRAZ's announced programme, an inspection checks three things: whether you hold a valid data controller licence in the correct tier; whether you have appointed a certified Data Protection Officer notified on Form DP2; and whether you have data governance and cybersecurity measures in place (processing records, privacy notices, policies, processor contracts, access control, backups, training, a breach procedure).

The inspections enforce SI 155 (licensing and DPO appointment) and the Act's substantive duties: section 10 of SI 155 (notified processing activities, written processor agreements, CPD for the DPO), sections 15 and 16 of the Act (information to data subjects), section 18 and SI 155 section 16 (security measures, policies, testing), sectio…

Read the full answer, with the law and an example

Can POTRAZ shut down a business for data protection non-compliance?

POTRAZ does not close companies, but it can refuse, suspend or revoke your data controller licence and order you to stop unlawful processing. Because almost everything a business does involves personal information, a stop order or a revoked licence has much the same effect as a closure until you comply.

SI 155 conditions the licence on compliance and gives POTRAZ the power to refuse and, by implication, to suspend or revoke it; processing without a valid licence is an offence. Section 6 of the Act gives the Authority its enforcement functions. Section 34 provides that "any person aggrieved by the decision of the Authority may appeal to t…

Read the full answer, with the law and an example

Is not knowing about the CDPA a defence in Zimbabwe?

No. Ignorance of the law is not a defence in Zimbabwean criminal law, and the POTRAZ licensing and Data Protection Officer requirements have been gazetted since 13 September 2024 with a six-month transition period and wide publicity. What helps is showing that you acted as soon as you knew.

The Criminal Law (Codification and Reform) Act, which the Cyber and Data Protection Act amends, follows the general rule that ignorance of the law does not excuse. SI 155 was published in the Government Gazette in September 2024, POTRAZ issued guidance and public notices through 2025, and the inspection programme was announced in July 202…

Read the full answer, with the law and an example

Will I be punished for registering late with POTRAZ?

Technically the offence was committed for the unlicensed period and POTRAZ retains its discretion, but there is no late fee in SI 155 of 2024, the fee is the ordinary tier fee, and regulators, POTRAZ included, treat voluntary late compliance very differently from non-compliance discovered in an inspection or after a complaint.

SI 155's Second Schedule contains no late-application or penalty fee; a late applicant pays the same tier fee and application fee as anyone else. The offence provision applies to processing without a licence after the transition period, and prosecution is at the discretion of the authorities. Nothing in the Act or Regulations creates an a…

Read the full answer, with the law and an example

What happens if I do not report a data breach to POTRAZ?

Failing to notify POTRAZ within 24 hours is itself a breach of section 19 of the Cyber and Data Protection Act and of SI 155, on top of whatever security failure caused the incident. Breaching the security duty in section 18 carries the top penalty (level 11 or seven years), and breaches rarely stay secret.

Section 19 requires notification to the Authority "within twenty-four (24) hours of any security breach"; SI 155 prescribes Form DP3, requires responses to POTRAZ's follow-up questions within 14 days, and, with POTRAZ's 2025 Breach Notification Guidelines, requires notification of affected individuals within 72 hours where the breach is l…

Read the full answer, with the law and an example

Can customers sue my business for misusing their data in Zimbabwe?

Yes, in addition to POTRAZ action. The Cyber and Data Protection Act gives people enforceable rights and a complaint route to POTRAZ; separately, a person who suffers loss because you mishandled their information can pursue ordinary civil remedies, and employees increasingly raise data-handling failures in labour disputes.

Section 14 gives every data subject rights of access, objection, correction and deletion, and section 6 gives POTRAZ the function of investigating complaints. The Act does not exclude the ordinary civil law: a person harmed by an unlawful disclosure can sue for breach of confidence, for defamation where false information is spread, or for…

Read the full answer, with the law and an example

Do banks and large clients in Zimbabwe ask for your POTRAZ licence number?

Increasingly, yes. Banks, insurers, mobile network operators and large corporates are themselves on POTRAZ's priority inspection list and must hold written processing agreements with their suppliers. Expect tenders, supplier onboarding forms and due-diligence questionnaires to ask for your data controller licence number and your Data Protection Officer's details.

Section 18 of the Act requires a controller to choose processors that provide sufficient guarantees of security and to bind them by contract; SI 155 section 10 requires a written data processing agreement. A bank that shares customer data with a courier, a printer, a call centre or a software vendor is therefore obliged to check and contr…

Read the full answer, with the law and an example

What are the consequences of CDPA non-compliance for directors and managers?

Offences under the Cyber and Data Protection Act and SI 155 of 2024 can be prosecuted against the data controller and, depending on the facts, against the officers who caused or permitted the contravention. POTRAZ's 2026 enforcement messaging speaks of fines or prison for responsible executives; boards should therefore govern the issue and minute that they did.

Section 33 imposes imprisonment as well as fines, and imprisonment can only be served by individuals; Zimbabwean criminal law applies corporate offences to the directors and officers who knew of and consented to them. Section 24 requires the controller to demonstrate accountability, which in a company means governance at board level. Sepa…

Read the full answer, with the law and an example

Can POTRAZ enforce the CDPA against a foreign company?

Against your Zimbabwean operations, assets, local representatives and directors, yes; and the practical lever is market access, because Zimbabwean banks, payment providers and partners increasingly ask for a POTRAZ licence. Foreign firms serving Zimbabweans generally find it simpler to license, appoint a local Data Protection Officer and comply.

The Act applies to the processing of personal information in Zimbabwe and of Zimbabwean data subjects, and its cybercrime chapter (section 166 of the amended Criminal Law Code) asserts jurisdiction over offences committed wholly or partly in Zimbabwe, by Zimbabwean nationals or residents, or against Zimbabwean computer systems. SI 155 lic…

Read the full answer, with the law and an example

Is POTRAZ extending the data protection licence deadline or offering an amnesty?

Do not plan on one. The SI 155 transition period ended on 12 March 2025, POTRAZ declined to extend it, and mandatory inspections began on 1 September 2026. POTRAZ's public position is that the awareness phase is over and the enforcement phase has begun; any change would be announced by POTRAZ itself.

SI 155 gave existing controllers six months from 13 September 2024 to apply for a licence and 90 days to appoint a DPO. Those periods are fixed in the Regulations and could only be extended by a further statutory instrument, which has not been issued. The Second Schedule contains no amnesty or late-registration mechanism; late applicants …

Read the full answer, with the law and an example

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.