Compliance tools

Can compliance software report a data breach to POTRAZ automatically?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

It prepares the notification; a human submits it. When an incident is logged, good software starts the 24-hour clock, walks the Data Protection Officer through the facts POTRAZ asks for and generates a completed Form DP3 plus a draft notice to affected individuals for the 72-hour deadline. The DPO reviews, submits through the official POTRAZ channel and records the reference number.

What the law says

Section 19 of the Act provides that "the data controller shall notify the Authority within twenty-four (24) hours of any security breach affecting data he or she processes". SI 155 prescribes Form DP3 and requires the controller to respond to POTRAZ's follow-up information requests within 14 days; POTRAZ's 2025 Data Breach Notification Guidelines set out the content expected (nature of the breach, categories and approximate numbers of data subjects, likely consequences, measures taken) and the 72-hour notification to individuals where the breach is likely to result in a high risk to their rights and freedoms.

Example

At 07:30 a Monday, a Harare school's DPO learns that a laptop with 380 pupils' records was stolen from a teacher's car on Saturday night. She logs the incident; the software records "awareness: Monday 07:30" as the start of the 24-hour period, prompts her for the facts, flags children's and health data as high risk, and produces Form DP3 and a parents' notice. She checks the numbers with the head teacher, corrects the count to 412, submits Form DP3 to POTRAZ at 11:00 and sends the parents' notice the same afternoon. The file shows every timestamp.

In practice

Automatic sending is deliberately excluded from responsible tools: an incorrect number or a wrong data category sent to the regulator is worse than a considered notification two hours later. Use the software to make the 24 hours manageable, and keep a human signature on what goes to POTRAZ.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.