Penalties

What does POTRAZ check during a data protection inspection?

Zimbabwe · Cyber and Data Protection Act [Chapter 12:07] Reviewed 9 September 2026

Short answer

Based on POTRAZ's announced programme, an inspection checks three things: whether you hold a valid data controller licence in the correct tier; whether you have appointed a certified Data Protection Officer notified on Form DP2; and whether you have data governance and cybersecurity measures in place (processing records, privacy notices, policies, processor contracts, access control, backups, training, a breach procedure).

What the law says

The inspections enforce SI 155 (licensing and DPO appointment) and the Act's substantive duties: section 10 of SI 155 (notified processing activities, written processor agreements, CPD for the DPO), sections 15 and 16 of the Act (information to data subjects), section 18 and SI 155 section 16 (security measures, policies, testing), section 19 (breach procedure) and section 24 (accountability). POTRAZ's July 2026 notice described a risk-based approach assessing licensing compliance, cybersecurity measures and data governance practices.

Example

A Tier 2 medical laboratory in Harare is inspected in October 2026. The inspector asks for: the licence (in date, Tier 2); the DPO's Form DP2 and certificate; the processing record (patients, referring doctors, staff, couriers, the LIMS vendor); the patient consent form and privacy notice; processing agreements with the LIMS vendor and the courier; the access-control policy and an example of the audit log; the breach plan and the incident register (one incident, notified within 24 hours); and the training register. The interview with the DPO and the laboratory director takes ninety minutes.

In practice

Prepare an "inspection binder" (physical or in your compliance software) with those items in that order. If you have the eight items in Q100, the inspection is a conversation about how you do things, not a search for whether you do anything.

General information, not legal advice. This page covers Zimbabwean law only: the Cyber and Data Protection Act [Chapter 12:07], Statutory Instrument 155 of 2024 and POTRAZ’s 2025 Implementation Guidelines. It is not the EU GDPR and not South Africa’s POPIA. Fees, fine levels and deadlines are as gazetted and published by POTRAZ at 9 September 2026; check the latest POTRAZ notices before acting. Businesses named in examples are fictional.