Zimbabwe now has a regulated data protection profession, and the training pipeline that feeds it is actively running.
The Data Protection Officer Certification Course is delivered jointly by the Postal and Telecommunications Regulatory Authority of Zimbabwe and the Harare Institute of Technology. It is a mandatory requirement for certification and registration as a Data Protection Officer in Zimbabwe. Without it, no organisation can lawfully designate you in the role.
Cohorts are moving. One ran in Gweru from 26 May to 5 June. A Harare cohort is in session now, with eight contact days from 19 to 28 August and a four hour examination on 8 September. Further intakes are expected in September and November.
If you have been reading about the compliance obligations landing on Zimbabwean organisations and wondering who is supposed to satisfy them, this is the answer, and the route in is more open than most coverage suggests.
You may not need a degree
This is the part that most reporting gets wrong. POTRAZ publishes two entry routes on its own course notice. The standard route is a first degree in any relevant field.
The special entry route requires a minimum of five O Level passes including English Language, plus at least two A Level passes. Alternatively, a diploma with at least two years of relevant experience.
That second route matters. A compliance clerk, an IT support technician, a records officer or a practice administrator with a diploma and two years behind them is eligible. Articles telling readers that a degree is effectively compulsory are turning away candidates who qualify under POTRAZ’s published criteria.
Separately, the regulations under Statutory Instrument 155 of 2024 speak to the skills a data controller should look for when appointing an officer, referencing data science, data analytics, information security, audit and other relevant fields. Those are the qualities that make you employable once certified. They are not the gate on the course itself.
How to apply
Applications go through POTRAZ. The application form is available on the POTRAZ website at potraz.gov.zw, on the Data Protection Officer training page.
Submit the completed form together with proof of payment of the application fee, certified copies of your academic certificates and your National ID.
The coordinator contact published for applications and enquiries is dpotraining@hit.ac.zw.
Because intake dates are announced rather than fixed to a calendar, the practical advice is to email the coordinators directly and ask when the next cohort opens and when applications close. The Gweru cohort had an application deadline roughly eleven days before the course began, so the window between announcement and cut off is short.
The fees
The application fee is US$30, non refundable. It is paid into a POTRAZ account, not an HIT account.
Course tuition has been reported at US$1,250, payable once your application is approved. Confirm the current figure with the coordinators before you budget, because published amounts have shifted and the tuition is by far the dominant cost.
What registration day looks like
Registration precedes teaching. Successful applicants complete an acceptance form and have their documents verified on site.
Bring original documents, not copies. Bring a passport size photograph with your name written on the back. Bring the POTRAZ generated receipt.
The course structure
The Harare cohort is instructive on shape.
Training is physical, in person, and runs for eight contact days. For the August cohort that is 19 to 28 August.
Contact days are followed by a self study period. The examination is not sat at the end of teaching.
The examination is four hours long. For the August cohort it falls on 8 September, eleven days after the final contact day.
This is worth planning around. If you are taking leave from work, eight days of classroom time and an exam a week and a half later is a different arrangement from a continuous fortnight.
What certification gives you
On passing, POTRAZ issues a Data Protection Certificate in your name. That certificate is the artefact. It is what a data controller presents when notifying the Authority of your appointment.
The role is not tied to a single employer. A certified officer can act for more than one data controller, which is the practical answer for organisations too small to justify a full time appointment: a cluster of schools, a group of clinics, a diocese, an association of small traders. Whether shared appointments are expressly permitted is a question worth putting to POTRAZ in writing before you build a practice on it.
Beyond holding the role, certified officers are positioned for the adjacent work that the compliance regime is generating: assisting controllers through licensing, drafting privacy notices, building registers of processing activities and standing up breach response procedures.
Before you commit
Two things to establish for yourself rather than taking from any article, including this one.
Confirm the current tuition figure directly with the coordinators.
And if your motivation is a compliance deadline at your own organisation, ask POTRAZ precisely which obligation attaches to which date, and what the position is for a controller whose officer is enrolled but not yet certified. That is a question about your employer’s exposure, and it deserves an answer in writing from the Authority rather than an inference from a course schedule.

