POTRAZ starts inspecting on 1 September. Here is exactly what it will ask for

A printed application form and pen on a desk

By TechBytes Africa Staff

From 1 September the Postal and Telecommunications Regulatory Authority of Zimbabwe begins mandatory inspections of organisations that hold personal data, under Regulatory Notice 2 of 2026. Officers will check whether you hold a data controller licence and whether you have appointed a data protection officer.

Most Zimbabwean organisations do not have either. The obligation has existed since September 2024 and the deadline to comply passed in March 2025.

This guide is drawn from the text of the regulations themselves rather than from summaries of them, because published accounts of what the fees are have been wrong in both directions. Here is what the law says.

Do you need a licence

Almost certainly yes, if you hold personal data on 50 or more people.

Statutory Instrument 155 of 2024 requires a licence from anyone who decides the means, purpose or outcome of processing personal data, decides what data to collect, decides which individuals to collect it from, or obtains commercial gain from processing it. The 50 person figure is not stated as a threshold in so many words. It arises because the lowest licence tier begins at 50 data subjects, so there is no licence category below that number.

Personal data here means what you would expect: names, addresses, phone numbers, national identity numbers, employment records, health information and biometric data, which the regulations define as including fingerprints, palm veins and face recognition.

The four tiers, by number of data subjects:

  • Tier 1: 50 to 1,000
  • Tier 2: 1,001 to 100,000
  • Tier 3: 100,001 to 500,000
  • Tier 4: more than 500,000

Exemptions. Processing for personal, family or household affairs is exempt entirely. Law enforcement and journalistic, historical or archival purposes are exempt from licensing, but must still register with the Authority and comply with the data protection principles in the Act. Being exempt from a licence is not the same as being outside the law.

What it costs

This is where published reporting has gone astray. One account gave the range as US$50 to US$500 and another as US$50 to US$2,000. The Second Schedule to the regulations sets it out as follows, payable in USD or in ZiG at the official rate.

Licence fees:

  • Application fee for Tier 2, 3 or 4: US$30
  • Tier 1 initial or renewal: US$50
  • Tier 2: US$300
  • Tier 3: US$500
  • Tier 4: US$2,500

Data protection officer training and certification:

  • Zimbabwean citizens: US$1,250 per person
  • International: US$1,450 per person
  • Training application fee: US$30 for citizens, US$50 for international applicants

Training accreditation, for institutions wanting to deliver the course: US$5,000 per annum.

So a small organisation at Tier 1 faces US$50 for the licence, and US$1,280 to get one person certified as its DPO. The certification cost is twenty five times the licence fee, and it is the number that will decide whether small organisations comply.

What you have to do

1. Appoint a data protection officer. The regulations require it, and set the qualification bar as skill, qualifications or experience in data science, data analytics, information security systems, information systems audit, law, audit or any other relevant qualification, plus knowledge of national data protection law and an understanding of your own operations. The DPO must complete a certification course approved by the Authority.

2. Notify POTRAZ of the appointment using Form DP2. You must also notify any change to the DPO’s phone, email or address within 14 days, and any dismissal or resignation within 14 days.

3. Apply for the licence using Form DP1, with the application fee. The Authority must request further information, issue the licence, or reject the application with reasons, within 14 days. The licence runs for 12 months and renewal must be applied for at least three months before expiry.

4. Notify the Authority of your processing activities. Specifically: all processing activities performed, any modification of personal data collected indirectly, any intention to transfer or share data outside Zimbabwe, and any processing involving biometric or genetic data.

5. Put security measures in place. The regulations name risk assessments, organisational policies, physical and technical measures across all data phases, and processes to test whether those measures actually work.

6. Have a breach procedure ready. Breaches must be reported to the Authority within 24 hours of becoming aware, using Form DP3. Where a breach is likely to pose a high risk to individuals’ rights, you must also tell those people within 72 hours. You must respond to information requests within 14 days and conclude the investigation with a report within 21 days.

7. If you process children’s data, there is more. Parental or guardian consent, reasonable efforts to verify that consent, regular data protection impact assessments, data protection by design and by default, and no automated decision making that affects children’s rights.

One obligation that catches people: you cannot subject anyone to a decision based solely on automated processing that produces legal effects, without their consent or a legal basis. If you use automated scoring for credit, hiring or eligibility, read that clause carefully.

Who gets inspected first

Veritas has published the order, and POTRAZ will work down the list from the top:

  1. Financial institutions
  2. Insurance companies
  3. Local authorities
  4. Health care providers
  5. Mining enterprises
  6. Religious organisations
  7. Schools, tertiary institutions and professional bodies
  8. Government ministries, departments and agencies
  9. NGOs and private voluntary organisations

Churches, schools and NGOs sitting in the second half of that list have somewhat more time. Not much.

The penalties

Processing personal data without a licence carries a fine not exceeding level 11 or imprisonment for up to seven years, or both. The same maximum applies to failing to renew a licence, submitting false information, breaching the data controller obligations, failing to secure data, and failing to notify a breach.

Failing to appoint a data protection officer carries a lower maximum: a fine not exceeding level 7 or imprisonment up to two years, or both.

What to do this week if you have not started

Appoint someone as DPO and get them booked onto the certification course, because that is the long lead item and everything else waits on it. Fill in Form DP1 and DP2, both available through POTRAZ. Write down what personal data you hold, why, where it lives and who it goes to, since the forms ask and an inspector will ask.

For guidance on whether you need a licence at all, POTRAZ has published guidelines and can be reached at beans@potraz.zw, ushe@dpa.zw or marere@dpa.zw, or on 0242-333032 extension 1129. The Data Protection Authority sits at 1110 Performance Close, Mt Pleasant Business Park, Harare.

One thing worth knowing: the Authority maintains a public register of licensed data controllers, inspectable at its premises or on its website. Anyone can check whether you are on it. So can your customers.


This is a summary of a legal instrument, not legal advice. Read SI 155 of 2024 in full, or take advice, before making compliance decisions.

Comments are disabled