
The Postal and Telecommunications Regulatory Authority of Zimbabwe, POTRAZ, has commenced mandatory compliance inspections and assessments in terms of Section 6(1)(a) read together with Section 21(3) and (4) of the Cyber and Data Protection Act [Chapter 12:07].
The Cyber and Data Protection Act came into effect in September 2024 and imposes mandatory obligations on both public and private organisations that process personal data. Central to these obligations is the requirement to obtain a Data Controller Licence. The initial deadline for registration was 31 March 2025. While some organisations have complied, others have yet to heed the provisions of the Act. In response, POTRAZ has opened a compliance window to allow non-registered entities to regularise their status.
To enforce adherence, the Authority will dispatch inspectors to monitor compliance with effect from 1 September 2026. The inspections will be conducted using a risk-based approach, with priority given to sectors that handle large volumes of personal data and are therefore considered high risk.
The first round of inspections will target financial institutions, insurance companies, local authorities, healthcare providers, mining enterprises, religious organisations, schools, tertiary institutions, professional bodies, government ministries, departments and agencies, as well as non-governmental organisations and private voluntary organisations.
Under the Act, any organisation that holds personal data relating to 50 or more individuals is required to obtain a Data Controller Licence. In addition to obtaining a licence, organisations are required to appoint a certified Data Protection Officer. The officer may be an employee of the organisation or an independent professional engaged for that purpose.POTRAZ has warned that penalties for non-compliance are severe and have been clearly stipulated in the law. Offenders face sanctions that include fines and imprisonment of up to seven years.
The Authority says the inspections are part of broader efforts to strengthen data protection, safeguard citizens’ privacy, and ensure that institutions entrusted with personal information adhere to national and international best practices.

