POTRAZ Commences Compliance Inspections Under Cyber and Data Protection Act

Potraz director general, Dr Gift Machengete

The Postal and Telecommunications Regulatory Authority of Zimbabwe, POTRAZ, has commenced mandatory compliance inspections and assessments in terms of Section 6(1)(a) read together with Section 21(3) and (4) of the Cyber and Data Protection Act [Chapter 12:07].

The Cyber and Data Protection Act came into effect in September 2024 and imposes mandatory obligations on both public and private organisations that process personal data. Central to these obligations is the requirement to obtain a Data Controller Licence. The initial deadline for registration was 31 March 2025. While some organisations have complied, others have yet to heed the provisions of the Act. In response, POTRAZ has opened a compliance window to allow non-registered entities to regularise their status.

To enforce adherence, the Authority will dispatch inspectors to monitor compliance with effect from 1 September 2026. The inspections will be conducted using a risk-based approach, with priority given to sectors that handle large volumes of personal data and are therefore considered high risk.

The first round of inspections will target financial institutions, insurance companies, local authorities, healthcare providers, mining enterprises, religious organisations, schools, tertiary institutions, professional bodies, government ministries, departments and agencies, as well as non-governmental organisations and private voluntary organisations.

Under the Act, any organisation that holds personal data relating to 50 or more individuals is required to obtain a Data Controller Licence. In addition to obtaining a licence, organisations are required to appoint a certified Data Protection Officer. The officer may be an employee of the organisation or an independent professional engaged for that purpose.POTRAZ has warned that penalties for non-compliance are severe and have been clearly stipulated in the law. Offenders face sanctions that include fines and imprisonment of up to seven years.

The Authority says the inspections are part of broader efforts to strengthen data protection, safeguard citizens’ privacy, and ensure that institutions entrusted with personal information adhere to national and international best practices.

Leave a Reply

Business

ZSE and Lloyd Corporate Capital Partner to Unlock Growth Capital for Zimbabwe’s SMEs Through ZEEX

The Zimbabwe Stock Exchange Limited and Lloyd Corporate Capital have signed a Memorandum of Understanding (MOU) aimed at channelling growth capital and blended finance into the country’s SME sector through the Zimbabwe Entrepreneurship Exchange, ZEEX. Announced in Harare in July 2026, the partnership brings together ZSE’s regulated capital market infrastructure and Lloyd Corporate Capital’s expertise […]

Read More
Business

Seed Co Records 22% Volume Jump in Q1 as Winter Cereal Demand Rebounds

Seed Co Limited has opened FY27 with stronger volumes and a narrower loss, supported by improved macroeconomic conditions and disciplined cost management. For the first quarter ended 30 June 2026, the group recorded a 22% increase in volumes sold to 4,145 MT, up from 3,393 MT in the same period last year. Revenue rose 19% […]

Read More
Business

Delta Corporation Posts Strong Q1 Growth as Capacity Expansion and Stable ZiG Drive Momentum

Delta Corporation Limited has opened the 2026 financial year with strong trading momentum, underpinned by a stable operating environment, firm consumer demand and double-digit volume growth across its core beverage categories. For the first quarter ended 30 June 2026, Group beverage volume rose by 14% to approximately 3.4 million hectolitres, with Zimbabwe operations excluding regional […]

Read More