POTRAZ Commences Compliance Inspections Under Cyber and Data Protection Act

Potraz director general, Dr Gift Machengete

The Postal and Telecommunications Regulatory Authority of Zimbabwe, POTRAZ, has commenced mandatory compliance inspections and assessments in terms of Section 6(1)(a) read together with Section 21(3) and (4) of the Cyber and Data Protection Act [Chapter 12:07].

The Cyber and Data Protection Act came into effect in September 2024 and imposes mandatory obligations on both public and private organisations that process personal data. Central to these obligations is the requirement to obtain a Data Controller Licence. The initial deadline for registration was 31 March 2025. While some organisations have complied, others have yet to heed the provisions of the Act. In response, POTRAZ has opened a compliance window to allow non-registered entities to regularise their status.

To enforce adherence, the Authority will dispatch inspectors to monitor compliance with effect from 1 September 2026. The inspections will be conducted using a risk-based approach, with priority given to sectors that handle large volumes of personal data and are therefore considered high risk.

The first round of inspections will target financial institutions, insurance companies, local authorities, healthcare providers, mining enterprises, religious organisations, schools, tertiary institutions, professional bodies, government ministries, departments and agencies, as well as non-governmental organisations and private voluntary organisations.

Under the Act, any organisation that holds personal data relating to 50 or more individuals is required to obtain a Data Controller Licence. In addition to obtaining a licence, organisations are required to appoint a certified Data Protection Officer. The officer may be an employee of the organisation or an independent professional engaged for that purpose.POTRAZ has warned that penalties for non-compliance are severe and have been clearly stipulated in the law. Offenders face sanctions that include fines and imprisonment of up to seven years.

The Authority says the inspections are part of broader efforts to strengthen data protection, safeguard citizens’ privacy, and ensure that institutions entrusted with personal information adhere to national and international best practices.

Business

Old Mutual Posts Strong First-Half Growth, Raises Dividend and Launches R1 Billion Buyback

Old Mutual Limited delivered a solid set of unaudited interim results for the six months ended 30 June 2026, supported by stronger sales, improved margins, disciplined cost management and good progress on its strategic reset. The Group reported 21% growth in both Life Annualised Premium Equivalent sales and gross flows, reflecting improved competitiveness across South […]

Read More
Business

WestProp Shareholders Approve Restructuring Plan and Minority Exit Offer

WestProp Holdings Limited shareholders have approved a comprehensive scheme of reconstruction that will split the company’s assets and offer eligible minority shareholders in Alpha Holdings Africa an exit at a significant premium. The resolutions were passed at an Extraordinary General Meeting held on Tuesday, 1 September 2026. Shareholders representing 76.18% of the register attended in […]

Read More
Business

Revitus REIT Delivers Strong 2025 Growth on Higher Income and Asset Upgrades

Revitus Property Opportunities Real Estate Investment Trust closed 2025 with a marked improvement in financial performance, supported by stronger rental income, investment gains, and ongoing upgrades across key properties. For the year ended 31 December 2025, the REIT posted a profit of US$4.6 million, a sharp increase from the prior year. The result was driven […]

Read More