POTRAZ Commences Compliance Inspections Under Cyber and Data Protection Act

Potraz director general, Dr Gift Machengete

The Postal and Telecommunications Regulatory Authority of Zimbabwe, POTRAZ, has commenced mandatory compliance inspections and assessments in terms of Section 6(1)(a) read together with Section 21(3) and (4) of the Cyber and Data Protection Act [Chapter 12:07].

The Cyber and Data Protection Act came into effect in September 2024 and imposes mandatory obligations on both public and private organisations that process personal data. Central to these obligations is the requirement to obtain a Data Controller Licence. The initial deadline for registration was 31 March 2025. While some organisations have complied, others have yet to heed the provisions of the Act. In response, POTRAZ has opened a compliance window to allow non-registered entities to regularise their status.

To enforce adherence, the Authority will dispatch inspectors to monitor compliance with effect from 1 September 2026. The inspections will be conducted using a risk-based approach, with priority given to sectors that handle large volumes of personal data and are therefore considered high risk.

The first round of inspections will target financial institutions, insurance companies, local authorities, healthcare providers, mining enterprises, religious organisations, schools, tertiary institutions, professional bodies, government ministries, departments and agencies, as well as non-governmental organisations and private voluntary organisations.

Under the Act, any organisation that holds personal data relating to 50 or more individuals is required to obtain a Data Controller Licence. In addition to obtaining a licence, organisations are required to appoint a certified Data Protection Officer. The officer may be an employee of the organisation or an independent professional engaged for that purpose.POTRAZ has warned that penalties for non-compliance are severe and have been clearly stipulated in the law. Offenders face sanctions that include fines and imprisonment of up to seven years.

The Authority says the inspections are part of broader efforts to strengthen data protection, safeguard citizens’ privacy, and ensure that institutions entrusted with personal information adhere to national and international best practices.

Business

TSL Limited Posts 8% Revenue Growth To US$42.9 Million On Strong Agriculture And Logistics Performance

TSL Limited recorded 8 percent revenue growth to US$42.9 million for the nine months ended 31 July 2026, up from US$39.8 million in the prior year, with operating profit before tax also rising 8 percent to US$12.9 million despite a mixed operating environment. In a trading update, the company said the environment remained relatively stable […]

Read More
Business

Rainbow Tourism Group Delivers 13% Revenue Growth To US$50.3 Million As Foreign Currency Earnings Jump 28%; Declares US$2.8 Million Dividend

Rainbow Tourism Group Limited has delivered a resilient performance for the financial year ended 31 December 2025, with revenue growing by 13 percent to US$50.3 million from US$44.4 million in 2024, underpinned by commercial diversification, cost leadership and a record capital investment programme. In his Chairman’s statement, Douglas Hoto said the Group maintained a stable […]

Read More
Business

Hippo Valley Returns To Strong Profitability On Record Local Sales And Operational Efficiencies

Hippo Valley Estates Limited has reported a strong turnaround in performance for the year ended 31 March 2026, moving from a net debt position to a net cash position of US$13.4 million and growing profit by 79% to US$24.1 million. The sugar producer said the performance was anchored on revenue enhancement, cost management and sustainable […]

Read More