Data Protection Compliance: Zimbabwe Entities Face Mandatory Inspections from September 2026

With mandatory data protection inspections set to begin on 1 September 2026, legal expert Vengai Madzima explains who must comply, what licences are needed, and how to avoid penalties.

Create an editorial news illustration for an article about 'Data Protection Compliance: Zimbabwe Entities Face Mandatory Inspections from September 2026'. The specific country is Zimbabwe (ZW); make visual cues accurate to this exact country and avoi

As Zimbabwe prepares for the enforcement of the Cyber and Data Protection Act, entities handling personal information are being urged to review their compliance status ahead of the 1 September 2026 deadline set by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).

Vengai Madzima, Senior Partner at Madzima Chidyausiku Museta Legal Practitioners, said the right to privacy and data protection is a constitutional right, and all organisations that collect personal data—including identity details, financial information, health status, and employment data—must ensure they are compliant.

Who Needs a Data Controller Licence?

Under the Cyber and Data Protection Act (Chapter 12:07) and its licensing regulations, entities that act as data controllers and are not exempt must obtain a data controller licence from POTRAZ. Licences are renewed annually and vary based on the volume of data handled.

Exemptions exist for certain activities, such as family or household matters, law enforcement, and journalistic or historical purposes, but the list is not exhaustive.

Key Compliance Requirements

Data controllers should also appoint a certified data protection officer (DPO) to monitor compliance, conduct audits, train staff, and serve as the liaison with POTRAZ.

In the event of a data breach, the Data Protection Authority must be notified within 24 hours. If the breach poses a real risk to individuals, affected people must be informed within 72 hours.

Ongoing Obligations

Madzima stressed that data protection is a continuous duty: entities should collect personal information only for legitimate purposes, secure it adequately, and retain it only as long as necessary.

With mandatory inspections and assessments starting in two days, non-compliant organisations could face enforcement action. Businesses, government agencies, universities, and financial institutions are advised to act promptly.