As Zimbabwe prepares for the enforcement of the Cyber and Data Protection Act, entities handling personal information are being urged to review their compliance status ahead of the 1 September 2026 deadline set by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).
Vengai Madzima, Senior Partner at Madzima Chidyausiku Museta Legal Practitioners, said the right to privacy and data protection is a constitutional right, and all organisations that collect personal data—including identity details, financial information, health status, and employment data—must ensure they are compliant.
Who Needs a Data Controller Licence?
Under the Cyber and Data Protection Act (Chapter 12:07) and its licensing regulations, entities that act as data controllers and are not exempt must obtain a data controller licence from POTRAZ. Licences are renewed annually and vary based on the volume of data handled.
Exemptions exist for certain activities, such as family or household matters, law enforcement, and journalistic or historical purposes, but the list is not exhaustive.
Key Compliance Requirements
Data controllers should also appoint a certified data protection officer (DPO) to monitor compliance, conduct audits, train staff, and serve as the liaison with POTRAZ.
In the event of a data breach, the Data Protection Authority must be notified within 24 hours. If the breach poses a real risk to individuals, affected people must be informed within 72 hours.
Ongoing Obligations
Madzima stressed that data protection is a continuous duty: entities should collect personal information only for legitimate purposes, secure it adequately, and retain it only as long as necessary.
With mandatory inspections and assessments starting in two days, non-compliant organisations could face enforcement action. Businesses, government agencies, universities, and financial institutions are advised to act promptly.






