Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024
Anyone who decides how personal data is used in Zimbabwe must now hold a POTRAZ data controller licence — US$50 to US$2 500 a year by tier — appoint a data protection officer within 90 days, and report breaches within 24 hours.
These regulations, made by the Minister of ICT, Postal and Courier Services under section 32 of the Cyber and Data Protection Act [Chapter 12:07], build the licensing machinery for data controllers and put the Data Protection Authority (POTRAZ) in charge of it.
Who must be licensed: any person who decides the means, purpose or outcome of processing, decides what personal data is collected or from whom, or obtains commercial gain from processing personal data. Applications go in on Form DP1 with the fee in the Second Schedule; POTRAZ must issue, reject with reasons, or ask for more information within 14 days. Licences last 12 months and are renewed on the same form, with the renewal filed at least 3 months before expiry. Organisations already controlling data when the regulations were promulgated had 6 months to apply. Processing without a licence, or continuing after the 6 months, is an offence carrying a fine of up to level 11 or up to seven years' imprisonment, or both.
Licences come in four tiers by the number of data subjects: tier 1 for 50 to 1 000, tier 2 for 1 001 to 100 000, tier 3 for 100 001 to 500 000, and tier 4 for more than 500 000. Fees in the Second Schedule are payable in USD or in ZiG at the official rate: a US$30 application fee for tiers 2, 3 and 4; then initial or renewal fees of US$50 (tier 1), US$300 (tier 2), US$500 (tier 3) and US$2 500 (tier 4). Training accreditation costs US$5 000 a year; DPO training and certification is US$1 250 per Zimbabwean and US$1 450 per international candidate, with training application fees of US$30 and US$50 respectively. Processing for personal or household use, journalistic, historical or archival purposes is exempt from licensing, though the journalistic, historical and archival category must still register and comply with the data protection principles.
Every data controller must appoint a data protection officer within 90 days of promulgation (or of a DPO contract ending) and notify POTRAZ on Form DP2, including within 14 days any change of the DPO's contact details or the DPO's dismissal or resignation. Failing to appoint a DPO is an offence carrying up to a level 7 fine or two years' imprisonment. DPOs need relevant qualifications — data science, analytics, information security, IS audit, law or audit — plus knowledge of national data protection law, and must complete a POTRAZ-approved certification course. Only accredited, fee-paying providers may run that training.
Controllers must notify POTRAZ of all processing activities, any indirect collection modified, any intended transfer of data outside Zimbabwe and any processing of biometric or genetic data. Solely automated decisions with legal effects need the data subject's consent or a legal basis. Children's data may not be processed without parental or guardian consent, needs regular data protection impact assessments, must follow privacy by design and by default, and may not be subject to automated decision-making affecting the child's rights.
On breaches: a controller must report a personal data breach to POTRAZ within 24 hours of becoming aware of it, using Form DP3, and must tell affected data subjects within 72 hours where the breach is likely to be a high risk to their rights and freedoms. Controllers must respond to POTRAZ information requests on breaches within 14 days and finish the investigation and file a report within 21 days of notification. Most of the offences in the regulations carry a fine of up to level 11 or up to seven years' imprisonment, or both; the level amounts themselves are on the standard scale and are not printed in this instrument.
The regulations were gazetted on 13 September 2024 and state no separate commencement date, so the six-month licensing and 90-day DPO deadlines run from promulgation.
What changed
- A POTRAZ data controller licence is mandatory for anyone determining the purposes and means of processing personal data; existing controllers had 6 months to apply
- Four licence tiers by number of data subjects, with annual fees of US$50, US$300, US$500 and US$2 500 and a US$30 application fee for tiers 2 to 4
- Every controller must appoint a certified data protection officer within 90 days and notify POTRAZ on Form DP2
- Data breaches must be reported to POTRAZ within 24 hours on Form DP3, and to affected individuals within 72 hours for high-risk breaches; investigation report due within 21 days
- Controllers must notify POTRAZ of cross-border transfers and of biometric or genetic data processing, and need parental consent plus impact assessments for children's data
- Unlicensed processing and most other breaches carry a fine up to level 11 or up to seven years' imprisonment; failure to appoint a DPO up to level 7 or two years
Who this affects
- Banks, insurers, medical aid societies and hospitals processing client data
- Telecoms operators, ISPs and app companies
- Schools, universities and employers holding staff and student records
- Government ministries and departments processing personal data
- Newly appointed data protection officers and accredited DPO trainers
Plain-language summary — not legal advice. Always read the full instrument.