StoneGuard › The Act explained

The Cyber and Data Protection Act and SI 155 of 2024, explained

Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] is the country’s data protection law, enforced by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ). Statutory Instrument 155 of 2024 requires every organisation holding personal data to license with POTRAZ as a data controller, and CDPG 1 of 2025 makes staff training mandatory. Compliance inspections begin on 1 September 2026.

Last reviewed 2 September 2026.

The Cyber and Data Protection Act [Chapter 12:07]

The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s data protection law. It governs how organisations collect, store, use and share personal data, and it sets the rights people have over data held about them. the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is the authority that administers and enforces it.

Personal data is any information that identifies a living person. Names, phone numbers, national ID numbers, addresses, email addresses, payroll records, patient files, CCTV footage and job applications all count.

The Act also recognises sensitive data, which is given stronger protection. This includes health data, data about children and biometric data.

Statutory Instrument 155 of 2024: the licensing requirement

Statutory Instrument 155 of 2024 is the instrument that turned the Act into a registration obligation. It requires every organisation that holds personal data to license with POTRAZ as a data controller.

It also sets the procedure. You apply for the Data Controller licence on Form DP1 and you notify your Data Protection Officer appointment on Form DP2. The licence is issued to a legal entity, runs for twelve months, and is renewed annually.

Licence fees are set by tier, based on the number of records an organisation holds, and are paid to POTRAZ at cost.

A $30 application fee, ex VAT, applies from Tier 2 upward. It is not charged at Tier 1 or on renewals.
TierRecords heldLicence fee (ex VAT)
Tier 1Up to 1,000 records$50
Tier 2Up to 100,000 records$300
Tier 3Up to 500,000 records$500
Tier 4Over 500,000 records$2,500

CDPG 1 of 2025: training became mandatory

CDPG 1 of 2025 makes staff data protection training a requirement for licensed data controllers. Training records are part of what an organisation is expected to be able to show.

In practice this means a delivered session with an attendance record, refreshed on a cycle, rather than a policy document circulated by email.

What the Act requires you to have in place

Enforcement

POTRAZ inspections begin on 1 September 2026. Inspections are risk based, and healthcare is in the first wave along with other high volume and sensitive data environments.

The move from a registration deadline to an inspection programme is the point at which documentation stops being advisory. An inspector asks to see the licence, the appointment, the registers, the procedures and the training records.

Frequently asked questions

What is the Cyber and Data Protection Act in Zimbabwe?

The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s data protection law. It governs how organisations collect, store, use and share personal data, sets out the rights of the people that data is about, and is administered and enforced by POTRAZ.

What does SI 155 of 2024 require?

Statutory Instrument 155 of 2024 requires every organisation that holds personal data to license with POTRAZ as a data controller. It sets the procedure, using Form DP1 for the licence application and Form DP2 to notify the Data Protection Officer appointment, and it sets licence fees by tier based on how many records the organisation holds.

What is CDPG 1 of 2025?

CDPG 1 of 2025 is the guideline that makes staff data protection training mandatory for licensed data controllers in Zimbabwe. Organisations are expected to be able to show that training was delivered and recorded.

What counts as personal data under the Act?

Any information that identifies a living person. Names, phone numbers, national ID numbers, addresses, email addresses, payroll records, patient files, CCTV footage and job applications are all personal data. Health data, data about children and biometric data are treated as sensitive data and carry stronger obligations.

Who enforces data protection law in Zimbabwe?

the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) administers and enforces the Cyber and Data Protection Act [Chapter 12:07]. POTRAZ issues Data Controller licences and carries out the compliance inspections that begin on 1 September 2026.

Get licensed and inspection ready

A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.

Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.