StoneGuard › The Act explained
Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] is the country’s data protection law, enforced by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ). Statutory Instrument 155 of 2024 requires every organisation holding personal data to license with POTRAZ as a data controller, and CDPG 1 of 2025 makes staff training mandatory. Compliance inspections begin on 1 September 2026.
Last reviewed 2 September 2026.
The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s data protection law. It governs how organisations collect, store, use and share personal data, and it sets the rights people have over data held about them. the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is the authority that administers and enforces it.
Personal data is any information that identifies a living person. Names, phone numbers, national ID numbers, addresses, email addresses, payroll records, patient files, CCTV footage and job applications all count.
The Act also recognises sensitive data, which is given stronger protection. This includes health data, data about children and biometric data.
Statutory Instrument 155 of 2024 is the instrument that turned the Act into a registration obligation. It requires every organisation that holds personal data to license with POTRAZ as a data controller.
It also sets the procedure. You apply for the Data Controller licence on Form DP1 and you notify your Data Protection Officer appointment on Form DP2. The licence is issued to a legal entity, runs for twelve months, and is renewed annually.
Licence fees are set by tier, based on the number of records an organisation holds, and are paid to POTRAZ at cost.
| Tier | Records held | Licence fee (ex VAT) |
|---|---|---|
| Tier 1 | Up to 1,000 records | $50 |
| Tier 2 | Up to 100,000 records | $300 |
| Tier 3 | Up to 500,000 records | $500 |
| Tier 4 | Over 500,000 records | $2,500 |
CDPG 1 of 2025 makes staff data protection training a requirement for licensed data controllers. Training records are part of what an organisation is expected to be able to show.
In practice this means a delivered session with an attendance record, refreshed on a cycle, rather than a policy document circulated by email.
POTRAZ inspections begin on 1 September 2026. Inspections are risk based, and healthcare is in the first wave along with other high volume and sensitive data environments.
The move from a registration deadline to an inspection programme is the point at which documentation stops being advisory. An inspector asks to see the licence, the appointment, the registers, the procedures and the training records.
The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s data protection law. It governs how organisations collect, store, use and share personal data, sets out the rights of the people that data is about, and is administered and enforced by POTRAZ.
Statutory Instrument 155 of 2024 requires every organisation that holds personal data to license with POTRAZ as a data controller. It sets the procedure, using Form DP1 for the licence application and Form DP2 to notify the Data Protection Officer appointment, and it sets licence fees by tier based on how many records the organisation holds.
CDPG 1 of 2025 is the guideline that makes staff data protection training mandatory for licensed data controllers in Zimbabwe. Organisations are expected to be able to show that training was delivered and recorded.
Any information that identifies a living person. Names, phone numbers, national ID numbers, addresses, email addresses, payroll records, patient files, CCTV footage and job applications are all personal data. Health data, data about children and biometric data are treated as sensitive data and carry stronger obligations.
the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) administers and enforces the Cyber and Data Protection Act [Chapter 12:07]. POTRAZ issues Data Controller licences and carries out the compliance inspections that begin on 1 September 2026.
A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.
Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.