Data protection compliance for businesses in Zimbabwe
Data protection compliance in Zimbabwe means licensing with POTRAZ as a data controller under Statutory Instrument 155 of 2024, appointing a Data Protection Officer, keeping a record of processing activities, publishing clear notices, having breach and data subject request procedures, and training your staff. StoneGuard runs all of it with a certified DPO, from $250.
Last reviewed 2 September 2026.
What compliance actually means for a business
Most business owners hear "data protection" and think of servers and hackers. The obligation is broader and more ordinary than that. If your business holds information about identifiable people, you are a data controller and the law applies to you.
Your customer database is personal data. So is your payroll, your staff files, your CCTV footage, your visitors book, the CVs in the recruitment inbox and the WhatsApp group where orders come in.
You have to be licensed. Statutory Instrument 155 of 2024 requires every organisation holding personal data to license with POTRAZ as a data controller, in the exact registered name of the entity.
You have to appoint an officer. A Data Protection Officer is appointed and notified to POTRAZ. At Tier 1 this applies where you process sensitive data such as health, children or biometric data.
You have to write it down. A record of processing activities, a privacy policy, consent wording, a breach procedure and a data subject request procedure.
You have to train people. Staff training is mandatory under CDPG 1 of 2025, with a record of who attended and when.
You have to keep it current. The licence is renewed annually and the registers are maintained. Compliance is a cycle rather than a one off filing.
It applies across sectors
The obligation is not limited to technology companies. Any organisation holding personal data is caught by it, which in practice means almost every registered business, and public and voluntary bodies as well.
Healthcare. Patient records are sensitive data, which carries stronger obligations, and healthcare is in the first wave of POTRAZ inspections.
Financial services and insurance. High volumes of identity, income and transaction data, which puts these organisations high on a risk based inspection list.
Retail and hospitality. Customer lists, loyalty programmes, bookings, CCTV and card data.
Schools and colleges. Records about children, which the Act treats as sensitive data.
Mining, manufacturing and logistics. Large payrolls, contractor records, site access control and biometric clocking systems.
NGOs and voluntary organisations. Beneficiary data, which is often sensitive and often collected in the field.
Government and local authorities. Citizen and ratepayer records held at scale.
What it costs a business
Two separate numbers, always. The StoneGuard service fee covers the work. POTRAZ fees are paid to POTRAZ at cost, ex VAT.
StoneGuard compliance packages start at $250, and the $90 consultation that opens the engagement is credited in full toward the package. The ongoing DPO retainer starts when the licence is granted and is quoted for your organisation.
Government fees payable to POTRAZ, ex VAT. POTRAZ adds VAT on its own invoice.
POTRAZ tier
Records held
Licence fee (ex VAT)
Application fee
Tier 1
Up to 1,000 records
$50
Not applicable
Tier 2
Up to 100,000 records
$300
$30
Tier 3
Up to 500,000 records
$500
$30
Tier 4
Over 500,000 records
$2,500
$30
Where to start
The first question is what personal data you actually hold, because that sets your tier and your fee. The consultation works it out with you rather than asking you to guess.
Consultation. A $90 consultation opens the engagement. We work out what personal data you hold, which POTRAZ tier you fall into and what is missing. The fee is credited in full toward your package when you proceed.
Gap analysis. A certified Data Protection Officer assesses your organisation against the Cyber and Data Protection Act on the StoneGuard platform and gives you a scored report with the gaps ranked.
Licensing. We prepare and file your Data Controller licence application and your DPO appointment notification, and we handle the correspondence with POTRAZ until the licence is granted.
Documentation. Your record of processing activities, privacy policy, consent wording, breach response procedure and data subject request procedure are drafted and put in place.
Training. Staff training is delivered, which CDPG 1 of 2025 makes mandatory for licensed data controllers.
Ongoing DPO. A certified Data Protection Officer stays on record for you after the licence is granted, keeps the registers current, handles data subject requests and breaches, files the annual renewal and attends POTRAZ inspections.
Why businesses choose StoneGuard
Certified Data Protection Officers. Your compliance is run by a certified DPO who goes on record for your organisation, not by a template pack you are left to fill in yourself.
One fixed package, not line by line. Packages start at $250 and cover the whole licensing job. POTRAZ fees are paid to POTRAZ at cost, ex VAT, and are separate from the StoneGuard service fee. You will always see two numbers, never one blended figure.
Everything on one platform. Your assessment, registers, reports and remediation tasks live in the StoneGuard platform, so you can show an inspector current evidence instead of hunting through email.
Hosted in Zimbabwe. Your compliance data is stored and hosted on infrastructure in Zimbabwe, in line with the Cyber and Data Protection Act.
It does not stop at registration. Registration is the start of the obligation. The licence runs for twelve months and has to be renewed, the registers have to stay current, and an inspector will ask for evidence of both.
Frequently asked questions
Which businesses in Zimbabwe need to comply with data protection law?
Any organisation that holds personal data. Statutory Instrument 155 of 2024 requires every organisation holding personal data to license with POTRAZ as a data controller. If you keep a customer list, run a payroll or hold staff files, the obligation applies to your business.
We are a small company. Is there a threshold below which this does not apply?
Your size determines your POTRAZ tier and therefore your licence fee, not whether you have to register. A small company with under 1,000 records sits at Tier 1, where the licence fee is $50 ex VAT and the $30 application fee does not apply.
What documents does a compliant business need to have?
A current Data Controller licence, evidence of the Data Protection Officer appointment, a record of processing activities, a privacy policy and consent wording, a breach response procedure, a data subject request procedure, staff training records as required by CDPG 1 of 2025, and impact assessments for higher risk processing such as health data or data about children.
Is a privacy policy on our website enough?
No. A privacy policy is one item on a longer list. Without a licence, an appointed officer, a current record of processing activities, working procedures and delivered training, a policy on its own does not put an organisation in a defensible position at an inspection.
How do we get started?
Book the $90 consultation. We work out what data you hold, which POTRAZ tier you fall into and what is missing, and the fee is credited in full toward your package when you proceed. Packages start at $250.
Get licensed and inspection ready
A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.