StoneGuard › ISPs and community networks

Data protection for ISPs and community networks in Zimbabwe

A Zimbabwean internet service provider needs two separate licences from POTRAZ: the telecoms licence it already holds, and a data controller licence under Statutory Instrument 155 of 2024 for the subscriber personal data it processes. They are issued by the same regulator under different statutes, and holding one does not cover the other.

Last reviewed 2 September 2026.

Your telecoms licence is not a data controller licence

This is the single most common misunderstanding among operators, and it is an entirely understandable one, because the same organisation issues both.

the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is established under the Postal and Telecommunications Act [Chapter 12:05]. That is the statute your network, service or access licence comes from, and it is the relationship most operators think of when they think of POTRAZ.

Section 5 of the Cyber and Data Protection Act [Chapter 12:07] then does something separate. It designates that same Authority as the Data Protection Authority. Section 6 sets out the functions attaching to that second role, which include regulating how personal information may be processed, enforcing fair processing, conducting inquiries and investigations, and receiving and investigating complaints about data processing.

So POTRAZ wears two statutory hats. As telecoms regulator it licenses you to operate a network and carry traffic. As Data Protection Authority it licenses you, separately, to process the personal data of the people using that network. The second licence is the one operators do not know they need.

If you have been told, or have assumed, that your existing POTRAZ licence covers your obligations to subscribers, it does not, and section 3(3) of SI 155 makes processing without a data controller licence an offence carrying a fine of up to level 11 or imprisonment of up to seven years or both.

What an ISP actually processes

Operators tend to picture personal data as the billing database. The reality is broader, because a network generates personal data continuously as a by-product of carrying traffic, and much of it is more revealing than the billing record.

Two of those deserve particular attention. Biometric access control brings section 10(2)(d) of SI 155 into play, which requires you to notify the Authority of processing involving biometric and genetic data. And captive portal sign-ups are collected at the moment a person most wants connectivity and least wants to read a notice, which makes the lawfulness of that collection worth examining rather than assuming.

Session and traffic data is personal data

An operator will sometimes argue that logs are technical records rather than personal data. That argument does not hold where the record can be tied back to an identifiable person, and on a subscriber network it almost always can, because the whole point of the authentication system is to know whose session it is.

What makes this category sensitive in substance, whatever its formal classification, is what it reveals. A session log shows when somebody is at home, when they are awake, when they went away and for how long. Tied to the sites contacted, it can reveal a great deal more. That is the reason access to it should be narrow and logged, and the reason a casual internal request for "the logs for this customer" should meet a process rather than a helpful colleague.

Community ISPs and co-operative networks

A community network, a village wifi co-operative or a small WISP serving a suburb usually assumes it is too small and too informal for any of this. That assumption is worth testing against two facts.

The first is that the tier categories in section 6 of Statutory Instrument 155 of 2024 formally begin at 50 data subjects. A community network with a couple of hundred connected households is well past that once account holders, the people named on those accounts, volunteers and committee members are counted.

The second is that the duty to apply in sections 3 and 4 attaches to whoever determines the purposes and means of the processing, and section 3(2)(d) expressly reaches a person processing to obtain a commercial gain "or other benefit". A non profit or cost recovery model does not put a network outside it.

Where subscriber data leaves the country

Operators are more exposed to cross-border obligations than most businesses, because the supporting systems are so often hosted elsewhere. Section 10(2)(c) of Statutory Instrument 155 of 2024 requires a controller to notify the Authority of any intention to transfer or share data subject information outside Zimbabwe. The notifiable event is the intention, so it belongs before the platform goes live.

Section 28 of the Cyber and Data Protection Act [Chapter 12:07] governs the transfer itself, and section 29 addresses transfers to a country that does not assure an adequate level of protection. Contravening section 28 is one of the five sections named in section 33(2), carrying a fine of up to level 11 or imprisonment of up to seven years or both.

None of this means those platforms cannot be used. It means the intention is notified, the arrangement is papered under section 10(4)(f), and your subscriber notice honestly describes where the data goes.

Which tier an operator falls into

The count that sets your tier is data subjects, meaning people, not employees and not customers alone. It includes current and former staff, seasonal and casual workers, customers, enquirers who never bought, suppliers and their contact people, and anyone on a mailing list. Most organisations that assume they are small find they cross a tier boundary once the count is done properly, which is one of the things the consultation settles before anything is filed.

For an operator the count is dominated by subscribers and by everyone named on a subscriber account, plus former subscribers whose records are still held. Because churn accumulates, an ISP that currently serves a few thousand active customers can be holding data on considerably more people than that. Hotspot and captive portal registrations count too, and they are the records operators most often forget they have.

Bands are the licence categories in section 6 of SI 155 of 2024. Fees are payable to POTRAZ at cost, ex VAT. POTRAZ adds VAT on its own invoice.
Licence tierData subjects (SI 155 s6)Licence fee (ex VAT)Application fee
Tier 1Minimum 50, maximum 1,000$50Not applicable
Tier 21,001 to 100,000$300$30
Tier 3100,001 to 500,000$500$30
Tier 4More than 500,000$2,500$30

An operator processing for more than 500,000 data subjects sits in Tier 4. Between the active base, the churned base and public wifi sign-ups, national operators reach that faster than they expect, which is another reason to have a retention rule that is actually applied.

Where operators most often come up short

How StoneGuard gets it done

POTRAZ fees are paid to POTRAZ at cost, ex VAT, and are separate from the StoneGuard service fee. You will always see two numbers, never one blended figure.

Frequently asked questions

We already have a POTRAZ licence as an ISP. Do we still need a data controller licence?

Yes, and they are two different things. POTRAZ is established under the Postal and Telecommunications Act [Chapter 12:05], which is where your telecoms licence comes from. Section 5 of the Cyber and Data Protection Act [Chapter 12:07] separately designates that same Authority as the Data Protection Authority, and Statutory Instrument 155 of 2024 requires a separate data controller licence, applied for on Form DP1, for the processing of personal data. One regulator, two statutory roles, two licences. Holding the telecoms licence does not cover the data protection obligation.

Do community networks and small WISPs need to register?

The duty in sections 3 and 4 of Statutory Instrument 155 of 2024 attaches to whoever determines the purposes and means of processing personal data, and section 3(2)(d) reaches processing for commercial gain "or other benefit", so a cost recovery or non profit model does not sit outside it. The tier categories formally begin at 50 data subjects, and a community network with a couple of hundred connected households is well past that once account holders, volunteers and committee members are counted. The licence is applied for in the exact registered name of the trust, co-operative or company that runs the network.

Is subscriber session and traffic data personal data?

Where it can be tied to an identifiable subscriber, yes, and on an authenticated network it generally can be. Session logs, allocated IP addresses, connection times and data volumes attached to a named account are information about that person. In substance they are revealing records, because they show when somebody is at home and when they are not, which is why access to them should be restricted to named roles and logged.

Which POTRAZ tier does an ISP fall into?

It is set by the number of data subjects, counting active subscribers, everyone named on a subscriber account, former subscribers whose records are still held, hotspot and captive portal registrations, and staff. Tier 2 runs from 1,001 to 100,000 at $300 ex VAT plus the $30 application fee, Tier 3 to 500,000 at $500, and Tier 4 above that at $2,500. Churn accumulates, so operators are frequently a tier higher than their active base suggests.

Does an ISP need a Data Protection Officer?

A licensed controller appoints one under section 12(1) of Statutory Instrument 155 of 2024, notified to the Authority on Form DP2. Given the volume and the revealing nature of subscriber and session data, and the fact that most operators also run biometric access control at sites, the requirement applies squarely. Failing to appoint is an offence under section 12(6) carrying a fine of up to level 7 or imprisonment of up to two years.

Our billing and RADIUS platform is hosted outside Zimbabwe. Is that a problem?

It is manageable, but it has to be handled rather than ignored. Section 10(2)(c) of Statutory Instrument 155 of 2024 requires you to notify the Authority of any intention to transfer or share data subject information outside Zimbabwe, section 28 of the Act governs the transfer, and section 29 covers countries that do not assure an adequate level of protection. You also need a written agreement with the provider under section 10(4)(f).

We resell another operator’s bandwidth. Are we a controller?

If you decide what subscriber data is collected, from whom, and what happens to it, you are a controller in your own right regardless of whose capacity you are carrying. Where you also process data on another operator’s instructions, you are a processor for that work as well. Most resellers are both, and the classification is settled at the consultation before anything is filed.

How long can we keep subscriber logs?

The answer has to come from a defined, justified retention period rather than from default storage behaviour. Where a licence condition or another law requires particular records to be retained for a period, that requirement operates alongside your data protection duties rather than replacing them, and the interaction between the two is worth taking advice on. What is not defensible is keeping everything indefinitely because nobody decided otherwise, which raises your tier and widens the impact of any breach.

Get licensed and inspection ready

A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.

Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.