StoneGuard › NGOs and PVOs
An NGO or private voluntary organisation operating in Zimbabwe is a data controller and must license with POTRAZ. Beneficiary records are frequently sensitive data, and reporting to an overseas donor is a transfer of personal information outside Zimbabwe, which section 10(2)(c) of Statutory Instrument 155 of 2024 requires you to notify.
Last reviewed 2 September 2026.
This is the first thing to settle, because it is the most common misunderstanding in the sector. The licensing duty is not about profit.
Section 3(2)(d) of Statutory Instrument 155 of 2024 extends to a person who processes personal information to obtain a commercial gain "or other benefit". More directly, section 3(2)(a) to (c) and section 4(1) attach the duty to whoever decides the means, purpose and outcome of the processing, and what data is collected from whom. An organisation running a beneficiary registration exercise is doing exactly that.
The exemptions in section 8 are personal, family or household affairs, law enforcement, and journalistic, historical or archival purposes. There is no charitable, humanitarian or voluntary exemption, and the law enforcement and journalistic categories still have to register with the Authority even though they need not license.
Programme data is usually richer and more sensitive than commercial customer data, and it is usually held about people in a weaker bargaining position. Both facts raise the standard.
This is the obligation that catches the sector hardest, because it is built into the funding model. Section 10(2)(c) of Statutory Instrument 155 of 2024 requires a data controller to notify the Authority of any intention to transfer or share information of data subjects outside Zimbabwe. Note that the notifiable event is the intention, so it is something to do before the reporting cycle rather than after it.
Section 28 of the Cyber and Data Protection Act [Chapter 12:07] governs the transfer of personal information outside Zimbabwe, and section 29 deals with transfers to a country that does not assure an adequate level of protection. Contravening section 28 is one of the five sections named in section 33(2), carrying a fine of up to level 11 or imprisonment of up to seven years or both.
The practical fix is usually a combination of three things: notifying the intention properly, minimising what actually crosses the border by aggregating or pseudonymising before reporting, and papering the arrangement with the recipient. Most donors accept aggregated reporting once asked.
Consent collected at a distribution point, from someone who believes that declining will cost them assistance, is fragile. The law does not describe it in those terms, but an inspector reviewing a consent process will look at whether the person had a real choice and whether they understood what they were agreeing to.
Where children are involved, section 10(5) requires the consent of the parent or legal guardian, requires reasonable efforts to verify that it came from the parent or guardian, and requires regular data protection impact assessments to identify and mitigate risks to children.
The count that sets your tier is data subjects, meaning people, not employees and not customers alone. It includes current and former staff, seasonal and casual workers, customers, enquirers who never bought, suppliers and their contact people, and anyone on a mailing list. Most organisations that assume they are small find they cross a tier boundary once the count is done properly, which is one of the things the consultation settles before anything is filed.
For an NGO the count is dominated by beneficiaries rather than staff. A programme that has reached tens of thousands of households over several years is counting all of those individuals, not just this year’s caseload, unless a retention schedule has been applied and followed.
| Licence tier | Data subjects (SI 155 s6) | Licence fee (ex VAT) | Application fee |
|---|---|---|---|
| Tier 1 | Minimum 50, maximum 1,000 | $50 | Not applicable |
| Tier 2 | 1,001 to 100,000 | $300 | $30 |
| Tier 3 | 100,001 to 500,000 | $500 | $30 |
| Tier 4 | More than 500,000 | $2,500 | $30 |
Each legal entity licenses in its own registered name. Where an international organisation operates through a locally registered entity, it is that entity that appears on the licence.
POTRAZ fees are paid to POTRAZ at cost, ex VAT, and are separate from the StoneGuard service fee. You will always see two numbers, never one blended figure.
Yes. The licensing duty in sections 3 and 4 of Statutory Instrument 155 of 2024 attaches to whoever determines the purposes and means of processing personal data, regardless of profit. An NGO registering beneficiaries, running surveys or holding case files is a data controller and must apply for a data controller licence.
No. Section 8 of Statutory Instrument 155 of 2024 exempts only processing for personal, family or household affairs, for law enforcement, and for journalistic, historical or archival purposes. There is no charitable or humanitarian exemption. Law enforcement and journalistic, historical or archival controllers must in any case still register with the Authority.
Not without dealing with the cross border rules first. Section 10(2)(c) of Statutory Instrument 155 of 2024 requires you to notify the Authority of any intention to transfer or share data subject information outside Zimbabwe, and section 28 of the Cyber and Data Protection Act [Chapter 12:07] governs the transfer itself, with section 29 covering countries that do not assure an adequate level of protection. Contravening section 28 is one of the offences in section 33(2). In many cases the cleanest answer is to report in aggregate so that no personal data crosses the border at all.
It is set by the number of data subjects, which for an NGO usually means beneficiaries rather than staff. Tier 1 covers 50 to 1,000 at $50 ex VAT, Tier 2 covers 1,001 to 100,000 at $300 ex VAT plus the $30 application fee, and Tier 3 covers 100,001 to 500,000 at $500 ex VAT. Organisations with multi year programme histories are often a tier higher than they assume.
Where sensitive data is processed, and health information, children’s data and case files all qualify, the officer requirement applies even at Tier 1. The appointment is notified on Form DP2 under section 12 of Statutory Instrument 155 of 2024, and failing to appoint one is an offence under section 12(6).
Yes, and a continuing one rather than a single event. Where a survey tool, case management system or file store keeps Zimbabwean beneficiary data on servers outside the country, or where a regional office can read it, personal information is being shared outside Zimbabwe and the notification and transfer rules apply.
A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.
Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.