StoneGuard › Retail and wholesale
A Zimbabwean retailer is a data controller and must license with POTRAZ. Customer accounts, credit and layby books, loyalty programmes, CCTV footage and marketing lists are all personal data, and credit vetting brings the automated decision rules in section 10(3) of Statutory Instrument 155 of 2024 into play.
Last reviewed 2 September 2026.
Retailers are among the last businesses to think of themselves as data holders, because the transaction that matters most to them, a cash sale to an anonymous walk-in, involves no personal data at all. Everything around that transaction does.
The moment you open an account, run a layby, extend credit, sign somebody up to a loyalty programme, take a delivery address, record a mobile money number or point a camera at the shop floor, you are processing personal data and the duty in section 4(1) attaches.
Account and credit customer files carry more sensitive material than retailers generally appreciate. A credit application typically gathers an identity document, an employer, a salary figure, a payslip, a residential address, next of kin and one or two guarantors who never walked into the shop themselves but whose personal data you now hold.
Two obligations follow directly. The guarantors and next of kin are data subjects in their own right, with the same rights as the customer, and they are frequently people nobody told that a file exists. And section 10(3) of Statutory Instrument 155 of 2024 prohibits subjecting a data subject to a decision based solely on automated processing which produces legal effects concerning them, without their consent or a provision established by law.
That second point matters for any retailer running automated credit scoring or an automatic approval and decline rule. A credit refusal is a decision with a real effect on the person. If it is made solely by a system with no human involvement, section 10(3) is engaged and you need either consent or a legal basis, and in practice a documented point of human review is the simpler answer.
These are the two systems that generate the most personal data in a retail business and receive the least governance, because both are usually procured as security or marketing rather than as data processing.
Section 10(4)(f) of Statutory Instrument 155 of 2024 requires a written data processing agreement with each data processor. Retailers typically use more processors than almost any other kind of business, and typically have written agreements with none of them.
Section 10(4)(a) makes the controller accountable for a representative, agent, assignee, processor, recipient or data protection officer who contravenes, and section 33(6) of the Act makes the controller liable for fines incurred by its agent or assignee. If your loyalty platform leaks, it is your notification and your exposure.
The count that sets your tier is data subjects, meaning people, not employees and not customers alone. It includes current and former staff, seasonal and casual workers, customers, enquirers who never bought, suppliers and their contact people, and anyone on a mailing list. Most organisations that assume they are small find they cross a tier boundary once the count is done properly, which is one of the things the consultation settles before anything is filed.
Retail counts climb faster than in almost any other sector, because a loyalty programme converts anonymous shoppers into named data subjects at scale and never lets them go. A single supermarket with a mature loyalty scheme can be well into Tier 3. A chain counts across the whole legal entity, not per branch.
| Licence tier | Data subjects (SI 155 s6) | Licence fee (ex VAT) | Application fee |
|---|---|---|---|
| Tier 1 | Minimum 50, maximum 1,000 | $50 | Not applicable |
| Tier 2 | 1,001 to 100,000 | $300 | $30 |
| Tier 3 | 100,001 to 500,000 | $500 | $30 |
| Tier 4 | More than 500,000 | $2,500 | $30 |
Where a group operates several registered companies, each licenses in its own registered name. Where one company operates many branches, that is one licence covering the whole count.
POTRAZ fees are paid to POTRAZ at cost, ex VAT, and are separate from the StoneGuard service fee. You will always see two numbers, never one blended figure.
If it holds personal data, yes. A retailer that runs customer accounts, a credit or layby book, a loyalty programme, a delivery service, CCTV or a payroll is determining the purposes and means of processing personal data, which is the test in section 4(1) of Statutory Instrument 155 of 2024. Section 8 exempts only personal, family or household affairs, law enforcement, and journalistic, historical or archival purposes. A purely cash business with no customer records still holds staff records.
Yes. CCTV records identifiable people, so it is processing personal data and it is a processing activity that belongs in your record of processing under section 10(2)(a). In practice it needs a visible notice, a defined retention period that is actually applied, and a rule about who may review footage and on what grounds. Section 18(4) of the Cyber and Data Protection Act [Chapter 12:07] separately requires appropriate technical and organisational measures to protect it.
Yes, that is legitimate processing for a genuine business purpose. What the law asks is that customers and their guarantors are told what is held and why, that access is restricted to the people who need it, that the file is secured, and that a retention period is set and applied rather than the file being kept forever after the account settles.
A phone number given to complete a purchase, claim a warranty or open an account was not given for marketing. The defensible position is a separate, recorded permission for marketing, obtained at the point of collection, with an opt-out that works and is honoured. Bulk messaging a till-collected list is the complaint most likely to reach the regulator first, because every recipient can see it happened.
It is set by the number of data subjects, and retail counts climb quickly because loyalty programmes convert shoppers into named records permanently. Tier 2 runs from 1,001 to 100,000 at $300 ex VAT plus the $30 application fee, and Tier 3 to 500,000 at $500. A chain counts across the whole legal entity rather than per branch.
Passing customer details to a collector is a disclosure to a third party, so it needs a lawful basis, it should be disclosed in your account terms and privacy notice, and section 10(4)(f) of Statutory Instrument 155 of 2024 requires a written agreement with the collector. What it does not permit is publishing or circulating a defaulter’s personal details, which is a disclosure with no lawful basis behind it.
Section 10(3) of Statutory Instrument 155 of 2024 prohibits subjecting a data subject to a decision based solely on automated processing which produces legal effects concerning them, without their consent or a provision established by law. A credit approval or refusal is such a decision. The practical answer for most retailers is to keep a recorded point of human review in the decision, which is easier to evidence than a consent trail.
A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.
Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.