Data protection for schools and colleges in Zimbabwe
A Zimbabwean school is a data controller and must license with POTRAZ. Learner records are data about children, which section 10(5) of Statutory Instrument 155 of 2024 singles out for parental consent, regular impact assessments and data protection by design. A school processing children’s data also needs a Data Protection Officer.
Last reviewed 2 September 2026.
Why a school is a data controller
A school decides what information to collect about learners, from whom, and what happens to it afterwards. That is the definition of a controller in section 4(1) of the regulations, and it is why the obligation attaches to schools as squarely as it attaches to a bank.
The volume tends to surprise people. Once the count is done properly, a single school of a few hundred learners is usually holding data on several thousand individuals.
Learner records. Enrolment forms, birth certificates, national registration numbers, previous school reports, exam results, disciplinary files and attendance registers.
Health information. Allergies, chronic conditions, medication held at the sanatorium, sick bay notes and immunisation records. This is health data, which the Act treats as sensitive.
Parent and guardian records. Contact details, employment information, fee accounts, bank details for debit orders and correspondence about arrears.
Staff records. Payroll, national IDs, contracts, qualifications, disciplinary matters and medical aid membership.
Images and media. Photographs and video from prize giving, sports fixtures and productions, and anything published to the school website or social media.
Systems and premises. The school management system, the fee platform, CCTV, biometric gates and clocking systems, transport manifests and boarding house records.
Messaging. Parent WhatsApp groups, broadcast lists and the class group where a teacher shares results, all of which expose one parent’s number to every other parent unless configured carefully.
The children’s data rules apply to you directly
Section 10(5) of Statutory Instrument 155 of 2024 sets out a specific regime for children’s information. For most organisations it is a corner case. For a school it is the main event, and it is the part of the law a school is most likely to be measured against.
Children’s personal information may not be processed without the consent of the parent or legal guardian of the child.
The school must make reasonable efforts to verify that the consent was actually given or authorised by the parent or guardian, taking available technology into account. A tick box on a form completed by an older learner is not verification.
All of the data processing principles apply with attention, not in outline.
Regular data protection impact assessments must be conducted to identify and mitigate privacy risks to children. Regular means recurring, not once at licensing.
Data protection by design and by default must be ensured, which reaches procurement decisions about learning platforms and attendance systems.
Children’s data may not be subjected to automated decision making that affects children’s rights.
Contravening section 10 is an offence under section 10(6), carrying a fine of up to level 11 or imprisonment of up to seven years or both.
A school needs a Data Protection Officer
At Tier 1 the officer requirement bites where an organisation processes sensitive data, which includes health information and data about children. A school does both before breakfast, so the question is not whether an officer is needed but who it is going to be.
Section 12 requires the appointment to be notified to the Authority in writing on Form DP2, within ninety days. Any change to the officer’s phone number, email or physical address must be notified within fourteen days, as must a resignation or dismissal. Failing to appoint an officer at all is an offence under section 12(6), carrying up to level 7 or two years.
Section 13 sets qualifications, and section 13(2) requires the officer to have completed a certification course approved by the Authority. Section 10(1) then requires the school to fund that officer’s continuing professional development to maintain the certification. For most schools an outsourced officer is materially cheaper than training and retaining an internal one.
Which tier a school falls into
The count that sets your tier is data subjects, meaning people, not employees and not customers alone. It includes current and former staff, seasonal and casual workers, customers, enquirers who never bought, suppliers and their contact people, and anyone on a mailing list. Most organisations that assume they are small find they cross a tier boundary once the count is done properly, which is one of the things the consultation settles before anything is filed.
For a school the count is learners, parents and guardians, current staff, former staff, and alumni whose records you still hold. A school that keeps records going back a decade is counting those records too, unless it has a retention schedule that says otherwise and has actually been followed.
Bands are the licence categories in section 6 of SI 155 of 2024. Fees are payable to POTRAZ at cost, ex VAT. POTRAZ adds VAT on its own invoice.
Licence tier
Data subjects (SI 155 s6)
Licence fee (ex VAT)
Application fee
Tier 1
Minimum 50, maximum 1,000
$50
Not applicable
Tier 2
1,001 to 100,000
$300
$30
Tier 3
100,001 to 500,000
$500
$30
Tier 4
More than 500,000
$2,500
$30
In practice a day school of moderate size clears Tier 1 comfortably and sits in Tier 2. A group of schools under one legal entity counts across the group. Where the schools are separate legal entities, each licenses in its own registered name.
What a compliant school actually has
A current data controller licence. In the exact registered name of the entity that runs the school, whether that is a trust, an association or a company.
A notified Data Protection Officer. Appointed, certified and notified on Form DP2, with the contact details kept current.
A record of processing activities. Covering the management system, the fee platform, the sanatorium, CCTV, biometrics, transport and the boarding house.
A parent facing privacy notice. In language a parent will actually read, explaining what the school holds, why, for how long, and who it is shared with.
Separate consent for images. Photography and media consent handled separately from enrolment, and capable of being withdrawn without the child being disadvantaged.
Impact assessments. On children’s data generally, and specifically on any biometric attendance or access system, conducted regularly rather than once.
A breach procedure that fits in twenty four hours. Naming who declares a breach out of term time, and where Form DP3 is kept.
A request procedure. For parents asking for their child’s records, and for former learners asking for theirs.
Written agreements with processors. The management system vendor, the bus operator, the caterer, the photographer and the exam board are all processors, and section 10(4)(f) requires a written agreement with each.
Trained staff, on record. Training is mandatory for licensed controllers under CDPG 1 of 2025, with a record of who attended and when.
Where schools most often come up short
Photographs published without a usable consent. Prize giving images on Facebook, with names, where consent was bundled into enrolment years ago and never refreshed.
Parent WhatsApp groups. A group of two hundred parents exposes every parent’s phone number to every other parent. A broadcast list does not, and is the safer default for one way announcements.
Biometric systems with no assessment. Fingerprint gates and clocking systems process biometric data, which section 10(2)(d) requires you to notify to the Authority, and which section 10(5) requires you to assess where children are involved.
Old learner files nobody owns. Boxes of paper records in a store room, with no retention schedule, are the first thing an inspector asks about and the hardest thing to defend.
Results shared in group chats. Individual academic performance sent to a class group is a disclosure to every other family in the class.
No written agreement with the management system vendor. The single largest holder of learner data is usually a third party platform, and usually on nothing more than an invoice.
How StoneGuard gets it done
Consultation. A $90 consultation opens the engagement. We work out what personal data you hold, which POTRAZ tier you fall into and what is missing. The fee is credited in full toward your package when you proceed.
Gap analysis. A certified Data Protection Officer assesses your organisation against the Cyber and Data Protection Act on the StoneGuard platform and gives you a scored report with the gaps ranked.
Licensing. We prepare and file your Data Controller licence application and your DPO appointment notification, and we handle the correspondence with POTRAZ until the licence is granted.
Documentation. Your record of processing activities, privacy policy, consent wording, breach response procedure and data subject request procedure are drafted and put in place.
Training. Staff training is delivered, which CDPG 1 of 2025 makes mandatory for licensed data controllers.
Ongoing DPO. A certified Data Protection Officer stays on record for you after the licence is granted, keeps the registers current, handles data subject requests and breaches, files the annual renewal and attends POTRAZ inspections.
POTRAZ fees are paid to POTRAZ at cost, ex VAT, and are separate from the StoneGuard service fee. You will always see two numbers, never one blended figure.
Frequently asked questions
Do schools in Zimbabwe need a POTRAZ data controller licence?
Yes. A school determines the purposes and means of processing personal data about learners, parents and staff, which is the test in section 4(1) of Statutory Instrument 155 of 2024. There is no exemption for schools: section 8 exempts only personal, family or household affairs, law enforcement, and journalistic, historical or archival purposes.
Does a school need a Data Protection Officer?
Yes. A school processes health information and data about children, both of which are sensitive, so the officer requirement applies even at Tier 1. The appointment is notified to POTRAZ on Form DP2 under section 12, and failing to appoint one is an offence under section 12(6) carrying up to level 7 or two years.
Can a school publish photographs of learners?
Only with a consent that is real. Section 10(5) of Statutory Instrument 155 of 2024 requires the consent of the parent or legal guardian for processing children’s information, and requires the school to make reasonable efforts to verify that the consent came from the parent or guardian. In practice that means media consent handled separately from enrolment, recorded per child, refreshed periodically, and capable of being withdrawn.
Which POTRAZ tier is a school?
It depends on the number of data subjects, counting learners, parents and guardians, current and former staff, and alumni whose records are still held. Tier 1 covers 50 to 1,000 data subjects at $50 ex VAT, and Tier 2 covers 1,001 to 100,000 at $300 ex VAT plus the $30 application fee. Most schools of any size sit in Tier 2 once the count is done properly.
Do we need parental consent for everything we do with learner data?
Consent is required for processing children’s information under section 10(5), and it is the safest basis for anything beyond the core business of educating the child, such as photography, media and optional activities. The practical approach is a clear enrolment notice covering what the school must do to run the school, with separate, withdrawable consents layered on top for the discretionary uses.
What about our biometric attendance or gate system?
Biometric data gets specific treatment. Section 10(2)(d) of Statutory Instrument 155 of 2024 requires you to notify the Authority of processing involving biometric and genetic data, and where the data subjects are children, section 10(5) requires regular data protection impact assessments and data protection by design and by default. A biometric system installed without an assessment is one of the clearer gaps an inspector can find.
We are a small private college. Is there a threshold below which this does not apply?
Size sets your tier and therefore your fee, not whether the obligation applies. The tier categories in section 6 formally begin at 50 data subjects, but the duty to apply in sections 3 and 4 carries no size floor, and there is no small institution exemption in section 8.
Get licensed and inspection ready
A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.