StoneGuard › Schools

Data protection for schools and colleges in Zimbabwe

A Zimbabwean school is a data controller and must license with POTRAZ. Learner records are data about children, which section 10(5) of Statutory Instrument 155 of 2024 singles out for parental consent, regular impact assessments and data protection by design. A school processing children’s data also needs a Data Protection Officer.

Last reviewed 2 September 2026.

Why a school is a data controller

A school decides what information to collect about learners, from whom, and what happens to it afterwards. That is the definition of a controller in section 4(1) of the regulations, and it is why the obligation attaches to schools as squarely as it attaches to a bank.

The volume tends to surprise people. Once the count is done properly, a single school of a few hundred learners is usually holding data on several thousand individuals.

The children’s data rules apply to you directly

Section 10(5) of Statutory Instrument 155 of 2024 sets out a specific regime for children’s information. For most organisations it is a corner case. For a school it is the main event, and it is the part of the law a school is most likely to be measured against.

Contravening section 10 is an offence under section 10(6), carrying a fine of up to level 11 or imprisonment of up to seven years or both.

A school needs a Data Protection Officer

At Tier 1 the officer requirement bites where an organisation processes sensitive data, which includes health information and data about children. A school does both before breakfast, so the question is not whether an officer is needed but who it is going to be.

Section 12 requires the appointment to be notified to the Authority in writing on Form DP2, within ninety days. Any change to the officer’s phone number, email or physical address must be notified within fourteen days, as must a resignation or dismissal. Failing to appoint an officer at all is an offence under section 12(6), carrying up to level 7 or two years.

Section 13 sets qualifications, and section 13(2) requires the officer to have completed a certification course approved by the Authority. Section 10(1) then requires the school to fund that officer’s continuing professional development to maintain the certification. For most schools an outsourced officer is materially cheaper than training and retaining an internal one.

Which tier a school falls into

The count that sets your tier is data subjects, meaning people, not employees and not customers alone. It includes current and former staff, seasonal and casual workers, customers, enquirers who never bought, suppliers and their contact people, and anyone on a mailing list. Most organisations that assume they are small find they cross a tier boundary once the count is done properly, which is one of the things the consultation settles before anything is filed.

For a school the count is learners, parents and guardians, current staff, former staff, and alumni whose records you still hold. A school that keeps records going back a decade is counting those records too, unless it has a retention schedule that says otherwise and has actually been followed.

Bands are the licence categories in section 6 of SI 155 of 2024. Fees are payable to POTRAZ at cost, ex VAT. POTRAZ adds VAT on its own invoice.
Licence tierData subjects (SI 155 s6)Licence fee (ex VAT)Application fee
Tier 1Minimum 50, maximum 1,000$50Not applicable
Tier 21,001 to 100,000$300$30
Tier 3100,001 to 500,000$500$30
Tier 4More than 500,000$2,500$30

In practice a day school of moderate size clears Tier 1 comfortably and sits in Tier 2. A group of schools under one legal entity counts across the group. Where the schools are separate legal entities, each licenses in its own registered name.

What a compliant school actually has

Where schools most often come up short

How StoneGuard gets it done

POTRAZ fees are paid to POTRAZ at cost, ex VAT, and are separate from the StoneGuard service fee. You will always see two numbers, never one blended figure.

Frequently asked questions

Do schools in Zimbabwe need a POTRAZ data controller licence?

Yes. A school determines the purposes and means of processing personal data about learners, parents and staff, which is the test in section 4(1) of Statutory Instrument 155 of 2024. There is no exemption for schools: section 8 exempts only personal, family or household affairs, law enforcement, and journalistic, historical or archival purposes.

Does a school need a Data Protection Officer?

Yes. A school processes health information and data about children, both of which are sensitive, so the officer requirement applies even at Tier 1. The appointment is notified to POTRAZ on Form DP2 under section 12, and failing to appoint one is an offence under section 12(6) carrying up to level 7 or two years.

Can a school publish photographs of learners?

Only with a consent that is real. Section 10(5) of Statutory Instrument 155 of 2024 requires the consent of the parent or legal guardian for processing children’s information, and requires the school to make reasonable efforts to verify that the consent came from the parent or guardian. In practice that means media consent handled separately from enrolment, recorded per child, refreshed periodically, and capable of being withdrawn.

Which POTRAZ tier is a school?

It depends on the number of data subjects, counting learners, parents and guardians, current and former staff, and alumni whose records are still held. Tier 1 covers 50 to 1,000 data subjects at $50 ex VAT, and Tier 2 covers 1,001 to 100,000 at $300 ex VAT plus the $30 application fee. Most schools of any size sit in Tier 2 once the count is done properly.

Do we need parental consent for everything we do with learner data?

Consent is required for processing children’s information under section 10(5), and it is the safest basis for anything beyond the core business of educating the child, such as photography, media and optional activities. The practical approach is a clear enrolment notice covering what the school must do to run the school, with separate, withdrawable consents layered on top for the discretionary uses.

What about our biometric attendance or gate system?

Biometric data gets specific treatment. Section 10(2)(d) of Statutory Instrument 155 of 2024 requires you to notify the Authority of processing involving biometric and genetic data, and where the data subjects are children, section 10(5) requires regular data protection impact assessments and data protection by design and by default. A biometric system installed without an assessment is one of the clearer gaps an inspector can find.

We are a small private college. Is there a threshold below which this does not apply?

Size sets your tier and therefore your fee, not whether the obligation applies. The tier categories in section 6 formally begin at 50 data subjects, but the duty to apply in sections 3 and 4 carries no size floor, and there is no small institution exemption in section 8.

Get licensed and inspection ready

A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.

Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.