StoneGuard › POTRAZ inspections

POTRAZ inspections: what inspectors ask for and how to prepare

POTRAZ compliance inspections under the Cyber and Data Protection Act [Chapter 12:07] begin on 1 September 2026. They are risk based, and healthcare is in the first wave along with other high volume and sensitive data environments. An inspector asks for your Data Controller licence, your DPO appointment, your registers, your procedures and your training records. StoneGuard prepares all of it with a certified DPO.

Last reviewed 2 September 2026.

What changed on 1 September 2026

Compliance inspections begin on 1 September 2026. Registration under Statutory Instrument 155 of 2024 had been the obligation for some time. What is new is that POTRAZ now comes to look.

Inspections follow a risk based model. Priority goes to organisations that hold large volumes of personal data and to those that hold sensitive data. Healthcare is in the first wave.

If you are in a first wave sector, the practical question is no longer whether to register. It is whether you can produce current evidence on the day.

What an inspector asks to see

An inspection is an evidence exercise. These are the items an organisation is expected to be able to produce.

Where organisations come up short

Getting inspection ready with StoneGuard

A $90 consultation establishes where you stand, and is credited in full toward your package when you proceed. Packages start at $250. POTRAZ fees are paid to POTRAZ at cost, ex VAT, and are separate from the StoneGuard service fee. You will always see two numbers, never one blended figure.

Your certified DPO attends the inspection with you and produces the evidence from the platform.

Frequently asked questions

When did POTRAZ inspections start?

POTRAZ compliance inspections under the Cyber and Data Protection Act [Chapter 12:07] begin on 1 September 2026.

Which sectors are inspected first?

Inspections follow a risk based model, with priority given to high volume and sensitive data environments. Healthcare is in the first wave.

What does a POTRAZ inspection cover?

An inspector asks for your Data Controller licence, evidence of your Data Protection Officer appointment, your record of processing activities, your privacy policy and consent wording, your breach response and data subject request procedures, your staff training records, your impact assessments where higher risk processing applies, and your security measures for both systems and paper records.

We are registered with POTRAZ. Is that enough for an inspection?

Registration is the starting point, not the finish. An inspection tests the documentation the licence presupposes: current registers, working procedures, delivered training and evidence of security. Organisations that registered and stopped there are the ones that struggle on the day.

How quickly can we get inspection ready?

It depends on what already exists. The consultation establishes the gap in the first conversation, and the $90 fee is credited in full toward the package. The work that takes time is the gap analysis, the registers and the training, so the sooner it starts the better positioned you are.

Get licensed and inspection ready

A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.

Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.