StoneGuard › SI 155 of 2024

SI 155 of 2024 explained, section by section

Statutory Instrument 155 of 2024 is the regulation that turned Zimbabwe's data protection law into a licensing regime. It requires anyone who determines the purposes and means of processing personal data to apply to POTRAZ on Form DP1, sets four licence tiers by data subject count, and requires a Data Protection Officer notified on Form DP2.

Last reviewed 2 September 2026.

What SI 155 of 2024 actually is

Its full name is the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024. It was made by the Minister responsible for information and communication technologies, in consultation with the Authority, under section 32 of the Cyber and Data Protection Act [Chapter 12:07].

The distinction between the Act and the regulation is worth holding on to, because they do different jobs. The Act sets out the principles: what personal data is, how it may be processed, what a data subject is entitled to, what security you owe. Statutory Instrument 155 of 2024 is the machinery: who has to apply for a licence, on which form, in which tier, at what fee, by when, and what happens if you do not.

A third document, CDPG 1 of 2025, sits alongside them and is where the mandatory training obligation for licensed controllers comes from.

Who has to license (sections 3 and 4)

Section 3(1) is blunt: no person shall process personal information for the purposes set out in section 3(2) unless they are licensed with the Authority. Section 3(2) then describes those purposes by intention rather than by industry.

Section 4(1) repeats the duty in the classic formulation: any person, whether alone or jointly with others, who determines the purposes and means of the processing of personal data shall apply for a data controller licence. There is no size floor written into either section, and no exemption for small companies, charities or voluntary bodies.

The four licence categories (section 6)

Section 6 sets the categories by the number of data subjects whose information you process. The fee follows the category, so the tier decision is the fee decision.

Bands are the licence categories in section 6 of SI 155 of 2024. Fees are payable to POTRAZ at cost, ex VAT. POTRAZ adds VAT on its own invoice.
Licence tierData subjects (SI 155 s6)Licence fee (ex VAT)Application fee
Tier 1Minimum 50, maximum 1,000$50Not applicable
Tier 21,001 to 100,000$300$30
Tier 3100,001 to 500,000$500$30
Tier 4More than 500,000$2,500$30

The count that sets your tier is data subjects, meaning people, not employees and not customers alone. It includes current and former staff, seasonal and casual workers, customers, enquirers who never bought, suppliers and their contact people, and anyone on a mailing list. Most organisations that assume they are small find they cross a tier boundary once the count is done properly, which is one of the things the consultation settles before anything is filed.

One drafting point that comes up constantly is worth naming honestly. Tier 1 is written as a minimum of 50 and a maximum of 1,000 data subjects, so a controller processing for fewer than 50 people fits none of the four defined categories, while the duty to apply in sections 3 and 4 carries no size floor at all. That is a gap in the regulation rather than an exemption, and a genuinely very small body should get a considered answer on it rather than assume either way.

The forms, and the deadlines attached to them

SI 155 carries four schedules, and three of them are forms you will actually use.

  1. Apply on Form DP1. Section 4(2) requires a written application in Form DP1, submitted to the Authority together with the fee specified in the Second Schedule.
  2. POTRAZ responds within 14 days. Section 4(3) gives the Authority fourteen days to do one of three things: request further information or supporting documents, issue the licence, or reject the application and give reasons.
  3. The licence may carry conditions. Section 4(4) allows the Authority to issue a licence with such conditions as it may specify, and section 5(1) makes the twelve month validity subject to compliance with those conditions.
  4. Appoint a DPO within 90 days. Section 12(5) requires a Data Protection Officer to be appointed within ninety days of promulgation, or of the termination of a previous officer’s contract.
  5. Notify the DPO on Form DP2. Section 12(1) and 12(2) require the appointment to be notified to the Authority in writing, in Form DP2.
  6. Keep the notification current. Section 12(3) requires any change to the officer’s phone number, email address or physical address to be notified within fourteen days, and section 12(4) requires notice of a dismissal or resignation within fourteen days of termination.
  7. Renew three months early. Section 5(2) requires a renewal application, again on Form DP1 and again with the fee, at least three months before the licence expires.
ScheduleFormWhat it is for
First ScheduleForm DP1Application for a data controller licence, and renewal of it
Second ScheduleFeesThe application, licence and training fees
Third ScheduleForm DP2Notifying the Authority of your Data Protection Officer
Fourth ScheduleForm DP3Notifying the Authority of a security breach

What section 10 puts on the controller

Section 10 is the substantive obligations section, and it is the one most likely to be quoted back at an organisation during an inspection. It has two halves: things you must tell the Authority, and things you must do.

The children’s data rules (section 10(5))

Section 10(5) is a separate regime inside section 10, and any school, paediatric practice, children’s ministry or child focused programme should read it as a checklist.

Contravening section 10, including this subsection, is an offence under section 10(6) carrying a fine of up to level 11 or imprisonment of up to seven years or both.

The Data Protection Officer (sections 12, 13 and 14)

SI 155 does not simply say "appoint someone". It sets qualifications, requires certification, and lists the functions the officer must actually perform.

Who is exempt (section 8)

The exemptions are narrow, and they are the whole list. Section 8(1) exempts controllers processing personal data for personal, family or household affairs, for law enforcement, and for journalistic, historical or archival purposes.

Section 8(2) then qualifies two of those three. Law enforcement controllers and journalistic, historical or archival controllers are exempt from applying for a licence, but are still required to register with the Authority and to comply with the data protection principles under the Act. Only genuinely personal, family or household processing falls outside altogether.

It is worth saying plainly what is not on that list: there is no exemption for small businesses, for non profits, for churches, for schools, for sole traders or for organisations that hold data only on paper.

The offences SI 155 creates

Maximum penalties as set out in SI 155 of 2024. Fines are expressed as levels on the standard scale.
SectionConductMaximum penalty
3(3)Processing without a data controller licence within the stipulated time framesLevel 11 or 7 years or both
4(6)Continuing to process without a licence after the transition periodLevel 11 or 7 years or both
5(3)Failing without just cause to renew by the expiry dateLevel 11 or 7 years or both
7Submitting false information when applying for a licenceLevel 11 or 7 years or both
10(6)Contravening the controller obligations in section 10Level 11 or 7 years or both
11(4)Providing DPO certification training without accreditationLevel 11 or 7 years or both
12(6)Failing to appoint a Data Protection OfficerLevel 7 or 2 years or both

The instruments express fines as a level on the standard scale rather than as an amount of money. The level is fixed in the law, but the value of each level is set by the standard scale and is revised from time to time, so the sensible thing is to confirm the current value rather than to rely on a figure quoted on a website. What is fixed, and what matters for planning, is the seriousness: these are criminal offences carrying prison terms, not administrative charges.

Frequently asked questions

What is SI 155 of 2024?

Statutory Instrument 155 of 2024 is the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024, made under section 32 of the Cyber and Data Protection Act [Chapter 12:07]. It is the regulation that requires organisations holding personal data to license with POTRAZ as data controllers, sets the four licence tiers and fees, and requires the appointment of a Data Protection Officer.

Who must register under SI 155 of 2024?

Any person who determines the purposes and means of processing personal data, under section 4(1). Section 3(2) describes it by intention: deciding the means, purpose or outcome of processing, deciding what data is collected, deciding whose data is collected, or obtaining commercial gain or other benefit from the processing. There is no exemption based on size.

What is the 50 data subject threshold in SI 155?

Section 6 sets Tier 1 as a licence for a person processing information for a minimum of 50 and a maximum of 1,000 data subjects, so the defined tier categories formally begin at 50. That is a threshold for the categories, not an exemption: the duty to apply in sections 3 and 4 has no size floor. A controller with fewer than 50 data subjects fits no defined category, which is a genuine gap in the drafting rather than a permission to ignore the regulation.

Which form do I use to apply for a data controller licence?

Form DP1, in the First Schedule, for both the original application and the annual renewal. Form DP2, in the Third Schedule, notifies the Authority of your Data Protection Officer. Form DP3, in the Fourth Schedule, is the security breach notification.

How long does POTRAZ take to issue a data controller licence?

Section 4(3) gives the Authority fourteen days from receiving the application to either request further information or supporting documents, issue the licence, or reject the application with reasons. In practice a request for further information is common, so an application that is complete and correct the first time is the thing that shortens the process.

Is SI 155 of 2024 the same as the Cyber and Data Protection Act?

No. The Cyber and Data Protection Act [Chapter 12:07] is the primary legislation and sets the principles, the rights and the security duties. Statutory Instrument 155 of 2024 is a statutory instrument made under section 32 of that Act, and it creates the licensing regime, the tiers, the fees, the forms and the DPO appointment duty. You have to comply with both.

Get licensed and inspection ready

A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.

Contact StoneGuard: email [email protected], WhatsApp +263 77 272 4514, or call +263 77 143 6742. StoneGuard is based in Harare, Zimbabwe.