The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) will begin mandatory inspections of organisations that process personal information from 1 September 2026, as authorities move to enforce compliance with the country’s data protection laws.
The inspections will be conducted under the Cyber and Data Protection Act and will focus on how organisations collect, store, use and protect personal information.
POTRAZ, which is Zimbabwe’s Data Protection Authority, said the inspections will be risk-based, meaning organisations in sectors considered to handle large amounts of sensitive personal information will be among the first to be assessed.
The targeted sectors include financial institutions, insurance companies, local authorities, healthcare providers, mining companies, religious organisations, schools, tertiary institutions, professional bodies, Government ministries and departments, as well as NGOs and PVOs.
During the inspections, POTRAZ will assess whether organisations are complying with requirements under the data protection framework, including whether they are properly registered as data controllers and have appropriate measures in place to protect personal information.
The regulator is also expected to examine organisations’ data protection arrangements, including the appointment of Data Protection Officers (DPOs) where required.
The inspections follow the introduction of mandatory data controller licensing under Statutory Instrument 155 of 2024. Organisations processing personal information were required to obtain licences, with the initial deadline set for March 12, 2025.
The regulations apply to organisations holding personal information such as names, telephone numbers, addresses, national identification numbers, employment records, health information and biometric data.
Organisations holding personal information belonging to 50 or more people are generally required to obtain a data controller licence, subject to exemptions provided under the law.
POTRAZ has adopted a tiered licensing system based on the number of people whose information an organisation processes. Annual licence fees range from US$50 for organisations handling 50 to 1 000 data subjects to US$2 500 for those handling more than 500 000.
The regulator has also warned of serious consequences for organisations that fail to comply.
Under the data protection framework, processing personal information without the required licence, or failing to adequately secure personal information, can attract significant penalties, including fines and imprisonment.
Organisations are also required to report data breaches to POTRAZ within 24 hours, while affected individuals must be notified within 72 hours.
With the inspections set to begin next month, organisations that have not yet regularised their data protection obligations face increasing pressure to comply before POTRAZ begins its assessments.
The inspections are expected to provide the regulator with a clearer picture of how Zimbabwean organisations are handling personal information and whether businesses and institutions are meeting the country’s data protection requirements.











Comments