August 17, 2026

Keeping You posted

With Trusted Zimbabwe News as well as Local and Regional Perspectives.

POTRAZ Director General, Gift Machengete. Pic by Shingirai Vambe

POTRAZ Sets September Deadline for Data Protection Compliance

By Shingirai Vambe

Zimbabwe is moving into a new phase of data protection enforcement as the country seeks to close persistent data security gaps and strengthen compliance with emerging global standards, particularly amid the rapid expansion of artificial intelligence, digital services and data-driven technologies.

The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), which has for more than two years been engaging organisations and providing training and awareness programmes for Data Protection Officers and other responsible officials, has now given institutions a firm deadline to bring their operations into line with the country’s data protection requirements.

The regulator has announced that it will begin mandatory compliance inspections and assessments of data controllers from 1 September 2026, marking a significant shift from awareness and capacity-building towards active enforcement of Zimbabwe’s data protection regime.

In a regulatory notice issued to The Post on Sunday and signed by POTRAZ Director-General Dr Gift Kalisto Machengete, the authority said the inspections would be conducted in terms of the Cyber and Data Protection Act [Chapter 12:07].

The notice, titled Regulatory Notice 2 of 2026 – Mandatory Compliance Inspections and Assessments of Data Controllers in Line with the Cyber and Data Protection Act [Chapter 12:07], reminds public and private institutions that the country’s data protection framework imposes specific legal obligations on organisations that collect, process, store or otherwise handle personal information.

POTRAZ said the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024, promulgated through Statutory Instrument 155 of 2024, came into effect in September 2024.

The regulations established a mandatory requirement for organisations processing personal data to obtain a Data Controller Licence, with the initial compliance deadline set for 12 March 2025.

With that deadline having passed, the regulator is now moving towards physical and documentary assessments of institutions to establish whether they have complied with the law.

“As the designated Data Protection Authority under section 5 of the Cyber and Data Protection Act [Chapter 12:07], the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) will from 1 September 2026 be conducting mandatory compliance inspections and assessments in terms of Section 6(1)(a) as read with Section 21(3) and (4) of the Cyber & Data Protection Act [Chapter 12:07],” the notice states.

The inspections will not initially cover every organisation at once. POTRAZ said it would adopt a risk-based approach, beginning with sectors considered particularly sensitive because of the volume or nature of personal information they process.

Among the sectors identified for the first phase of inspections are financial institutions, insurance companies, local authorities, healthcare providers and mining enterprises.

Schools, universities, tertiary institutions and professional bodies will also fall under the compliance exercise, alongside religious organisations, Government ministries, departments and agencies, non-governmental organisations and private voluntary organisations.

The inclusion of these sectors underscores the growing importance of data protection across virtually every area of Zimbabwe’s economy and public administration.

Banks and insurance companies, for instance, routinely process sensitive financial and identity information. Healthcare institutions handle medical records, while schools and universities maintain extensive databases containing information about students, parents, employees and other stakeholders.

Local authorities similarly hold large amounts of personal information relating to residents, property owners, ratepayers and businesses, while Government departments remain major custodians of citizens’ identity, social and economic information.

The mining sector, meanwhile, is increasingly becoming data-intensive as companies adopt digital systems, automated operations, biometric access controls, surveillance technologies and other data-driven platforms.

The regulator’s intervention comes at a time when the value of personal information has increased dramatically.

The rapid adoption of artificial intelligence has intensified concerns around how personal data is collected, stored and transferred, particularly as organisations increasingly use cloud computing, automated decision-making systems, facial recognition, biometric technologies and AI-powered applications.

The proliferation of digital platforms has also increased the risks associated with data breaches, identity theft, unauthorised profiling, cybercrime and the commercial exploitation of personal information.

For Zimbabwe, therefore, the implementation of the data protection framework is increasingly becoming more than a question of regulatory compliance. It is emerging as an important component of national cybersecurity, digital trust and the country’s broader digital transformation agenda.

POTRAZ has over the past two years invested in awareness programmes and capacity building, including training Data Protection Officers and helping institutions understand their responsibilities under the new legal framework.

The regulator’s latest notice suggests that the period of sensitisation is now giving way to a more rigorous enforcement phase.

Organisations that have not yet obtained the required licences have been urged to use the remaining period to regularise their affairs.

POTRAZ said institutions can still apply for Data Controller licences and seek guidance from the authority ahead of the inspections.

The regulator emphasised that licensing should not be viewed merely as a bureaucratic requirement but as an important demonstration of an organisation’s commitment to protecting the information entrusted to it by employees, customers, clients, students, patients, citizens and other stakeholders.

“Licensing as a data controller is not just a statutory obligation; it is a demonstration of your commitment to safeguarding personal data entrusted to you by all your stakeholders,” POTRAZ said.

The regulator further described data as “the new currency”, stressing that responsible data management is increasingly central to Zimbabwe’s ambitions of creating a secure and digitally enabled economy.

“Now that data is the new currency, it is everyone’s responsibility to process personal data fairly and lawfully to achieve the national vision of a safe and secure digitally enabled Zimbabwe,” the notice said.

The compliance inspections could therefore become a major test of how seriously organisations have taken the country’s data protection legislation since the regulations were introduced.

For institutions that have invested in compliance, the inspections could provide an opportunity to demonstrate that systems, policies and internal controls are functioning as required.

For those that have delayed compliance, however, the regulator’s new enforcement posture could expose significant weaknesses in how personal information is collected, processed, stored and protected.

The development also places greater responsibility on Data Protection Officers, who are expected to play a central role in helping institutions understand and meet their statutory obligations.

As Zimbabwe accelerates its adoption of artificial intelligence and other emerging technologies, the ability to protect personal information will increasingly determine public confidence in the country’s digital transformation.

The September inspections therefore represent more than a routine regulatory exercise. They mark the beginning of a more assertive phase in Zimbabwe’s attempt to build a culture of accountability around personal data and ensure that technological advancement does not come at the expense of citizens’ privacy and security.

For organisations across the identified sectors, the message from POTRAZ is increasingly clear: the era of voluntary awareness is giving way to mandatory compliance, and institutions that process personal data will now be expected to demonstrate that they have put the necessary systems, personnel and safeguards in place.