Zimbabwe and UK data protection, in plain language
What do you want to sort out?
Ask a data-protection question in your own words, or pick one below. You will get a straight answer and one thing to do next.
We match your question to a free check. We do not store what you type.
Ask a data-protection question
- Do data-protection laws even apply to my little business?
- Do I have to register with the ICO or pay the data-protection fee?
- Do I need a POTRAZ licence to hold customer data?
- Which POTRAZ tier am I, and how much is the licence?
- I'm not based in Zimbabwe or the UK but I have users there — do the rules apply?
- How much does compliance actually cost?
- Where do I even start?
- Do I need a Data Protection Officer?
- Can the same person be the DPO and the owner or founder?
- Does my DPO need a certificate or training in Zimbabwe?
- Do I need a privacy policy on my website?
- What has to go in a privacy notice?
- Do I have to tell people how I use data I got from somewhere else?
- Do I need a cookie banner?
- Do I need consent for Google Analytics or tracking?
- Do I always need consent to collect personal data?
- What's my lawful basis — and which one do I pick?
- Can I rely on legitimate interests instead of consent?
- Can I send marketing emails to people who haven't opted in?
- Can I email existing customers?
- Can I buy or rent a marketing list?
- Do I need consent for SMS or WhatsApp marketing?
- We had a data breach — do I have to report it?
- What actually counts as a data breach?
- How long do I have to report a breach — 72 hours or 24?
- Do I have to tell the customers whose data leaked?
- Someone asked for all the data I hold on them — what do I do?
- How long do I have to respond to a subject access request?
- Can I charge for a data request, or refuse it?
- Someone asked me to delete their data — do I have to?
- How long can I keep customer data?
- When do I have to delete old data?
- Do I need to write down everything I do with data?
- Can I store customer data on US servers or use a US cloud?
- Can I send personal data outside Zimbabwe or the UK?
- Do I need a contract with my software suppliers?
- Is my SaaS, CRM or email tool compliant?
- We share data with a partner — what do we need?
- Can I collect data about children, and do I need parental consent?
- What is special-category or sensitive data, and what's different?
- Can I use ChatGPT or AI tools with customer data?
- My staff are pasting data into AI tools — is that a problem?
- Do I need a DPIA, and how do I do one?
- I'm building an app — what privacy work do I need before launch?
- What are the fines if I get this wrong?
- What happens if the regulator gets a complaint about me?
Or start from what you want
Six things people usually come here to do.
The questions people ask most
Every one of these opens a free check that answers it.
Do I have to register with the ICO or pay the data-protection fee?
Probably yes — in the UK you pay the ICO fee; in Zimbabwe you need a POTRAZ licence by tier. Two minutes to find out.
Start now — no account neededDo I need a privacy policy on my website?
If you collect any personal data, yes — and a copy-pasted template usually will not pass.
Coming soonWe had a data breach — do I have to report it?
Maybe, and fast: 24 hours to POTRAZ in Zimbabwe (including a suspected breach), 72 hours to the ICO in the UK. Triage it now.
Coming soonSomeone asked for all the data I hold on them — what do I do?
You must respond, free, within a month. Check your DSAR readiness.
Coming soonDo I need a Data Protection Officer?
UK: usually no. Zimbabwe: usually yes, certified, within 90 days. Check your obligation.
Start now — an account saves your resultDo I need a cookie banner?
Non-essential cookies need real opt-in — scan your site.
Coming soonCan I send marketing emails to people who haven't opted in?
Only with consent or a valid soft opt-in. Check before you send.
Coming soonHow long can I keep customer data?
Only as long as you have a purpose — build a retention schedule.
Start — you will need an organisation code (we can make one)Can I use ChatGPT or AI tools with customer data?
Carefully — check your AI readiness and shadow-AI exposure.
Coming soonDo data-protection laws even apply to my little business?
Almost certainly — get your exposure score.
Start — you will need an organisation code (we can make one)Can I store customer data on US servers or use a US cloud?
It's a transfer and needs a safeguard — run a transfer check.
Coming soonDo I need a contract with my software suppliers?
Yes — every processor needs a DPA. Check your vendors.
Coming soonWhat are the fines if I get this wrong?
Zimbabwe: up to a level 11 fine and 7 years, but a DPO-appointment lapse is lower at level 7 and 2 years. We show the current cash value from the standard scale rather than a fixed number.
Start now — no account neededDo I always need consent to collect personal data?
Often not consent — find your correct lawful basis.
Coming soonI'm building an app — what privacy work do I need before launch?
A full pre-launch privacy stack — run the app-builder checklist.
Coming soonWhich POTRAZ tier am I, and how much is the licence?
Your data-subject count sets your tier — and your tier sets the licence fee, shown live from the current fee schedule.
Start now — an account saves your result
Prefer to start by who you are?
What kind of organisation is it?
Start from your world
- Startups & SaaSYou're building fast — bake privacy in before it costs you.
- Small & medium enterprisesA calm, plain-language route through the basics.
- Charities & NGOsProtect beneficiaries and donors on a mission budget.
- HealthcarePatient trust starts with how you handle their data.
- EducationStudents, staff and parents — handle their data with care.
- Financial ServicesMeet privacy expectations without slowing the business.
- Retail & E-commerceFrom loyalty programmes to checkout — get the data flows right.
- Professional ServicesClient confidentiality, formalised.
- Public SectorServe citizens well — with data practices they can trust.
- Technology & AI teamsShip AI and platforms without a shadow-data problem.
Free, always.
Every check on Privacy Lab is free to run and free to read. You can use it without an account. We built it because good privacy advice should not be something only large organisations can afford.