POTRAZ and its data-protection role
Also known as: data protection authority zimbabwe, dpa zimbabwe, postal and telecommunications regulatory authority of zimbabwe, the authority, zimbabwe privacy regulator
POTRAZ is the Postal and Telecommunications Regulatory Authority of Zimbabwe. Zimbabwe’s Cyber and Data Protection Act designates it as the Data Protection Authority, giving it functions related to regulating personal-data processing, guidance, complaints, investigations and enforcement. This article describes its data-protection role; it does not suggest that POTRAZ is the regulator for other jurisdictions.
Term explanation
At a glance
POTRAZ is Zimbabwe’s postal and telecommunications regulator and the authority designated to perform the country’s data-protection regulatory functions. In privacy materials it may be called POTRAZ, the Data Protection Authority or simply “the Authority”.
Understanding which regulator is involved matters because organisations may need to submit notifications, licence applications, DPO details, breach reports or cross-border-transfer material. Individuals may also need the correct regulator when raising a complaint or seeking guidance.
In plain language
The Cyber and Data Protection Act assigns the Authority functions that include setting conditions for lawful processing, promoting and enforcing fair processing, issuing opinions, conducting inquiries and investigations, receiving complaints, carrying out research and supporting cross-border cooperation.
Later regulations and implementation guidelines give practical form to this role. They address matters such as controller licensing, DPO appointment, breach reporting and transfer requirements. Their legal status is not identical: the Act and statutory regulations are binding law, while implementation guidelines explain and operationalise the regime but should not be presented as if they were Acts of Parliament.
Why it matters
Depending on its activity and the applicable provisions, an organisation may interact with POTRAZ when applying for or renewing a controller licence, notifying a DPO appointment or change, reporting a personal-data breach, making notifications connected to processing or international transfers, responding to an information request, cooperating with an inquiry, or seeking guidance.
The required form, deadline and legal basis should be checked for the specific process. An email or informal conversation should not be assumed to satisfy a prescribed written form.
A practical example
An organisation discovers a suspected breach. Its incident team should not wait until the investigation is complete before checking the applicable notification duty. The Zimbabwe overlay in the Data breach article explains the current recorded timetable and links to the relevant legal resources and regulator process.
General principles
When an individual may interact with POTRAZ
A person who is concerned about how an organisation uses their data should normally contact the organisation first where practical, using its privacy or DPO contact. If the issue is not resolved, the person may consider the complaint route available through the Authority. The current official process and contact details should always be verified rather than copied indefinitely into an article.
Keep regulator information current
Regulator forms, portals, addresses and procedural guidance can change more quickly than the underlying statute. The Hub should store operational links as reviewed resources with a verification date rather than embedding contact details throughout article prose. A broken filing route can cause real harm where a deadline is running.
Practical next steps
Confirm which jurisdictions and regulatory frameworks apply. Use the latest official forms and channels, retain proof of submission and record the legal basis, deadline and response. For legally significant filings, obtain appropriate professional advice.
Related terms: CDPA; data protection authority; controller licensing; DPO; data breach; cross-border transfer
Jurisdiction guidance
Select more lenses from the Hub landing page to compare across jurisdictions.
No jurisdiction-specific guidance is published for this lens yet.
Related terms
- Cross-border transfer of personal data — cross-border transfer
- Data Protection Officer (DPO) — DPO
- Personal-data breach — data breach
- Zimbabwe’s Cyber and Data Protection Act (CDPA) — CDPA
Sources & citations
Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.
- ACT — Cyber and Data Protection Act (Chapter 12 07) (ACT)
ACT · primary · Read in the Legal Library
- CDPG 1 of 2025 — Compliance Assessments (CDPG-1-2025-CA)
CDPG-1-2025-CA · cites · Read in the Legal Library
- CDPG 1 of 2025 — Licensing of Data Controllers (CDPG-1-2025-LDC)
CDPG-1-2025-LDC · cites · Read in the Legal Library
- SI 155 of 2024 — Licensing of Data Controllers & Appointment of DPOs (SI155)
SI155 · cites · Read in the Legal Library
Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.