Skip to content

Privacy Hub · plain-language reference

← Privacy Hub

POTRAZ and its data-protection role

Also known as: data protection authority zimbabwe, dpa zimbabwe, postal and telecommunications regulatory authority of zimbabwe, the authority, zimbabwe privacy regulator

POTRAZ is the Postal and Telecommunications Regulatory Authority of Zimbabwe. Zimbabwe’s Cyber and Data Protection Act designates it as the Data Protection Authority, giving it functions related to regulating personal-data processing, guidance, complaints, investigations and enforcement. This article describes its data-protection role; it does not suggest that POTRAZ is the regulator for other jurisdictions.

ZW_CDPA
EU_GDPR
GB_UK_GDPR
v2 · published 31 Jul 2026

Term explanation

At a glance

POTRAZ is Zimbabwe’s postal and telecommunications regulator and the authority designated to perform the country’s data-protection regulatory functions. In privacy materials it may be called POTRAZ, the Data Protection Authority or simply “the Authority”.

Understanding which regulator is involved matters because organisations may need to submit notifications, licence applications, DPO details, breach reports or cross-border-transfer material. Individuals may also need the correct regulator when raising a complaint or seeking guidance.

In plain language

The Cyber and Data Protection Act assigns the Authority functions that include setting conditions for lawful processing, promoting and enforcing fair processing, issuing opinions, conducting inquiries and investigations, receiving complaints, carrying out research and supporting cross-border cooperation.

Later regulations and implementation guidelines give practical form to this role. They address matters such as controller licensing, DPO appointment, breach reporting and transfer requirements. Their legal status is not identical: the Act and statutory regulations are binding law, while implementation guidelines explain and operationalise the regime but should not be presented as if they were Acts of Parliament.

Why it matters

Depending on its activity and the applicable provisions, an organisation may interact with POTRAZ when applying for or renewing a controller licence, notifying a DPO appointment or change, reporting a personal-data breach, making notifications connected to processing or international transfers, responding to an information request, cooperating with an inquiry, or seeking guidance.

The required form, deadline and legal basis should be checked for the specific process. An email or informal conversation should not be assumed to satisfy a prescribed written form.

A practical example

An organisation discovers a suspected breach. Its incident team should not wait until the investigation is complete before checking the applicable notification duty. The Zimbabwe overlay in the Data breach article explains the current recorded timetable and links to the relevant legal resources and regulator process.

General principles

When an individual may interact with POTRAZ

A person who is concerned about how an organisation uses their data should normally contact the organisation first where practical, using its privacy or DPO contact. If the issue is not resolved, the person may consider the complaint route available through the Authority. The current official process and contact details should always be verified rather than copied indefinitely into an article.

Keep regulator information current

Regulator forms, portals, addresses and procedural guidance can change more quickly than the underlying statute. The Hub should store operational links as reviewed resources with a verification date rather than embedding contact details throughout article prose. A broken filing route can cause real harm where a deadline is running.

Practical next steps

Confirm which jurisdictions and regulatory frameworks apply. Use the latest official forms and channels, retain proof of submission and record the legal basis, deadline and response. For legally significant filings, obtain appropriate professional advice.

Related terms: CDPA; data protection authority; controller licensing; DPO; data breach; cross-border transfer

Jurisdiction guidance

Select more lenses from the Hub landing page to compare across jurisdictions.

GLOBAL
Global baseline

No jurisdiction-specific guidance is published for this lens yet.

Sources & citations

Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.


Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.