roles
Do you need a DPO?
Updated 19 Jul 2026
Do you need a DPO?
In Zimbabwe
Yes, in almost every case. The Cyber and Data Protection Act (s. 19) and SI 155 of 2024 require every registered controller to appoint a Data Protection Officer within 90 days of registration. The DPO can be internal or contracted, but the appointment must be notified to POTRAZ.
In the UK
Under UK GDPR Article 37, a DPO is mandatory when:
- You are a public authority (courts excepted).
- Your core activities require systematic monitoring of data subjects on a large scale.
- Your core activities involve large-scale processing of special-category or criminal-conviction data.
If none apply, you may still appoint one voluntarily — many organisations do, because it clarifies accountability.
What the DPO actually does
- Monitors compliance with the Act / UK GDPR.
- Advises on Data-Protection Impact Assessments.
- Acts as the point of contact for the authority and data subjects.
- Reports to the highest level of management — not to a business unit that owns processing.
Independence is the whole point. A DPO who reports to the marketing team is a DPO in name only.
Looking for something practical? Explore the free privacy tools.