CDPG 1 of 2025 — Licensing of Data Controllers
CDPG-1-2025-LDC · v1 · release faf85cbc
CDPG 1 of 2025 — Licensing of Data Controllers — Verbatim Transcription (OCR)
Citation key: CDPG-1-2025-LDC · Category: Implementation Guideline · Pages: 13
Source PDF: CDPA Implementation Guidelines/CDPG 1 of 2025 - Licensing of Data Controllers.pdf
⚠️ This PDF is image-only; text below is OCR-derived (tesseract @180dpi). Faithful to the page but may contain OCR errors — verify exact figures/fees against the source PDF before quoting in legal advice.
<!-- ===== PAGE 1 of 13 (OCR) ===== -->
‘creating a level playing field’
CYBER AND DATA PROTECTION
IMPLEMENTATION GUIDELINE ON
LICENSING OF DATA CONTROLLERS
CDPG 1 OF 2025
<!-- ===== PAGE 2 of 13 (OCR) ===== -->
3.1
3.1.1 3.1.2 3.1.3 3.1.4 3.1.5 3.1.6 3.1.7
PURPOSE AND EFFECTIVE DATE
This guideline is issued in accordance with section 6 (1) of the Cyber and Data Protection Act [Chapter 12:07] (hereinafter referred to as “the CDPA’). POTRAZ, the designated Data Protection Authority is mandated to set conditions for the lawful processing of personally identifiable information, and this includes having a register of all data processing activities and licensing of data controllers. All controllers that engage in processing personally identifiable data shall be registered and licensed unless exempt from such registration or licensing under the Act and regulations. This guideline seeks to assist data controllers navigate the licensing process by explaining the various licensing categories, fees, and applicable exemptions from licensing as well as fines for non-compliance. A step-by-step guide on how to register and obtain a data controlling license is also outlined.
The guideline shall be read in conjunction with the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations (S.I. 155 of 2024) (hereinafter referred to as ‘the Regulations’). This guideline is effective from the date of publication by the Authority.
INTRODUCTION
According to Section 3 of the Regulations, no individual or entity is permitted to process personal information for the purposes specified in the regulations unless licensed by the Authority. “Processing” means any operation or sets of operations which are performed on personal data or on sets of personal data whether or not by automated means, such as:
EXAMPLES OF DATA SUBJECTS AND PERSONALLY IDENTIFIABLE INFORMATION
The Regulations provide for four (4) licence categories that are premised on the number of data subjects that a controller collects personally identifiable information from. Data subjects include:
employees,
daily walk in-visitors,
members/ clients,
service providers,
suppliers,
individuals accessing the data controller's website, or
any other person from whom personally identifiable information is processed.
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPGI OF 2025
<!-- ===== PAGE 3 of 13 (OCR) ===== -->
3.2
3.2.1 3.2.2 3.2.3 3.2.4 3.2.5 3.2.6 3.2.7
4] 4.2 4.3 4.4 4.5 4.6 4.7
4.8 4.9
4.10 4.11 4.12 4.13
5.1 5.2 5.3 5.4 5.5 5.6 5.7
In terms of section 3 of the CDPA, personally identifiable information is information relating to a data subject and includes but is not limited to the following:
name, address, telephone number,
race, national or ethnic origin, colour, religious or political beliefs of associations,
age, sex, marital status, or family status,
an identifying number, symbol, or other particulars assigned to that person,
fingerprints, blood type or inheritable characteristics,
Healthcare history, including physical or mental disability,
Educational, financial, criminal or employment history.
WHO IS A DATA CONTROLLER?
Section 3 of the CDPA stipulates that a data controller is a natural or legal person who is licensable by the Authority. For a person to qualify as a data controller they must answer yes to one or more of the following:
Do you decide to collect or process personal data?
Do you decide what the purpose or outcome of the processing is to be?
Do you decide what personal data should be collected?
Do you decide which individuals to collect personal data about?
Do you obtain a commercial gain or other benefit from the processing?
Do you expect any payment for services from another controller?
Are you processing the personal data because of a contract between you and the data subject?
Do you collect personal data of your employees or other third parties?
Do you make decisions about the data subjects concerned as part of or because of the processing?
Do you exercise professional judgement in the processing of the personal data?
Do you have a direct relationship with the data subjects?
Do you have complete autonomy as to how the personal data is processed and stored? Have you appointed data processors to process the personal data on your behalf?
WHO IS ELIGIBLE FOR LICENSING?
All data controllers who meet the minimum threshold of the number of data subjects must be licensed. This requirement applies to institutions established in terms of the laws of Zimbabwe such as:
public entities,
state owned enterprises,
government ministries, department, and agencies,
private and public companies,
partnerships of professionals such as doctors, lawyers, engineers, and architects,
religious entities such as churches and mosques,
health service providers such as hospitals, clinics, pharmacies,
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPGI OF 2025
<!-- ===== PAGE 4 of 13 (OCR) ===== -->
5.8
5.9
5.10 5.11 5.12 5.13 5.14 5.15 5.16 5.17 5.18 5.19 5.20
educational institutions,
retailers and wholesalers,
hoteliers,
local authorities,
financial institutions,
insurers,
transporters,
payment solution providers,
political parties,
non-governmental organisations including trade unions/trusts, associations and societies social clubs such as sports clubs, gymnasiums,
professional bodies and
any entities as maybe deemed by the Authority as data controllers.
NB: The above list is not exhaustive but provides a guideline of the categories of data controllers covered under the Act.
SHOULD FOREIGN ENTITIES COMPLY WITH THE LICENCING REGULATIONS?
Where an entity is not established in term of the laws of Zimbabwe but collects personally identifiable information from Zimbabwe or the means of processing such personal data is located in Zimbabwe, the foreign entity is required to designate a data controller representative for purposes of compliance with Section 4 of the Act.
LICENSING CATEGORIES/TIERS
The applicable licensing tiers are as follows:
Tier Number of data subjects | Registration & License fees
1 50 to 1000 $50
2 1001 to 100 000 $300
3 100 001 to 500 000 $500
4 500 000 and above $2500
EXEMPTIONS FROM LICENSING AND REGISTRATION
Section 8 of the Regulations exempts certain categories of data controllers from obtaining a license from the Authority. Each exempted category must still adhere to the Act’s overarching data protection principles, ensuring that personal information is protected, managed responsibly and ethically, even without the requirement for licensing.
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPGI OF 2025
<!-- ===== PAGE 5 of 13 (OCR) ===== -->
8.1
8.1.1
8.1.2
8.2
8.2.1
8.2.2
8.2.3
8.2.4
8.3
8.3.1 8.3.2 8.3.3 8.3.4
The exemptions are in three (3) categories which are:
Personal, family, or household matters
Individuals who process personal information solely for personal or family purposes are exempt from licensing and registration as a data controller. Individuals are allowed to keep the addresses, phone numbers and pictures without the need to obtain a data controller licence from the Authority.
The Act and the Regulations do not define what constitutes personal, family or household affairs. The Authority therefore guides as follows in determining the activities that constitute personal, family and household affairs. Such activities include:
Social networking or managing family-related social media groups, sharing home/ family gathering photos, personal phone books, or
Personal use such as school association groups, neighbourhood update groups, hobby, and craft groups, where data is used for purely private or familial reasons with no commercial benefit.
Personal, family or household affairs not connected to commercial or professional activities.
To further guide on this matter, it is also important for individuals to ask the following questions to be able to ascertain whether they are covered under the exemption.
Are your data collection activities likely to result in personal data being shared with an indefinite number of people rather than to limited community of family, friends, and acquaintances?
Do you have a personal relationship with the data subject?
Does the scale and frequency of data processing indicate some professional or business activity on your behalf?
Is there a possibility of your data processing activities having an adverse impact on people including an intrusion into their privacy?
Law enforcement
Entities involved in law enforcement are exempt from licensing requirements due to the nature of their public function. Those exempt under law enforcement are:
The police,
The judiciary,
Military, and
State security.
However, the Authority may issue guidelines on safeguards to be considered even for law enforcement purposes. Though exempted from obtaining a license, the law enforcement agencies must register their data controlling activities with the Authority and are not exempt from adhering to certain data protection principles.
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPGI OF 2025
<!-- ===== PAGE 6 of 13 (OCR) ===== -->
8.4
9.1
9.2 9.2.1 9.2.2
10. 10.1
Journalistic, historical, or archival purposes
Activities focused on journalism, historical documentation, or archival work are also exempt from licensing. This exemption seeks to balance the rights to privacy with the freedom of information and freedom of expression. It seeks to allow the media to report factual and accurate information. It also enables information to be processed accurately for historical and archival purposes. While exempted for journalistic purposes, they may be still be required to licence as a controller for other purposes.
For journalistic exemptions to apply, the journalists must exercise their rights without breaching data processing principles and upholding of the rights of data subjects.
This exemption applies to licensed journalists acting in the course of their work if:
there is a reasonable belief that the publication will be in the public interest,
there is an already established public interest; and
the data is processed with the intention of publication.
The exemption also applies to the National Archives of Zimbabwe, which processes data for public information and historical record-keeping.
LICENSING CONDITIONS
The Authority can impose certain licensing conditions on data controllers as provided for in
Section 4 (4) of the Regulations.
Special licensing conditions
Data controllers in Tier 1 are deemed to be small scale controllers who process minimal amounts of personal data. Such controllers in Tier 1 are exempted from appointing a DPO. However, this is dependent on the nature of processing and sector of operation as determined by the Authority.
Validity, suspension, and cancellation of data controlling licenses
A data controller license is valid for a period of 12 months.
A data controller license may be suspended or cancelled by the Authority if the data controller fails to meet any terms and conditions of its licence as set by the Authority.
KEY STEPS TO OBTAINING A DATA CONTROLLER LICENSE
A data controller should consider the following steps prior to applying for licensing: - Step 1: Identify if they meet the criteria to be classified as a data controller.
Step 2: Identify the classes and categories of personal data processed.
Step 3: List the sensitive personal data processed.
Step 4: Identify any transfer of personal data outside Zimbabwe.
Step 5: Identify the risks and safeguards for protection of personal data.
Step 7: Identify the Licensing Tier.
Step 9: Submit the Application Form (DP1) annexed hereto.
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPGI OF 2025
<!-- ===== PAGE 7 of 13 (OCR) ===== -->
10.2
Once a completed application form is submitted, the Authority has 14 days within which to
11. 12. 12.1 a) b) ¢) q) €) f) 12.2 12.3 13.
Request for further information.
PROVISION OF FALSE INFORMATION ON LICENSE CATEGORY
Under Section 7 of the Regulations, it is an offense for any data controller to knowingly submit information that is false or materially misleading during the registration process. This provision is intended to ensure that all data controllers provide accurate and truthful information when applying for a license, as false data could have serious implications for compliance and accountability.
OFFENCES AND PENALTIES
The Regulations provide for the following offences:
Failure to obtain a data controlling license within the stipulated time Section 3 (3) of the Regulations.
Continuing to process data after the stipulated time without a data controlling license Section
Failure to renew a data controlling license Section 5 (3) of the Regulations.
Submission of false or misleading information for the purposes of registration in terms of
Section 7 of the Regulations.
Failure to discharge the data controller obligations in terms of Section 10 (6) of the Regulations.
Failure to appoint a data protection officer within ninety (90) days of promulgation of the Regulations as per Section 12 (6).
If a data controller is found guilty of any of these offences, they may be liable to a fine not exceeding level 11, a prison sentence of up to seven years, or both a fine and imprisonment. These significant penalties underscore the importance of maintaining transparency and accuracy in the data processing and registration processes, as well as the regulator's commitment to uphold ethical standards in data protection practices.
REGISTRATION AND LICENSING DEADLINE
According to Section 4(5) of the Regulations, all data controllers that are not exempt from registration and licensing must be registered and licensed with the Authority within 6 months from the date of promulgation of the Regulations. The deadline for licensing as a data controller is 12 March 2025.
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPGI OF 2025
<!-- ===== PAGE 8 of 13 (OCR) ===== -->
Data Controller Licensing Process flow
Decision Fe eT 1 |
by the Authority
For further guidance on licensing requirements and process, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at regulator@potraz.zw or dpa@potraz.zw or call +263 242 333032/46/48.
ISSUED ON THIS 28th DAY OF JANUARY 2025
Ki pot ELE
DIRECTOR GENERAL
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPGI OF 2025
<!-- ===== PAGE 9 of 13 (OCR) ===== -->
‘creating a level playing field’
APPLICATION/ RENEWAL FORM (FIRST SCHEDULE) DP1
REGISTRATION & LICENCING AS A DATA CONTROLLER
Note: Before filling out this application form, consult the registration guide available on www.potraz.zw
Entity Name:
Registration Number (if applicable): | License Number (if applicable): Data Controller Category or Class
Tier:
Tick as appropriate
O Public / Government Dpt DH Private 0NGO TL Faith Based organisation OH Political organisation L) Other:
Entity Sector Entity Address: Phone Number: Email Address: Website:
Name: Phone Number: Email Address:
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPGI1 OF 2025
<!-- ===== PAGE 10 of 13 (OCR) ===== -->
Name:
Phone Number: Address: Email:
Website:
| O Consent of data
subject
O Contractual necessity
OU Legal obligation
O Vital interests of the data subject or other person
O Public interest
OU Performance of duties of a public entity O Legitimate interest
OU Research upon authorization
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPG1 OF 2025
<!-- ===== PAGE 11 of 13 (OCR) ===== -->
SECTION 3 — CATEGORIES OF SENSITIVE PERSONAL DATA
Oo Applicable O Not Applicable (Tick as appropriate) If applicable, please fill in the below details otherwise proceed to section 4.
PLEASE SELECT THE TYPE(S)
OF
SENSITIVE PERSONAL DATA
YOU PROCESS
(Tick as appropriate)
SPECIFY PURPOSE(S) FOR
PROCESSING SENSITIVE
PERSONAL DATA
GROUND FOR PROCESSING
(Tick as appropriate)
O Person’s race
OSocial origin
O Genetic or biometric information
O Political opinion
0 Health status
O Criminal records
O Religious or philosophical beliefs
O Sexual life or family details
O Medical records
O Consent of data subject
O Obligations of the data controller/ data processor or exercising specific rights of the data subject
O Vital interests of the data subject or other person
O Preventive or occupational medicine, public health
O Archiving, scientific, and historical research or statistical purposes
SECTION 4 — DATA PROCESSOR'S INVOLVEMENT
OH Applicable O Not Applicable (Tick as appropriate) If applicable, please list your Data Processors and fill in the details below, otherwise proceed to section 5.
NAME OF DATA PROCESSOR(S)
DO YOU HAVE WRITTEN DATA PROCESSING
CONTRACT(S) WITH THE DATA
PROCESSOR(S)?
O YES ONO (Tick as appropriate)
SECTION 5— TRANSFER OF PERSONAL DATA OUTSIDE ZIMBABWE
0 Applicable CINot Applicable (Tick as appropriate)
If applicable, please list the countries in the section below, otherwise proceed to section 6.
Note: You will need to apply for a separate authorization to transfer personal data outside of Zimbabwe and to provide data sharing agreements.
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPG1 OF 2025
<!-- ===== PAGE 12 of 13 (OCR) ===== -->
Do you store personal data outside of Zimbabwe? 1] YES C1 NO (Tick as appropriate)
If YES, you need to apply for a separate authorization to store personal data outside of Zimbabwe.
Certificate of incorporation oO
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPG1 OF 2025
<!-- ===== PAGE 13 of 13 (OCR) ===== -->
I certify that the above information is correct and complete and hereby apply to be registered as a Data Controller under the Cyber & Data Protection Act [Chapter 12:07] of 2021 and Statutory Instrument 155 of 2024, Cyber and Data Protection Regulations relating to the protection of personal data and privacy.
Signature: Date:
Name:
(*Applicant / Person authorized to sign on behalf of Applicant)
FOR OFFICE USE ONLY
Fee Class/ Tier. eee eee eee eee nee Total So Receipt
Recommending Officer:..
Reviewing
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON LICENSING OF DATA CONTROLLERS, CDPGI OF 2025
A data controller is the person or organisation that decides why personal data will be used and the essential means of using it. A controller remains responsible even when another organisation processes the information on its behalf. The legal test, licensing duties and terminology can vary, so check the jurisdiction view for the rules that apply.
A data processor is a person or organisation that handles personal data for a controller and under the controller’s instructions. Hosting companies, payroll providers and outsourced support services may act as processors in some arrangements. Their role depends on what they actually decide and do, not simply on the label used in a contract.
POTRAZ is the Postal and Telecommunications Regulatory Authority of Zimbabwe. Zimbabwe’s Cyber and Data Protection Act designates it as the Data Protection Authority, giving it functions related to regulating personal-data processing, guidance, complaints, investigations and enforcement. This article describes its data-protection role; it does not suggest that POTRAZ is the regulator for other jurisdictions.