CDPG 2 of 2025 — CPD Assessment for Certified DPOs
CDPG-2-2025 · v1 · release faf85cbc
CDPG 2 of 2025 — CPD Assessment for Certified DPOs — Verbatim Transcription
Citation key: CDPG-2-2025 · Category: Implementation Guideline · Pages: 6
Source PDF: CDPA Implementation Guidelines/CDPG 2 of 2025 - CPD Assessment for certified DPOs.pdf
Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.
Data Protection Authority Implementation Guidelines on the
Page 17
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on Continuous Professional Development Assessment for Certified Data Protection Officers CDPG 2 of 2025
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 18
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on Continuous Professional Development Assessment for Certified Data Protection Officers
1. Purpose
These guidelines are in terms of section 20(5) of the Cyber and Data Protection Act, which empowers the Authority to make guidelines for the qualifications of the DPO. Data Protection Officers (DPOs) who are certified in terms of Section 13(2) of S.I. 155 of 2024. It ensures DPOs maintain up-to-date knowledge and practical skills in data protection and other related matters.
2. Scope
These guidelines apply to all individuals who hold the Data Protection Certification and who intend to maintain authorisation to practice as a DPO in Zimbabwe.
3. Key Principles
4. Annual CPD Requirement
‘creating a level playing field’
Each certified DPO is required to earn 12 CPD points per calendar year, with a structured allocation to ensure balanced professional development. At least 4 points must be in the privacy framework, and another 4 points in Breach Management. In comparison, the remaining 4 points may be obtained from any other approved
Data Protection Authority Implementation Guidelines on the
Page 19
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
data-protection-related topics, such as privacy law updates, Data Protection Impact Assessments (DPIAs), children’s data, cross-border data transfers, ethics, or records management. For certifications granted mid- year, the CPD requirement is pro-rated at 1 point per full calendar month of certification remaining in that year, with proportional expectations for privacy framework and breach management content, rounded to the nearest 0.25 point to ensure fairness and consistency. A DPO is not required to earn the CPD points in the year that they obtain their certification. You are also required to attend at least one major Authority event such as the annual symposium.
5. Qualifying Activities & Points
Data Protection Authority Implementation Guidelines on the
Page 20
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
programme, as well as the integrity of the provider, ensuring impartiality of content and full disclosure of sponsorships or conflicts of interest.
7. Evidence & Submission by DPOs
DPOs are required to submit their CPD evidence to the Authority by 31 December following the end of each CPD year, which runs from 1 January to 31 December. The submission pack may be uploaded via the CPD portal or sent by email and must include a completed CPD Summary Log (using the official Authority’s template), certificates of attendance or transcripts, accreditation references (Authority’s Event CPD Code or Accreditation Letter), and, where contributory activities are claimed, supporting documentation such as a copy of the publication (or DOI/URL), a conference agenda showing the DPO as a listed speaker, or completion/assessment records. All DPOs are required to retain their underlying evidence for at least 24 months, as it may be requested during an audit.
8. Point Calculation Rules
For CPD allocation, 60 minutes of learning equals one contact hour, excluding breaks longer than 10 minutes. CPD points may be rounded to the nearest 0.25 point. Attendance at identical or substantively similar content more than once in the same year will not be credited, as duplicative learning does not count towards annual requirements. Additionally, up to three CPD points earned between October and December may be carried over into the next CPD year.
9. Quality Assurance, Audit & Misrepresentation
The Authority reserves the right to conduct random or risk-based audits of CPD submissions at any time, requesting corroborating evidence to verify compliance. Outcomes of these audits may include acceptance of the submission, a request for further documentation to be provided within 30 days, or denial of credits where insufficient proof exists. Any false claims or forged evidence will result in immediate sanction under this guideline (see Section 12 of these guidelines) and may also be referred for enforcement under applicable law or professional codes.
10. Roles & Responsibilities
DPOs are responsible for planning their annual learning, identifying and addressing competency gaps, ‘cearnringe the arequitredi pnointsg, ma intaaining alcceuratev receords,l s ubpmittinlg aevideyncei onn timge, an d ufphioeldingl d’ professional ethics. POTRAZ, as the regulatory authority, will publish annual CPD priority themes, accredit non-POTRAZ events, maintain the CPD portal and related processes, audit submissions, and issue or
Data Protection Authority Implementation Guidelines on the
Page 21
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
withdraw good-standing status as necessary. Event organisers and providers are responsible for ensuring their programmes meet required standards of quality, that qualified speakers are engaged, that accurate attendance records are kept, and that all post-event reporting obligations are fulfilled.
11. Non-Compliance & Sanctions
12. Waivers, Deferrals & Special Circumstances
In exceptional cases such as serious illness, bereavement, parental leave, or other extraordinary circumstances, DPOs may apply for a waiver or deferral. Requests must be submitted to the Authority in writing, supported by appropriate documentation, by 31 January. Where granted, Authority may either defer the submission deadline or pro-rate the CPD requirement for that year. Generally, the maximum allowable deferral is 12 months.
13. Ethics, Conflicts of Interest & Independence
DPOs must conduct themselves with integrity, avoiding any conflicts of interest that could compromise their independence or breach confidentiality. Event sponsors must always be disclosed, and purely marketing- oriented content will not qualify for CPD credit unless it is clearly educational in nature and independently curated.
14. Communication of Status
To promote transparency and accountability, the Authority will maintain a register of certified DPOs in good standing. Employers, organisations, and data controllers may verify the status of a DPO through this register or by requesting written confirmation directly from the Authority.
15. Data Protection & Records
All CPD submissions will be processed by the Authority in line with applicable data protection laws. Records will be retained only for as long as necessary to fulfil regulatory purposes, including audits, dispute resolution, or enforcement actions.
16. Disputes & Appeals
‘DcPOsr wheo diasagrete iwinth a gCPD- realated delceision vmaye first lse ekp infolrmaal reysoluitionn byg cont acftinig ethe ld’ Authority’s CPD administration within 30 days of the decision. If the matter remains unresolved, a formal appeal may be lodged with the Authority’s Certification Committee within 30 days of the informal outcome,
Data Protection Authority Implementation Guidelines on the
Page 22
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
supported by objective evidence. Appeals will be reviewed by an independent panel, and the decision of that panel will be final.
17. Guidelines Review
These guidelines are subject to annual review to ensure they remain aligned with legislative developments, technological advancements, and professional best practices. The Authority will notify all certified DPOs of any material amendments and their effective dates. For further guidance on licensing requirements and process, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at regulator@potraz.zw or call +263 242 333032/48 .
‘creating a level playing field’
A Data Protection Officer is an independent privacy-compliance specialist who helps an organisation understand its duties, monitor its practices, advise on risk and act as a contact point for people and regulators. A DPO should have suitable expertise, resources and freedom from conflicting roles. Whether appointment, certification or notification is required depends on the jurisdiction.