Skip to content

Research · authority data, public-interest

← Back to Legal library

CDPG 2 of 2025 — CPD Assessment for Certified DPOs

CDPG-2-2025 · v1 · release faf85cbc

cdpg
non binding
published 2026-07-30
reviewer-approved transcription
Educational information — not legal advice.Sanitised transcription for research. The linked PDF remains the authoritative source; consult a qualified practitioner for advice on specific facts.
Download PDF
Original PDF

CDPG-2-of-2025-CPD-Assessment-for-certified-DPOs.pdf

application/pdf · 2.0 MB

Sanitised text

CDPG 2 of 2025 — CPD Assessment for Certified DPOs — Verbatim Transcription

Citation key: CDPG-2-2025 · Category: Implementation Guideline · Pages: 6

Source PDF: CDPA Implementation Guidelines/CDPG 2 of 2025 - CPD Assessment for certified DPOs.pdf

Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.


Page 1 of 6

Data Protection Authority Implementation Guidelines on the

Page 17

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

Implementation Guidelines on Continuous Professional Development Assessment for Certified Data Protection Officers CDPG 2 of 2025

‘creating a level playing field’

Page 2 of 6

Data Protection Authority Implementation Guidelines on the

Page 18

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

Implementation Guidelines on Continuous Professional Development Assessment for Certified Data Protection Officers

1. Purpose

These guidelines are in terms of section 20(5) of the Cyber and Data Protection Act, which empowers the Authority to make guidelines for the qualifications of the DPO. Data Protection Officers (DPOs) who are certified in terms of Section 13(2) of S.I. 155 of 2024. It ensures DPOs maintain up-to-date knowledge and practical skills in data protection and other related matters.

2. Scope

These guidelines apply to all individuals who hold the Data Protection Certification and who intend to maintain authorisation to practice as a DPO in Zimbabwe.

3. Key Principles

a)Certified DPO must undertake continuous learning and development to continue practising as such.
b)DPOs must earn 12 CPD points each calendar year to maintain their certification in good standing.
c)To guarantee quality and consistency, CPD activities are primarily drawn from Authority-organised events, while external events only qualify if they have been formally accredited by the Authority. This approach ensures regulator-led quality assurance and protects the integrity of the programme.
d)The CPD framework is also competency-focused, designed, with particular emphasis on artificial intelligence governance and cybersecurity/breach response.
3.Definitions:
a)CPD point (also “CPE point”): A unit of professional learning earned through qualifying activities. Four (4) contact hours = 1 CPD point. Points may be recorded in quarter-point increments (e.g., 1 hour = 0.25 point).
b)Calendar year: 1 January – 31 December.
c)Accredited provider: An organisation whose event has been approved by POTRAZ for CPD credit.
d)AI governance: Policies, processes, and controls for the safe, lawful, and ethical design, deployment, and oversight of AI systems.
e)Cybersecurity & breach management: Risk management, incident response, forensics, reporting/ notification, and lessons learned.

4. Annual CPD Requirement

‘creating a level playing field’

Each certified DPO is required to earn 12 CPD points per calendar year, with a structured allocation to ensure balanced professional development. At least 4 points must be in the privacy framework, and another 4 points in Breach Management. In comparison, the remaining 4 points may be obtained from any other approved

Page 3 of 6

Data Protection Authority Implementation Guidelines on the

Page 19

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

data-protection-related topics, such as privacy law updates, Data Protection Impact Assessments (DPIAs), children’s data, cross-border data transfers, ethics, or records management. For certifications granted mid- year, the CPD requirement is pro-rated at 1 point per full calendar month of certification remaining in that year, with proportional expectations for privacy framework and breach management content, rounded to the nearest 0.25 point to ensure fairness and consistency. A DPO is not required to earn the CPD points in the year that they obtain their certification. You are also required to attend at least one major Authority event such as the annual symposium.

5. Qualifying Activities & Points

1.1.CPD points may be earned through three main categories of activities. First, participation in Authority’s events, such as conferences, workshops, symposiums, and webinars, is automatically eligible, with credit awarded at the rate of 1 point per 4 contact hours (0.25 per hour).
1.2.Events organised by other institutions—whether local, regional, or international—are also eligible for credit, provided they are formally accredited by the Authority in accordance with Section 7, and they follow the same points allocation system of 1 point per 4 contact hours.
1.3.To encourage diverse forms of professional growth, certain additional contributory activities may also count towards CPD, though these are capped at a total of 4 points per year within the 12-point requirement. These include :
1.3.1.speaking or delivering training, credited at 0.75 points per hour with a maximum of 3 points annually;
1.3.2.scholarly or professional writing, where peer-reviewed journal articles or book chapters earn 2 points each (maximum 2 points per year), and practice articles, guidance notes, or equivalent works of at least 1,200 words earn 1 point each (maximum 2 points per year); and
1.3.3.structured self-study, such as reading major standards or official guidance of 10,000 words or more, or completing a graded e-module/assessment, credited at 0.5 point each (maximum 2 points annually).
1.4.To preserve rigour and consistency, at least 8 of the 12 required points must come from live or structured events (POTRAZ or POTRAZ-accredited), while the remaining up to 4 points may be earned through the contributory activities outlined above.
6.Accreditation of Non-POTRAZ Events.
a)Organisers seeking CPD accreditation must submit their request to the Authority (or via the CPD portal once operational) no later than 21 calendar days before the event.
b)The submission must include a concept note outlining the learning objectives, target audience, agenda with time allocations, delivery method, and any assessments to be used.
c)It should also contain detailed speaker profiles or CVs highlighting qualifications, experience, affiliations, potential conflicts of interest, and prior speaking engagements.
d)In addition, organisers must provide draft materials or a reading list, an evaluation form, and a clear attendance verification plan (e.g., sign-in sheets, platform logs, or proctoring measures). ‘ce)r Aeccreaditatiotn idencisiogns wi ll bae ba seld eon sevverael factolrs , ipncludlinag they releivannce ogf the cofnteinet to ld’ Zimbabwe’s Cyber and Data Protection Act and its associated regulations or guidelines.
f)Consideration will also be given to academic and professional rigour, including the clarity of learning outcomes, qualifications of speakers, and reliability of sources.
g)Other evaluation factors include the duration, interactivity, and assessment methods of the
Page 4 of 6

Data Protection Authority Implementation Guidelines on the

Page 20

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

programme, as well as the integrity of the provider, ensuring impartiality of content and full disclosure of sponsorships or conflicts of interest.

h)If the event meets the required standards, POTRAZ will issue an Accreditation Letter together with a unique Event CPD Code. This code will specify the number of approved hours, the topic classification and the equivalent CPD points.
i)Within 10 working days after the event, organisers are required to submit a package of post-event materials, including a signed attendance register or platform participation logs, the final programme and slides, a summary of participant feedback, and copies of certificates of attendance issued to delegates, each of which must display the Authority’s Event CPD Code.

7. Evidence & Submission by DPOs

DPOs are required to submit their CPD evidence to the Authority by 31 December following the end of each CPD year, which runs from 1 January to 31 December. The submission pack may be uploaded via the CPD portal or sent by email and must include a completed CPD Summary Log (using the official Authority’s template), certificates of attendance or transcripts, accreditation references (Authority’s Event CPD Code or Accreditation Letter), and, where contributory activities are claimed, supporting documentation such as a copy of the publication (or DOI/URL), a conference agenda showing the DPO as a listed speaker, or completion/assessment records. All DPOs are required to retain their underlying evidence for at least 24 months, as it may be requested during an audit.

8. Point Calculation Rules

For CPD allocation, 60 minutes of learning equals one contact hour, excluding breaks longer than 10 minutes. CPD points may be rounded to the nearest 0.25 point. Attendance at identical or substantively similar content more than once in the same year will not be credited, as duplicative learning does not count towards annual requirements. Additionally, up to three CPD points earned between October and December may be carried over into the next CPD year.

9. Quality Assurance, Audit & Misrepresentation

The Authority reserves the right to conduct random or risk-based audits of CPD submissions at any time, requesting corroborating evidence to verify compliance. Outcomes of these audits may include acceptance of the submission, a request for further documentation to be provided within 30 days, or denial of credits where insufficient proof exists. Any false claims or forged evidence will result in immediate sanction under this guideline (see Section 12 of these guidelines) and may also be referred for enforcement under applicable law or professional codes.

10. Roles & Responsibilities

DPOs are responsible for planning their annual learning, identifying and addressing competency gaps, ‘cearnringe the arequitredi pnointsg, ma intaaining alcceuratev receords,l s ubpmittinlg aevideyncei onn timge, an d ufphioeldingl d’ professional ethics. POTRAZ, as the regulatory authority, will publish annual CPD priority themes, accredit non-POTRAZ events, maintain the CPD portal and related processes, audit submissions, and issue or

Page 5 of 6

Data Protection Authority Implementation Guidelines on the

Page 21

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

withdraw good-standing status as necessary. Event organisers and providers are responsible for ensuring their programmes meet required standards of quality, that qualified speakers are engaged, that accurate attendance records are kept, and that all post-event reporting obligations are fulfilled.

11. Non-Compliance & Sanctions

1.1.If a DPO fails to meet the 12-point annual requirement by 31 January, their certification status will automatically be changed to Suspended, meaning they are no longer authorised to practice until compliance is achieved.
1.2.Continued non-compliance beyond 31 March will result in the cancellation of certification, and the individual will no longer be authorised to act as a DPO in Zimbabwe.
1.3.Reinstatement after cancellation will require full re-certification, which includes meeting the current entry requirements and may also involve the payment of an administrative fee.

12. Waivers, Deferrals & Special Circumstances

In exceptional cases such as serious illness, bereavement, parental leave, or other extraordinary circumstances, DPOs may apply for a waiver or deferral. Requests must be submitted to the Authority in writing, supported by appropriate documentation, by 31 January. Where granted, Authority may either defer the submission deadline or pro-rate the CPD requirement for that year. Generally, the maximum allowable deferral is 12 months.

13. Ethics, Conflicts of Interest & Independence

DPOs must conduct themselves with integrity, avoiding any conflicts of interest that could compromise their independence or breach confidentiality. Event sponsors must always be disclosed, and purely marketing- oriented content will not qualify for CPD credit unless it is clearly educational in nature and independently curated.

14. Communication of Status

To promote transparency and accountability, the Authority will maintain a register of certified DPOs in good standing. Employers, organisations, and data controllers may verify the status of a DPO through this register or by requesting written confirmation directly from the Authority.

15. Data Protection & Records

All CPD submissions will be processed by the Authority in line with applicable data protection laws. Records will be retained only for as long as necessary to fulfil regulatory purposes, including audits, dispute resolution, or enforcement actions.

16. Disputes & Appeals

‘DcPOsr wheo diasagrete iwinth a gCPD- realated delceision vmaye first lse ekp infolrmaal reysoluitionn byg cont acftinig ethe ld’ Authority’s CPD administration within 30 days of the decision. If the matter remains unresolved, a formal appeal may be lodged with the Authority’s Certification Committee within 30 days of the informal outcome,

Page 6 of 6

Data Protection Authority Implementation Guidelines on the

Page 22

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

supported by objective evidence. Appeals will be reviewed by an independent panel, and the decision of that panel will be final.

17. Guidelines Review

These guidelines are subject to annual review to ensure they remain aligned with legislative developments, technological advancements, and professional best practices. The Authority will notify all certified DPOs of any material amendments and their effective dates. For further guidance on licensing requirements and process, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at regulator@potraz.zw or call +263 242 333032/48 .

‘creating a level playing field’

Referenced by Privacy Hub
Data Protection Officer (DPO)

A Data Protection Officer is an independent privacy-compliance specialist who helps an organisation understand its duties, monitor its practices, advise on risk and act as a contact point for people and regulators. A DPO should have suitable expertise, resources and freedom from conflicting roles. Whether appointment, certification or notification is required depends on the jurisdiction.