CDPG 5 of 2025 — Licensing of MDAS
CDPG-5-2025 · v1 · release faf85cbc
CDPG 5 of 2025 — Licensing of Government Ministries, Departments and Agencies (MDAs) — Verbatim Transcription
Citation key: CDPG-5-2025 · Category: Implementation Guideline · Pages: 4
Source PDF: CDPA Implementation Guidelines/CDPG 5 of 2025 - Licensing of (MDAS).pdf
Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.
Data Protection Authority Implementation Guidelines on the
Page 36
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on the Licensing of Government Ministries, Departments & Agencies (MDAS) CDPG 5 of 2025
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 37
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on the Licensing of Government Ministries, Departments & Agencies (MDAS) Issued in terms of the Cyber and Data Protection Act [Chapter 12:07] (CDPA) as read together with Statutory Instrument 155 of 2024 – Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024
1. INTRODUCTION
These guidelines outline the procedure and requirements for the licensing of Government Ministries, Departments & Agencies (MDAs) as data controllers under Zimbabwe’s data protection legal framework. It is aimed at facilitating compliance with the Cyber and Data Protection Act and ensuring that MDAs operate within the bounds of lawful data processing. These guidelines serve to clarify how MDAs should apply for data controller licenses and the conditions under which Data Protection Officers (DPOs) should be appointed.
2. DEFINITIONS
For these guidelines, the following definitions shall apply:
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 38
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
3. ARE MDAs REQUIRED TO OBTAIN DATA CONTROLLING LICENSES?
4. HOW CAN MDAs OBTAIN DATA CONTROLLING LICENSES
5. APPOINTMENT OF DATA PROTECTION OFFICERS (DPOS) IN MINISTRIES
6. LICENSING OF AGENCIES AND PUBLIC AUTHORITIES
7. GENERAL REQUIREMENTS FOR ALL MDAs
According to Section 5 of the Regulations:
Data Protection Authority Implementation Guidelines on the
Page 39
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
organisational measures for data protection. The regulator shall also provide compliance feedback and capacity-building support where necessary.
8. AUDITS AND ASSESSMENTS
Licensed MDAs shall be subject to technical audits and compliance assessments to evaluate the adequacy of their data protection and information security controls. Such audits may include vulnerability testing, system reviews, and data handling evaluations conducted by POTRAZ or its appointed auditors. The outcome of each assessment shall form part of the institution’s compliance record and may influence renewal or suspension decisions.
9. OFFENCES
10. INSTITUTIONAL EFFICIENCY
Institutions that are not separate legal entities shall operate under the license of their parent institution. This approach minimises administrative burden and promotes efficiency by avoiding unnecessary license duplication and associated costs, thereby enabling ministries and agencies to focus resources on strengthening internal data protection mechanisms.
11. CONCLUSION
11.2 All MDAs are urged to adhere to these provisions and liaise with POTRAZ for any further
clarification. For further guidance on licensing requirements and process, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at regulator@potraz.zw or call +263 242 333032/48
‘creating a level playing field’
A data controller is the person or organisation that decides why personal data will be used and the essential means of using it. A controller remains responsible even when another organisation processes the information on its behalf. The legal test, licensing duties and terminology can vary, so check the jurisdiction view for the rules that apply.