Skip to content

Research · authority data, public-interest

← Back to Legal library

CDPG 5 of 2025 — Licensing of MDAS

CDPG-5-2025 · v1 · release faf85cbc

cdpg
non binding
published 2026-07-30
reviewer-approved transcription
Educational information — not legal advice.Sanitised transcription for research. The linked PDF remains the authoritative source; consult a qualified practitioner for advice on specific facts.
Download PDF
Original PDF

CDPG-5-of-2025-Licensing-of-MDAS.pdf

application/pdf · 1.7 MB

Sanitised text

CDPG 5 of 2025 — Licensing of Government Ministries, Departments and Agencies (MDAs) — Verbatim Transcription

Citation key: CDPG-5-2025 · Category: Implementation Guideline · Pages: 4

Source PDF: CDPA Implementation Guidelines/CDPG 5 of 2025 - Licensing of (MDAS).pdf

Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.


Page 1 of 4

Data Protection Authority Implementation Guidelines on the

Page 36

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

Implementation Guidelines on the Licensing of Government Ministries, Departments & Agencies (MDAS) CDPG 5 of 2025

‘creating a level playing field’

Page 2 of 4

Data Protection Authority Implementation Guidelines on the

Page 37

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

Implementation Guidelines on the Licensing of Government Ministries, Departments & Agencies (MDAS) Issued in terms of the Cyber and Data Protection Act [Chapter 12:07] (CDPA) as read together with Statutory Instrument 155 of 2024 – Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024

1. INTRODUCTION

These guidelines outline the procedure and requirements for the licensing of Government Ministries, Departments & Agencies (MDAs) as data controllers under Zimbabwe’s data protection legal framework. It is aimed at facilitating compliance with the Cyber and Data Protection Act and ensuring that MDAs operate within the bounds of lawful data processing. These guidelines serve to clarify how MDAs should apply for data controller licenses and the conditions under which Data Protection Officers (DPOs) should be appointed.

2. DEFINITIONS

For these guidelines, the following definitions shall apply:

Agency: Refers to any organisation or body that is established or functions as part of the government or public sector and is responsible for administering or providing services in the public interest. An Act of Parliament must establish an agency. Agencies include Independent Commissions, Boards and Authorities.
Government Department: A functional branch or administrative unit within a government ministry that carries out specified duties or responsibilities in line with the ministry’s broader mandate.
Ministry: a specialised government unit which is responsible for a broad administrative function within the Executive arm of government, which a line minister heads.
Public Authority: Refers to any organisation or body that is established by an Act of Parliament, which functions as part of the government or public sector and is responsible for administering or providing services in the public interest.
State-Owned Enterprise (SOE) means a legal entity in which the State holds a majority ownership interest, whether directly or indirectly, and which engages in commercial or public service activities on behalf of the Government of Zimbabwe.
Parastatal means a statutory body or corporation established by an Act of Parliament to perform specific governmental or public interest functions under ministerial supervision, and which operates with partial or complete financial support from the State.

‘creating a level playing field’

Polytechnic means a tertiary education institution that provides applied science, engineering, or technological education and training, usually offering diploma and degree-level programmes in technical and vocational disciplines.
Page 3 of 4

Data Protection Authority Implementation Guidelines on the

Page 38

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

3. ARE MDAs REQUIRED TO OBTAIN DATA CONTROLLING LICENSES?

3.1.In terms of Section 3 of the CDPA, public authorities who control the means of processing data are licensable by the Authority. MDAs are public authorities and must obtain a data control license under Section 4 of the Regulations.
3.2.There is no exemption on the licensing of MDAs in terms of Section 8 (1) of the Regulations. The exemption is only for personal, family, or household use, law enforcement, and journalistic or archival purposes.
3.3.MDAs are therefore required to obtain a data controlling license.

4. HOW CAN MDAs OBTAIN DATA CONTROLLING LICENSES

4.1.Every line ministry shall apply for a data processing license.
4.2.Government Departments are administrative units of Ministries, but do not have a separate legal persona; therefore, they are licensable by the Authority.
4.3.Agencies are separate legal entities and, as such, are licensable by the Authority.
4.4.When a Ministry applies for a data controller license, the license shall cover the Ministry and all its Departments.
4.5.The application shall be on a special form DP1A.
4.6.A license will be issued in the name of the Ministry and shall be deemed to include all the Departments under the Ministry.

5. APPOINTMENT OF DATA PROTECTION OFFICERS (DPOS) IN MINISTRIES

5.1.Every Ministry is required to appoint a Data Protection Officer (DPO).
5.2.The DPO must be trained and licensed by the Authority in terms of Section 13 (2) of the Regulations.

6. LICENSING OF AGENCIES AND PUBLIC AUTHORITIES

6.1.All Agencies and Public Authorities that are separately incorporated or registered under any law of Zimbabwe shall be treated as independent data controllers.
6.2.These entities must apply for licenses in their own capacity, even if they fall under the general oversight of a parent ministry.
6.3.This distinction is made because they possess separate legal personality and manage their own data independently.

7. GENERAL REQUIREMENTS FOR ALL MDAs

According to Section 5 of the Regulations:

7.1.All MDAs must renew their data controlling licenses annually.
7.2.All data controlling licenses must be renewed at least 3 months before the expiry of the data ‘crecontarollingt liicennse. g a level playing field’ POTRAZ shall be responsible for monitoring compliance with the licensing requirements under this guideline. Monitoring shall include periodic inspections, submission of compliance reports, and targeted reviews to ensure that all licensed institutions maintain appropriate technical and
Page 4 of 4

Data Protection Authority Implementation Guidelines on the

Page 39

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

organisational measures for data protection. The regulator shall also provide compliance feedback and capacity-building support where necessary.

8. AUDITS AND ASSESSMENTS

Licensed MDAs shall be subject to technical audits and compliance assessments to evaluate the adequacy of their data protection and information security controls. Such audits may include vulnerability testing, system reviews, and data handling evaluations conducted by POTRAZ or its appointed auditors. The outcome of each assessment shall form part of the institution’s compliance record and may influence renewal or suspension decisions.

9. OFFENCES

9.1.Any MDAs that fail to obtain a data controlling license within the stipulated timeframes shall be guilty of an offence and liable to a fine not exceeding level 11 or to imprisonment for a period not exceeding seven years or to both such fine and such imprisonment.
9.2.Any MDAs that fail to renew their data controlling license without just cause shall be guilty of an offence and liable to a fine not exceeding level 11 or to imprisonment for a period not exceeding 7 years or to both such fine and such imprisonment.
9.3.Any MDAs that fail to appoint a DPO within the stipulated period shall be guilty of an offence and liable to a fine not exceeding level 7 or to imprisonment not exceeding two years or to both such fine and such imprisonment.

10. INSTITUTIONAL EFFICIENCY

Institutions that are not separate legal entities shall operate under the license of their parent institution. This approach minimises administrative burden and promotes efficiency by avoiding unnecessary license duplication and associated costs, thereby enabling ministries and agencies to focus resources on strengthening internal data protection mechanisms.

11. CONCLUSION

11.1.These guidelines are intended to ensure consistency, legal clarity, and administrative efficiency in the implementation of Zimbabwe’s data protection regime within the public sector.

11.2 All MDAs are urged to adhere to these provisions and liaise with POTRAZ for any further

clarification. For further guidance on licensing requirements and process, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at regulator@potraz.zw or call +263 242 333032/48

‘creating a level playing field’

Referenced by Privacy Hub
Data controller

A data controller is the person or organisation that decides why personal data will be used and the essential means of using it. A controller remains responsible even when another organisation processes the information on its behalf. The legal test, licensing duties and terminology can vary, so check the jurisdiction view for the rules that apply.