Skip to content

Research · authority data, public-interest

Public-interest · living reference

Africa Privacy-Law Tracker

A side-by-side view of privacy and data-protection regimes. Every cell carries its own citation and last-reviewed date so you can trace the underlying law rather than take our word for it.

DimensionZimbabwe
POTRAZ (Postal & Telecommunications Regulatory Authority of Zimbabwe)
Reviewed 19 Jul 2026
United Kingdom
ICO (Information Commissioner's Office)
Reviewed 19 Jul 2026
Data-protection authority
The regulator responsible for enforcement.
POTRAZ acts as the Data Protection Authority alongside its telecoms mandate.
The Information Commissioner's Office (ICO) enforces the UK GDPR and DPA 2018.
Source: Data Protection Act 2018, s. 114· Reviewed 19 Jul 2026
DPO appointment
When a Data Protection Officer must be appointed.
Every data controller must appoint a Data Protection Officer within 90 days of registration.
Source: CDPA s. 19; SI 155 of 2024, reg. 8· Reviewed 19 Jul 2026
Mandatory for public authorities and for core processing that requires systematic monitoring or large-scale special-category processing.
Source: UK GDPR Art. 37· Reviewed 19 Jul 2026
Controller registration / licensing
Whether controllers must register or be licensed with the authority.
Data controllers must obtain a licence from POTRAZ before processing personal information.
Source: CDPA s. 6; SI 155 of 2024, regs. 3–6· Reviewed 19 Jul 2026
No licensing regime. Most controllers must pay the annual data-protection fee to the ICO under the 2018 Fee Regulations.
Registration / licence fees
Statutory fees payable to the authority.
Tiered by data-subject count: T1 (50–1 000) USD 50 · T2 (1 001–100 000) USD 300 · T3 (100 001–500 000) USD 500 · T4 (>500 000) USD 2 500. VAT 15.5% applies.
Source: SI 155 of 2024, Schedule of Fees· Reviewed 19 Jul 2026
Annual fee £52 (Tier 1, micro) · £78 (Tier 2, SME) · £3 763 (Tier 3, large). No fee for the licence itself — licensing not required.
Source: ICO Data Protection Fee, 2024· Reviewed 19 Jul 2026
Breach notification clock
How quickly a personal-data breach must be notified.
Notify POTRAZ within 24 hours and affected data subjects within 72 hours of discovering a breach.
Source: CDPA s. 21; SI 155 of 2024, reg. 12· Reviewed 19 Jul 2026
Notify the ICO within 72 hours of becoming aware of a personal-data breach; notify affected data subjects without undue delay where high risk.
Source: UK GDPR Arts. 33–34· Reviewed 19 Jul 2026
Data-subject rights
Core rights afforded to data subjects.
Access, rectification, erasure, objection, and the right to withdraw consent.
Source: CDPA ss. 14–17· Reviewed 19 Jul 2026
Access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making.
Source: UK GDPR Arts. 15–22· Reviewed 19 Jul 2026
Cross-border transfers
Rules governing transfers of personal data out of the jurisdiction.
Transfers require the recipient country to provide an adequate level of protection, or explicit safeguards / consent.
Source: CDPA s. 28· Reviewed 19 Jul 2026
Adequacy decisions, UK IDTA / Addendum to EU SCCs, BCRs, or Article 49 derogations.
Source: UK GDPR Arts. 44–49· Reviewed 19 Jul 2026
Penalties
Maximum administrative or criminal penalties for non-compliance.
Fines up to level 14 (currently ~USD 5 000) and/or imprisonment up to 7 years for serious offences.
Source: CDPA ss. 30–35· Reviewed 19 Jul 2026
Up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements.
Source: DPA 2018, s. 157; UK GDPR Art. 83· Reviewed 19 Jul 2026