Research · authority data, public-interest
Public-interest · living reference
Africa Privacy-Law Tracker
A side-by-side view of privacy and data-protection regimes. Every cell carries its own citation and last-reviewed date so you can trace the underlying law rather than take our word for it.
| Dimension | Zimbabwe POTRAZ (Postal & Telecommunications Regulatory Authority of Zimbabwe) Reviewed 19 Jul 2026 | United Kingdom ICO (Information Commissioner's Office) Reviewed 19 Jul 2026 |
|---|---|---|
Data-protection authority The regulator responsible for enforcement. | POTRAZ acts as the Data Protection Authority alongside its telecoms mandate. | The Information Commissioner's Office (ICO) enforces the UK GDPR and DPA 2018. |
DPO appointment When a Data Protection Officer must be appointed. | Every data controller must appoint a Data Protection Officer within 90 days of registration. | Mandatory for public authorities and for core processing that requires systematic monitoring or large-scale special-category processing. |
Controller registration / licensing Whether controllers must register or be licensed with the authority. | Data controllers must obtain a licence from POTRAZ before processing personal information. | No licensing regime. Most controllers must pay the annual data-protection fee to the ICO under the 2018 Fee Regulations. |
Registration / licence fees Statutory fees payable to the authority. | Tiered by data-subject count: T1 (50–1 000) USD 50 · T2 (1 001–100 000) USD 300 · T3 (100 001–500 000) USD 500 · T4 (>500 000) USD 2 500. VAT 15.5% applies. | Annual fee £52 (Tier 1, micro) · £78 (Tier 2, SME) · £3 763 (Tier 3, large). No fee for the licence itself — licensing not required. |
Breach notification clock How quickly a personal-data breach must be notified. | Notify POTRAZ within 24 hours and affected data subjects within 72 hours of discovering a breach. | Notify the ICO within 72 hours of becoming aware of a personal-data breach; notify affected data subjects without undue delay where high risk. |
Data-subject rights Core rights afforded to data subjects. | Access, rectification, erasure, objection, and the right to withdraw consent. | Access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making. |
Cross-border transfers Rules governing transfers of personal data out of the jurisdiction. | Transfers require the recipient country to provide an adequate level of protection, or explicit safeguards / consent. | Adequacy decisions, UK IDTA / Addendum to EU SCCs, BCRs, or Article 49 derogations. |
Penalties Maximum administrative or criminal penalties for non-compliance. | Fines up to level 14 (currently ~USD 5 000) and/or imprisonment up to 7 years for serious offences. | Up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. |