Zimbabwe
Authority: POTRAZ (Postal & Telecommunications Regulatory Authority of Zimbabwe)
Last reviewed: 19 Jul 2026
- Data-protection authorityThe regulator responsible for enforcement.
POTRAZ acts as the Data Protection Authority alongside its telecoms mandate.
Source: Cyber and Data Protection Act [Chapter 12:07], s. 5· Reviewed 19 Jul 2026
- DPO appointmentWhen a Data Protection Officer must be appointed.
Every data controller must appoint a Data Protection Officer within 90 days of registration.
Source: CDPA s. 19; SI 155 of 2024, reg. 8· Reviewed 19 Jul 2026
- Controller registration / licensingWhether controllers must register or be licensed with the authority.
Data controllers must obtain a licence from POTRAZ before processing personal information.
Source: CDPA s. 6; SI 155 of 2024, regs. 3–6· Reviewed 19 Jul 2026
- Registration / licence feesStatutory fees payable to the authority.
Tiered by data-subject count: T1 (50–1 000) USD 50 · T2 (1 001–100 000) USD 300 · T3 (100 001–500 000) USD 500 · T4 (>500 000) USD 2 500. VAT 15.5% applies.
Source: SI 155 of 2024, Schedule of Fees· Reviewed 19 Jul 2026
- Breach notification clockHow quickly a personal-data breach must be notified.
Notify POTRAZ within 24 hours and affected data subjects within 72 hours of discovering a breach.
Source: CDPA s. 21; SI 155 of 2024, reg. 12· Reviewed 19 Jul 2026
- Data-subject rightsCore rights afforded to data subjects.
Access, rectification, erasure, objection, and the right to withdraw consent.
Source: CDPA ss. 14–17· Reviewed 19 Jul 2026
- Cross-border transfersRules governing transfers of personal data out of the jurisdiction.
Transfers require the recipient country to provide an adequate level of protection, or explicit safeguards / consent.
Source: CDPA s. 28· Reviewed 19 Jul 2026
- PenaltiesMaximum administrative or criminal penalties for non-compliance.
Fines up to level 14 (currently ~USD 5 000) and/or imprisonment up to 7 years for serious offences.
Source: CDPA ss. 30–35· Reviewed 19 Jul 2026