Regulation & Compliance · Soho Connect Research Desk · 12 min read

POTRAZ Data Protection Inspections Start 1 September 2026: What Zimbabwean Organisations Must Do

POTRAZ will begin risk-based data-controller inspections on 1 September 2026. This guide explains who is first, what the law requires and how to assemble an evidence file without confusing technical readiness with legal advice.

Compliance file, shield and calendar marking POTRAZ data protection inspections from 1 September 2026

POTRAZ has announced that mandatory compliance inspections and assessments of data controllers will begin on 1 September 2026. The programme will use a risk-based approach and will start with ten named sector groups. The practical implication is simple: organisations should be able to show that their privacy, licensing, governance, security and incident-response controls work in practice—not merely that a policy exists.

This guide separates what the current sources establish from what remains uncertain. It is general operational information, not legal advice or an official POTRAZ inspection questionnaire.

What exactly was announced?

Regulatory Notice 2 of 2026 says the Postal and Telecommunications Regulatory Authority of Zimbabwe, acting as the Data Protection Authority, will conduct mandatory compliance inspections and assessments from 1 September 2026 under the Cyber and Data Protection Act [Chapter 12:07].

The notice links the inspection programme to the licensing regime created by the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024—SI 155 of 2024. That instrument took effect in September 2024 and set a 12 March 2025 licensing deadline for affected public and private organisations.

The first sectors named are:

  • financial institutions;
  • insurance companies;
  • local authorities;
  • healthcare providers;
  • mining enterprises;
  • religious organisations;
  • schools, tertiary institutions and professional bodies;
  • Government ministries, departments and agencies;
  • non-governmental organisations; and
  • private voluntary organisations.

The phrase “starting with” matters. It describes the initial risk focus; it is not evidence that every controller outside those sectors is permanently excluded.

Who is a data controller?

In plain language, a data controller is the person or organisation that decides why and how personal data is processed. Processing is broad: it includes collecting, recording, storing, organising, using, sharing, changing, erasing or destroying information.

Personal data is wider than a customer spreadsheet. Depending on the organisation, it can include names, telephone numbers, identity numbers, addresses, employee files, financial records, health information, CCTV images, photographs, fingerprints and other biometric or sensitive information.

A useful first test is therefore not “Are we a technology company?” It is: Do we determine the purpose and method for handling information about identifiable people?

Data Controller Licence tiers and fees

SI 155 of 2024 sets four fee tiers:

TierNumber of data subjectsInitial or renewal fee
Tier 150–1,000US$50
Tier 21,001–100,000US$300 plus US$30 application fee
Tier 3100,001–500,000US$500 plus US$30 application fee
Tier 4More than 500,000US$2,500 plus US$30 application fee

A licence is valid for 12 months, and an application for renewal is required three months before expiry.

There is an important edge case. The instrument’s licensing trigger and its fee tiers are drafted in separate provisions, while the first fee tier begins at 50 data subjects. An organisation near or below that level should obtain written POTRAZ or qualified legal guidance rather than convert a simplified media summary into a definitive exemption from the wider Act.

What can an inspection assess?

Section 21 of the Act provides for inspection where processing presents specific risks and for further inspection during working hours with reasonable notification. POTRAZ also has investigation and enforcement functions and may require relevant information or documents.

That makes retrievability important. Evidence should be current, internally consistent and understandable to the people responsible for operating the control. A copied privacy policy is weak evidence when the website, HR files, CCTV system, suppliers or staff behaviour contradict it.

The legal framework points to the following evidence families:

  1. Licence evidence: application, licence, payment proof, data-subject tier calculation, expiry date and renewal owner.
  2. DPO evidence: appointment, regulator notification, approved certification, reporting line, independence and contact route.
  3. Data inventory: systems and paper records, categories of people and data, purposes, legal bases, locations, owners, recipients and transfers.
  4. Privacy and consent: current notices, form wording, consent records where consent is used, and version history.
  5. Data-subject rights: intake, identity checks, access, correction, objection and deletion workflows, response records and escalation.
  6. Processor governance: supplier register, written processing terms, access boundaries, breach duties, return or deletion clauses and review dates.
  7. Security evidence: risk assessment, access controls, network architecture, backups, encryption, patching, logging, physical safeguards and change records.
  8. Incident readiness: response plan, breach register, notification templates, decision authority, contact tree and evidence-preservation process.
  9. Retention and disposal: retention schedule, deletion approvals, paper destruction, backup treatment and legal-hold exceptions.
  10. High-risk processing: documentation for biometrics, genetic data, children’s data, health data, large-scale monitoring and cross-border transfers.

This is a Soho Connect operational readiness model derived from the published duties. It is not presented as an official POTRAZ questionnaire or scoring system.

Deadlines operational teams must know

The regulations require notification to POTRAZ of a qualifying personal-data breach within 24 hours after awareness. Where the breach is likely to create high risk for affected people, they must be informed within 72 hours. A final report is required within 21 days.

Those clocks are too short to design a process after the incident. The organisation needs, in advance:

  • a clear threshold for escalating a suspected event;
  • a named decision-maker and backup;
  • a current regulator and DPO contact route;
  • a method for preserving logs and other evidence;
  • supplier notification duties that operate quickly enough; and
  • approved factual templates that can be completed without inventing certainty.

The regulations also require appointment and notification of a DPO and provide a 90-day appointment period after licensing, together with approved training and certification requirements. The statutory fee schedule lists local DPO training and certification at US$1,250 plus a US$30 application fee, and international certification at US$1,450 plus a US$50 application fee. These are regulatory fees, not Soho Connect prices.

A practical five-week readiness sequence

First 48 hours: establish ownership

Name an executive sponsor, the DPO or interim privacy lead, the IT/security owner and the records/process owner. Confirm the licence number, tier, expiry, renewal date, DPO status and actual data-subject count. Stop using unsupported “fully compliant” claims.

Week 1: map the real data estate

Inventory databases, cloud services, email accounts, paper files, CCTV, access-control systems, websites, forms, messaging channels and portable devices. Record sensitive data, children’s data, biometrics, cross-border transfers, privileged suppliers and systems exposed to the internet.

Week 2: close high-consequence gaps

Prioritise exposed administration panels, default or shared accounts, weak access control, missing backups, flat guest/staff/CCTV networks, uncontrolled exports, obsolete retention and suppliers without written processing terms.

Week 3: rehearse evidence-producing workflows

Run a sample access request, a correction request, a deletion decision, a lost-laptop scenario and a supplier breach. Measure escalation time, document decisions and record where the process fails.

Week 4 onward: assemble one indexed evidence file

Link each policy to an owner, procedure, system configuration and sample record. Assign remediation dates and preserve proof—signed records, screenshots, configuration exports, logs, tickets, training attendance and completed workflow samples. Keep the file current after 1 September instead of treating inspection preparation as a one-off event.

What Soho Connect can and cannot do

Soho Connect can support the technical-security portion of an evidence file through an authorised review of business WiFi, routers, guest networks, CCTV networks and exposed management services. A scoped assessment can document weaknesses, remediation actions and before-and-after technical evidence.

It does not issue a Data Controller Licence, certify a DPO, give a legal opinion or guarantee that POTRAZ will find an organisation compliant. Those decisions remain with POTRAZ and appropriately qualified professionals.

Be cautious of any supplier promising “instant compliance” from one template, firewall, training certificate or audit. Compliance is a continuing operating state across law, governance, people, contracts, systems and evidence.

What remains uncertain

The notice establishes the start date and initial sectors, but the sources reviewed do not publish a detailed inspection questionnaire, scoring model, site-visit cadence or sector order. Those details may emerge through official guidance or inspection practice.

This guide should be updated if POTRAZ publishes the notice online, issues an official questionnaire or sector checklist, amends the fee schedule, changes SI 155, formally clarifies the under-50 position, or publishes reliable findings from the first inspections.

Primary sources

POTRAZ Data Inspection Questions

When do POTRAZ data protection inspections start?

Regulatory Notice 2 of 2026 says mandatory compliance inspections and assessments of data controllers will begin on 1 September 2026.

Which sectors will POTRAZ inspect first?

The initial risk-based list covers financial institutions, insurers, local authorities, healthcare providers, mining enterprises, religious organisations, schools and tertiary institutions, professional bodies, Government bodies, NGOs and PVOs. The notice says “starting with”, so the list should not be treated as permanently exclusive.

Does every Zimbabwean organisation need a Data Controller Licence?

SI 155 of 2024 defines licensable controllers and sets the first fee tier at 50 data subjects. Because the licensing trigger and tier thresholds are drafted separately, organisations near or below 50 records should obtain direct POTRAZ or legal guidance instead of assuming all duties disappear.

How long is a Data Controller Licence valid?

The regulations state that a licence is valid for 12 months and that renewal should be applied for three months before expiry.

What evidence should be ready for an inspection?

Prepare licence and DPO records, a data inventory, lawful-processing evidence, current privacy notices, rights procedures, written processor contracts, security evidence, incident records, retention rules and documentation for high-risk processing.

How quickly must a personal-data breach be reported?

The regulations require notification to POTRAZ within 24 hours of awareness. Where high risk to affected people is likely, they must be informed within 72 hours, and a final report is required within 21 days.

Can Soho Connect certify legal compliance?

No. Soho Connect can assess and document defined technical network-security controls. Licensing, DPO certification, legal interpretation and the final compliance determination remain with POTRAZ and qualified professionals.