EXPLAINER: From Creches to clinics, what Potraz’s data inspections mean for everyone

Emmanuel Kafe

CheckPoint Desk

IMAGINE waking up to find your medical records leaked online or discovering your phone number and national ID have been sold to marketers without your knowledge.

Or perhaps you are a WhatsApp group administrator with hundreds of members and suddenly find yourself wondering, “Does Postal and Telecommunications Regulatory Authority of Zimbabawe (Potraz) want to inspect me too?”

Not quite. But if you are a school, church, clinic, business or any organisation collecting people’s personal information, the answer is different.

Starting September 1, Potraz will begin mandatory inspections and assessments of organisations that process personal data under the Cyber and Data Protection Act.

The announcement came through Regulatory Notice 2 of 2026, published last week.

The move reflects a reality that has quietly reshaped the digital world: data has become the new currency.

Every time you open a bank account, register at a clinic, enrol a child at school, apply for a job, sign up for mobile money or simply fill in a customer loyalty form at a supermarket, you leave behind pieces of personal information.

To organisations, that data is valuable. To criminals, it can be even more valuable. And to you, it is part of your identity.

Simply put, this is about how safely your personal information is handled.

What is personal data?

Personal data is any information that can identify you.

That includes your name, mobile number, national identity number, home address, employment records, bank details, medical history and even biometric information such as fingerprints or facial recognition data.

Every day Zimbabweans hand over this information to banks, schools, hospitals, churches, employers, insurance companies, online businesses and Government departments.

The law says organisations that collect and store such information have a responsibility to protect it.

And why is Potraz inspecting organisations?

“Can a digitised economy thrive without trust? The answer is no. Trust is a vital economic asset and central to that trust is privacy,” ICT, Postal and Courier Services Minister Tatenda Mavetera said at the Third National Data Privacy Symposium in Bulawayo earlier this year.

The country’s Cyber and Data Protection Act appointed Potraz as the country’s Data Protection Authority.

To operationalise the law, Government introduced the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024, through Statutory Instrument 155 of 2024.

Those regulations required organisations processing personal data to obtain a Data Controller Licence by March 12, 2025.

That deadline has long passed.

Potraz’s latest notice signals that it is now moving from education and awareness to enforcement.

From September 1, inspectors will begin checking whether organisations are complying with the law.

The authority says inspections will be conducted using a risk-based approach, meaning sectors handling large volumes of sensitive personal information will be inspected first.

These include: financial institutions, insurance companies, local authorities and healthcare providers.

Mining companies, religious organisations, schools, tertiary institutions and professional bodies are also some of the organisations that will be inspected.

Government ministries, departments and agencies, non-governmental organisations and private voluntary organisations are also in line.

For many Zimbabweans, this means institutions they interact with almost every day could soon face compliance inspections.

Who needs a licence?

The law generally requires organisations that process personal information belonging to 50 or more people to obtain a data controller licence.

That could include: a private school with pupil records, a church keeping membership registers, a clinic storing patient files, a supermarket operating a customer loyalty programme or a a company maintaining employee records.

There are some exemptions, including purely personal or household use, certain law enforcement activities and some journalistic, historical and archival work, although specific registration requirements may still apply in some of these cases.

What changes for ordinary Zimbabweans?

Data analyst and former computer science lecturer Mr Edmore Zimogwi said for the average citizen, the inspections should mean organisations become more careful with personal information.

“Instead of collecting information simply because it might be useful one day, institutions are expected to collect only what they genuinely need.

“They must also store it securely, restrict who has access to it and dispose of it properly when it is no longer required,” he said.

He also said, if implemented effectively, fewer Zimbabweans should have to worry about identity documents being copied unnecessarily, customer databases being shared without consent or sensitive records being exposed through poor security.

“The inspections are also intended to encourage organisations to have proper systems for responding when something goes wrong.

“If there is a data breach, organisations are required to notify Potraz within 24 hours and inform affected individuals within 72 hours, allowing people to take steps such as changing passwords, monitoring bank accounts or protecting themselves against identity theft”

Compliance comes at a cost

Obtaining a Data Controller Licence is not free.

The annual licence fee depends on the number of people’s records an organisation processes.

Tier One, covering organisations handling information for between 50 and 1 000 people, costs US$50 annually.

Tier Two, covering up to 100 000 data subjects, costs US$300, while Tier Three costs US$500 and Tier Four, for organisations processing data on more than 500 000 people, costs US$2 500.

Tiers Two to Four also attract a US$30 application fee.

The licence remains valid for 12 months and must be renewed before expiry.

However, licensing is only part of the compliance requirements.

Every data controller must also appoint a Data Protection Officer (DPO) and notify Potraz of the appointment.

The DPO is responsible for ensuring the organisation complies with data protection laws, handles complaints and oversees privacy policies.

Potraz requires DPOs to complete an approved certification programme offered through accredited institutions.

For many small businesses, this has become the biggest hurdle, with certification costing significantly more than the licence itself.

To reduce costs, some organisations are opting to hire external consultants who serve as Data Protection Officers for multiple clients rather than employing full-time specialists.

What happens if an organisation ignores the law?

The penalties are severe.

Processing personal information without a valid Data Controller Licence can attract a Level 11 fine, imprisonment of up to seven years, or both.

Similar penalties apply to organisations that fail to adequately protect personal data.

These provisions underline how seriously Government views the protection of citizens’ personal information in an increasingly digital economy.

More than a regulatory exercise

In its notice, Potraz says licensing is “not just a statutory obligation” but a demonstration of an organisation’s commitment to safeguarding personal information entrusted to it.

The authority also notes that “data is the new currency”, making it everyone’s responsibility to process personal information fairly and lawfully.

For ordinary Zimbabweans, the inspections are not about paperwork or licences.

They are about ensuring that when you hand over your identity number to a school, your medical records to a hospital or your banking details to a financial institution, those organisations treat your personal information with the same care they expect others to show towards their own.

From September 1, that promise will no longer rely on trust alone.

It will increasingly be backed by inspections, legal obligations and the possibility of stiff penalties for organisations that fail to protect the personal information Zimbabweans entrust to them.

 

 

Related Posts

WFP shifts to long-term resilience as Super El Niño threat emerges

Theseus Mauruki Shambare THE United Nations World Food Programme (WFP) has begun activating anticipatory measures to cushion Zimbabwean farmers against the potential effects of a forecast Super El Niño, marking…

Association of Healthcare Funders seek Parliament’s intervention over Medical Services Amendment Act

Nyore Madzianike Senior Reporter The Association of Healthcare Funders of Zimbabwe has appealed to Parliament to intervene and consider its concerns on amendments made to the Medical Services Amendment Act.…

Leave a Reply

Your email address will not be published. Required fields are marked *

×