Data Protection Compliance Deadline: Zimbabwe Firms Face POTRAZ Inspections from September 1

Create an editorial news illustration for an article about 'Data Protection Compliance Deadline: Zimbabwe Firms Face POTRAZ Inspections from September 1'. The specific country is Zimbabwe (ZW); make visual cues accurate to this exact country and avoi

Zimbabwean businesses, government agencies, universities and financial institutions that collect personal data have only hours left before the 1 September 2026 deadline for mandatory data protection inspections and assessments by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).

Legal expert Vengai Madzima of Madzima Chidyausiku Museta Legal Practitioners says all entities handling personal information—whether relating to customers, suppliers, employees or the public—must ensure full compliance with the Cyber and Data Protection Act and its licensing regulations. He reminded organisations that privacy and data protection are constitutionally protected rights. Viewing compliance through that lens can make the requirements easier to accept.

Any entity that qualifies as a data controller and does not fall under the exempt categories must obtain an annual data controller licence. The licence tiers vary depending on the volume of data handled. In addition, data controllers are required to implement systems that protect personal data at all times. If a breach occurs, they must report it to the Data Protection Authority within 24 hours. Where the breach poses a real risk, affected individuals must be notified within 72 hours.

Madzima also highlighted the requirement to appoint a certified data protection officer (DPO), whose duties include conducting compliance audits, training employees on data protection, and acting as a liaison between the entity and POTRAZ. Exempted processing activities include certain family matters, specified law enforcement operations, and historical or journalistic activities, though the list is not exhaustive.

Data protection is an ongoing obligation, Madzima stressed. Entities are expected to collect personal information only for legitimate purposes, secure it, and keep it only for as long as necessary. With inspections set to begin imminently, Zimbabwean data controllers have little time left to review their governance frameworks and close any gaps.