The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) will start mandatory compliance inspections and assessments of data controllers from 1 September 2026, acting under Section 6(1)(a), read with Section 21(3) and (4), of the Cyber and Data Protection Act [Chapter 12:07].
The move follows Regulatory Notice 2 of 2026, issued under the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (Statutory Instrument 155 of 2024), which took effect in September 2024. Those regulations made it mandatory for public and private organisations processing personal data to obtain a Data Controller Licence, originally by 12 March 2025.
REGULATORY NOTICE 2 OF 2026 – MANDATORY COMPLIANCE INSEPCTIONS AND ASSESSMENTS OF DATA CONTROLLERS 15.7.26_0001
POTRAZ, designated Zimbabwe’s Data Protection Authority under Section 5 of the Act, says it will apply a risk-based approach to the inspections, starting with nine priority sectors: financial institutions, insurance companies, local authorities, healthcare providers, mining enterprises, religious organisations, schools and tertiary institutions, professional bodies, government ministries, departments and agencies (MDAs), and non-governmental and private voluntary organisations.
Organisations that have not yet secured a Data Controller Licence are being urged to apply before inspections begin. POTRAZ has set up dedicated channels for licensing enquiries, reachable via beans@potraz.zw, ushe@dpa.zw, and marere@dpa.zw, or by phone on 0242-333032, extension 1129.
In the notice, Director General Dr G.K. Machengete framed licensing as more than a statutory box tick, positioning it as evidence of an organisation’s commitment to safeguarding the personal data entrusted to it by stakeholders.
For Zimbabwean businesses, the announcement raises the stakes on data governance. Since the licensing regulations took effect nearly two years ago, enforcement has largely rested on voluntary compliance. The September 2026 inspection rollout signals a shift toward active verification, with the named sectors many handling large volumes of sensitive personal and financial data will likely to face the earliest scrutiny.
Organisations across banking, insurance, healthcare, mining, education, government, and the NGO sector should treat the coming months as a compliance window: reviewing data processing practices, appointing Data Protection Officers where required, and formalising licence applications ahead of the September deadline.