Data Protection Compliance Deadline Looms for Zimbabwean Entities

Posted by

–

Create an editorial news illustration for an article about 'Data Protection Compliance Deadline Looms for Zimbabwean Entities'. The specific country is Zimbabwe (ZW); make visual cues accurate to this exact country and avoid flags or symbols of simil

As the September 1, 2026 date approaches, businesses, government agencies, universities and financial institutions across Zimbabwe are being urged to review their compliance with the Cyber and Data Protection Act and its licensing regulations. The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) has announced that from that date, mandatory data protection inspections and assessments will begin for entities that collect personal information and are not exempt.

Legal practitioner Vengai Madzima, Senior Partner at Madzima Chidyausiku Museta Legal Practitioners, explains that the right to privacy and data protection remains a constitutional right. Any entity that handles personal information relating to customers, suppliers, employees or members of the public must ensure its compliance position is in order. This includes details such as identity information, financial records, health status and employment data.

Entities that qualify as data controllers are required to obtain an annual data controller licence. The licence category depends on the volume of data handled. In addition, data controllers must implement systems that protect personal data at all times. If a breach occurs, the controller must report it to the Data Protection Authority within 24 hours. Where the breach poses a real risk to personal information, affected individuals must be notified within 72 hours.

Certain data processing activities are exempt under the regulations. These include family matters, specified law enforcement purposes, and historical or journalistic activities. The list is not exhaustive, but entities should confirm whether their operations fall within an exemption.

Another key requirement is the appointment of a certified data protection officer. This officer monitors compliance with the law, conducts compliance audits, trains employees on data protection, and acts as a link between the entity and POTRAZ.

Madzima stresses that data protection is an ongoing obligation. Entities should collect personal information only for legitimate purposes, secure it, and keep it only for as long as necessary. With inspections starting September 1, 2026, organisations are advised to act now to avoid penalties and ensure they meet all statutory requirements.