Register as a data controller
Assess whether your organisation must apply to POTRAZ for a data controller licence using Form DP1 and maintain its registration.
Consulting service · Zimbabwe CDPA [Chapter 12:07]
RN Hope provides practical Data Protection Compliance consulting to help organisations assess, implement and maintain compliance with Zimbabwe's Cyber and Data Protection Act [Chapter 12:07] and its supporting regulations.
The Cyber and Data Protection Act [Chapter 12:07] governs the processing of personal information in Zimbabwe, establishes a Cyber Security Centre and designates POTRAZ as the Data Protection Authority.
The framework applies broadly to data controllers and processors handling personal information connected to Zimbabwe, including private businesses and public bodies.
Assess whether your organisation must apply to POTRAZ for a data controller licence using Form DP1 and maintain its registration.
Designate a DPO to oversee compliance, data-subject requests and liaison with the Authority, with notification using Form DP2.
Collect personal data for specified, explicit and legitimate purposes, keep it accurate and limit use to those purposes.
Apply stricter controls to health, genetic, biometric, political, religious and other sensitive personal data.
Use appropriate technical and organisational measures to prevent loss, unauthorised access, alteration or destruction.
Maintain a response process for notifying the Authority and affected people where required, including Form DP3 workflows.
Tell people who processes their data, why it is used, how long it is kept and how they may exercise their rights.
Confirm an adequate level of protection or another lawful basis before transferring personal information outside Zimbabwe.
Keep the policies, records, assessments and evidence needed to show that compliance is active and maintained.
Controllers and processors should apply risk-appropriate safeguards covering access control, encryption, monitoring, staff training and supplier oversight.
A response plan should identify affected data, contain the incident, preserve evidence and support notifications to POTRAZ and affected people where required.
Our consultants combine governance guidance with practical engineering so compliance is reflected in policies, systems and everyday operations.
Review data flows, policies and systems against the CDPA, SI 155 of 2024 and current implementation guidance.
Prepare for data controller licence applications, DPO appointment notifications and renewal tracking.
Structure and document DPIAs for higher-risk processing activities and technology changes.
Design access control, encryption, logging, backup and network safeguards aligned with Section 18.
Create incident runbooks, escalation paths and notification workflows for personal-data breaches.
Prepare privacy notices, internal policies, retention schedules and processor documentation for legal review.
Build practical awareness for leadership, DPOs and staff who handle personal information.
Monitor controls, track actions and review the programme as operations and regulatory guidance evolve.
RN Hope provides technical and organisational compliance consulting and works alongside your legal counsel where formal legal interpretation is required.
Information current as of October 2026. Verify against the official gazette, POTRAZ publications and your legal advisor, as the Act, statutory instruments and Authority guidance may be amended or updated.