The 1 September 2026 deadline that every Zimbabwean SMB has been treating as hypothetical is now 25 days away. POTRAZ has confirmed that inspections under the Cyber and Data Protection Act begin on that date, and the regulator's posture is enforcement, not education. If your organisation holds personal data on 50 or more people, you are in scope, and "we're working on it" is not a defence.
The headline rule comes from Statutory Instrument 155 of 2024. Any data controller — that is, any organisation that determines the purpose and means of processing personal data — that processes personal data of 50 or more data subjects must hold a data controller licence from POTRAZ. The exceptions are narrow: purely personal or household activity, certain journalistic work, and certain archival activities. Everything else, from your church's membership roll to your school's learner database to your hospital's patient records to the loyalty list at the corner tuckshop, needs the licence.
That licence is the cheap part of the bill. POTRAZ has set the data controller licence at roughly US$50 per year for small operators. The number that actually scares the country's small business community is what comes next.
Every licensed data controller has to appoint a Data Protection Officer and notify POTRAZ of the appointment. That DPO has to be certified. POTRAZ runs the certification course in partnership with educational institutions — Harare Institute of Technology is the most prominent delivery partner — and the price is US$1,250 for Zimbabwean applicants, plus a US$30 non-refundable application fee paid to HIT or POTRAZ. Add in the licence itself, plus incidental costs like drafting a privacy notice, building a register of processing activities, and standing up a breach-response template, and you land closer to US$1,330 in year one than the US$50 figure most operators have been quoting.
That is the math that has kept compliance numbers stubbornly low. POTRAZ's own outreach has acknowledged that most small operators have read the licence requirement, done the arithmetic, and quietly decided not to bother. For a tuckshop running a loyalty database, or a church with 200 congregants on a phone list, the cost of doing nothing was theoretical until now. From 1 September it is not.
The enforcement picture is straightforward. POTRAZ inspectors will assess whether you hold a valid data controller licence, whether you have appointed and notified a DPO, and whether your processing activities — consent collection, retention schedules, security safeguards, breach notification — meet the Cyber and Data Protection Act's requirements. Non-compliance is not a paperwork fine. The Act provides for penalties that include administrative fines and, for serious breaches, criminal liability. For an SMB operating on thin margins, the realistic worst case is being forced to stop processing until you are compliant — which is itself a business-ending event.
The fastest path to compliance for most small operators looks like this. Step one: confirm you actually process personal data of 50 or more people. Step two: appoint a DPO — that can be an existing staff member, a director, or an external consultant who already holds the POTRAZ certification. Step three: register the appointment with POTRAZ. Step four: complete the data controller licence application through POTRAZ. Step five: build the minimum viable compliance pack — a privacy notice, a data inventory, a consent collection flow, and a breach-response procedure. The first four steps are mechanical and can be completed in weeks. The fifth is the work that compounds.
The uncomfortable truth is that the 1 September deadline will function less as a regulatory event and more as a market event. Operators who scramble through compliance in the next month will pay the US$1,330 and move on. Operators who don't will quietly shrink their data collection, delete their marketing lists, or — for the larger operators whose customer relationships depend on it — discover that the cost of compliance was always lower than the cost of going dark. The Cyber and Data Protection Act has been on the books since 2021. The 2024 statutory instrument gave the licensing regime teeth. The September inspection window is the moment those teeth become visible.
For anyone reading this with a customer database on a laptop and a privacy policy that still says "we respect your privacy" in italics, the next 25 days are not a courtesy warning. They are the window.
Photo by Claudio Schwarz on Unsplash