Zimbabwe Data Protection Deadline Looms: What Businesses Must Do Before 1 September 2026

With POTRAZ set to begin mandatory data protection inspections from 1 September 2026, all entities handling personal information in Zimbabwe must ensure they are licensed, have a data protection officer, and have proper breach response measures in place.

Create an editorial news illustration for an article about 'Zimbabwe Data Protection Deadline Looms: What Businesses Must Do Before 1 September 2026'. The specific country is Zimbabwe (ZW); make visual cues accurate to this exact country and avoid fl

With the start of mandatory data protection inspections only days away, Zimbabwean businesses, government agencies and other organisations that handle personal information are being urged to finalise their compliance measures under the Cyber and Data Protection Act [Chapter 12:07].

The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) has announced that from 1 September 2026 it will begin mandatory inspections and assessments of entities that collect personal data and are not covered by exemptions.

Speaking through a recent legal discussion, Vengai Madzima, Senior Partner at Madzima Chidyausiku Museta Legal Practitioners, reminded entities that the right to privacy and data protection is a constitutional right. He said all bodies that process personal information relating to customers, suppliers, employees or the public must comply with the law and its licensing regulations.

Once an entity determines that it is a data controller and does not fall under the exempted data processing activities, it must obtain a data controller licence. These licences vary depending on the volume of data handled and must be renewed annually.

In addition to licensing, data controllers are expected to implement systems that protect personal data at all times. If a breach of privacy occurs, the data controller must report the breach to the Data Protection Authority within 24 hours. If the breach poses a real risk to the personal information held, the affected individuals must be notified within 72 hours.

The regulations provide certain exemptions for processing personal data, including for family matters, specified law enforcement, historical and journalistic activities. This list is not exhaustive.

Entities must also appoint a certified data protection officer who is knowledgeable about Zimbabwe’s data protection laws. The officer’s duties include monitoring compliance, conducting audits, training employees, and serving as a liaison between the entity and POTRAZ.

Madzima stressed that data protection is an ongoing obligation. Entities should collect personal information only for legitimate purposes, secure it, and keep it only for as long as necessary.