Zimbabwe's Cyber and Data Protection Act establishes a tiered registration system for data controllers, administered by POTRAZ. Understanding which tier your organisation falls into is the starting point for compliance — every tier carries different obligations.
A data controller is any person or organisation that determines the purposes for which, and the manner in which, personal data is processed. This covers the vast majority of organisations operating in Zimbabwe — from large financial institutions to a single-person professional practice.
If your organisation collects details about employees, customers, patients, students, donors, suppliers, or any other identifiable individuals — and decides what to do with that information — you are a data controller and must register with POTRAZ.
Registration is not a one-time event. It must be renewed annually, and significant changes in your processing activities must be notified to the regulator. Non-registration is itself a breach of the CDPA.
POTRAZ classifies data controllers into four tiers based on the scale and nature of their processing activities. Each tier carries different registration obligations.
Limited volume of personal data. Low-risk processing activities. Typically processes data about employees and a modest number of clients or service users.
Moderate volume of personal data across multiple categories. Processing may include employee data, customer records and some sensitive categories. Some automated processing.
High volume of personal data. Regular processing of sensitive categories. Complex data flows, multiple systems, and likely cross-border data sharing.
Very large volumes of personal data. High-risk processing including profiling, financial data and sensitive personal information. Significant infrastructure and accountability requirements.
Registering at the wrong tier — or failing to register at all — is a compliance failure. POTRAZ assigns tiers based on a review of your processing activities. Datahyve can help you understand your position, prepare the correct documentation, and manage the registration process end to end.
Get POTRAZ Registration SupportRegistration is more than submitting a form. It involves demonstrating that your organisation has the governance structures required for your tier.
You must be able to describe what personal data you hold, where it comes from, what you use it for, who you share it with, and how long you retain it. This is often the first compliance gap Datahyve identifies in assessments.
Data subjects must be informed of their rights and how their data is used. POTRAZ expects compliant privacy notices and internal data handling policies to be in place.
You must demonstrate that appropriate technical and organisational security measures protect the personal data you hold. What 'appropriate' means depends on your tier and the sensitivity of the data.
Registration is renewed annually. Changes to your processing activities during the year must also be notified. Datahyve's managed compliance service takes this off your plate entirely.
Datahyve manages the POTRAZ data controller registration process from tier assessment through to submission and renewal — so you can focus on running your organisation.