Knowledge Centre

Data Controller Tiers in Zimbabwe

Zimbabwe's Cyber and Data Protection Act establishes a tiered registration system for data controllers, administered by POTRAZ. Understanding which tier your organisation falls into is the starting point for compliance — every tier carries different obligations.

The Foundation

First: are you a data controller?

A data controller is any person or organisation that determines the purposes for which, and the manner in which, personal data is processed. This covers the vast majority of organisations operating in Zimbabwe — from large financial institutions to a single-person professional practice.

If your organisation collects details about employees, customers, patients, students, donors, suppliers, or any other identifiable individuals — and decides what to do with that information — you are a data controller and must register with POTRAZ.

Registration is not a one-time event. It must be renewed annually, and significant changes in your processing activities must be notified to the regulator. Non-registration is itself a breach of the CDPA.

Examples of data controllers in Zimbabwe

A school collecting student and parent records
A retailer holding customer purchase history
A hospital managing patient medical records
An NGO with beneficiary and donor databases
An employer holding staff personal information
A bank processing customer financial data
A church holding congregation membership records
An insurance company with policyholder data
Registration Tiers

The four data controller tiers

POTRAZ classifies data controllers into four tiers based on the scale and nature of their processing activities. Each tier carries different registration obligations.

Tier 1Small-scale processing

Limited volume of personal data. Low-risk processing activities. Typically processes data about employees and a modest number of clients or service users.

Typical organisations

  • Sole traders and micro-businesses
  • Small community organisations
  • Individual professionals (lawyers, accountants, doctors)
  • Small charities and associations
Tier 2Medium-scale processing

Moderate volume of personal data across multiple categories. Processing may include employee data, customer records and some sensitive categories. Some automated processing.

Typical organisations

  • Medium-sized businesses and retail chains
  • Schools and educational institutions
  • NGOs with field operations
  • Private medical practices and clinics
Tier 3Large-scale processing

High volume of personal data. Regular processing of sensitive categories. Complex data flows, multiple systems, and likely cross-border data sharing.

Typical organisations

  • Large corporates and listed companies
  • Private hospitals and health groups
  • Universities and large educational institutions
  • Large NGOs and development organisations
Tier 4Critical-scale processing

Very large volumes of personal data. High-risk processing including profiling, financial data and sensitive personal information. Significant infrastructure and accountability requirements.

Typical organisations

  • Banks, insurance companies and financial institutions
  • Telecoms and internet service providers
  • Government agencies and public authorities
  • Digital platforms with large user bases

Don't guess your tier

Registering at the wrong tier — or failing to register at all — is a compliance failure. POTRAZ assigns tiers based on a review of your processing activities. Datahyve can help you understand your position, prepare the correct documentation, and manage the registration process end to end.

Get POTRAZ Registration Support

What does POTRAZ registration involve?

Registration is more than submitting a form. It involves demonstrating that your organisation has the governance structures required for your tier.

Data mapping and inventory

You must be able to describe what personal data you hold, where it comes from, what you use it for, who you share it with, and how long you retain it. This is often the first compliance gap Datahyve identifies in assessments.

Privacy policies and notices

Data subjects must be informed of their rights and how their data is used. POTRAZ expects compliant privacy notices and internal data handling policies to be in place.

Security measures

You must demonstrate that appropriate technical and organisational security measures protect the personal data you hold. What 'appropriate' means depends on your tier and the sensitivity of the data.

Annual renewal

Registration is renewed annually. Changes to your processing activities during the year must also be notified. Datahyve's managed compliance service takes this off your plate entirely.

Frequently asked questions

Need help with POTRAZ registration?

Datahyve manages the POTRAZ data controller registration process from tier assessment through to submission and renewal — so you can focus on running your organisation.