The government’s decision to require organisations that process personal data to obtain annual licences from the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) has come under sharp criticism, with analysts warning the costs could place a heavy financial burden on businesses, churches, schools and civic organisations, while ultimately pushing up prices for consumers.
The criticism follows the publication of Regulatory Notice 2 of 2026, in which POTRAZ announced that from 1 September 2026 it will begin mandatory compliance inspections and assessments of data controllers under the Cyber and Data Protection Act.
Under Statutory Instrument 155 of 2024, organisations processing personal data belonging to 50 or more individuals are required to obtain a data controller licence from POTRAZ.
The law covers organisations collecting or processing information such as names, addresses, phone numbers, national identity numbers, employment records, health information and biometric data.
On this topic
Although the licensing requirement took effect in September 2024, with a compliance deadline of 12 March 2025, many organisations are believed to have yet to register.
The licensing framework forms part of the Cyber and Data Protection Act, under which POTRAZ serves as Zimbabwe’s Data Protection Authority.
The government says the measures are intended to strengthen the protection of personal information and improve accountability in the handling of sensitive data amid growing concerns over cybercrime, identity theft and data breaches.
The inspections raise questions about the readiness of thousands of organisations that may not realise they fall within the scope of the law.
Schools with class registers, churches with membership records, medical practices holding patient files and retailers with customer databases could all require licences if they process personal information relating to at least 50 people.
Although the law provides exemptions for personal or household use, law enforcement activities and certain journalistic, historical or archival activities, organisations engaged in some of those areas may still be subject to registration requirements under the regulatory framework.
Organisations handling data for between 50 and 1 000 people pay US$50 annually, while those processing between 1 001 and 100 000 records pay US$300 plus a US$30 application fee. Organisations with larger databases pay between US$500 and US$2 500 depending on their size.
However, the licence fee represents only part of the compliance cost.
Every registered organisation is required to appoint a certified Data Protection Officer and notify POTRAZ.
Certification currently costs US$1 250, excluding a US$30 application fee, meaning even a small organisation paying the lowest licence fee could face compliance costs exceeding US$1 300 in its first year unless it hires an external consultant.
Failure to comply carries severe penalties, as organisations processing personal data without a licence risk a Level 11 fine, imprisonment of up to seven years for their chief executive officer, or both.
Similar penalties apply for failing to adequately protect personal data, while data breaches must be reported to POTRAZ within 24 hours and affected individuals notified within 72 hours.
Reacting to the development, Legal expert, Dr Vusumuzi Sibanda, said while regulating the use of personal information was an internationally accepted practice, Zimbabwe’s licensing model and associated fees raised serious concerns.
“The control of personal information is something that happens across the world to make sure that personal information is not abused or used beyond the interests of the owners of that information,” he said.
“But what is new and strange is the need for registration and licence fees so that organisations must register. You can make sure people comply when they keep information without forcing companies to register and pay licence fees.”
Dr Sibanda argued the government could enforce compliance with data protection standards without creating an expensive licensing regime, saying the regulations extend beyond large corporations to churches and voluntary organisations that collect only basic membership information.
“Imagine having licences for churches and voluntary organisations simply because they handle personal information,” he said.
“In church, how do people really handle personal information? They don’t require identity documents in most cases because membership is voluntary. Why would you require those organisations to make such payments?”
He warned such requirements could eventually extend to community-based organisations such as burial societies, savings clubs and other informal associations that maintain membership records.
Dr Sibana also described the fees as an unnecessary financial burden rather than a genuine data protection measure.
“It is something one can see as a desperate means of raising money from people. Unfortunately, it is very sad from where I’m looking at it. I think the government has run out of ideas.”
Another analyst, Mxolisi Ncube, echoed those concerns, warning stakeholders were likely to recover the cost of compliance from consumers.
“Complying with these rules costs stakeholders a lot of money, meaning people must expect more expensive airtime, data and other charges,” he said.
While the government argues the regulations are designed to strengthen privacy protections and improve accountability in the handling of personal information, analysts believe the cost of compliance risks undermining those objectives by placing an excessive burden on organisations, particularly small businesses, churches, schools and community groups.
With inspections due to begin in September, thousands of organisations now face the prospect of either absorbing significant compliance costs or risking substantial fines and possible criminal penalties.


Leave a Reply