Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (SI 155 of 2024) (Zimbabwe)
zw-licensing-regs-2024 · Regulation
Statutory Instrument 155 of 2024, the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024, is the principal subsidiary legislation under Zimbabwe's Cyber and Data Protection Act [Chapter 12:07]. Promulgated on 13 September 2024, it operationalises the Act's registration and accountability requirements and is administered by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) as the Data Protection Authority. The Regulations create a structured licensing regime for entities that process personal data for commercial gain or other benefit. Data controllers are tiered by the number of data subjects involved, Tier 1 (50 - 1,000), Tier 2 (1,001 - 100,000), Tier 3 (100,001 - 500,000), and Tier 4 (over 500,000), with each tier subject to corresponding licensing requirements. Controllers must obtain a data controller licence from POTRAZ. The Regulations also require the appointment of a Data Protection Officer, with notification to POTRAZ within 90 days of the Regulations' commencement (or of the termination of a previous DPO), and prescribe DPO qualifications, experience, and an approved certification course. They reiterate the Act's breach-reporting duties (notification to the Authority within 24 hours, and to affected data subjects within 72 hours where the breach poses a high risk). A six-month compliance window ran from promulgation, giving a deadline of 13 March 2025. Non-compliance attracts fines up to level 11 or imprisonment of up to seven years. This entry was created during a June 2026 documentation pass and is AI-drafted; the primary text is available via ZimLII and POTRAZ. Reviewer should confirm the fee schedule and any subsequent amendments. Source language: English.
- Principal subsidiary legislation under the Cyber and Data Protection Act [Chapter 12:07]; promulgated 13 September 2024 (SI 155 of 2024).
- Establishes a tiered data-controller licensing regime (Tier 1: 50 - 1,000 to Tier 4: over 500,000 data subjects).
- Requires data controllers to obtain a licence from POTRAZ.
- Requires appointment of a Data Protection Officer, with notification to POTRAZ within 90 days and prescribed qualifications and certification.
- Reiterates breach reporting to the Authority within 24 hours and to data subjects within 72 hours for high-risk breaches.
- Six-month compliance window from promulgation (deadline 13 March 2025).
- Non-compliance: fines up to level 11 or up to seven years' imprisonment.
- Reviewer action: confirm fee schedule and any subsequent amendments.