Zimbabwe's telecoms regulator POTRAZ began compliance inspections of data controllers on 1 September 2026. Under Regulatory Notice 2 of 2026, it is checking whether organisations hold the licences the Cyber and Data Protection Act requires. Reporting on the notice says a risk-based approach will start with sectors that hold large volumes of sensitive data: financial institutions, insurers, local authorities, health providers, schools, mining companies, religious bodies and government ministries. The Zimbabwean legal-information group Veritas has warned that the same powers could reach civil society membership lists.
The case for the regime
The strongest argument for enforcement is simple. A data protection law with no enforcement is a dead letter. Banks, insurers and hospitals hold intimate records, and breaches in poorly secured systems harm real people. Licensing under Statutory Instrument 155 of 2024 applied from September 2024, with a compliance deadline of 12 March 2025. Many organisations reportedly never registered (CITE). A regulator that never checks has no credibility. Breach reporting is also a sensible rule: reports say breaches must go to POTRAZ within 24 hours, and affected individuals must be told within 72 hours.
We accept all of that. The problem is design, not intent.
Where proportionality breaks down
The licensing threshold is low. Organisations that process the personal data of 50 or more individuals need a licence, which CITE notes could cover schools, churches, clinics and small retailers. Fees run from US$50 a year for the smallest databases up to US$2,500 for the largest. Each licensed body must also appoint a certified Data Protection Officer, and certification alone costs US$1,250 plus a US$30 application fee. CITE estimates that even the smallest licensed organisation could pay more than US$1,300 in its first year unless it hires an outside consultant. For a bank that is a rounding error. For a village church, a community clinic or a small advocacy group it is a serious barrier.
The penalties are also severe. CITE reports that processing personal data without a licence can bring a Level 11 fine, up to seven years' imprisonment for the CEO, or both. A criminal sanction of that weight for a paperwork failure by a small organisation is out of proportion. An administrative fine with a cure period would do the job. A Business Times report on POTRAZ's plans says administrative sanctions are still being pushed for but are not yet in place. That leaves criminal exposure as the regulator's main tool.
The independence problem
Data protection regulators are meant to be independent because they sit between the state and personal information, including the state's own. According to Veritas, POTRAZ is not independent: the President appoints its board and the Minister can issue it directives. Veritas also says the inspection and document-demand powers in sections 21(3) and 6 are broad enough to reach civil society membership lists. We could not verify the statutory text for ourselves, so we attribute these readings to Veritas. The gazetted Act is available on the Veritas site for readers who want to check.
If Veritas is right, the risk is concrete. A membership list reveals who belongs to an opposition-aligned union, a church network, or a rights organisation. Compelling that list under a data protection law turns a privacy statute into a tool for mapping associations. The risk is not that POTRAZ will do so on day one. It is that no structural safeguard prevents it, and the law's own tool for stopping it, an independent regulator, is missing.
The speech context
This matters because of how the same Act has been used before. Section 164C, added to the Criminal Law (Codification and Reform) Act by the data protection law, criminalises transmitting "false data messages intending to cause harm". The Committee to Protect Journalists reported that freelance sports journalist Hope Chizuzu was arrested and charged under it on 29 September 2022 (CPJ). In February 2026, Zimbo Live journalist Pellagia Mupurwa was charged with the same offence after interviewing Budiriro residents who accused a businessman of seizing a property (allAfrica). The Zimbabwe Union of Journalists said reputational disputes belong in civil courts and that the Act should be urgently reviewed.
None of this proves that licence inspections will be abused. But a state that has already used the Act against reporters is the wrong place to leave an unchecked power to demand records.
A comparison worth drawing
Surveillance of associations is a problem for democracies too. On 1 October 2026 a US federal judge in Manhattan refused to dismiss a suit by three unions challenging the State and Homeland Security departments' social media monitoring of visa and green card holders. The court said the threat of immigration consequences is enough to deter a person of ordinary firmness from exercising First Amendment rights (EFF). The lesson carries over: the chilling effect on association does not depend on the government ever acting on what it learns.
What proportionate enforcement would look like
- Tier the licensing. Exempt small non-commercial bodies, or replace licences with a free notification.
- Replace criminal exposure with graduated administrative penalties. Warnings and cure periods should come first, and prison should be reserved for deliberate or harmful abuse.
- Protect associational data. Membership and donor lists of civil society groups should need prior judicial authorisation before POTRAZ can demand them.
- Make the regulator independent. The board should have fixed terms and a transparent appointment process, and the Minister's directive power should be limited or removed.
Zimbabwe is right to enforce data protection. It should do so in a way that does not give a government with a record of prosecuting online speech an open-ended right to inspect who belongs to what.