Zimbabwe's telecoms regulator has set a date for its first real enforcement sweep under the country's data protection law — and the list of targets reads less like a corporate compliance audit than a census of civil society. POTRAZ's Regulatory Notice 2 of 2026 announces mandatory compliance inspections beginning September 1, 2026, under the Cyber and Data Protection Act, with a stated risk-based approach that starts with banks, insurers and hospitals but explicitly sweeps in local authorities, schools, universities, churches, government ministries, mining firms, professional bodies and NGOs (Techzim).
The steelman
Before the Cyber and Data Protection Act [Chapter 12:07] (No. 5 of 2021), Zimbabwe had essentially no statutory limit on how banks, telecoms operators or the state itself could collect, store or resell personal data (Data Protection Act No. 5/2021, POTRAZ). A national data protection authority, mandatory breach notification, and a licensing floor for organisations holding sensitive records is not, in itself, an unreasonable ask — it is the same architecture Kenya, Nigeria and South Africa have built over the past decade, and one Zimbabwean banks and hospitals arguably should have had years ago. Starting inspections with the highest-risk data holders, as POTRAZ says it will, is a defensible sequencing choice.
Where it breaks
The trouble is the threshold. Under the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, any organisation processing personal data — names, phone numbers, addresses, employment or health records — for 50 or more people must register and, in most cases, license as a data controller (SI 155 of 2024, POTRAZ; Techzim). Fifty records is not a threshold that isolates data brokers or ad-tech firms — it's a threshold that a rural parish register, a primary school's enrolment list, a burial society's membership roll, or a single active WhatsApp group clears in an afternoon. Legal analyst Dr. Vusumuzi Sibanda put it bluntly to CITE Zimbabwe: forcing churches and community groups into a commercial licensing regime built for data-driven businesses is, in his framing, absurd on its face (CITE Zimbabwe, July 30, 2026).
The penalties compound the mismatch. Processing personal data without a licence can draw a level 11 fine or up to seven years' imprisonment for the responsible officer, with a separate two-year exposure for failing to appoint a certified data protection officer (Veritas Bill Watch 40-2024; Techzim). That is not a proportionate administrative penalty ladder — it is criminal law, aimed by default at a church treasurer or a headteacher who never made a data-driven business decision in their life. Veritas argued in November 2024 that applying licensing and imprisonment to something as mundane as maintaining an email list exceeds what is necessary to prevent data misuse and infringes the freedom of expression and conscience guarantees in Zimbabwe's Constitution — a critique that reads more urgently now that a concrete inspection date exists.
The compliance tax
Licence fees are tiered from $50 for organisations holding data on 50–1,000 people up to $2,500 for the largest controllers, but a small NGO or church also needs a certified data protection officer, a credential that alone runs upward of $1,250 — pushing first-year compliance costs past $1,300 for organisations with no compliance budget to speak of (CITE Zimbabwe; Techzim). Analyst Mxolisi Ncube warned the same costs will simply be passed downstream to consumers through higher service prices — the opposite of what data protection regulation is supposed to deliver.
Civil society flagged this gap well before the inspection notice. MISA Zimbabwe's November 2024 analysis of the licensing regulations recommended the Data Protection Authority "revise the exemption categories to include schools and other charitable organisations," on the grounds that such bodies process personal data as a byproduct of their core mission rather than for commercial gain (MISA Zimbabwe). That recommendation was not adopted — schools and churches are named explicitly among Regulatory Notice 2's first-wave inspection targets.
The independence problem
MISA raises a second concern that matters as much as cost: POTRAZ's board is appointed by the President, and the same body now functions simultaneously as telecoms regulator, Cybersecurity Centre and data protection authority. A licensing gate that can be delayed or denied, MISA warns, creates room for "political influence" over which media houses, NGOs or advocacy groups get to operate lawfully. A discretionary licence-and-imprisonment regime aimed at civil society, sitting inside a regulator with no structural independence from the executive, is precisely the combination that turns a legitimate privacy law into a instrument of selective pressure.
A narrower path
None of this requires scrapping data protection oversight in Zimbabwe. It requires POTRAZ to do what it says it is already doing for banks and hospitals — risk-calibrate — and extend that logic to the threshold itself, not just the inspection order. A substantially higher subject-count floor for non-commercial religious, educational and charitable processing, civil (not criminal) first-offense penalties, and a licensing appeals process insulated from POTRAZ's other regulatory hats would preserve the Act's legitimate core — breach notification, security duties for real risk-holders — without making a criminal defendant out of every pastor with a congregation list.