By Jonathan Mbiriyamveka
Harare — Zimbabwe’s data protection compliance landscape continues to expand, with 831 organisations now formally licensed as Data Controllers under the Cyber and Data Protection Act.
However, authorities have warned that more than 3,000 entities remain non-compliant, setting the stage for stepped-up regulatory enforcement in 2026.

Speaking at the Second Data Controller License Handover Ceremony at the Rainbow Towers, POTRAZ Director General Dr. Gift Machengete said today’s licensing of 255 new Data Controllers reflects a growing appreciation among institutions for lawful and ethical data processing. The ceremony was held alongside the 6th Data Protection Officer (DPO) Certification event.
Dr. Machengete revealed that POTRAZ has received 1,001 licence applications this year alone, a significant increase from previous periods.
He attributed the surge to extensive national outreach programmes that saw POTRAZ engage every sector—from churches, schools and universities, to government departments, security agencies, state enterprises, banks and hospitals.

“Data is the bloodstream of today’s institutions,” he said. “When it is mishandled or exposed, the entire system is placed at risk. Our job is to ensure Zimbabwean citizens’ data is properly protected and processed in accordance with the law.”
As part of its compliance roadmap, POTRAZ has conducted 30 awareness trainings, issued 12 implementation guidelines, undertaken 10 voluntary assessments, 15 ad hoc assessments, and authorised 24 cross-border data transfers.
In addition, more than 985 Data Protection Officers have now been trained through the POTRAZ–HIT programme, positioning Zimbabwe as a regional leader in privacy capacity building.
But with thousands of organisations yet to abide by statutory requirements, the DG warned that 2026 will mark a transition from capacity-building to enforcement.

In Quarter 3 of 2026, POTRAZ will publish a list of non-compliant entities “as a warning shot,” he said. By Quarter 4, full sanctions will be imposed on organisations that fail to comply, in accordance with the Cyber and Data Protection Act.
“POTRAZ will walk with you through the compliance journey,” Dr. Machengete said, “but the road will not be endless. We have given institutions sufficient time to get their houses in order.”
The Minister of ICT, Postal and Courier Services, Hon. Tatenda Mavetera, commended the growing compliance levels and urged organisations to regard data protection as a continuous obligation, not a one-time administrative exercise.
With the clock ticking toward the enforcement phase, institutions across all sectors are now under pressure to secure licences, designate certified DPOs, and implement lawful data governance systems—or risk becoming among the thousands potentially facing penalties in 2026.
