POTRAZ Enlists Whistleblowers, Global Partners in New Data Privacy Crackdown

Regulator unveils 2025 strategy leveraging public tips and international alliances to hunt unlicensed data controllers and breach offenders.

By Jonathan Mbiriyamveka | Harare

In a bold move to strengthen data protection, the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) will now rely on whistleblower reports and cross-border collaborations to identify and penalize organisations flouting the country’s data privacy laws, Director General Dr Gift Gift Machengete announced at the weekend.

The new enforcement roadmap, revealed during a stakeholders’ meeting in Harare, signals POTRAZ’s shift toward globalized enforcement amid rising data breaches and unlicensed handling of citizen data.

“No violator will hide—whether they’re in Harare or operating beyond our borders,” Dr Machengete warned in Compliance and Enforcement presentation.

Whistleblower Channels: POTRAZ will prioritize investigations based on tips from employees or customers exposing illegal data handling.

International Data Sharing: Joint operations with regional and global regulators to track cross-border data transfers lacking proper notifications.

Unlicensed Controller Hunt: Targeted raids on entities operating without Data Controller Licenses, mandatory since 2024.

A 2024 POTRAZ report showed 68% of Zimbabwean businesses lacked compliant data policies, risking fines up to US$10,000 under the Data Protection Act.

The whistleblower policy mirrors strategies in the EU and South Africa, where such initiatives boosted compliance by 40%.

“This is a game-changer,” said Linda Ndlovu, a Harare-based IT lawyer.

“Many companies ignore data laws because enforcement was weak. Now, even insiders can hold them accountable.”

POTRAZ plans public awareness campaigns to educate citizens on reporting violations, with a dedicated portal launching in July 2025.

About Author